Skip to content
Cu CopperMailer
How it works Product Pricing Docs Security Company Legal Polski Sign in Request access
Home/Data Processing Addendum

Data Processing Addendum

Effective date: 29 July 2026 · Last updated: 29 July 2026 · Version 1.0
This Addendum forms part of the Terms of Service and applies automatically whenever we process personal data on your behalf. A counter-signed PDF is available on request from legal@coppermailer.com.

In one sentence: for the content of the mailboxes you connect, you are the controller and CopperMailer is your processor, acting only on your instructions, under Article 28 GDPR.

1. Parties and scope

  1. This Addendum is between the customer identified in the account (“Controller”) and JC Establishment LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States (“Processor”).
  2. It applies to processing of personal data contained in Customer Data by the Processor in the course of providing the Service.
  3. Terms defined in the Terms of Service have the same meaning here. “GDPR” means Regulation (EU) 2016/679 and, where relevant, the UK GDPR as incorporated by the European Union (Withdrawal) Act 2018.
  4. In case of conflict between this Addendum and the Terms of Service on data protection matters, this Addendum prevails.

2. Details of processing (Art. 28(3))

Subject matterProvision of AI-assisted email reply automation.
DurationFor as long as the Controller’s account remains open, plus the deletion periods in clause 10.
Nature and purposeReceiving, storing, indexing, analysing and generating responses to email; routing, tagging, escalation, analytics, backup, support and security operations.
Types of personal dataNames, email addresses, telephone numbers, postal addresses, order and account references, message content and attachments, IP addresses and technical metadata: whatever the Controller’s correspondents include in their messages.
Categories of data subjectThe Controller’s customers, prospects, suppliers, employees and any other person who emails a connected mailbox.
Special categoriesNot intended. The Controller must not deliberately route special-category or criminal-offence data through the Service without first agreeing additional safeguards in writing. Where such data arrives incidentally in an inbound message, the Processor applies the same technical and organisational measures.

3. Processor obligations

The Processor shall:

  1. process personal data only on documented instructions from the Controller, including as to international transfers, unless required otherwise by EU or Member State law, in which case it will inform the Controller before processing, unless that law prohibits it on important grounds of public interest. Use of the Service in accordance with the documentation constitutes documented instruction;
  2. immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law;
  3. ensure that persons authorised to process the data are bound by confidentiality obligations that survive the end of their engagement, and are trained on data protection before access is granted;
  4. implement the technical and organisational measures in Annex A (clause 11) in accordance with Article 32;
  5. respect the conditions on sub-processing in clause 4;
  6. assist the Controller, by appropriate technical and organisational measures and insofar as possible, in fulfilling requests from data subjects exercising their rights under Chapter III;
  7. assist the Controller in complying with Articles 32 to 36 (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of processing and the information available;
  8. at the Controller’s choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless retention is required by law;
  9. make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits under clause 8.

4. Sub-processors

  1. The Controller grants a general written authorisation for the Processor to engage sub-processors.
  2. The current list is published in Annex B, below, and forms part of this Addendum.
  3. The Processor will notify the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the account’s notification address and by updating that page. Customers may subscribe to change notifications at privacy@coppermailer.com.
  4. The Controller may object on reasonable data-protection grounds within 30 days of notice. The parties will discuss in good faith; if no resolution is found, the Controller may terminate the affected part of the Service without penalty and receive a prorated refund of the unused prepaid fees.
  5. The Processor imposes on every sub-processor, by written contract, data protection obligations no less protective than those in this Addendum, and remains fully liable to the Controller for the sub-processor’s performance.

5. International transfers

  1. The Processor’s default hosting region is the United States. On request before onboarding, a workspace can be provisioned in the EU region (Germany) so that Customer Data is stored at rest within the European Economic Area.
  2. Where personal data is transferred outside the EEA, the Processor relies on Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses, which are incorporated into this Addendum by reference: Module Two (controller to processor) between the Controller and the Processor, and Module Three (processor to processor) between the Processor and its sub-processors.
  3. For the purposes of the SCCs: the docking clause applies; clause 9 option 2 (general written authorisation, 30 days) applies; clause 11 optional independent dispute resolution does not apply; clause 17 selects the law of Ireland; clause 18(b) selects the courts of Ireland. Annexes I, II and III are populated by clauses 2, 11 and Annex B respectively.
  4. The Processor is established in the United States and is the data importer under the SCCs. We have not appointed an Article 27 representative in the European Union, because we do not currently target the Service at consumers in the EEA; if that changes we will appoint one and name it here before doing so. EEA and UK customers can reach our privacy team directly at privacy@coppermailer.com.
  5. Transfer impact assessments are maintained and available on request. Supplementary measures include encryption in transit and at rest, pseudonymisation where feasible, and a policy of challenging overbroad government access requests and notifying the Controller unless legally prohibited.
  6. UK transfers use the UK International Data Transfer Addendum to the SCCs; Swiss transfers use the SCCs with the adaptations required by the FDPIC.

