Inovamail Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") applies when your organization uses Inovamail and we process personal data on your behalf — you are the controller, we are the processor. Because Inovamail is end-to-end encrypted, we cannot read your encrypted message content; our processing centres on account, Member, and service metadata. This summary is for convenience and does not replace the full text below.
1. Introduction & Incorporation
1.1 This DPA forms part of, and is incorporated by reference into, the Terms of Service (the "Terms") between the customer identified in the applicable Account or order (the "Customer", including where the Customer uses the Service's organization features as an "Organization") and [LEGAL ENTITY NAME], operating as "Inovamail" ("Inovamail", "we", "us"). Capitalized terms not defined in this DPA have the meanings given in the Terms.
1.2 This DPA applies where and to the extent that Inovamail Processes Personal Data on the Customer's behalf in the course of providing the Service, as further described in Section 3 and Annex I.
1.3 Acceptance. The Customer accepts and enters into this DPA (a) by creating or using an Organization, adding Members, or otherwise using the Service in a manner that causes Inovamail to Process Personal Data on the Customer's behalf; or (b) by executing this DPA where a signed copy is requested from [LEGAL EMAIL]. The individual accepting on behalf of the Customer represents that they have authority to bind the Customer.
1.4 This DPA is entered into for the benefit of the Customer and, where required by Applicable Data Protection Law, the Customer's data subjects to the extent of their statutory third-party rights. It does not otherwise confer rights on any third party.
1.5 Personal data that Inovamail Processes for its own purposes as an independent controller — such as Account registration, billing, security, and service-usage data — is governed by the Privacy Policy, not this DPA.
2. Definitions
2.1 In this DPA:
- "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, as applicable: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 (the "UK GDPR") and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, and other applicable Canadian federal or provincial privacy laws; and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, together with its regulations (the "CCPA"), and comparable US state privacy laws.
- "Controller" means the entity that determines the purposes and means of the Processing of Personal Data (including a "business" under the CCPA and an equivalent term under other Applicable Data Protection Law).
- "Processor" means the entity that Processes Personal Data on behalf of the Controller (including a "service provider" under the CCPA).
- "Sub-processor" means any third-party processor engaged by Inovamail to Process Customer Personal Data on the Customer's behalf.
- "Personal Data" means any information relating to an identified or identifiable natural person, or that otherwise constitutes "personal data", "personal information", or an equivalent term under Applicable Data Protection Law; and "Customer Personal Data" means Personal Data that Inovamail Processes on the Customer's behalf under this DPA, as described in Annex I.
- "Processing" (and "Process") means any operation performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates (including a "consumer" under the CCPA).
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise Processed by Inovamail or its Sub-processors.
- "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under s.119A of the UK Data Protection Act 2018 (version B1.0, in force 21 March 2022), as amended or replaced from time to time.
- "Restricted Transfer" means a transfer of Customer Personal Data to a country or recipient that Applicable Data Protection Law would prohibit absent an approved transfer mechanism (such as an adequacy decision, the SCCs, or the UK Addendum).
- "Service Provider", "Business", "Sell", and "Share" have the meanings given to "service provider", "business", "sell", and "share" in the CCPA.
- "Member" means an individual end user (for example, an employee or contractor of the Customer) whose account, addresses, or settings the Customer administers within its Organization.
- "E2E Content" means message content, attachments, and account keys protected by the Service's end-to-end and zero-knowledge encryption, which Inovamail is technically unable to decrypt or read.
2.2 Where Applicable Data Protection Law uses a different term for a concept defined above (for example, "organization" and "personal information" under PIPEDA, or "person responsible" under Quebec Law 25), the defined terms in this DPA shall be read to include the corresponding concept.
3. Roles & Scope of Processing
3.1 Roles. As between the parties, the Customer is the Controller (or, under the CCPA, the Business) of Customer Personal Data, and Inovamail is the Processor (or, under the CCPA, a Service Provider) Processing Customer Personal Data on the Customer's behalf and on its documented instructions.
