← All legal

Data Processing Agreement

Last updated: 2026-08-31

This Data Processing Agreement (the "DPA") forms part of our Terms of Service and applies automatically to every customer. There is no signature dance: if you use trustyourinbox and the GDPR, UK GDPR, or a similar law applies to you, these terms already bind us. If your procurement process needs a countersigned copy, and we will sign the same text.

1. Who is who

  • You (the customer) are the controller: you decide why domains are monitored and what happens with the results.
  • We (trustyourinbox, the operator of trustyourinbox.com) are the processor: we process the data described below only to provide the service, on your instructions.

"Personal data", "processing", "controller", "processor", and "data subject" carry the meanings given in the GDPR. "GDPR" means Regulation (EU) 2016/679, and includes the UK GDPR where UK law applies.

2. What we process, and why

  • Subject matter and purpose: providing DMARC monitoring and the related features of the service (report parsing, dashboards, digests, alerts, DNS fixes you approve). Nothing else. We never process your data for advertising and we never sell it.
  • Categories of personal data: account data (name, email address, workspace settings); the domain names you monitor; DMARC aggregate report data (sending server IP addresses, message counts, authentication results); audit log entries; product-usage analytics as described in the Privacy Policy. DMARC aggregate reports contain no message bodies, no recipient addresses, and no subject lines by design.
  • Data subjects: your users who sign in to the service, and the operators of servers that send mail as your domains (their server IP addresses appear in aggregate reports).
  • Duration: the life of your account, plus the deletion windows in the Privacy Policy (account data purged 30 days after deletion; raw report files after 7 days).

3. Our obligations as your processor

We will:

  • Process personal data only to provide the service and on your documented instructions (your use of the dashboard, API, and settings are those instructions), unless law requires otherwise, in which case we tell you first where legally allowed.
  • Make sure everyone with access is bound by confidentiality.
  • Apply the technical and organizational measures described on our Security page: encryption at rest and in transit, workspace-scoped tenant isolation enforced at the query layer, least-privilege production access, hashed credentials, and an audit log of data-modifying actions.
  • Help you respond to data subject requests (access, rectification, erasure, portability, objection). Most of this is self-serve: account data is editable in the dashboard, exports are built in on every plan, and account deletion is self-serve.
  • Notify you without undue delay, and in any case within 72 hours of discovery, if a personal data breach affects your data, with enough detail for your own notification duties.
  • Assist you, to the extent reasonable for a service of this shape, with data protection impact assessments and consultations with supervisory authorities that concern our processing.
  • Delete your personal data when you delete your account or workspace, per the retention windows in the Privacy Policy, unless law requires us to keep a copy.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA: this page, the Security page, the subprocessor list, and written answers to reasonable security questionnaires. On-site audits are not a fit for a service of our size; we answer the questions instead, honestly.

4. Subprocessors

You give general authorization for the subprocessors listed at /legal/subprocessors. Each one is bound by data protection terms at least as protective as this DPA. We remain fully responsible to you for their performance.

We will email account owners at least 30 days before adding a new subprocessor. If you object on reasonable data-protection grounds and we cannot offer a workaround, you may cancel the affected service and we will refund any prepaid fees for the unused period.

5. International transfers

We are US-based and our subprocessors process data primarily in the United States. Where the GDPR applies to a transfer, the European Commission's Standard Contractual Clauses (Module Two: controller to processor, Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference, with us as data importer and you as data exporter. Annex I is completed by section 2 of this DPA, Annex II by the Security page, and Annex III by the subprocessor list. Where the UK GDPR applies, the UK International Data Transfer Addendum to the SCCs is incorporated the same way.

6. Liability and precedence

Liability under this DPA follows the limitations in the Terms of Service. If this DPA conflicts with the Terms on a data protection matter, this DPA wins; if it conflicts with the SCCs, the SCCs win.

7. Changes

If we materially change this DPA, we will email customers in advance and update the "Last updated" date above. Changes apply prospectively.

See also: Subprocessors · Privacy Policy · Security · Terms of Service.