Envelaro
ProductPricingSecurityMigrationEmail checkResources
Log inStart free trial
InvitationInviting small businesses to evaluate EnvelaroRequest an evaluation
Envelaro home

Data processing addendum

The terms governing Envelaro’s processing of customer personal data for the managed service.

Status
Effective
Last updated
26 August 2026

On this page

1. Application2. Roles and instructions3. Processing details4. Processor commitments5. Subprocessors6. International transfers7. Information and audit

1. Application

This Data Processing Addendum forms part of the Service Terms when Envelaro processes personal data on a customer’s behalf. It applies from the date the customer accepts the Service Terms or signs an order that incorporates it.

If a signed order contains a specifically negotiated data-processing term that conflicts with this addendum, that signed term controls for the conflict.

2. Roles and instructions

For customer mailbox, account, and administrative data processed to provide the service, the customer will generally act as controller or business and Envelaro as processor or service provider. Envelaro will process that data only on documented instructions, including those inherent in providing the contracted service.

3. Processing details

  • Subject matter: hosted email, mailbox administration, security, support, migration, backup, and recovery.
  • Data subjects: customer users, administrators, correspondents, contacts, and support participants.
  • Data types: account identifiers, configuration, message content and metadata, contacts, logs, authentication records, and support data.
  • Duration: the service term plus documented retention, deletion, backup, security, and legal-compliance periods.

4. Processor commitments

  • Confidentiality obligations for authorised personnel.
  • Risk-appropriate technical and organisational security measures.
  • Reasonable assistance with data-subject requests, impact assessments, and regulatory consultations.
  • Notice of confirmed personal-data breaches without undue delay as required by the final agreement.
  • Deletion or return of customer personal data after termination, subject to documented legal and backup exceptions.

5. Subprocessors

The customer authorises the subprocessors on Envelaro’s current public list. Envelaro requires subprocessors to protect personal data consistently with their role and provides notice and a reasonable objection process where applicable law requires it.

6. International transfers

Where restricted transfers occur, the parties will use an applicable lawful transfer mechanism, which may include approved standard contractual clauses and supplementary measures.

7. Information and audit

Envelaro will provide reasonable compliance information and, where legally required, support a proportionate audit process that protects other customers, security, confidentiality, and operational continuity. Independent reports and written responses will be used before an on-site audit where they adequately address the request.

Contact

Questions, rights requests, or abuse reports can be submitted through our contact page. Please do not include passwords, mailbox contents, or unnecessary sensitive information.

Related documents

PrivacyTermsAcceptable useCookies
Envelaro

Envelaro - Dependable business email.

support@envelaro.com

Product

Email hostingEmail health checkSecurityMigrationPricingManaged private deployment

Free tools

DMARC checkerDKIM checkerSPF checkerDomain blocklistIP blocklist

Company

AboutFAQContactStatus

Legal

PrivacyWebsite termsService termsBilling and refundsAcceptable useCookies

Trust

Managed service modelData processingData lifecycleSubprocessorsService availability
© 2026 EnvelaroBuilt for teams worldwide.