Data processing agreement
Version 2026-10-01. Applies to our delivery network.
In plain words
- Your mail lives on your server. We never host your mailboxes and never keep copies of your messages.
- When you use our delivery network, it carries your mail between the internet and your server. It handles each message in memory while passing it along, and never stores, logs or shares the contents.
- If your server is offline, the sender gets "try again later" and retries. Nothing waits with us.
- We store only what we need to route your mail and keep the network safe: your server's public key, your domain names and their public signing keys, your sending limits, the list of recipients your invite allows, counts, and a record of administrative actions.
- We delete that record of your service within 30 days after it ends.
- We tell you about a breach within 48 hours of learning about it.
- We give you 30 days' notice before adding a new sub-processor, and you can object.
- Our server is in Atlanta, Georgia, USA. Standard contractual clauses cover transfers of EU, UK and Swiss data.
The rest of this page is the binding text. The summary above does not change it.
1. Who this agreement is between
1.1 This data processing agreement ("DPA") is between Scaled Minds (d/b/a), operator of eMailPlane, with its address at 4030 Wake Forest Rd Ste 349, Raleigh, NC 27609, USA ("we", "us"), and the customer that accepts it ("you"). It forms part of our Terms of Service (the "Agreement"). You accept it when you accept the Agreement, or when you sign it.
1.2 Roles. For personal data in mail that our delivery network carries for you, you are the controller (or a processor acting for your own customers) and we are your processor (or sub-processor). Under the California Consumer Privacy Act ("CCPA"), we are your service provider.
1.3 What is not covered. Your server, its mailboxes, stored messages, signing keys and backups run on infrastructure you control. We do not operate, access or store them, so they are outside this DPA. The details of your own account with us (your sign-in email, billing details and similar) are covered by our Privacy Policy, where we act as controller.
1.4 Definitions. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings in the GDPR. "Data protection law" means every law that applies to the processing under this DPA, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP") and the CCPA. "Delivery network" means our service that carries mail between the internet and your server for the domains you register with it. "Customer personal data" means personal data we process for you through the delivery network.
2. Details of the processing
| Item | Details |
|---|---|
| Subject matter | Carrying email for the domains you register with the delivery network: receiving mail from senders and passing it to your server over your server's own encrypted connection to us, and passing your server's outgoing mail to recipients' mail servers. |
| Nature | Receiving, passing on and, for outgoing mail, adding a second signature for our network; checking each outgoing message against your registered domains, your sending limits, the suppression list and, during the beta, your invite's recipient list. |
| Purpose | Only to deliver your mail and keep the delivery network safe from abuse. Never for advertising, profiling, selling data or training AI models. |
| Duration | From when your server is approved on the delivery network until your service ends, plus the deletion periods in section 10. |
| Frequency | Continuous, as mail arrives and leaves. |
| Data subjects | Your users, and the people who exchange email with them. |
| Data handled in memory only, never stored | Message content (headers, body, attachments), sender and recipient addresses, and the connecting sender's IP address and greeting name, which we pass to your server so it can judge the sender itself. |
| Data we store | Your server's public identity key and an optional label; your registered domain names and their public signing keys (private keys stay on your server); your sending limits; the recipient list your invite allows, which can contain email addresses you choose; hourly recipient counts; one-way hashed delivery keys that stop a retried message from being sent twice; and an audit trail of administrative actions that records ids and counts, never addresses or content. |
| Logs | Delivery network logs record server ids, counts and reason codes. When our network refuses a recipient that is not on your invite's list, the log records the recipient's domain, never the full address. |
| Special categories | We do not ask for special categories of data. Any that appear in mail content pass through in memory only. |
3. Our obligations
3.1 Instructions. We process customer personal data only on your documented instructions, which are the Agreement, this DPA and your configuration of the delivery network (registered domains, server approval, limits), unless the law requires otherwise. If the law requires other processing, we tell you first unless the law forbids it. We tell you promptly if we believe an instruction breaks data protection law.
3.2 Requests from authorities. If an authority asks us for customer personal data, we ask it to go to you, disclose only what the law compels, and tell you first unless the law forbids it. Because we do not store mail content or addresses in transit, we cannot produce them.
