Legal

Data Processing Addendum

Last updated July 2026

This Data Processing Addendum (DPA) forms part of the EmailCos Terms of Service between you (the Customer, acting as data controller) and EmailCos (Pty) Ltd (acting as data processor). It is aligned to GDPR (EU/UK) and POPIA (South Africa). A countersigned PDF is available on request at dpa@emailcos.com.

1. Roles and scope

You are the data controller for personal data contained in email you route through EmailCos. EmailCos is the data processor and processes that personal data only on your documented instructions.

2. Subject matter and duration

Subject matter
Analysis, classification, and drafting of email you connect to EmailCos
Duration
For as long as you maintain an active subscription plus 30 days
Nature of processing
Automated, in-memory analysis via LLM inference
Purpose
Provide the EmailCos service and derived features you configure

3. Categories of data and data subjects

  • Identifiers: sender / recipient email addresses, display names.
  • Content: message subject and body, transiently, during analysis.
  • Metadata: sending-domain authentication (SPF, DKIM, DMARC), timestamps.
  • Data subjects: your users, your customers, and any correspondents who email them.

4. Processor obligations

  • Process personal data only on documented instructions from the controller.
  • Ensure personnel with access are bound by confidentiality.
  • Implement the security measures described in /security.
  • Assist the controller with data-subject requests and DPIAs where required.
  • Notify the controller of confirmed personal-data breaches within 72 hours.
  • Delete or return personal data at the end of the service, at controller's choice.

5. Sub-processors

You authorise EmailCos to engage the sub-processors below. Material changes are announced at least 30 days in advance, giving you time to object.

OpenAI
LLM inference, zero-retention endpoints
Supabase
Managed Postgres, auth, object storage
Fly.io
Compute (US / EU / UK / ZA regions)
Lemon Squeezy
Billing (Merchant of Record)

6. International transfers

Where personal data is transferred outside the EEA, the UK, or South Africa, the parties rely on the EU Standard Contractual Clauses (Module 2, controller-to-processor), the UK International Data Transfer Addendum, and, for South Africa, the transfer safeguards under POPIA §72. Business-plan customers may pin processing and storage to a specific region.

7. Security

The technical and organisational measures required by GDPR Article 32 and POPIA §19 are described in full at /security and are incorporated into this DPA by reference.

8. Audits

On written request, and no more than once per 12 months, EmailCos will make available the information necessary to demonstrate compliance with this DPA — including its most recent SOC 2 report when available. On-site audits are conducted on Business plans under mutually agreed scope and notice.

9. Return and deletion

On termination, EmailCos will delete personal data within 30 days, or return it in a portable format on request. Backup copies expire on their normal rotation and are never restored to production.

10. Signing this DPA

Email dpa@emailcos.com with your legal entity name and billing email. We countersign and return a PDF within two business days.

⚡ See plans