InboxMon

Legal

Data Processing Addendum

Last updated: 16 August 2026

This Data Processing Addendum (DPA) is part of the Terms of Service between you (the Controller) and InboxMon (the Processor) when you use the Service to process personal data that is subject to the GDPR, UK GDPR, or a similar law. It prevails over the Terms only where they conflict on processing of that Customer Data. Capitalized terms follow the Terms unless defined here.

1. Subject and roles

You determine the purposes of processing Customer Data (ESP event data, VIP and hygiene lists, and mail delivered to a dedicated monitoring inbox you created). We process that data only to provide, secure, and support the Service, including subprocessors in Section 5. We do not decide why you monitor a domain or which addresses you whitelist.

Account data (your login and billing) is outside this DPA; we are controller of that data under the Privacy Policy.

2. Instructions

You instruct us to process Customer Data as the product does when you use it (ingest webhooks you point at us, store and display events, run detection you enable, receive mail sent to your monitoring alias, send alerts to channels you configure). Additional written instructions must be feasible in the product. We will tell you if an instruction appears unlawful.

3. Confidentiality and personnel

We require persons authorized to process Customer Data to keep it confidential and to access it only as needed for the Service.

4. Security

We implement commercially reasonable technical and organizational measures appropriate to the nature of a monitoring SaaS (encryption in transit, authentication, tenant scoping in the application, logging). You are responsible for workspace access, MFA, and secrecy of webhook and Slack URLs.

5. Subprocessors

You authorize the following categories and current providers:

  • Vercel — application hosting
  • Supabase — database and authentication
  • Inngest — asynchronous processing
  • Cloudflare — inbound routing for monitoring aliases
  • Stripe — payment processing if you pay
  • Resend or equivalent, Twilio, Slack — only if you enable those alert channels

Your ESPs are not our subprocessors. We may replace a subprocessor with one in the same category. We will keep the list on this page current. If GDPR applies, you may object to a new subprocessor for reasonable data-protection reasons within 14 days of the list change; if we cannot accommodate the objection, either party may terminate the affected Service as the sole remedy.

6. International transfers

You authorize transfers of Customer Data to countries where we or subprocessors operate, including India (importer) and the countries of the subprocessors in Section 5. Where Chapter V GDPR (or UK equivalent) requires a transfer tool, Module Two of the European Commission Standard Contractual Clauses (controller to processor, Decision 2021/914) and the UK addendum if required apply. You are the data exporter. We are the data importer, established in Thane, Maharashtra, India. The clauses are completed by this DPA (including Section 11) and the Privacy Policy — not by a blank incorporation.

7. Assistance

Taking into account the nature of processing, we will assist you with reasonable requests relating to data-subject rights, DPIAs, and consultations with authorities, insofar as the product exposes the data. We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data, with information we can reasonably provide.

8. Return and deletion

During the subscription you may export features the product provides (for example hygiene lists). After the Service ends we will delete or de-identify Customer Data within a reasonable period, except backups that expire on a rolling cycle or records we must keep by law. A dedicated monitoring inbox is not an archive; plan retention may delete older captures while the account is still open.

9. Audits

You may request, no more than once per 12 months and on 30 days' notice, a written summary of our security measures. On-site audits are not offered unless required by a supervisory authority or a mandatory statute. Confidentiality applies to anything you receive.

10. Liability

Liability under this DPA is subject to the limitations and exclusions in the Terms, including the cap (and zero cap if you have paid nothing), except where a statute makes that limitation unenforceable for that claim.

11. SCC annex information

  • Importer. Operator of InboxMon. Place of business: Thane, Maharashtra, India. Contact: hello@inboxmon.com.
  • Data subjects. Your workspace users; recipients reflected in ESP events you send us; senders and others whose mail is addressed to a monitoring alias you created.
  • Categories of data. Account identifiers; ESP event metadata and hashed recipient identifiers; VIP and hygiene lists you enter; headers and bodies of mail to your monitoring alias; alert-channel URLs you configure.
  • Frequency and purpose. Continuous, to provide the Service as you use it (ingest, detect, display, alert).
  • Retention. Plan caps and product jobs (for example 14-day raw webhook payloads, monitoring-inbox history by plan, drop of SMTP event partitions older than three months). Account data until the workspace is deleted plus records we must keep by law.
  • Security. Section 4. Subprocessors: Section 5. Competent supervisory authority: as determined under the SCCs for the exporter.