3.3 CCPA. We do not sell or share customer personal data, as those terms are defined in the CCPA. We do not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the delivery network. We do not combine it with personal data we receive from anyone else. We comply with the CCPA's obligations for service providers and tell you if we can no longer meet them, and you may take reasonable steps to stop and remedy unauthorised use.
4. People with access
4.1 One named operator. During the beta, the owner of the business is the only person who operates the delivery network. Before anyone else gets operator access, they will be bound by a written duty of confidentiality, and we will update this section.
4.2 AI coding tools have no access. We use AI coding tools to build our software. They are excluded from emergency access to the delivery network's running processes and from customer personal data passing through it. This is enforced, not only promised: the delivery network's processes block other programs on the same server from reading their memory or tracing them, and write no memory dumps; and an automated test, which runs before every build of the delivery network, fails the build if any address or message content could reach its logs.
4.3 Emergency access. If a person ever needs to look inside a running delivery network process, it follows a written procedure: the access is announced first, the whole session is recorded, debuggers and memory dumps are never used, and no message data or address is ever copied out.
5. Security
We maintain at least these measures, as built today:
- Your server connects out to us. We cannot open a connection into your server.
- Encrypted connection. Your server connects to us over TLS 1.3 and proves its identity with its own key, created on your server and never sent to us.
- Approval with a passkey. A server joins the delivery network only with a single-use invite, plus a code that expires in 15 minutes and is approved, with a passkey, by the person your invite names. Every approval is emailed to that person. Replacing an approved server waits out a cooling-off period (24 hours by default) before the new server takes over.
- No stored mail. Mail passes straight through. If your server is offline, the sender is told to try again later and nothing is kept.
- Sender checks. Outgoing mail must come from your registered domains and carry a valid signature from your registered key before it leaves.
- Limits and stop switches. Per-customer hourly and daily limits, a network-wide daily limit, your invite's recipient list during the beta, and several independent ways to stop outgoing mail at once. Stopping outgoing mail never stops incoming mail.
- Hardened services. Minimal images, no administrator rights inside the containers, read-only file systems, no swap and no memory dumps.
- Encrypted backups. Our backups are encrypted before they leave our server.
- Honest limits. Our outgoing connections to recipients' servers use TLS whenever the recipient offers it, but we do not yet refuse to deliver when a recipient does not. The delivery network runs on a server it shares with our other services, and a person with full administrator rights on that server is the trust boundary, which is why section 4.3 exists.
We may change these measures as long as the overall level of protection does not go down.
6. Sub-processors
6.1 General authorisation. You authorise us to use the sub-processors on our sub-processor list. On the date of this version they are:
| Sub-processor | What it does | Where |
|---|---|---|
| SSDNodes (upstream provider HIVELOCITY, Inc.) | Hosts the server the delivery network runs on. | Data centre in Atlanta, Georgia, USA |
| Cloudflare, Inc. (R2 storage) | Stores our encrypted nightly backups, which contain the stored data in section 2 but never mail content. | US company; storage location per bucket setting: {{R2_LOCATION}} |
6.2 Our duties. We bind each sub-processor by written terms that protect customer personal data at least as well as this DPA, and we remain responsible to you for their work.
6.3 Changes. We tell you at least 30 days before a new or replacement sub-processor starts handling customer personal data, by email to your account owner and on the sub-processor list. You may object in writing within those 30 days on reasonable data protection grounds. We will try to resolve it. If we cannot, you may stop using the delivery network, or end the Agreement, without any early-termination charge, and we refund any prepaid fees for the delivery network for the period after it stops.
7. Helping you with requests
Most requests from data subjects are answered from your own server, where your mail lives. Taking into account the nature of the processing, we help you answer them for the data we hold: your invite's recipient list, your domain registrations, and logs within their 14-day window. If a data subject contacts us directly about customer personal data, we pass the request to you and do not answer it ourselves unless you ask us to.
8. Personal data breaches
8.1 We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting customer personal data.
8.2 The notice says, as far as we know at the time: what happened, the categories and approximate number of data subjects and records involved, the likely consequences, and what we have done and will do about it. We send further details as we learn them.
