Legal
Data Processing Addendum
Last updated 27 August 2026 · Effective 27 August 2026
This Data Processing Addendum (“DPA”) forms part of the Terms and Conditions between you and Norbert Shavdia, trading as MailMonk (“MailMonk”, “we”, “us”). It applies whenever we process personal data contained in Customer Data on your behalf.
It takes effect automatically when you accept the Terms. You do not need to sign or request it. If your organization requires a countersigned copy, write to legal@mailmonk.co.
1. Definitions
- Data Protection Law — the EU General Data Protection Regulation (2016/679) (“GDPR”); the GDPR as retained in UK law together with the UK Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection (“FADP”); and the Georgian Law on Personal Data Protection — each as applicable to the processing.
- Controller, processor, data subject, personal data, processing, personal data breach, supervisory authority — as defined in the GDPR.
- Customer Personal Data — personal data contained in Customer Data that we process on your behalf under the Terms.
- SCCs — the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- UK Addendum — the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
- Sub-processor — a third party engaged by us to process Customer Personal Data.
Terms defined in the Terms and Conditions — Account, Customer Data, Domain, Mailbox, Plan, Service, User — have the same meaning here.
2. Roles of the parties
2.1 For Customer Personal Data, you are the controller and we are the processor. Where you are yourself a processor acting for another controller, you warrant that you have authority to instruct us as a sub-processor on that controller’s behalf, and references to you in this DPA include that controller as the context requires.
2.2 We are an independent controller of the data that exists because you are our customer — your name and sign-in address, the Domains and Mailboxes you create, your Plan and billing status, and our logs and security records. That processing is governed by our Privacy Policy, not by this DPA.
2.3 The scope, nature, purpose, and duration of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.
3. Your instructions
3.1 We process Customer Personal Data only on your documented instructions, including on transfers, unless required otherwise by law to which we are subject. Where the law requires it, we will inform you before processing unless that law prohibits us from doing so on important grounds of public interest.
3.2 Your instructions are: the Terms, this DPA, and the configuration and actions you carry out through the Service — creating and deleting Mailboxes and Domains, sending and deleting messages, and the settings you choose. Additional instructions outside that scope require prior written agreement and may attract a fee.
3.3 We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to give legal advice and are not responsible for assessing the lawfulness of the Customer Personal Data you route through the Service.
3.4 You are responsible for the lawfulness of the Customer Personal Data and of your collection of it, for having a valid legal basis, and for any notices or consents your data subjects require.
4. Confidentiality
We ensure that any person authorized to process Customer Personal Data is bound by an appropriate duty of confidentiality, is trained in their obligations, and has access only to what their task requires. As described in the Privacy Policy, personnel access message content only where you request support that requires it, where necessary to investigate a specific abuse or security incident, or where legally compelled.
5. Security
5.1 We implement and maintain the technical and organizational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.
5.2 We may update those measures provided the change does not materially reduce the overall level of security.
5.3 You are responsible for your own use of the Service: the strength and secrecy of your credentials, whether you enable a second factor, who you grant access to, and what you choose to send and store.
6. Sub-processors
6.1 You give a general authorization for us to engage sub-processors. The current list is in Annex III and is maintained at mailmonk.co/subprocessors.
6.2 We will give at least 30 days’ notice by email to your Account address before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period by writing to legal@mailmonk.co.
6.3 If you object and we cannot make the Service available to you without the sub-processor, you may terminate the affected part of the Service by notice and receive a pro-rata refund of fees paid for the unused portion of the current term. This is your sole remedy for an objection.
6.4 We impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. Data subject requests
7.1 The Service gives you direct control over Customer Personal Data. You can search, correct, export, and delete messages, Mailboxes, and Domains yourself, which is how most data subject requests are satisfied without involving us. The export in your account produces the records as JSON and every message as a standard .eml file, which is intended to satisfy the right to portability.
7.2 Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise data subject rights.
7.3 If we receive a request directly from a data subject relating to Customer Personal Data, we will not respond to it substantively. We will refer them to you and, where we can identify the Account, tell you promptly.
8. Personal data breach
8.1 We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification will describe, so far as we know it: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where we cannot provide all of it at once, we will provide it in phases without further undue delay.
8.3 We will assist you in meeting your own notification obligations to supervisory authorities and data subjects. Our notification is not an admission of fault or liability.
9. Impact assessments
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that relate to your use of the Service. Annex I and Annex II are intended to supply most of what such an assessment needs.
10. Deletion and return
10.1 You can delete Customer Personal Data yourself at any time from the dashboard. Deletion of a message, Mailbox, Domain, or the whole Account is immediate and irreversible: the records and the stored message bodies and attachments are erased at once.