6. Data subject requests

  1. The Service provides self-service tools to search, export, correct and delete individual records, so the Controller can normally answer requests without our help.
  2. If a data subject contacts the Processor directly, the Processor will not respond substantively but will refer the request to the Controller without undue delay, and in any case within 5 business days.
  3. Additional assistance beyond the self-service tools is provided free of charge for reasonable volumes.

7. Personal data breach

  1. The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data.
  2. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, to the extent known, with updates as the investigation progresses.
  3. The Processor will not notify a supervisory authority or data subjects on the Controller’s behalf unless instructed to do so in writing.
  4. Notification is not an admission of fault or liability.

8. Audit rights

  1. The Processor makes available its security documentation and completes customer security questionnaires free of charge. It holds no third-party audit report and no penetration test summary today; both will be offered here once they exist.
  2. The Controller may request an audit no more than once in any 12-month period, on 30 days’ written notice, during business hours, without unreasonably disrupting the Processor’s operations, and subject to confidentiality. Where a recognised third-party report addresses the scope, that report satisfies the request.
  3. Additional audits, or audits following a confirmed material breach, may be conducted more frequently; the Controller bears reasonable costs of audits it initiates beyond the annual allowance.

9. Confidentiality and staff

Access to Customer Data by Processor personnel is limited to what is necessary to operate and support the Service, granted on a least-privilege basis, logged, and reviewed whenever a role changes. Support staff access production Customer Data only against a documented support request from the Controller. All personnel are bound by written confidentiality undertakings before access is granted.

10. Return and deletion

  1. The Controller may export Customer Data at any time in CSV and JSON.
  2. On termination, Customer Data remains available for export for 30 days, is then deleted from production systems, and rotates out of encrypted backups within a further 60 days.
  3. Earlier deletion is available on written request to privacy@coppermailer.com.
  4. The Processor may retain data where required by EU or Member State law, in which case it continues to protect it and processes it only for the purpose requiring retention.
  5. A certificate of deletion is issued on request.

11. Annex A: technical and organisational measures

  • Encryption. TLS 1.2+ in transit; AES-256 at rest for databases, object storage and backups; keys managed in a hosted KMS with rotation.
  • Access control. Mandatory MFA on all administrative accounts; role-based permissions; least privilege; access reviewed whenever a role changes and revoked immediately on departure.
  • Tenant isolation. Logical separation of Customer Data with tenant identifiers enforced at the data-access layer and tested automatically.
  • Network. Private subnets, security groups, WAF, DDoS protection, no public database endpoints, bastion-free administrative access via short-lived credentials.
  • Application security. Peer-reviewed code, dependency scanning, static analysis and secret scanning in CI, prompt-injection defences and output filtering. External penetration testing is planned but has not yet been commissioned.
  • Logging and monitoring. Centralised, append-only audit logs held in managed storage; alerting on anomalous access; 12-month retention.
  • Resilience. Automated encrypted daily backups, retained 30 days; multi-availability-zone deployment. Restores are tested before being relied on. We do not publish an RPO or RTO figure, because we have not yet run the failure drills that would let us stand behind one.
  • Incident response. Documented plan with defined severities; automated alerting; written post-incident reviews sent to affected customers. There is no 24×7 on-call rotation.
  • Vendor management. Security review before onboarding a sub-processor and annually thereafter.
  • People. Written confidentiality undertakings for everyone with production access, documented onboarding and offboarding, and security training before access is granted.
  • Data minimisation. Optional PII redaction before model inference; customer-configurable retention within a 12-month ceiling; no use of Customer Data for training shared or third-party models.

12. Liability and general

  1. Each party’s liability under this Addendum is subject to the limitations in clause 18 of the Terms of Service, except where the GDPR provides otherwise.
  2. This Addendum is governed by the laws of the State of Wyoming, United States, without prejudice to clause 5.3.
  3. If any provision is invalid, the remainder continues in force.
  4. Signature: this Addendum is incorporated by reference into the Terms of Service and requires no separate signature. A signed copy can be issued on request to legal@coppermailer.com.

13. Annex B: current sub-processors

Every party listed here is bound by a written data-processing agreement with obligations no less protective than those in this Addendum.

Change notice. We announce new or replacement sub-processors at least 30 days before they start processing, by email to your account notification address and by updating this Annex. To subscribe to notifications, email privacy@coppermailer.com with the subject “subprocessor updates”. You may object under clause 4.4 above.