3.2 Customer as processor. If the Customer is itself a processor acting on behalf of a third-party controller, Inovamail Processes Customer Personal Data as the Customer's sub-processor. In that case the Customer warrants that its instructions and its appointment of Inovamail, including under this DPA, have been authorised by the relevant controller, and the Customer remains Inovamail's sole point of contact.
End-to-end encryption limits what we can process. E2E Content is encrypted on the Data Subject's device with keys Inovamail does not hold in usable form. Inovamail cannot read, search, disclose, or recover E2E Content, and cannot recover data protected by a lost passphrase or private key. Inovamail's Processing under this DPA therefore centres on data it can technically access: Member account and administration data, message metadata and routing data, configuration and settings data, and other Customer Personal Data described in Annex I.
3.3 Scope. The subject matter, duration, nature and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I. Inovamail will Process Customer Personal Data only for the purposes described there and in the Customer's documented instructions under Section 4.
3.4 Customer responsibilities. The Customer is responsible for the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was obtained; for establishing a lawful basis for the Processing (including any consent or notice required for Member data, correspondents' data, and any contact data the Customer chooses to process through the Service); for its instructions complying with Applicable Data Protection Law; and for its own compliance obligations as Controller.
Your obligations as Controller. You must ensure you have the right to put Personal Data into the Service and to instruct us to Process it — including notices or consents required for Members you administer and for any third-party contact data you upload, collect, or process using the Service. Inovamail does not verify your lawful basis and is not responsible for your obligations as Controller.
4. Processing on Documented Instructions
4.1 Inovamail will Process Customer Personal Data only on the Customer's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by law to which Inovamail is subject; in that case, Inovamail will inform the Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.2 The parties agree that the Customer's complete and final documented instructions are: (a) the Terms and this DPA (including the Annexes); (b) the Customer's and its Members' configuration and use of the Service and its features (including organization administration, workflows, integrations, and settings); and (c) any additional written instructions agreed by the parties in writing. Additional or changed instructions outside the functionality of the Service require prior written agreement, including on any additional fees.
4.3 Inovamail will inform the Customer without undue delay if, in Inovamail's opinion, an instruction infringes Applicable Data Protection Law. Inovamail may suspend performance of that instruction until the Customer confirms or modifies it, and is not obliged to perform a legal review of the Customer's instructions.
4.4 Inovamail will not Process Customer Personal Data for its own purposes, and will not sell it, rent it, or use it for advertising, profiling, or training purposes. For the avoidance of doubt, Inovamail is technically unable to Process E2E Content for any purpose.
5. Confidentiality
5.1 Inovamail will ensure that persons it authorises to Process Customer Personal Data (including employees and contractors) are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and Process Customer Personal Data only as needed to perform their role in providing the Service.
5.2 Access to Customer Personal Data is limited to personnel who require it for the purposes described in this DPA, on a need-to-know basis, and confidentiality obligations survive the end of the relevant engagement.
6. Security Measures
6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks to Data Subjects, Inovamail will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR (and equivalents under other Applicable Data Protection Law), including the measures described in Annex II.
6.2 These measures include, at minimum: end-to-end and zero-knowledge encryption of E2E Content; encryption of Personal Data in transit and, where applicable, at rest; access controls and authentication for Inovamail systems; and processes for regularly testing, assessing, and evaluating the effectiveness of the measures. Further information about the Service's security practices is available on the Security page.
6.3 Inovamail may update the measures in Annex II from time to time, provided the updates do not materially reduce the overall level of protection of Customer Personal Data during the term of this DPA.
6.4 The Customer is responsible for its own secure use of the Service, including: administering Member access and permissions; enabling and enforcing available security features (such as two-factor authentication, strong passphrases, and security enforcement settings); protecting credentials, recovery codes, and keys under its or its Members' control; and assessing whether the Service's security is appropriate for the Customer's intended Processing. Inovamail cannot recover E2E Content protected by a passphrase or key that the Customer or its Members have lost.
7. Sub-processing
7.1 General authorisation. The Customer grants Inovamail a general written authorisation to engage Sub-processors to Process Customer Personal Data, subject to this Section 7. The Sub-processors currently engaged by Inovamail are listed on the Subprocessors page, which forms Annex III of this DPA and which the Customer confirms it has reviewed and approved as at the date it enters into this DPA.
