Blog · Security

EU-hosted email for AI agents: a GDPR checklist

An AI agent with an inbox handles other people’s personal data from its first email. These are the questions a privacy review will ask, with our answers and the code to erase one person on request.

Published
By
Agentboxd team
Reading time
8 min

An AI agent with an inbox handles personal data from the first email it receives. The sender’s name and address, whatever they wrote, the attachments, the signature with a phone number: all of it lands in a system you are responsible for. If you or the people writing to your agent are in the EU, the GDPR applies to that mail the same way it applies to a support inbox run by people.

This checklist goes through the questions a privacy review will ask about agent email, with what Agentboxd does for each, so you can check our answers against your own needs. It is a practical guide, not legal advice: your own situation, and your own lawyer, decide what you need.

TL;DR: know who the controller is (you), sign a DPA, know where the mail is stored and which third parties read it, keep mail only as long as you need it, and be able to find and delete everything about one person on request.

#Who is responsible for what

For mail your agents receive and send, you are the controller: you decide why the agent has an inbox and what it does with the mail. Agentboxd is your processor: we store and process the mail on your instructions. Your instructions are your settings (retention, AI processing) and the API calls you make.

The people who write to your agent are the data subjects. They didn’t sign up for anything. That is why the rest of this list matters: they rely on you, and you rely on your processor.

#The checklist

QuestionWhat to checkWith Agentboxd
Is there a signed DPA?GDPR Article 28 needs a contract with every processor.A DPA template you can read now; we complete it with your details and both sign it.
Where is the mail stored?The country of the servers and of the backups.Production on a dedicated server at Contabo in France, off-site backups on a second Contabo server in the EU.
Which third parties see the mail?Every sub-processor, what it sees and when.Three, listed with exactly what each sees on our sub-processor page.
Does any mail leave the EU?Transfers to third countries and their safeguards.Only if you turn on AI processing. With it set to Off, no email content leaves our server in France.
How long is mail kept?A retention period you can justify.30 days on Free, 1 year on Builder, 2 years on Team, or a shorter period you choose.
Can you erase one person?Article 17 requests.Find their threads by address, delete them, delete the contact. Code below.
Can you give one person their data?Article 15 requests.The same search, then export the threads through the API.
What happens after a breach?The processor must tell you in time for your 72 hours.We notify you within 48 hours at most.
Will you hear about new sub-processors?Notice and a chance to object.30 days’ notice, by email if you subscribe on the sub-processor page.
What happens when you leave?Deletion or return of the data.Deleted from live systems within 30 days of the end of the return period; backups age out within 14 days after that.

The rest of this article goes through the parts that need more than a line.

#Where the mail lives

Everything Agentboxd stores runs on a dedicated server at Contabo in France. That covers mail, attachments, contacts, knowledge documents and account data. Nightly backups go to a second Contabo server in the EU, encrypted before they leave the production server. Backups are kept for 14 days.

Hosting in the EU isn’t an option you have to ask for or pay extra for. It is where the service runs, on every plan.

Our site has no analytics or tracking scripts, and the mail we send for you carries no tracking pixel and no rewritten links.

#AI processing: the one setting that decides transfers

Reading mail with a model is where agent email differs most from a normal mailbox. Each workspace has one setting, AI processing, that decides exactly what leaves our server:

  • Off. No email content leaves the Agentboxd server. Login codes and magic links are still found by pattern matching on our own server. You get no categories, no injection or phishing scores, and no reply drafts.
  • Categorize (the default). For each inbound message, our classification partner TypeSafe AI (JEV), in the United States, gets the sender, the subject, the first 3,000 characters of the new text, our SPF, DKIM and DMARC results, attachment names and types, and up to 2,000 characters of text from attachments (the full list is on the AI processing page). Not the attachment files. In return you get categories, labels, and the injection and phishing scores.
  • Full. Everything in Categorize, plus reply drafts and structured extraction from attachments, written by DeepSeek in China, and only when someone asks for one.

So the setting is the answer to “does mail leave the EU?”. At Off, no. At Categorize, a limited part of each inbound message goes to one processor in the US. At Full, more goes to a processor in China, on request.

One exception that doesn’t depend on the setting: from 26 October 2026, if you list an agent card in the public directory, its name, description, skills and address are checked by JEV before they are listed. That is text you chose to publish, not mail.

Our DPA says how each transfer is covered: the EU standard contractual clauses or, for the US, the EU-US Data Privacy Framework where the recipient is certified. It also says, plainly, that these safeguards are still being put in place for the two AI sub-processors. Until they are, we recommend that EU customers keep AI processing below Full. Check the current status on the DPA before you sign.

You change the setting under Settings in the dashboard. The full description of each level is on the AI processing page.

#Retention: keep mail only as long as you need it

The GDPR asks you to keep personal data no longer than you need it. Each plan sets how long we keep mail: 30 days on Free, 1 year on Builder, 2 years on Team, and unlimited or agreed on Scale. Once a day, messages older than that are deleted with their attachments and stored raw copies. Deleted mail can’t be recovered.

You can choose a shorter period for the whole workspace under Settings. If your agent only needs mail for a week, set a week. Two details matter for a review:

  • Pinned mail stays. A message with the keep label never expires. Use it for what you have a reason to keep, such as a signed order, and nothing else.
  • Contacts and knowledge documents are not covered by retention. They stay until you delete them. Include them in your own review.

