1. Application
This Data Processing Addendum forms part of the Service Terms when Envelaro processes personal data on a customer’s behalf. It applies from the date the customer accepts the Service Terms or signs an order that incorporates it.
If a signed order contains a specifically negotiated data-processing term that conflicts with this addendum, that signed term controls for the conflict.
2. Roles and instructions
For customer mailbox, account, and administrative data processed to provide the service, the customer will generally act as controller or business and Envelaro as processor or service provider. Envelaro will process that data only on documented instructions, including those inherent in providing the contracted service.
3. Processing details
- Subject matter: hosted email, mailbox administration, security, support, migration, backup, and recovery.
- Data subjects: customer users, administrators, correspondents, contacts, and support participants.
- Data types: account identifiers, configuration, message content and metadata, contacts, logs, authentication records, and support data.
- Duration: the service term plus documented retention, deletion, backup, security, and legal-compliance periods.
4. Processor commitments
- Confidentiality obligations for authorised personnel.
- Risk-appropriate technical and organisational security measures.
- Reasonable assistance with data-subject requests, impact assessments, and regulatory consultations.
- Notice of confirmed personal-data breaches without undue delay as required by the final agreement.
- Deletion or return of customer personal data after termination, subject to documented legal and backup exceptions.
5. Subprocessors
The customer authorises the subprocessors on Envelaro’s current public list. Envelaro requires subprocessors to protect personal data consistently with their role and provides notice and a reasonable objection process where applicable law requires it.
6. International transfers
Where restricted transfers occur, the parties will use an applicable lawful transfer mechanism, which may include approved standard contractual clauses and supplementary measures.
7. Information and audit
Envelaro will provide reasonable compliance information and, where legally required, support a proportionate audit process that protects other customers, security, confidentiality, and operational continuity. Independent reports and written responses will be used before an on-site audit where they adequately address the request.
Contact
Questions, rights requests, or abuse reports can be submitted through our contact page. Please do not include passwords, mailbox contents, or unnecessary sensitive information.