7.2 Flow-down. Inovamail will impose on each Sub-processor, by written contract, data-protection obligations that are materially no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures, and (where the Sub-processing involves a Restricted Transfer) an approved transfer mechanism under Section 13.
7.3 Notice of changes. Inovamail will give the Customer advance notice of the addition or replacement of a Sub-processor at least thirty (30) days before the new Sub-processor Processes Customer Personal Data, by updating the Subprocessors page and/or by notice through the Service or by email. The Customer is responsible for subscribing to or checking the mechanism offered for such notices.
7.4 Right to object. The Customer may object to a new Sub-processor on reasonable, documented data-protection grounds by writing to [PRIVACY EMAIL] within thirty (30) days of the notice. The parties will discuss the objection in good faith; Inovamail may offer a commercially reasonable alternative (for example, a configuration that avoids the Sub-processor). If no alternative is available within a reasonable period, the Customer may, as its sole and exclusive remedy, terminate the affected part of the Service (or, if it cannot be separated, the Terms as they relate to the affected Organization) on written notice, and Inovamail will refund any prepaid fees for the terminated portion covering the period after the effective date of termination, in accordance with the Terms.
7.5 Liability. Where a Sub-processor fails to fulfil its data-protection obligations with respect to Customer Personal Data, Inovamail remains liable to the Customer for the performance of that Sub-processor's obligations, subject to Section 15.
8. Assistance with Data Subject Rights
8.1 Taking into account the nature of the Processing, Inovamail will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to Data Subject requests to exercise rights under Applicable Data Protection Law (including access, rectification, erasure, restriction, portability, objection, and equivalent rights such as opt-out rights under the CCPA and rights under PIPEDA and Quebec Law 25).
8.2 The Service's self-service features — including organization administration tools, Member account management, and export and deletion functions — are the primary means of this assistance, and the Customer will use them where they are sufficient to respond to a request. Where they are not sufficient, Inovamail will provide reasonable additional assistance on written request, and may charge a reasonable fee for assistance that is manifestly excessive or outside the functionality of the Service, where permitted by Applicable Data Protection Law.
8.3 If a Data Subject makes a request directly to Inovamail regarding Customer Personal Data, Inovamail will, to the extent legally permitted, promptly forward the request to the Customer and will not respond substantively except to direct the Data Subject to the Customer or as required by law. The Customer is responsible for responding to such requests.
8.4 E2E limits. Inovamail cannot access, produce, correct, or selectively extract E2E Content. Assistance with respect to E2E Content is necessarily limited to actions that do not require decryption — for example, deleting encrypted data or an account, or assisting the Customer and its Members to use client-side tools to which they hold the keys.
9. Personal Data Breach Notification
9.1 Inovamail will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be made to the Organization's administrator contact (and/or the Customer's registered email) and may be provided in phases as information becomes available.
9.2 To the extent the information is available to Inovamail, the notification will describe: (a) the nature of the Personal Data Breach, including where possible the categories and approximate numbers of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (d) a contact point for further information.
9.3 Inovamail will provide reasonable cooperation and information to help the Customer meet its own breach obligations under Applicable Data Protection Law, including notification to supervisory authorities and Data Subjects under Articles 33 and 34 GDPR / UK GDPR, reporting to the Commission d'accès à l'information under Quebec Law 25, and reporting and record-keeping for breaches of security safeguards under PIPEDA. As between the parties, the Customer is responsible for deciding whether and how to notify authorities and Data Subjects, and for making those notifications.
9.4 Inovamail's notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability. The Customer will not make public statements attributing a breach to Inovamail without a reasonable factual basis. Note that, by design, E2E Content remains encrypted even if underlying storage is compromised; the availability of that protection does not by itself mean an incident is not a Personal Data Breach for metadata or other accessible data.
10. Impact Assessments & Prior Consultation
10.1 Taking into account the nature of the Processing and the information available to Inovamail, Inovamail will provide reasonable assistance to the Customer with data protection impact assessments and with prior consultation of supervisory authorities, where required of the Customer under Articles 35 and 36 GDPR / UK GDPR or equivalent provisions of other Applicable Data Protection Law (including privacy impact assessments under Quebec Law 25), in each case solely in relation to the Processing of Customer Personal Data by Inovamail under this DPA.