For one-off sign-ups, a temporary inbox goes further: it expires on its own, after at most 24 hours, and its mail goes with it.

#Erasing one person

When someone asks you to delete what you hold about them, you need to find every conversation they were part of, delete it, and delete their contact record. Deleting a contact alone isn’t enough: its messages stay.

The thread list takes a participant filter. It matches part of an address, so the code below checks each thread’s participants for an exact match before deleting anything.

erase.ts
import { Agentboxd, AgentboxdError } from 'agentboxd';

const mr = new Agentboxd(); // reads AGENTBOXD_API_KEY

/** Delete every thread a person took part in, then their contact record. */
async function erasePerson(address: string) {
  const email = address.trim().toLowerCase();

  // Collect first, delete after, so deleting doesn't shift the pages.
  const ids: string[] = [];
  let cursor: string | undefined;
  do {
    const page = await mr.threads.listAll({ participant: email, cursor });
    for (const t of page.data) {
      if (t.participants.some((p) => p.toLowerCase() === email)) ids.push(t.id);
    }
    cursor = page.next_cursor ?? undefined;
  } while (cursor);

  for (const id of ids) await mr.threads.delete(id); // messages, attachments and extracted text

  try {
    const contact = await mr.contacts.byAddress(email);
    await mr.contacts.delete(contact.id);
  } catch (e) {
    if (!(e instanceof AgentboxdError && e.status === 404)) throw e; // 404: no contact record
  }
  return { threads: ids.length };
}
erase.py
from agentboxd import Agentboxd, NotFoundError, iter_all

mr = Agentboxd()  # reads AGENTBOXD_API_KEY


def erase_person(address: str) -> dict:
    """Delete every thread a person took part in, then their contact record."""
    email = address.strip().lower()

    # Collect first, delete after, so deleting doesn't shift the pages.
    ids = [
        t["id"]
        for t in iter_all(mr.threads.list_all, participant=email)
        if any(p.lower() == email for p in t["participants"])
    ]
    for thread_id in ids:
        mr.threads.delete(thread_id)  # messages, attachments and extracted text

    try:
        contact = mr.contacts.by_address(email)
        mr.contacts.delete(contact["id"])
    except NotFoundError:
        pass  # no contact record
    return {"threads": len(ids)}
the same calls with curl
# Threads with this person (check participants for an exact match)
curl -s "https://api.agentboxd.com/v1/threads?participant=jane@example.com" \
  -H "Authorization: Bearer $AGENTBOXD_API_KEY"

# Delete one thread with all its messages and attachments
curl -s -X DELETE https://api.agentboxd.com/v1/threads/<thread id> \
  -H "Authorization: Bearer $AGENTBOXD_API_KEY"

# Find and delete the contact record
curl -s https://api.agentboxd.com/v1/contacts/by-address/jane@example.com \
  -H "Authorization: Bearer $AGENTBOXD_API_KEY"
curl -s -X DELETE https://api.agentboxd.com/v1/contacts/<contact id> \
  -H "Authorization: Bearer $AGENTBOXD_API_KEY"

Deleting a thread also removes the event copies of its messages and cancels their pending webhook deliveries. Two things it can’t reach: copies your own systems already took (from webhooks, or from your agent’s memory), and our backups, which age out within 14 days. Delete the first yourself; mention the second in your answer to the person.

Deleting needs the right keys: messages:write for threads, and a workspace-wide key for contacts (inbox-scoped keys get 403).

#Answering an access request

An access request uses the same search. List the person’s threads as above, then fetch each with GET /v1/threads/:id (or mr.threads.get) to get its messages in order, following the cursor on long threads, and add the contact record from GET /v1/contacts/by-address/:address. That is everything the workspace holds about them, as JSON you can turn into a readable export.

#Breaches, audits and new sub-processors

  • Breaches. If a breach affects your data, we tell you without undue delay and within 48 hours at most, so you can meet your own 72-hour deadline to notify your supervisory authority.
  • Sub-processor changes. We give 30 days’ notice before adding or replacing one. Subscribe on the sub-processor page to get it by email, and you can object.
  • Audits. The DPA describes the information we give and when you can audit. Audits of the data centre itself are covered by the hosting provider’s own certifications and reports.

We don’t hold a SOC 2 report or an ISO 27001 certificate today. If your review requires one, say so before you build on us. Our security measures are described on the security page and in Annex 2 of the DPA.

#FAQ

Is the agent’s email address itself personal data?

Often not, when it is a role address like research-bot@yourcompany.com. The mail it receives almost always is: names, addresses and whatever people write.

Do we need a data protection impact assessment?

It depends on what your agent does with the mail. Reading customer mail and acting on it with a model is the kind of new processing where an assessment is worth doing. The DPA commits us to help with the information you need for it.

Can we keep everything in the EU and still use the injection scores?

Not today. The scores come from the Categorize level, which sends part of each inbound message to a processor in the United States. At Off, nothing leaves our server, and you rely on sender checks, scoped keys and send limits instead.

Does deleting a contact delete their mail?

No. It deletes the contact’s name, notes, labels and metadata. Their messages stay until you delete the threads, or until retention removes them.

Where is the DPA, and can we sign it?

The template is on the DPA page. Ask us there for a signed copy with your company’s details.