Ezra Mail
FeaturesHow it worksFor teamsSecurityPricing
Sign inStart for free
Documents
  • All documents
  • Terms of service
  • Privacy policy
  • Data processing agreement
  • Sub-processors
  • Security measures
  • Acceptable use policy
  • Cookie policy
Version 2026-10-07 · effective 7 October 2026

This translation is provided for convenience. The Polish version of this document is binding and prevails in case of any discrepancy. Wersja polska

Data processing agreement

An agreement under Article 28(3) GDPR between an organization using Ezra Mail and the Service Provider. It applies on every plan, including the free one.

Contents
  1. § 1. Parties and conclusion
  2. § 2. Definitions
  3. § 3. Subject matter, nature and purpose
  4. § 4. Processing on documented instructions
  5. § 5. Confidentiality
  6. § 6. Security of processing
  7. § 7. Sub-processing
  8. § 8. Transfers outside the EEA
  9. § 9. Assistance with data subject rights
  10. § 10. Personal data breaches
  11. § 11. Impact assessments and consultation
  12. § 12. Information and audits
  13. § 13. Deletion or return of data
  14. § 14. Liability
  15. § 15. Final provisions
  16. Annex 1. Description of processing

§ 1. Parties and conclusion

  1. The parties to this agreement are: the Customer on whose behalf an Organization was created in the Ezra Mail service (the “Controller”), and Operator usługi Ezra Mail (the “Processor”).
  2. The agreement is concluded on the Controller’s behalf by the Organization Owner, who accepts it electronically when creating the Organization or in the Organization settings. The Processor records the version of the agreement, the date of acceptance and the person who accepted it; this information is visible in the Organization settings. Electronic form is the form required by Article 28(9) GDPR.
  3. The agreement is part of the agreement for the provision of the Ezra Mail service concluded under the Terms of service (the “Main Agreement”) and remains in force for its duration and until data is deleted in accordance with § 13.
  4. On the Enterprise Plan the parties may conclude an agreement with different content in documentary or written form; it then takes precedence.

§ 2. Definitions

Capitalized terms have the meaning given in the Terms of service, and in addition: GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council; Data — personal data processed by the Processor on behalf of the Controller as part of the Service, described in Annex 1; Sub-processor — an entity to which the Processor entrusts the processing of Data. Other terms (e.g. “processing”, “personal data breach”) have the meaning set out in Article 4 GDPR.

§ 3. Subject matter, nature and purpose

  1. The Controller entrusts the Processor with processing Data to the extent, for the purpose and for the duration described in Annex 1, solely to provide the Service in accordance with the Main Agreement.
  2. Processing covers the operations needed to provide the Service: collection, recording, storage, organization, structuring (including tagging), consultation, use to generate drafts and replies, transmission (sending mail), export and erasure.
  3. The Controller represents that it is entitled to process and entrust the Data and that the instructions it gives are lawful.

§ 4. Processing on documented instructions

  1. The Processor processes Data only on documented instructions from the Controller, including with regard to transfers of Data to a third country, unless required to do so by Union or Polish law; in that case it informs the Controller of that legal requirement before processing, unless the law prohibits such information.
  2. Documented instructions are: this agreement, the Main Agreement, and the settings and actions performed by the Organization’s Users in the Service and through the API (e.g. creating a mailbox, enabling automatic replies, choosing an AI Provider, setting the retention period, deleting messages, exporting).
  3. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
  4. The Processor does not use the Data for its own purposes, including advertising, profiling or training AI models.

§ 5. Confidentiality

The Processor gives access to Data only to persons who need it to provide or maintain the Service, have written authorization and have committed themselves to confidentiality or are under a statutory obligation of confidentiality. The obligation continues after the cooperation with these persons ends. Staff access message content only when necessary to fix a failure, handle a request from the Controller or fulfil a legal obligation, and such access is logged.

§ 6. Security of processing

  1. The Processor applies technical and organizational measures ensuring a level of security appropriate to the risk, as referred to in Article 32 GDPR, described in Security measures, which constitutes Annex 2.
  2. The Processor may change these measures provided that the change does not reduce the overall level of protection of the Data.
  3. The Controller is responsible for security on its side, in particular for managing User access, roles and API tokens, password strength and the security of its own accounts with providers (Resend, AI Provider).

§ 7. Sub-processing

  1. The Controller gives general authorization to engage the Sub-processors listed on the Sub-processors page, which constitutes Annex 3.
  2. The Processor informs the Owners by email and on the list at least 14 days before adding or replacing a Sub-processor. Within that period the Controller may raise a reasoned objection at privacy@saauf.xyz. If the parties do not agree on a solution, the Controller may terminate the Main Agreement with effect from the date of the change.
  3. The Processor imposes on Sub-processors data protection obligations no less protective than those in this agreement and remains liable to the Controller for their performance.
  4. Services the Controller uses under its own agreements — its own Resend account and an AI Provider with the Controller’s key — are not Sub-processors of the Processor. Data is passed to them on the Controller’s instruction, given by connecting the account or saving the key.

§ 8. Transfers outside the European Economic Area

Data is transferred to a third country only on the basis of an adequacy decision (including the EU-US Data Privacy Framework) or standard contractual clauses adopted by the European Commission, with supplementary measures where needed. Locations and transfer bases are set out in Annex 3.

