Data processing agreement
Art. 28 GDPR terms for personal data processed on your organisation’s behalf.
Updated 15 August 2026
Draft pending legal review. Placeholders in brackets must be completed before publication.
1. Roles
Your organisation is the controller of personal data contained in connected mailboxes and derived records. [Legal entity name] is the processor and processes that data only on documented instructions from the controller, of which these terms and the use of the service form part.
2. Subject matter and duration
Subject matter: provision of the OVIOO workspace — email, references, tasks, documents and related AI features. Duration: the term of the subscription plus the 30-day retention window.
3. Nature and purpose
- Synchronising, storing and displaying mail and attachments.
- Producing suggestions: TODOs, reference matches, tags, summaries and drafts, where enabled.
- Search, audit logging, backup and support.
4. Categories of data and data subjects
- Data subjects: the controller’s staff, its customers, suppliers and anyone who corresponds with the connected mailboxes.
- Data: names, contact details, message content and metadata, attachments, and any personal data those contain.
- No special-category data is required by the service; if the controller processes it, it does so on its own responsibility.
5. Confidentiality
Personnel with access are bound by confidentiality obligations and receive access on a least-privilege, logged basis.
6. Security
We implement appropriate technical and organisational measures, including encryption in transit and at rest, per-organisation isolation, encrypted credential storage, session revocation, audit logging and access control. See the security page.
7. Subprocessors
The controller authorises the subprocessors listed on the subprocessors page. We will give at least 30 days notice before adding or replacing one, and the controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the controller may terminate the affected service.
8. Data subject requests
We assist the controller in responding to access, correction, deletion, restriction, portability and objection requests, taking into account the nature of the processing and the information available to us.
9. Personal data breach
We notify the controller without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting its data, with the information available at the time.
10. Audits
On reasonable notice and no more than once per year (unless required by a supervisory authority), we will make available the information necessary to demonstrate compliance and cooperate with audits, subject to confidentiality and reasonable cost.
11. International transfers
Where personal data is transferred outside the EEA, the parties rely on the EU Standard Contractual Clauses, which are incorporated by reference, with the roles and annexes populated by this agreement.
12. Deletion and return
On termination the controller may export its data. After the 30-day retention window we delete it, except where storage is required by law.