# Agentboxd Data Processing Addendum (template) > **TEMPLATE — have it reviewed by counsel before signing.** This document is a starting point prepared by > Agentboxd. It has not yet been reviewed by a lawyer and is not an offer until both parties sign a completed > copy. Text in [square brackets] must be completed or confirmed. Version 1.1, 2026-09-25. This Data Processing Addendum ("**DPA**") forms part of the agreement under which Agentboxd provides its email inbox and API service (the "**Agreement**") between: - **[Customer legal name]**, [address], [registration number] (the "**Customer**", acting as controller); and - **[Agentboxd legal entity name]**, [address], [registration number] ("**Agentboxd**", acting as processor). It applies to Personal Data that Agentboxd processes on the Customer's behalf when providing the service at https://agentboxd.com and https://api.agentboxd.com (the "**Service**"). ## 1. Definitions "**GDPR**" means Regulation (EU) 2016/679. "**Data Protection Law**" means the GDPR, the UK GDPR and the Data Protection Act 2018 where applicable, the Swiss Federal Act on Data Protection where applicable, and national laws implementing or supplementing them. "**Personal Data**", "**Processing**", "**Controller**", "**Processor**", "**Data Subject**", "**Personal Data Breach**" and "**Supervisory Authority**" have the meanings given in the GDPR. "**Customer Personal Data**" means Personal Data processed by Agentboxd on behalf of the Customer under the Agreement. "**Sub-processor**" means a third party engaged by Agentboxd that processes Customer Personal Data. "**SCCs**" means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914. ## 2. Roles and scope 2.1 The Customer is the controller (or a processor acting for its own controller) of Customer Personal Data, and Agentboxd is its processor. Annex 1 describes the processing. 2.2 For account and billing data about the Customer's own users (sign-in email, name, workspace membership), Agentboxd acts as an independent controller under its privacy notice; this DPA does not apply to that data. 2.3 The Customer is responsible for having a lawful basis for the processing, for the instructions it gives, and for deciding whether the Service is appropriate for the data its inboxes receive, including any special categories of data. Agentboxd does not offer a service designed for regulated health data and does not sign business associate agreements. ## 3. Instructions 3.1 Agentboxd processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by Union or Member State law to which Agentboxd is subject; in that case Agentboxd informs the Customer of that legal requirement before processing, unless that law prohibits it (GDPR Art. 28(3)(a)). 3.2 The Agreement, this DPA, the Customer's configuration of the Service (for example inboxes, webhooks, lists, retention and the **AI processing** setting) and its use of the API are the Customer's complete instructions. Additional instructions must be in writing and are subject to agreement on any cost. 3.3 Agentboxd informs the Customer immediately if, in its opinion, an instruction infringes Data Protection Law (GDPR Art. 28(3), last subparagraph). 3.4 **AI processing setting.** Each workspace has a setting (`off`, `categorize`, `full`) that controls whether email content is sent to the AI Sub-processors listed in Annex 3. Selecting `categorize` (the default) or `full` is an instruction to use the corresponding Sub-processors to the extent described in Annex 3; selecting `off` is an instruction not to. The setting takes effect from the next message processed. ## 4. Confidentiality Agentboxd ensures that every person authorised to process Customer Personal Data is bound by an obligation of confidentiality (contractual or statutory), and accesses Customer Personal Data only as needed to provide the Service, to handle a support request made by the Customer, to investigate abuse of the Service, to respond to a security incident, or where required by law (GDPR Art. 28(3)(b)). ## 5. Security 5.1 Agentboxd implements the technical and organisational measures described in **Annex 2** to ensure a level of security appropriate to the risk (GDPR Art. 32). Agentboxd may update these measures provided the overall level of security is not reduced. 5.2 The Customer is responsible for the security of its own systems and credentials, including keeping API keys secret, scoping and revoking them, verifying webhook signatures, and treating email content received by its agents as untrusted input. ## 6. Assistance 6.1 **Data Subject requests.