Ezra Mail
FeaturesHow it worksFor teamsSecurityPricing
Sign inStart for free
Documents
  • All documents
  • Terms of service
  • Privacy policy
  • Data processing agreement
  • Sub-processors
  • Security measures
  • Acceptable use policy
  • Cookie policy
Version 2026-10-07 · effective 7 October 2026

This translation is provided for convenience. The Polish version of this document is binding and prevails in case of any discrepancy. Wersja polska

Sub-processors

Annex 3 to the data processing agreement. The providers we entrust with data as part of Ezra Mail, with purpose, location and transfer basis.

Service infrastructure

These providers process the data of every Organization. Sending and receiving mail through the service’s Resend account applies only to the @saauf.xyz domain.

ProviderPurposeDataLocationTransfer basis
Supabase
Supabase, Inc.
agreement / DPA
Database (PostgreSQL) and its backupsAll service data: accounts, organizations, mail, settings, activity logEuropean Union (Frankfurt, eu-central-1)Data stored in the database region; support access from the USA under SCCs
Vercel
Vercel Inc.
agreement / DPA
Application hosting and request processingData sent in requests, technical logs (IP address, time, path)Global edge network; functions in the EU regionEU-US Data Privacy Framework, SCCs
Resend
Plus Five Five, Inc. (Resend)
agreement / DPA
Sending and receiving mail on the @saauf.xyz domain, delivery statusesSender, recipients, subject and body of messages, delivery eventsUSA; sending from the EU region (eu-west-1)EU-US Data Privacy Framework, SCCs

AI providers

Ezra, the service’s AI model, runs on the infrastructure of the provider below. We use it only for Organizations that chose Ezra, and we send it only what is needed to prepare a reply: the thread, the knowledge base and the Organization’s instructions.

ProviderPurposeDataLocationTransfer basis
Google Gemini API
Google LLC
agreement / DPA
Engine of the Ezra model: generating AI replies and drafts for Organizations that use EzraCorrespondence in the thread, knowledge base and organization instructionsUSAEU-US Data Privacy Framework, SCCs; data from the paid API is not used to train models

An Organization can use Anthropic (Claude), Google (Gemini), OpenAI (ChatGPT), xAI (Grok) only with its own API key — the provider then acts under the Organization’s own agreement and is not our sub-processor.

Services under the Organization’s own agreements

These are not our sub-processors — the Organization uses them under its own agreement, and we pass data to them on its instructions:

  • The Organization’s own Resend account — sending and receiving mail on the Organization’s own domains.
  • An AI provider with the Organization’s key (Anthropic, Google, OpenAI or xAI).
  • Webhook URLs and API integrations configured by the Organization.

Changes to the list

We notify Organization Owners by email at least 14 days before adding or replacing a provider. Objections can be sent to privacy@saauf.xyz — the rules are set out in § 7 of the data processing agreement.

Ezra Mail

A team inbox with an AI assistant that writes in your tone — and always leaves you the last word.

Product

  • Features
  • For teams
  • Security
  • Pricing

Account

  • Create an organization
  • Sign in
  • Forgot password

Information

  • Terms of service
  • Privacy policy
  • Data processing agreement (DPA)
  • Sub-processors
  • Security
  • Acceptable use
  • Cookies
© 2026 Ezra MailContact: kontakt@saauf.xyz