10.2 Inovamail may satisfy this obligation in whole or in part by providing existing documentation, including Annex II, the Security page, and the Privacy Policy. Assistance that is manifestly excessive may be subject to a reasonable fee where permitted by Applicable Data Protection Law.
11. Return or Deletion of Personal Data
11.1 During the term, the Customer and its Members may retrieve and delete Customer Personal Data using the Service's export, administration, and deletion features.
11.2 Upon termination or expiry of the Service, Inovamail will, at the Customer's choice, delete or return the Customer Personal Data then held by Inovamail and delete existing copies, unless and to the extent that storage is required by law to which Inovamail is subject, in which case Inovamail will protect the retained data under this DPA, isolate it from further Processing, and delete it when the legal requirement ends. If the Customer does not exercise a choice within thirty (30) days of termination, Inovamail may proceed with deletion.
11.3 "Return" of E2E Content is limited to providing the encrypted data or export functions to the account holders who hold the keys; Inovamail cannot decrypt E2E Content for return, and deletion of the corresponding keys or ciphertext renders E2E Content permanently irrecoverable.
11.4 Deletion from active systems will occur promptly, and residual copies in encrypted backups will be deleted or overwritten as backups expire in the ordinary rotation cycle, and in any event within ninety (90) days of the deletion from active systems, during which period the backup copies remain protected by this DPA and are not restored to active systems except as needed for disaster recovery.
11.5 On written request made within thirty (30) days of termination, Inovamail will confirm deletion in writing.
12. Audits & Information
12.1 Inovamail will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and in Article 28 GDPR / UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to this Section 12.
12.2 Inovamail will in the first instance satisfy audit requests by providing: (a) this DPA and its Annexes; (b) the Security page and other security documentation; and (c) where available, summaries of third-party audit reports, assessments, or certifications covering the Service. The Customer will rely on such materials and will only request an on-site or remote inspection where the materials are insufficient to demonstrate compliance or where an inspection is required by a supervisory authority or by Applicable Data Protection Law. Inovamail does not represent that any particular third-party report or certification exists unless stated on the Security page.
12.3 Any audit or inspection: (a) requires at least thirty (30) days' prior written notice to [PRIVACY EMAIL], except where a shorter period is mandated by a supervisory authority or follows a confirmed Personal Data Breach; (b) may occur no more than once in any twelve (12) month period, except as required by Applicable Data Protection Law or a supervisory authority; (c) is conducted during normal business hours, with minimal disruption, and at the Customer's cost; (d) is subject to a confidentiality agreement, and the auditor may not be a competitor of Inovamail; and (e) does not extend to data of other customers, to systems or information whose disclosure would compromise the security of the Service or other customers, or to E2E Content, which Inovamail cannot decrypt for any auditor.
12.4 The Customer will provide Inovamail with a copy of audit findings relating to Inovamail, which are Inovamail's confidential information and may be used only to verify and improve compliance with this DPA.
12.5 Nothing in this Section limits any mandatory audit rights of the parties or of supervisory authorities under the SCCs or Applicable Data Protection Law.
13. International Transfers
13.1 Inovamail is a company registered in Canada. The Customer instructs Inovamail to Process Customer Personal Data in Canada and in the other locations shown on the Subprocessors page as necessary to provide the Service. For transfers from the European Economic Area, the parties note the European Commission's adequacy decision for Canada (commercial organisations subject to PIPEDA) to the extent it applies; the transfer mechanisms below apply to any Restricted Transfer not covered by an applicable adequacy decision.
13.2 EU SCCs. For Restricted Transfers subject to the GDPR, the SCCs are incorporated into this DPA by reference and are entered into between the Customer (as data exporter) and Inovamail (as data importer), completed as follows: Module Two (controller to processor) applies (or Module Three where Section 3.2 applies); in Clause 7, the optional docking clause applies; in Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 7.3 of this DPA; in Clause 11, the optional language does not apply; in Clause 17, Option 1 applies and the SCCs are governed by the law of [SCC GOVERNING LAW MEMBER STATE]; in Clause 18(b), disputes shall be resolved before the courts of [SCC GOVERNING LAW MEMBER STATE]; Annexes I, II, and III of the SCCs are completed with the information in Annexes I, II, and III of this DPA; and the competent supervisory authority is [COMPETENT SUPERVISORY AUTHORITY].