** Taking into account the nature of the processing, Agentboxd assists the Customer by appropriate technical and organisational measures in responding to requests from Data Subjects exercising their rights (GDPR Art. 28(3)(e)). The API lets the Customer find, export, correct and delete data (messages, attachments, contacts, knowledge). If Agentboxd receives a request directly, it redirects the Data Subject to the Customer and does not respond itself without the Customer's instruction, unless required by law. 6.2 **Other assistance.** Agentboxd assists the Customer in ensuring compliance with GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Agentboxd (GDPR Art. 28(3)(f)). ## 7. Sub-processors 7.1 The Customer gives Agentboxd general written authorisation to engage Sub-processors (GDPR Art. 28(2)). The Sub-processors authorised at the date of this DPA are listed in **Annex 3** and at https://agentboxd.com/legal/subprocessors. 7.2 Agentboxd gives the Customer at least **30 days' notice** before adding or replacing a Sub-processor, by updating that page and by email to the Customer's notice address [email] if the Customer asked to receive such notices. The Customer may object on reasonable grounds relating to data protection within that period. The parties then discuss the objection in good faith; if no solution is found (for example setting AI processing to `off` where the change concerns an AI Sub-processor), the Customer may terminate the affected part of the Service without penalty, with a pro-rata refund of prepaid fees for it. 7.3 Agentboxd imposes on each Sub-processor, by contract, data protection obligations that are in substance no less protective than those in this DPA (GDPR Art. 28(4)), and remains liable to the Customer for the Sub-processor's performance of those obligations. ## 8. Personal Data Breach 8.1 Agentboxd notifies the Customer **without undue delay** after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any case within **48 hours**, so that the Customer can meet its own obligation to notify the Supervisory Authority within 72 hours (GDPR Art. 33). 8.2 The notice includes, as far as then known: the nature of the breach including the categories and approximate number of Data Subjects and records concerned; the name and contact details of Agentboxd's contact point; the likely consequences; and the measures taken or proposed to address it and mitigate its effects. Information not yet known is provided in phases without undue further delay. 8.3 Agentboxd takes reasonable steps to contain and remediate the breach and to prevent recurrence, and cooperates with the Customer's investigation. Notifying a breach is not an acknowledgement of fault or liability. ## 9. International transfers 9.1 The Service is hosted in the European Union (production in France; backups in the EU). Customer Personal Data is transferred outside the EU/EEA only to the Sub-processors marked as such in Annex 3, and only to the extent the Customer's AI processing setting allows. 9.2 For each such transfer Agentboxd ensures an appropriate safeguard under GDPR Chapter V, namely the SCCs (Module 3, processor to processor) concluded with the Sub-processor, or an adequacy decision (including, for the United States, the EU-US Data Privacy Framework where the recipient is certified), together with a transfer impact assessment and supplementary measures where needed. [Status at the date of this template: these safeguards are being put in place for the AI Sub-processors; see Annex 3. Confirm before signing.] 9.3 Where the Customer is itself established outside the EU/EEA and receives data from the Service (for example via webhooks or the API), that transfer is made by the Customer, which is responsible for it. ## 10. Deletion or return 10.1 During the Agreement, the Customer can export Customer Personal Data through the API and delete it through the API, the dashboard, retention settings, or by request to support@agentboxd.com. 10.2 On termination, at the Customer's choice, Agentboxd deletes or returns all Customer Personal Data and deletes existing copies, unless Union or Member State law requires storage (GDPR Art. 28(3)(g)). Unless the Customer asks for return within 30 days of termination, Agentboxd deletes the data from the live systems within 30 days after that period. Copies in backups are deleted as the backups age out, within **14 days** of deletion from the live systems; until then they remain protected by this DPA and are not restored except to recover the Service. Agentboxd confirms deletion in writing on request. ## 11. Audits and information 11.1 Agentboxd makes available to the Customer all information necessary to demonstrate compliance with GDPR Article 28 (GDPR Art. 28(3)(h)). Agentboxd meets this primarily **through documentation**: on request, and subject to confidentiality, it provides its information security policies, its controls matrix mapped to the SOC 2 Trust Services Criteria, its sub-processor list and answers to a reasonable security questionnaire once per year. Agentboxd does not currently hold SOC 2, ISO 27001 or other third-party certifications; if it obtains any, it will make the reports available instead. 