§ 9. Assistance with data subject rights

  1. Taking into account the nature of the processing, the Processor assists the Controller in responding to requests from data subjects, primarily through features of the Service available to the Controller:
    • searching and reviewing correspondence with a given person (access, Article 15 GDPR);
    • deleting individual messages and threads, and deleting all messages with a given email address (erasure, Article 17 GDPR);
    • exporting the Organization’s data in JSON format (portability, Article 20 GDPR);
    • blocking a sender so they don’t receive automatic replies (objection, restriction).
  2. A request sent to the Processor by mistake is forwarded to the Controller without undue delay, no later than within 3 business days. The Processor does not respond to it on its own unless the Controller authorizes it to do so.

§ 10. Personal data breaches

  1. The Processor notifies the Controller of a personal data breach without undue delay, no later than 36 hours after becoming aware of it, by email to the Organization Owners’ addresses.
  2. The notification contains, as far as available: a description of the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken and proposed, and the contact details of the person providing information. Information not available at the time of notification is provided promptly afterwards.
  3. The Processor documents breaches, cooperates with the Controller in investigating them and takes steps to mitigate their effects. Notifying the supervisory authority and informing data subjects is the Controller’s responsibility.

§ 11. Impact assessments and consultation

The Processor provides the Controller with the information needed to carry out a data protection impact assessment (Article 35 GDPR) and prior consultation with the supervisory authority (Article 36 GDPR) as far as the Service is concerned. Basic information is contained in this agreement and its annexes.

§ 12. Information and audits

  1. The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, primarily in the form of written answers to questions and documentation, within 14 days of a request.
  2. If this information is not sufficient, the Controller may conduct an audit or inspection — itself or through an independent auditor bound by confidentiality — no more than once every 12 months, unless there is a justified suspicion of a breach of this agreement or the supervisory authority requires it. An audit must be announced at least 30 days in advance, conducted on business days and in a way that does not compromise the security of other customers. The Controller bears the costs of the audit.
  3. Audits do not extend to Sub-processors — for them the Processor provides available reports and certifications (e.g. SOC 2, ISO 27001).

§ 13. Deletion or return of data

  1. Throughout the term of the agreement the Controller can download an export of the Data in the Organization settings (JSON format) — this constitutes the return of Data within the meaning of Article 28(3)(g) GDPR.
  2. After the Owner deletes the Organization or the Main Agreement is terminated, the Processor deletes the Data from the production database without delay, no later than within 30 days. Data in backups is deleted as backups are overwritten, within no more than 30 days, and is not used in any way in the meantime.
  3. If the Processor terminates the agreement, the Controller has at least 30 days to download an export, unless termination is due to a material breach — in that case the export is made available at the Controller’s request.
  4. The deletion obligation does not apply to Data whose retention is required by Union or Polish law.

§ 14. Liability

The parties are liable to each other under the Main Agreement and Article 82 GDPR. The limitations of liability in the Terms of service do not limit the Processor’s liability towards data subjects, nor to the extent this would conflict with mandatory law.

§ 15. Final provisions

  1. The Processor may amend this agreement following the procedure for amending the Terms of service, in particular to align it with legislation or guidance from authorities. An amendment may not reduce the level of Data protection. A new version requires the Owner’s acceptance on the Website.
  2. Matters not governed by this agreement are subject to the GDPR, the Main Agreement and Polish law. In the event of conflict on data protection matters, this agreement prevails.
  3. Contact regarding the agreement: privacy@saauf.xyz; reporting security incidents: security@saauf.xyz.

Annex 1. Description of processing

Nature and purposeProviding a team mail service with an AI assistant: receiving, storing, organizing and sending the Organization’s email, preparing AI drafts and replies, managing member access.
Categories of data subjectsThe Controller’s correspondents (customers, business partners, candidates and other people writing to the Organization’s mailboxes or receiving messages from it); people whose data appears in message content, the knowledge base and instructions; the Controller’s employees and collaborators as far as data in the content is concerned.
Types of dataNames and email addresses of senders and recipients; message subjects and content (text and HTML); message identifiers; tags; delivery statuses; other data that correspondents or the Controller include in the content.
Special categories of dataThe Service is not intended for processing data under Articles 9 and 10 GDPR. If such data reaches the Organization’s mailboxes (e.g. in a message from a correspondent), the Controller is responsible for the legal basis for processing it and may set a shorter retention period or delete such messages.
Duration of processingThe term of the Main Agreement, taking into account the retention period set by the Controller (30, 90, 180, 365 or 730 days, or no automatic deletion) and the deadlines in § 13.
Place of processingAs set out in Annex 3.
Annex 2Security measures
Annex 3Sub-processors
Ezra Mail

A team inbox with an AI assistant that writes in your tone — and always leaves you the last word.

Product

  • Features
  • For teams
  • Security
  • Pricing

Account

  • Create an organization
  • Sign in
  • Forgot password

Information

  • Terms of service
  • Privacy policy
  • Data processing agreement (DPA)
  • Sub-processors
  • Security
  • Acceptable use
  • Cookies
© 2026 Ezra MailContact: kontakt@saauf.xyz