13.3 UK transfers. For Restricted Transfers subject to the UK GDPR, the SCCs as completed in Section 13.2 apply as amended by the UK Addendum, which is incorporated by reference. Table 1 of the UK Addendum is completed with the party details in Annex I; Table 2 with the SCCs as completed above; Table 3 with Annexes I–III of this DPA; and for Table 4, either party may end the UK Addendum as set out in Section 19 of the UK Addendum.
13.4 Swiss transfers. For Restricted Transfers subject to the FADP, the SCCs as completed in Section 13.2 apply with the adaptations commonly required by the Swiss Federal Data Protection and Information Commissioner (FDPIC), including that references to the GDPR are read as references to the FADP, the FDPIC is the competent supervisory authority, and Data Subjects in Switzerland may exercise and enforce their rights in Switzerland.
13.5 If the SCCs, the UK Addendum, or another mechanism relied on under this Section is amended, replaced, or invalidated, the parties will cooperate in good faith to implement a valid successor mechanism promptly, and Inovamail may update this Section by notice to reflect the successor mechanism.
13.6 Inovamail will not participate in any government or third-party access to Customer Personal Data except as required by valid legal process, and will handle such demands in accordance with its Law Enforcement Guidelines, including, where legally permitted, notifying the Customer and challenging overbroad demands. Inovamail is technically unable to disclose E2E Content in intelligible form.
14. CCPA/CPRA Service-Provider Terms
14.1 This Section applies to the extent Customer Personal Data includes "personal information" subject to the CCPA. For such personal information, the Customer is a Business (or, as applicable, a service provider to a Business) and discloses it to Inovamail solely for the limited and specified business purposes described in Annex I and the Terms: providing and securing the Service and as otherwise permitted for service providers under the CCPA.
14.2 Inovamail, as a Service Provider, will not: (a) Sell or Share the personal information; (b) retain, use, or disclose the personal information for any purpose other than the business purposes specified in this DPA and the Terms, including for any commercial purpose of its own, or outside the direct business relationship between the parties, except as permitted by the CCPA; or (c) combine the personal information with personal information it receives from or on behalf of other persons, or collects from its own interactions with the Data Subject, except as permitted by the CCPA for service providers.
14.3 Inovamail certifies that it understands the restrictions in Section 14.2 and will comply with them. Inovamail will notify the Customer without undue delay if it determines it can no longer meet its obligations under the CCPA, and the Customer may, upon such notice, take reasonable and appropriate steps in accordance with the CCPA to stop and remediate any unauthorised use of the personal information.
14.4 Inovamail will provide the same level of privacy protection to the personal information as is required of the Customer under the CCPA, will cooperate with the Customer in responding to and complying with consumer requests made under the CCPA, and grants the Customer the right to take the reasonable and appropriate steps contemplated by the CCPA to ensure that Inovamail uses the personal information in a manner consistent with the Customer's CCPA obligations, using the mechanisms in Section 12.
14.5 The parties acknowledge that Inovamail's Processing under this DPA is not a Sale or Share, and that no money or other valuable consideration is exchanged for personal information. This Section applies mutatis mutandis where the Customer is subject to comparable US state privacy laws that recognise a processor or service-provider role.
15. Liability
Liability under this DPA is limited. Each party's and its affiliates' total, aggregate liability arising out of or related to this DPA — together with all liability under the Terms — is subject to the exclusions and the cap on liability set out in the Terms of Service, and the cap applies once across the Terms and this DPA combined, not separately to each.
15.1 Each party's liability arising out of or in connection with this DPA (including the SCCs and the UK Addendum, to the maximum extent permitted under them), whether in contract, tort, or any other theory, is subject to the limitations and exclusions of liability in the Terms, except where and to the extent Applicable Data Protection Law or the SCCs prohibit such limitation — including a party's liability to Data Subjects under the third-party beneficiary provisions of the SCCs, and any liability that cannot be limited under applicable law.