8.3 Notifying you is not an admission of fault.
9. Impact assessments
We give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority about the delivery network, including this DPA and a description of how the delivery network is built and tested.
10. Deletion and return
| Data | When it is deleted |
|---|---|
| Message content, addresses and sender details in transit | Never stored, so nothing to delete. |
| Hashed delivery keys | Automatically after 72 hours. |
| Hourly recipient counts | Automatically after 48 hours. |
| Logs | Rotated out, and gone from our log store after 14 days. |
| Your server's registration, domains, public signing keys, invite and recipient list | Within 30 days after your service ends. A scheduled job deletes them 28 days after your server is removed from the delivery network. |
| Audit trail of administrative actions | Kept for the life of the service plus 24 months, then deleted. It holds ids and counts only, never addresses or content. After the registration is deleted, its ids no longer point to anything we hold about you. |
| Encrypted backups | Normally gone within 16 days after the data is deleted from our live systems, as older nightly backups are replaced. If nightly backups stop, the last copies are kept until backups resume, so that we never lose our only copy. |
On request before your service ends, we export to you the registration data we hold about your servers and domains. You already hold all of your mail and keys on your own server.
11. Audits
11.1 Once every 12 months, on request, we answer a reasonable written security questionnaire and give you our current security information, including this DPA and our test evidence for the delivery network.
11.2 An on-site audit is available only if a supervisory authority requires it, or after a personal data breach affecting your data. You give us 30 days' notice, the audit happens during business hours under a confidentiality agreement, you pay its cost, and it happens at most once in any 12 months. Audits are limited to the delivery network and must not give access to other customers' data.
12. International transfers
12.1 We process customer personal data in the United States. Where data protection law requires a transfer mechanism, these are incorporated into this DPA by reference and apply automatically:
- EU: the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, Module 2 (controller to processor), or Module 3 (processor to processor) where you are a processor.
- UK: the International Data Transfer Addendum to those clauses, issued by the UK Information Commissioner (version B1.0, in force 21 March 2022).
- Switzerland: those clauses as amended for the FADP.
12.2 For the EU clauses: Clause 7 (docking) applies; under Clause 9(a), Option 2 (general written authorisation) applies with the 30-day notice in section 6.3; the optional language in Clause 11 does not apply; under Clause 13, the supervisory authority is the one competent for you; under Clauses 17 and 18, the clauses are governed by the law of Ireland and disputes go to the courts of Ireland. Annex I is section 2 of this DPA (with you as data exporter and us as data importer, contact details as in section 1), Annex II is section 5, and Annex III is section 6.
12.3 For the UK Addendum: Tables 1 to 3 are completed with the information in this DPA and in clause 12.2, and either party may end the Addendum as set out in its Section 19. For Switzerland: the competent supervisory authority is the Federal Data Protection and Information Commissioner; references to the GDPR are read as references to the FADP; and "Member State" is read so that data subjects in Switzerland can bring claims in their place of habitual residence.
12.4 If the clauses conflict with this DPA, the clauses win.
13. Liability
13.1 Each party's liability under this DPA is subject to the limits of liability in the Agreement, including the cap of the fees you paid in the 12 months before the claim. This DPA does not create any uncapped liability or indemnity.
13.2 During the beta, the delivery network is provided as-is, as described in the Agreement.
13.3 Nothing in this section limits a data subject's rights under the standard contractual clauses.
14. Term, order and law
14.1 This DPA lasts as long as we process customer personal data for you, and its deletion duties survive until they are met.
14.2 If this DPA conflicts with the Agreement on data protection, this DPA wins.
14.3 Except as section 12 says for the standard contractual clauses, this DPA is governed by the law of the State of North Carolina, USA, and the state and federal courts for Wake County, North Carolina, have jurisdiction, the same as the Agreement.
15. Contact and signature
Data protection questions: privacy@emailplane.com, or by post to Scaled Minds, 4030 Wake Forest Rd Ste 349, Raleigh, NC 27609, USA.
You accept this DPA online with the Agreement; no signature is needed. If you need a signed copy, email legal@emailplane.com and an Authorized Representative of Scaled Minds will sign one with the same text.