11.2 If the documentation is not sufficient to demonstrate compliance, or a Supervisory Authority requires it, or after a Personal Data Breach affecting the Customer, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, on at least 30 days' written notice, during business hours, no more than once in any 12 months (except in the cases just listed), without access to other customers' data and without disrupting the Service. Each party bears its own costs, unless the audit reveals a material breach of this DPA by Agentboxd. Audits of physical data centres are satisfied by the hosting provider's own certifications and reports. ## 12. Liability and precedence 12.1 Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where Data Protection Law does not permit such limitation. 12.2 If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data. If the SCCs apply and conflict with this DPA, the SCCs prevail. ## 13. Term, law and jurisdiction This DPA lasts as long as Agentboxd processes Customer Personal Data under the Agreement. It is governed by the law of [an EU Member State, e.g. France], and the courts of [city] have jurisdiction, unless the SCCs require otherwise. **Signatures** | | Customer | Agentboxd | |---|---|---| | Name | | | | Title | | | | Date | | | | Signature | | | --- ## Annex 1 — Description of the processing | | | |---|---| | **Subject matter** | Providing email inboxes, sending and receiving email, storage, search, webhooks and related AI features for the Customer's AI agents and users | | **Duration** | The term of the Agreement plus the deletion periods in §10 | | **Nature and purpose** | Receiving email for the Customer's inboxes (MX), storing messages and attachments, parsing (reply extraction, verification code detection), threading, full-text search, contact records, knowledge documents, sending email on the Customer's instruction (DKIM-signed), delivering events by webhook or stream, usage metering, abuse prevention, backups; and, only as allowed by the AI processing setting, categorisation of inbound mail and reply drafts by AI Sub-processors | | **Categories of Data Subjects** | People who send email to, or receive email from, the Customer's inboxes (the Customer's customers, contacts, service providers, and any other correspondent); people named in email content, contacts, notes or knowledge documents; the Customer's users | | **Categories of Personal Data** | Email addresses and display names; message headers (including IP addresses of sending servers, SPF/DKIM/DMARC results); subjects, bodies and attachments (any content the senders include); contact records, notes, labels and metadata the Customer adds; knowledge documents; verification codes and links contained in mail; AI scores and labels; event and delivery logs | | **Special categories** | Not intended, but email content may contain special categories of data (GDPR Art. 9) or data about criminal convictions (Art. 10) sent by third parties; the Customer decides whether to use the Service for such data | | **Frequency** | Continuous | | **Retention** | Per the Customer's plan and retention setting (plan defaults: Free 30 days, Builder 1 year, Team 2 years, Scale as agreed); temporary inboxes until they expire (at most 24 hours); contacts and knowledge until deleted; backups 14 days | ## Annex 2 — Technical and organisational measures These measures describe the Service as it runs on the date above. Items marked *(planned)* are not in place yet and are listed so the Customer can see the roadmap; they are not commitments of current practice. **Hosting and physical security** - Production on a dedicated virtual server at Contabo in France (EU); off-site backups on a second Contabo server in the EU. Physical security of the data centres is provided by the hosting provider. **Encryption** - In transit: TLS for the website, dashboard and API with automatically renewed certificates and HSTS; STARTTLS offered on the inbound MX; SMTP submission requires TLS before authentication; opportunistic STARTTLS for outbound delivery; HTTPS to AI Sub-processors; SSH for backup transfer and deployment. - At rest: custom-domain DKIM private keys encrypted with AES-256-GCM; API keys, session tokens and sign-in tokens stored only as SHA-256 hashes; backup files root-only with checksums; off-site backup copies encrypted with GPG (OpenPGP) to a key held offline before they leave the production server, so the backup server stores only encrypted files. Local backup copies on the production server are not encrypted (root-only access). *(planned, provider-dependent)* disk