15.2 Any claims against Inovamail under or in connection with this DPA may be brought only by the Customer entity that is party to the Terms, and this DPA does not create rights for the Customer's affiliates or Members to bring claims directly against Inovamail except where Applicable Data Protection Law provides otherwise.
15.3 Nothing in this Section affects either party's liability to Data Subjects or supervisory authorities under Applicable Data Protection Law, or the allocation of responsibility between controller and processor under Article 82 GDPR / UK GDPR.
16. Order of Precedence & General
16.1 Precedence. In case of conflict: (a) with respect to Restricted Transfers, the SCCs (and, for UK transfers, the UK Addendum) prevail over this DPA and the Terms; (b) otherwise, with respect to the parties' data-protection obligations for Customer Personal Data, this DPA prevails over the Terms and any other agreement between the parties; and (c) in all other respects the Terms apply.
16.2 Term. This DPA takes effect when the Customer accepts it under Section 1.3 and remains in force as long as Inovamail Processes Customer Personal Data on the Customer's behalf, and thereafter to the extent of obligations that by their nature survive (including Sections 5, 11, 12, 15, and 16).
16.3 Changes. Inovamail may update this DPA from time to time to reflect changes in Applicable Data Protection Law, approved transfer mechanisms, regulatory guidance, or the Service, provided the update does not materially reduce the protection of Customer Personal Data. Updates take effect as described in the Terms; material updates will be notified in advance through the Service or by email.
16.4 Governing law. This DPA is governed by the law governing the Terms — the law of [PROVINCE], Canada — except where the SCCs, the UK Addendum, or mandatory Applicable Data Protection Law require otherwise (including the governing law of the SCCs stated in Section 13.2).
16.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the invalid provision will be replaced by a valid one that most closely achieves its intent.
16.6 No fees. Except as expressly stated (Sections 8.2 and 10.2), each party bears its own costs of complying with this DPA.
16.7 Contact. Questions and notices under this DPA may be sent to [PRIVACY EMAIL] (privacy) or [LEGAL EMAIL] (legal). Inovamail's privacy officer / data protection contact is [DPO NAME/CONTACT]. Where required: EU representative — [EU REPRESENTATIVE]; UK representative — [UK REPRESENTATIVE].
17. Annexes
Annex I — Details of Processing (and Annex I to the SCCs)
A. List of parties
| Data exporter (Customer) | Data importer (Inovamail) | |
|---|---|---|
| Name | [CUSTOMER LEGAL NAME] | [LEGAL ENTITY NAME] (operating as Inovamail) |
| Address | [CUSTOMER REGISTERED ADDRESS] | [REGISTERED ADDRESS], Canada |
| Contact | [CUSTOMER CONTACT] | [DPO NAME/CONTACT], [PRIVACY EMAIL] |
| Role | Controller (or processor per Section 3.2) | Processor |
| Signature & date | Deemed executed on acceptance per Section 1.3 | Deemed executed on acceptance per Section 1.3 |
B. Description of the processing / transfer
| Item | Description |
|---|---|
| Categories of data subjects | Members (employees, contractors, and other individuals whose accounts the Customer administers); the Customer's authorised administrators; individuals who correspond with the Customer or its Members by email; contacts and other individuals whose Personal Data the Customer or its Members choose to process through the Service (including via workflows, integrations, or outreach features); other categories identified by the Customer: [CUSTOMER CONTACT] to specify if applicable. |
| Categories of personal data | Member account and identity data (name, email addresses, aliases, role, settings); organization administration and configuration data; message metadata and routing data (sender/recipient addresses, timestamps, subject lines where not end-to-end encrypted, delivery and quarantine events); contact data processed by the Customer through the Service; workflow, integration, and log data associated with Members; support communications. E2E Content is stored only in encrypted form that Inovamail cannot read. |
| Special categories of data | None intended or required by the Service. The Customer and its Members and correspondents may incidentally include special categories of data in email content; such content, where end-to-end encrypted, is inaccessible to Inovamail. The Customer is responsible for applying restrictions and safeguards appropriate to any special categories it chooses to process. |
| Frequency of the transfer / processing | Continuous, for the duration of the Service. |
| Nature of the processing | Hosting and storage (encrypted); transmission, routing, and delivery of email; account and organization administration; execution of Customer-configured workflows and integrations; security operations (including anti-abuse, quarantine, and Fortress-mode features as configured); backup and restoration; support; deletion. |
| Purpose of the processing | Providing, securing, maintaining, and supporting the Service for the Customer under the Terms and this DPA; no other purpose. |
| Duration / retention | For the term of the Service, plus the deletion periods in Section 11 and any legally required retention. |
| Transfers to sub-processors | As set out in Annex III; nature and duration of sub-processing as described on the Subprocessors page. |
C. Competent supervisory authority
The competent supervisory authority for the purposes of the SCCs is [COMPETENT SUPERVISORY AUTHORITY], determined in accordance with Clause 13 of the SCCs. For UK transfers, the UK Information Commissioner's Office; for Swiss transfers, the FDPIC.
