Data Processing Addendum

Draft of September 18, 2026

Draft, not yet reviewed by counsel. This describes what the product actually does today, so a lawyer has something concrete to mark up rather than a blank page. Do not rely on it as a signed agreement until that review is done and this notice is gone.

Summary: You decide what happens to your mail. We only process it to run the service for you. We tell you who else touches it, we tell you quickly if something goes wrong, and you can get your data out or have it deleted at any time.

1. Parties and roles

This Addendum is between you ("Customer") and InflowMail LLC ("InflowMail"), and forms part of the Terms of Service. For the personal data in your mailboxes, Customer is the controller and InflowMail is the processor. Where Customer is itself a processor for its own clients, InflowMail is a subprocessor and this Addendum applies the same way.

2. What we process, and why

  • Subject matter: providing the InflowMail service: syncing, sorting, searching, sending and delegating email.
  • Duration: for as long as Customer's account is active, plus the deletion windows in section 8.
  • Categories of data: account details, message metadata (sender, recipients, subject, timestamps, folders, flags), message bodies and attachments within the plan's history window, and connection credentials.
  • Categories of data subjects: Customer's users, their delegates, and anyone who corresponds with them.
  • Special categories: The Service must not be used to process protected health information or other data requiring heightened protection under applicable law. InflowMail offers no business associate agreement and makes no HIPAA representations.

3. Our instructions

We process personal data only on Customer's documented instructions, which include using the service as configured in the app and this Addendum. We do not sell personal data, use it for advertising, or use Customer's mail to train AI models. If we believe an instruction breaks applicable law, we will say so rather than quietly comply.

4. Confidentiality and staff access

Access is limited to people who need it to operate or support the service, and they are bound to confidentiality. Because the service classifies mail, it decrypts mail to do so. Every decryption, including by our staff, is recorded and shown to the affected user on their security page. We consider that a stronger commitment than a promise not to look.

5. Security measures

  • Encryption in transit, and at rest on encrypted storage.
  • Connected-account credentials encrypted with a key unique to the account.
  • Access scoped per account at the data layer, with automated tests that fail the build if a query is not scoped.
  • Optional two-factor authentication, with trusted-device handling and lockout on repeated failures.
  • A log of helper activity on a mailbox, exportable by the owner as CSV.
  • Monitoring and alerting on the production service, with backups retained for 30 days.
  • InflowMail holds no SOC 2, ISO 27001 or comparable certification, and does not claim one.

6. Subprocessors

Customer authorises the subprocessors listed at /subprocessors, which names each company and what it receives. We will give at least 30 days' notice before adding a subprocessor that handles customer data. If Customer reasonably objects on data-protection grounds within 30 days of that notice, Customer may terminate the affected part of the service and receive a refund of prepaid, unused fees. Each subprocessor is bound to obligations no less protective than these.

7. Helping with data subject requests

The app lets Customer export and delete data directly, which handles most requests without involving us. Where it does not, we will help Customer respond to access, correction, deletion, restriction, objection and portability requests. If a data subject contacts us directly, we will refer them to Customer rather than answer for them.

8. Deletion and return

  • Disconnecting an account deletes the mail we cached for it.
  • Deleting the InflowMail account destroys the credential key and purges the data within 30 days.
  • Encrypted backups roll off within 30 days, so a deleted account can persist in backup until then.
  • Customer's mail remains with Customer's own provider throughout. We are a copy, never the original.

9. Incidents

If we become aware of a breach affecting Customer's personal data, we will notify Customer without undue delay and no later than 72 hours after becoming aware, with what we know, what we are doing, and what Customer may need to do. We will not wait for a complete picture before telling Customer something happened.

10. Audits

On reasonable request, and no more than once a year unless required by a regulator, we will answer a security questionnaire and provide the documentation we have. We are a small company without an audit report to hand over, and we would rather say that plainly than imply otherwise.

Where a regulator or a documented legal obligation requires more, we will support a remote audit once a year, at Customer's cost and subject to confidentiality.

11. International transfers

Data is processed in the United States. Where personal data is transferred from the EEA, the parties adopt Module Two (controller to processor) of the European Commission's Standard Contractual Clauses, incorporated by reference, with Customer as data exporter and InflowMail as data importer. Section 2 of this Addendum serves as Annex I (parties, categories and purpose) and section 5 as Annex II (technical and organisational measures). For transfers from the United Kingdom the parties adopt the UK International Data Transfer Addendum, and for Switzerland the equivalent adaptations.

12. Term, and how to sign

This Addendum applies for as long as we process personal data for Customer. It prevails over the Terms of Service where the two conflict on data protection. Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the Terms of Service. To put a countersigned copy on file, ask through the support form and say which entity should be named.

Was this page helpful?