1. Scope and roles
This DPA applies to the processing of personal data subject to the EU General Data Protection Regulation, the UK GDPR, or other data protection law where equivalent terms are required.
- You are the controller of the personal data contained in mail received at your email addresses and of the personal data of your own users.
- Mailcycle is the processor of that data.
- Mailcycle is a controller of your account and billing data, which is governed by the Privacy Policy, not by this DPA.
Terms not defined here have the meaning given in the GDPR.
2. Processing instructions
We process personal data only on your documented instructions. Your use of the Service, and the configuration you choose within it, constitute those instructions. Additional instructions must be agreed in writing and may be chargeable if they require work outside the Service.
We will tell you if, in our opinion, an instruction infringes applicable data protection law, and may suspend that instruction until it is resolved.
Where we are required by law to process beyond your instructions, we will inform you first unless that law prohibits it.
3. Confidentiality
Personnel authorised to process personal data are bound by contractual confidentiality obligations that survive the end of their engagement, and receive data protection and security training. Access is granted on a need-to-know basis and is reviewed.
4. Security measures
We implement and maintain appropriate technical and organisational measures under Article 32, described in Annex B. We may update them provided the level of protection is not reduced.
5. Subprocessors
You give general authorisation for us to engage subprocessors. Our current list is published at mailcycle.email/legal/subprocessors.
- Each subprocessor is bound by written terms imposing obligations no less protective than this DPA.
- We give at least 30 days' notice before adding or replacing a subprocessor. Subscribe to notifications on the subprocessor page.
- You may object on reasonable data protection grounds within that period. We will work with you on an alternative; if none is workable, you may terminate the affected Service without penalty and receive a pro rata refund of prepaid fees.
- We remain fully liable for our subprocessors' performance.
6. Data subject rights
The Service gives you the tools to access, export, correct and delete personal data in the mail your addresses receive yourself. Where a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will redirect them to you and tell you promptly.
Where you cannot fulfil a request using the Service, we will provide reasonable assistance taking account of the nature of the processing.
7. Breach notification
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not available at once, we will provide it in phases without undue further delay.
8. International transfers
Where processing involves a transfer of personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this DPA by reference and completed as follows:
- Clause 7 (docking clause) applies.
- Clause 9: Option 2, general written authorisation, with 30 days' notice as set out in section 5.
- Clause 11: the optional independent dispute resolution body does not apply.
- Clause 17: governed by the law of [Member State].
- Clause 18(b): the courts of [Member State].
- Annex I, II and III are populated by Annex A, Annex B and the subprocessor list respectively.
For UK transfers, the ICO's International Data Transfer Addendum is incorporated and applies to the Clauses above. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the FDPIC is the competent authority.
9. Audits
We will make available the information necessary to demonstrate compliance with Article 28, including our current security documentation and completed questionnaires.
You may audit no more than once in any 12-month period, on 30 days' written notice, during business hours, subject to confidentiality, at your cost, and without accessing other customers' data or systems that would compromise their security. Additional audits may be conducted where required by a supervisory authority or following a confirmed breach.
10. Return and deletion
You can export mail at any time in the app. Deleting the account removes personal data processed on your behalf from the live database immediately, with no export window afterwards, so export first. Copies in our database provider's point-in-time restore history are gone within 30 days. The same applies where we delete an account under the Terms. Certification of deletion is available on request.
11. Liability
Each party's liability under this DPA is subject to the limitations in section 14 of the Terms of Service, except where those limitations are prohibited by applicable data protection law.
Annex A: Processing details
| Subject matter | Provision of hosted email infrastructure |
| Duration | The term of the Terms of Service, plus the retention periods in section 10 |
| Nature and purpose | Receiving, storing and relaying email; sending email on your instruction; managing devices and email addresses |
| Categories of data subject | Your personnel and end users; senders of mail to your email addresses; recipients of mail you send |
| Categories of personal data | Email addresses; message content, subjects, headers and attachments; device identifiers, names reported during pairing and other device metadata; IP addresses in transient connection data, sampled service logs and hashed rate limit counters; timestamps |
| Special category data | Not requested or required. Mail content is unstructured and may incidentally contain it; you should not use the Service where special category data is central to the processing without agreeing additional measures with us. |
| Frequency | Continuous |
| Subprocessors | As listed at /legal/subprocessors |
| Competent supervisory authority | Information Commissioner's Office (United Kingdom) |
Annex B: Security measures
- Encryption in transit: TLS for the API and apps; STARTTLS on inbound SMTP where the sender supports it.
- Encryption of Customer Data: inbound mail and attachments are parsed in memory and sealed to a per-address X25519 public key before anything is stored. Messages over 25 MB are refused and attachments over 20 MB are not stored. Mail the Customer sends passes through in plain text and is not stored. Address labels and device metadata are encrypted on the Customer's device with ChaCha20 and HMAC-SHA-256. The private keys are derived from the Customer's recovery phrase. The Processor holds no copy of them and cannot decrypt Customer Data, including in response to a request from the Customer.
- Encryption at rest: all stored data is also encrypted by the hosting provider.
- Authentication: no passwords exist in the system. Accounts authenticate by answering a single-use challenge with a key derived from the recovery phrase, of which the Processor stores only the public half. Device credentials are scoped per device, minted only on explicit Operator confirmation, and independently revocable.
- Access control: a single administrator, using a separate console that opens only with its own key. Every administrative action is recorded in a tamper-evident audit log. The administrator can suspend, throttle, cap retention, change plans, record credits and refunds, resolve abuse reports and delete accounts. There is no means of accessing message content.
- Segregation: every device- and address-scoped operation is authorised against the owning account; identifiers alone confer no access.
- Resilience: point-in-time database restore for up to 30 days. Message bodies and attachments in object storage are not backed up.
- Rate limiting: burst limits at the network edge, and hourly and monthly quotas per account and per IP address, with keys stored only as hashes.
- Content handling: inbound MIME is parsed in memory on the server and sealed before storage; HTML is sanitised and trackers stripped on the Customer's device when a message is opened; remote content is never loaded; attachments are downloaded only through the authenticated API.
- Vulnerability management: a published vulnerability disclosure policy.
How to execute
For most customers no signature is needed: this DPA applies automatically as part of the Terms of Service. If your procurement process requires a countersigned copy, or you need us to review your own DPA template, email hello@mailcycle.email and we will turn it around.