10.2 On termination of the Terms, and in accordance with clause 10.2 of the Terms, we retain Customer Data for 30 days so that you can request an export, then delete it from active systems, with deletion from backups following within 90 days.
10.3 We may retain Customer Personal Data to the extent and for as long as required by law to which we are subject, and will continue to protect it in accordance with this DPA for as long as we hold it.
11. Audit
11.1 We will make available the information necessary to demonstrate compliance with this DPA, which will ordinarily be satisfied by this document, Annex II, the Privacy Policy, and any third-party audit reports or certifications our sub-processors publish.
11.2 Where that is not sufficient for a supervisory authority or for your own documented compliance obligations, you may request an audit no more than once in any twelve-month period, on at least 30 days’ written notice, at your cost, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or compromise the data of other customers. An audit may not involve access to another customer’s data under any circumstances.
11.3 A supervisory authority exercising a statutory power of audit is not subject to the limits in clause 11.2.
12. International transfers
12.1 We are established in Georgia and our sub-processors are established mainly in the United States, as set out in Annex III. Neither is the subject of a European Commission adequacy decision covering this processing, so transfers of Customer Personal Data out of the EEA, the UK, or Switzerland are made under the transfer mechanisms below.
12.2 EEA. The SCCs are incorporated into this DPA by reference and apply to transfers of Customer Personal Data from the EEA, with Module Two (controller to processor) applying, and:
- Clause 7 (the docking clause) is included;
- in Clause 9(a), Option 2 (general written authorization) applies, with the notice period in clause 6.2 above;
- in Clause 11(a), the optional independent dispute resolution language is not included;
- in Clause 17, the governing law is the law of the EU Member State in which you as data exporter are established; where that is not an EU Member State, the law of Ireland;
- in Clause 18(b), the forum is the courts of that same Member State, or Ireland;
- Annex I, Annex II, and Annex III below populate the corresponding annexes of the SCCs.
12.3 United Kingdom. For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference and amends the SCCs accordingly. In Table 1, the parties are those in Annex I(A). In Table 2, the Approved EU SCCs are those referred to in clause 12.2. In Table 3, the appendix information is Annexes I to III below. In Table 4, neither party may end the Addendum as set out in section 19.
12.4 Switzerland. For transfers subject to the FADP, the SCCs apply with these amendments: the competent authority is the Federal Data Protection and Information Commissioner; references to the GDPR are to the FADP; the term “member state” does not prevent data subjects in Switzerland from bringing proceedings in Switzerland; and, while the revised FADP protects the data of legal entities, the SCCs also protect such data.
12.5 If a transfer mechanism relied on here is invalidated or found insufficient, we will cooperate in good faith to put an alternative lawful mechanism in place without undue delay.
12.6 Government access requests. If we receive a legally binding request from a public authority for Customer Personal Data, we will notify you unless prohibited by law, challenge the request where there are reasonable grounds to consider it unlawful, and disclose only the minimum the request requires. We will make reasonable efforts to obtain a waiver of any prohibition on notifying you.
13. Liability, precedence, and term
13.1 Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations in Section 14 of the Terms, except where Data Protection Law does not permit that limitation. Nothing here limits a data subject’s rights under the SCCs.
13.2 In the event of a conflict, the SCCs prevail over this DPA, and this DPA prevails over the rest of the Terms, in each case to the extent of the conflict and in relation to the processing of Customer Personal Data only.
13.3 This DPA takes effect when you accept the Terms and continues until we have deleted all Customer Personal Data in accordance with clause 10.
13.4 We may update this DPA where necessary to reflect a change in Data Protection Law, a new transfer mechanism, or a change to the Service, giving notice as required by Section 16 of the Terms. We will not make a change that materially reduces your protection.
Annex I — Description of the processing
A. Parties
Data exporter (controller). You, the Account holder, being the customer identified in the Account. Contact details are those held on the Account. Activities relevant to the transfer: use of a hosted email service for domains you control. Role: controller.
Data importer (processor). Norbert Shavdia, trading as MailMonk, 17 Abashidze Street, Tbilisi, Georgia. Contact: legal@mailmonk.co. Activities relevant to the transfer: providing hosted email — mailbox provisioning, message receipt, storage, and sending. Role: processor.
B. Description of the transfer
- Categories of data subjects. You and your Users; the senders and recipients of messages handled by your Mailboxes; anyone whose personal data appears in the content or attachments of those messages. Because email is free-form, the last group is determined by your correspondents rather than by us.
- Categories of personal data. Names and email addresses; message subjects, bodies, and attachments; message headers and threading identifiers; delivery, authentication, and spam or virus verdicts; IP addresses and timestamps in logs; Mailbox and Domain configuration.