encryption. **Access control** - Customer side: passwordless sign-in (single-use 15-minute links or GitHub), hashed sessions with CSRF protection, API keys scoped to an inbox and to specific permissions, revocable at any time, rate limited. - Provider side: administrative access limited to named personnel over SSH with keys; the deployment key can only run the deploy script; the backup key is locked to one folder; the database and cache are not exposed to the internet; tenant isolation by workspace on every query. *(planned)* evidenced MFA on all administrative accounts, quarterly access reviews and disabling SSH password authentication (administrators log in with keys). **Data minimisation and AI controls** - A per-workspace AI processing switch (`off` / `categorize` / `full`) checked before every call to an AI Sub-processor and re-checked for queued jobs; unknown values fail closed. Categorisation receives only sender, subject, the first 3,000 characters of the new text, attachment names/types and authentication results. Reply drafts are created only on explicit request, receive a bounded context (≈12,000 characters), are never sent automatically and the model is given no tools. - Envelope-only webhook payloads available; logs exclude message bodies and credentials. **Protection against malicious content** - SPF, DKIM and DMARC evaluated and recorded on every inbound message; prompt-injection and phishing scores (when AI processing is on); untrusted-content markers in MCP results; customer HTML shown only in a sandboxed frame; attachments served as downloads with `nosniff` and a sandbox content security policy. **Availability and resilience** - Nightly verified database and file backups plus a backup before every deployment; 14-day retention locally and off-site; automated deployment with health checks and automatic rollback; container health checks and restart policies. Targets: RPO 24 hours, RTO 8 hours. Quarterly automated restore test of the latest backup into an isolated database, checked against production. Automated monitoring every 5 minutes (website, API, database, mail servers, containers, disk space, backup freshness, certificate expiry) with email alerts. *(planned)* external uptime monitoring; a timed full-rebuild recovery drill. **Abuse prevention** - Per-plan sending caps, burst limits, per-inbox limits, suppression lists, automatic suspension at a hard-bounce rate above 5 % or a complaint rate above 0.1 %, fail2ban and authentication lockouts on SMTP services. **Secure development and change management** - All changes through version control and automated checks (lint, type checking, unit and integration tests, documentation and permission coverage tests) before automatic deployment; secrets never stored in the code repository. *(planned)* automated dependency vulnerability scanning; independent penetration test. **Organisational measures** - Written information security policies (access control, change management, incident response, business continuity, data classification, retention, encryption, vendor management, risk assessment, secure development, logging and monitoring, acceptable use, security awareness), reviewed annually; incident response plan with breach notification; confidentiality obligations for personnel; vulnerability reports via security@agentboxd.com. ## Annex 3 — Authorised Sub-processors As of 2026-09-25. The current list is at https://agentboxd.com/legal/subprocessors. | Sub-processor | Purpose | Customer Personal Data | When | Location | Transfer safeguard | |---|---|---|---|---|---| | Contabo GmbH | Hosting of the Service and off-site backups | All Customer Personal Data | Always | EU (production in France; backups in the EU) | Not applicable (no transfer outside the EU/EEA) | | TypeSafe AI (JEV) | Categorisation of inbound email | Per inbound message: sender, subject, first 3,000 characters of the new text, attachment names and types, SPF/DKIM/DMARC results | Only when the workspace's AI processing is `categorize` (default) or `full` | United States (outside the EU/EEA), per the provider | SCCs Module 3 or EU-US Data Privacy Framework [to be confirmed before signing] | | DeepSeek | Reply drafts | The last 10 messages of one thread (extracted text), the contact's name, notes and metadata, up to 5 knowledge excerpts, the request's instructions | Only when AI processing is `full` **and** a draft is requested | China (outside the EU/EEA; no adequacy decision), per the provider's terms | SCCs Module 3 with a transfer impact assessment [to be put in place; until then Agentboxd recommends that EU customers keep AI processing below `full`] | Not Sub-processors (no Customer Personal Data): GitHub (source code and CI; independent controller for users who choose GitHub sign-in), GoDaddy (DNS).