Annex II — Technical & Organisational Security Measures (and Annex II to the SCCs)
Inovamail implements and maintains, and requires its Sub-processors to maintain, measures of at least the following kinds, appropriate to the risk of the Processing. This Annex describes categories of commitment; current implementation details are summarised on the Security page.
| Domain | Measures |
|---|---|
| Encryption | End-to-end and zero-knowledge encryption of E2E Content and account keys, such that Inovamail cannot decrypt them; encryption of Personal Data in transit (including transport-layer encryption for mail and web traffic, with configurable enforcement against plaintext fallback); encryption of Personal Data at rest where applicable; encrypted backups of account keys under the Data Subject's control. |
| Access control | Authentication and authorisation controls for Inovamail systems; least-privilege, role-based, need-to-know access to production systems and Customer Personal Data; two-factor authentication support for user accounts; access reviews and revocation on role change or departure. |
| Pseudonymisation & minimisation | Pseudonymisation and aggregation where applicable; data minimisation by design, including the availability of email aliases and the zero-knowledge architecture that keeps content out of Inovamail's reach. |
| Logging & monitoring | Logging of security-relevant events on Inovamail systems; monitoring for unauthorised access and abuse; protection of logs against tampering; defined log-retention practices. |
| Backup & resilience | Regular backups; redundancy and measures to restore availability and access to Personal Data in a timely manner after a physical or technical incident; capacity and continuity planning. |
| Personnel security | Confidentiality obligations for personnel (Section 5); security and privacy training appropriate to role; disciplinary processes for policy violations. |
| Vendor management | Due diligence on Sub-processors before engagement; written flow-down contracts per Section 7.2; periodic review of Sub-processor compliance. |
| Incident response | Documented incident-response process for detecting, assessing, containing, and remediating security incidents; breach notification per Section 9; post-incident review. |
| Testing & evaluation | Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures, including a coordinated vulnerability-disclosure channel described on the Security page. |
| Assistance measures (SCC Annex II) | The self-service, export, deletion, and administration tools and the assistance commitments in Sections 8–10 constitute the technical and organisational measures by which the data importer provides assistance to the data exporter. |
Annex III — Approved Sub-processors (and Annex III to the SCCs)
The authorised Sub-processors are those listed on the live Subprocessors page, which is incorporated into this DPA as Annex III and is updated in accordance with Section 7.3. As of the effective date of the Customer's acceptance, the approved Sub-processors are:
| Sub-processor | Purpose of sub-processing | Location | Transfer safeguard |
|---|---|---|---|
| [SUBPROCESSOR NAME] | [SUBPROCESSOR PURPOSE] | [SUBPROCESSOR LOCATION] | [TRANSFER SAFEGUARD] |
| [SUBPROCESSOR NAME] | [SUBPROCESSOR PURPOSE] | [SUBPROCESSOR LOCATION] | [TRANSFER SAFEGUARD] |
In case of any discrepancy between the table above and the live Subprocessors page, the live page (as most recently notified under Section 7.3) controls.