✉ Inovamail
← Legal Center

Inovamail Legal

Subprocessors

Effective: [EFFECTIVE DATE] · Last updated: [LAST UPDATED DATE] · Version [VERSION]

This page lists the third-party service providers ("subprocessors") that Inovamail engages to help deliver the Service, together with the categories of data they process. Because Inovamail is designed as a zero-knowledge, end-to-end encrypted service, no subprocessor can read the content of your end-to-end encrypted messages. This summary is for convenience and does not replace the full text below.

Contents

  1. 1. What a subprocessor is & purpose of this page
  2. 2. General authorization
  3. 3. Current subprocessors
  4. 4. How we vet subprocessors
  5. 5. Notice of changes & right to object
  6. 6. Contact

1. What a subprocessor is & purpose of this page

A subprocessor is a third party that Inovamail engages to process personal data on our behalf in order to provide the Inovamail service (the "Service"). Subprocessors act on our documented instructions and are permitted to process personal data only as needed to perform the specific services we retain them for.

This page identifies the categories of subprocessors we use, the service each provides, and the categories of data each processes. We publish it for transparency and to support the commitments we make in our Data Processing Agreement ("DPA") and our Privacy Policy.

In this page, "you" and "Customer" mean the individual or Organization that has entered into an agreement with Inovamail for the Service. Capitalized terms not defined here have the meaning given in our Terms of Service, DPA, or Privacy Policy.

Inovamail's zero-knowledge architecture means the content of end-to-end ("E2E") encrypted messages and the account encryption keys that protect them are encrypted before they reach our systems or any subprocessor. Neither Inovamail nor any subprocessor can read that content or recover those keys.

2. General authorization

Where Inovamail processes personal data on your behalf as a processor or service provider, you provide a general authorization for Inovamail to engage the subprocessors listed in Section 3, and any subprocessors we add through the change process in Section 5, subject to the terms of the DPA.

For each subprocessor we engage, we impose data-protection obligations that are, in substance, no less protective than those in the DPA, including appropriate confidentiality, security, and data-processing terms. Inovamail remains responsible to you for the performance of each subprocessor's data-protection obligations to the extent required by applicable law and the DPA.

This page supplements, and does not replace, the DPA. If there is any conflict between this page and the DPA regarding subprocessing, the DPA controls.

3. Current subprocessors

The table below lists the categories of subprocessors that support the Service. The bracketed, highlighted fields are placeholders to be completed by Inovamail with the actual provider names and processing regions before publication.

Subprocessor Service provided Data processed Location / region
[SUBPROCESSOR NAME] Cloud hosting & infrastructure (compute, storage, networking, and backups on which the Service runs; stores E2E-encrypted content as ciphertext only) Account identifiers, encrypted mailbox and file data (as ciphertext), IP addresses and connection metadata, service logs [SUBPROCESSOR LOCATION]
[SUBPROCESSOR NAME] Payment processing & subscription billing Billing contact details, plan and transaction records, partial payment-instrument data as handled by the processor (Inovamail does not store full card numbers) [SUBPROCESSOR LOCATION]
[SUBPROCESSOR NAME] Transactional email & notifications (account, security, and system messages such as verification, password-reset, and billing notices) Email address, message metadata, and the contents of the transactional notification being sent [SUBPROCESSOR LOCATION]
[SUBPROCESSOR NAME] Customer support & ticketing Contact details and any information you choose to include in a support request or correspondence [SUBPROCESSOR LOCATION]
[SUBPROCESSOR NAME] Product analytics (aggregate and event usage measurement to operate and improve the Service) Pseudonymous usage events, device and browser attributes, IP-derived approximate location [SUBPROCESSOR LOCATION]
[SUBPROCESSOR NAME] Error & performance monitoring (diagnostics and crash reporting) Diagnostic and crash data, technical logs, device/environment attributes, IP address [SUBPROCESSOR LOCATION]

Not every subprocessor processes data for every Customer or every plan; the subprocessors that apply to you depend on the features you use. Some functions above may be provided in-house rather than by a third party, in which case no subprocessor is listed. We may also rely on providers of ancillary services (such as domain, DNS, or content-delivery services) that support the Service.

4. How we vet subprocessors

Before engaging a subprocessor, and on an ongoing basis where appropriate, we take steps designed to ensure the subprocessor can meet our security and data-protection commitments. Depending on the nature of the processing, these steps may include:

  • Security & privacy review of the provider's technical and organizational measures, certifications, and track record;
  • Data-processing terms requiring the provider to process personal data only on our instructions, maintain confidentiality, implement appropriate security measures, and assist with data-subject requests and incident notification;
  • Data-minimization, so that a provider receives only the categories of data reasonably necessary for its service;
  • Cross-border transfer safeguards, such as standard contractual clauses or other lawful transfer mechanisms where a provider processes data outside your region; and
  • Ongoing oversight, including periodic re-assessment and the right to audit or obtain audit reports as provided in the DPA.

We maintain administrative, technical, and physical safeguards appropriate to the risk. We do not, however, warrant that any third party's systems are free from all vulnerabilities; our related liability is limited as set out in the Terms of Service and DPA.

5. Notice of changes & right to object

We may add, remove, or replace subprocessors as the Service evolves. When we intend to make a material change to the subprocessors that process personal data on your behalf, we will update this page and provide notice as described below.

Subscribing to updates

You can stay informed of changes by monitoring this page and, where offered, by subscribing to subprocessor-change notifications. To subscribe, or to request notice of changes by email, contact us at [PRIVACY EMAIL].

Right to object

Where you are a Customer for whom Inovamail acts as a processor or service provider, and the DPA gives you a right to object, you may object to a new subprocessor on reasonable, good-faith data-protection grounds within the period stated in the DPA (or, if none is stated, within thirty (30) days of our notice). If you object, we will work with you in good faith to address your concern. If we cannot reasonably do so, your sole and exclusive remedy is to terminate the affected part of the Service in accordance with the DPA and Terms of Service. Absent a timely objection, the change is deemed approved.

6. Contact

Questions about this page, our subprocessors, or subprocessor-change notifications may be sent to:

Inovamail — Privacy
Email: [PRIVACY EMAIL]
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]

For more on how we handle personal data, see our Privacy Policy and Data Processing Agreement.

Inovamail is operated by [LEGAL ENTITY NAME], a company registered in Canada (Business No. [BUSINESS NUMBER]), [REGISTERED ADDRESS].

Terms of Service Privacy Policy Acceptable Use Anti-Spam Cookies DPA Subprocessors Refunds Copyright/DMCA Law Enforcement SLA Security

© [EFFECTIVE DATE] [LEGAL ENTITY NAME]. Inovamail and the Inovamail logo are trademarks of their owner. Contact: [SUPPORT EMAIL].