- Sensitive data. Not requested or required. The Terms ask you not to use the Service to store special categories of personal data, payment card data, or regulated health information unless you have independently assessed the Service as appropriate. Where such data nonetheless appears in a message, the measures in Annex II apply to it as to all other content.
- Frequency of transfer. Continuous, for as long as the Account is active.
- Nature and purpose of processing. Receiving, filtering, storing, indexing, displaying, sending, backing up, exporting, and deleting email, and securing and supporting the Service, in each case to provide the Service under the Terms.
- Duration. The term of the Terms, plus the 30-day post-termination retention window in clause 10.2 of the Terms, plus up to 90 days for deletion from backups.
- Sub-processor transfers. Subject matter, nature, and duration as set out in Annex III.
C. Competent supervisory authority
The supervisory authority of the EU Member State in which you as data exporter are established. Where you are not established in the EU but are subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which your Article 27 representative is established. For UK transfers, the Information Commissioner’s Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.
Annex II — Technical and organizational measures
These are the measures actually in place, not a catalogue of what could be. We may improve them; we will not materially reduce them.
- Encryption in transit. All traffic to the Service is served over TLS. Mail transport uses opportunistic TLS to the extent the receiving or sending server supports it.
- Encryption at rest. Message bodies and attachments in object storage, and the database, are encrypted at rest by the providers named in Annex III.
- Access control — infrastructure. Access to cloud infrastructure uses short-lived credentials derived per deployment from a federated identity token, rather than long-lived access keys. Permissions follow least privilege and are scoped to the operations the Service performs.
- Access control — application. Every query for a message, thread, mailbox, domain, alias, or attachment is scoped to the owning Account in the query itself, so a record cannot be read by another customer even if an identifier is guessed or leaked.
- Authentication. Sign-in, session management, and multi-factor authentication are delegated to a specialist provider. We do not store passwords.
- Content isolation. Incoming HTML mail is sanitized before storage and rendered in an isolated frame, so content in a message cannot execute in your browser. Attachment downloads are served with pinned content types and dispositions so that non-image files cannot render as active content.
- Request integrity. State-changing requests are protected against cross-site request forgery by fetch-metadata and origin checks in addition to same-site cookies. Inbound webhooks from mail, payment, and identity providers are accepted only with a verified signature.
- Abuse and availability controls. Rate limits are enforced centrally in the database rather than per instance, so they hold under load. Inbound mail is scanned for spam and malware, and sender authentication results (SPF, DKIM, DMARC) are evaluated on receipt.
- Logging and incident detection. Application failures are reported to a structured incident system that classifies fault and alerts on those requiring intervention. Message bodies, attachments, and session recordings are never sent to it.
- Resilience and backup. The database provider maintains continuous backups with point-in-time recovery. Object storage is redundant across facilities. Inbound mail processing is reconciled on a schedule so that a message accepted by our servers is delivered even if part of the pipeline fails.
- Portability and deletion. Self-service export of the whole Account, and self-service deletion of a message, Mailbox, Domain, or Account, are available in the dashboard. Account deletion cascades to stored objects as well as records.
- Sub-processor assurance. Sub-processors are engaged under data processing agreements with obligations no less protective than these, and are selected in part on their published security certifications.
- Personnel. The Service is operated by a small team bound by confidentiality obligations, with access limited to what each task requires.
Annex III — Sub-processors
Each processes Customer Personal Data only on our instructions, under a data processing agreement, and none is permitted to use it for its own purposes. The duration of processing for each is the same as in Annex I(B).
| Entity | Processing | Personal data | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Receiving and sending mail (SES), storing message bodies and attachments (S3), and bounce and complaint notifications (SNS) | Message content, attachments, headers, sender and recipient addresses | United States (us-east-1) |
| Neon Inc. | Database holding accounts, domains, mailboxes, and message metadata | Account data, addresses, subjects, message metadata, body snippets | United States |
| Vercel Inc. | Application hosting, request routing, and platform logs | IP addresses, request metadata, data in transit | United States, with global edge routing |
| Clerk.dev, Inc. | Sign-in, session management, and account security | Name, email address, authentication and session records, IP address | United States |
| Stripe, Inc. and Stripe Payments Europe, Ltd. | Payments and subscription billing for paid plans | Name, email address, billing and payment details | United States and Ireland |
| Functional Software, Inc. | Error reporting — stack traces and the request that failed. Never message bodies, attachments, or session recordings | Error context, account identifiers, request metadata | United States |
Contact
Norbert Shavdia, trading as MailMonk
17 Abashidze Street, Tbilisi, Georgia
Data protection: legal@mailmonk.co