Infrastructure and platform

Sub-processorPurposeData processedLocationTransfer mechanism
Amazon Web Services, Inc.Application hosting, databases, object storage, backupsAll Customer DataUSA (us-east-1) by default; Frankfurt (eu-central-1) for workspaces provisioned in our EU regionSCCs for EU-origin data held in the USA
Cloudflare, Inc.CDN, WAF, DDoS protection, DNSIP addresses, request metadataGlobal edgeSCCs
Postmark (ActiveCampaign, LLC)Transactional email delivery: receipts, alerts, notificationsRecipient email address, message contentUSASCCs

AI model providers

Sub-processorPurposeData processedLocationTraining / retention
Anthropic PBCReply generation, classification, summarisation, embeddings for knowledge-base retrievalMessage content and knowledge sources sent for inferenceUSA, with EU endpoints where availableCommercial API terms: submitted data is not used to train models. Retention is per Anthropic’s published API policy.

Business operations

Sub-processorPurposeData processedLocationTransfer mechanism
Stripe, Inc. / Stripe Payments Europe LtdPayment processing, invoicing, tax calculation, fraud preventionBilling name, address, email, VAT number, card token; card details captured directly by StripeIreland / USASCCs + DPF; independent controller for payments
Sentry (Functional Software, Inc.)Error monitoring; PII scrubbing enabledStack traces, technical metadata, scrubbed request contextUSA, EU region for EU workspacesSCCs

Affiliates

JC Establishment LLC has no parent, no subsidiaries and no affiliated companies. Nothing is processed by a related entity, because there is no related entity. If that ever changes, this Annex is updated with 30 days’ notice.

Optional integrations you control

If you connect Google Workspace, Microsoft 365, HubSpot, Shopify, Zapier or your own IMAP server, those platforms process your data under your own agreement with them. They are not our sub-processors; you are their customer and we act on your instruction to exchange data with them.

Change history

This is the first published version of this Annex, so there is nothing to report yet. Every future addition, replacement or removal will be recorded here with its date, and we will not backfill entries for periods before this Annex existed.

Cu CopperMailer

Customer-service software for shared support inboxes: it answers the mail your own customers send you. Licensed software, sold as one-time purchases and delivered to your account in seconds. It replies to messages already in your mailbox and has no way to start a conversation.

Business address

JC Establishment LLC
trading as CopperMailer
30 N Gould St, Ste N
Sheridan, WY 82801
United States
support@coppermailer.com
Registered in
State of Wyoming, United States
Business activity
Publisher and licensor of its own customer-service software (SaaS). Merchant category 5734 – computer software.
VisaMastercardAmerican ExpressDiscoverApple PayGoogle Pay

Card payments processed by Stripe. Prices are quoted in USD; where a local payment method settles in another currency – PLN for customers in Poland, for example – the exact amount is shown before you confirm.

Product

  • How it works
  • The interface
  • Features
  • API & documentation
  • Pricing
  • How credits work
  • Security

Legal & payments

  • Merchant information
  • Payments
  • Terms of Service
  • Privacy Policy
  • Return & Refund Policy
  • Acceptable Use Policy
  • Cookie Policy
  • Data Processing Addendum
  • Sub-processors
  • All legal documents

Company

  • Request an account
  • Sign in
  • About us
  • Company details
  • Contact & support
  • Support hours
  • Informacje po polsku
  • Billing enquiries
  • Report abuse
  • Security disclosure

JC Establishment LLC, a limited liability company organised under the laws of the State of Wyoming, United States, trading as CopperMailer, is the seller, the invoicing entity and the merchant of record for every purchase made on this site. Business address: 30 N Gould St, Ste N, Sheridan, WY 82801, United States. Customer service: support@coppermailer.com, Monday to Friday, 09:00 to 17:00 Mountain Time (17:00 to 01:00 CET).

What we sell: licences and usage of our own cloud-hosted customer-service software, which drafts replies to email that our customers’ own correspondents have sent them. Software publishing, merchant category 5734; NAICS 511210, PKD 58.29.Z. Everything here is our own product, sold by us to the person who uses it, delivered digitally and immediately; no physical goods, no third-party sales and no money handled on anyone else’s behalf. See Business classification.

All prices are quoted, charged and refunded in United States dollars. Every purchase is a single charge that appears on your statement as JC Establishment – the legal name of the company behind CopperMailer, so you recognise it when it lands. There are no subscriptions, no renewals, no automatic top-ups and no handling or processing fees. Access is delivered digitally and applied to your account immediately on payment; no physical goods are sold or shipped. Card payments are processed by Stripe on Stripe-hosted fields, and CopperMailer never receives or stores full card numbers.

Terms of Service · Privacy Policy · Return & Refund Policy · Payments · Acceptable Use Policy · Cookie Policy · Business classification · Company details · Information for payment providers · Informacje dla klientów z Polski
Customer service: support@coppermailer.com · Billing and refunds: billing@coppermailer.com · Monday to Friday, 09:00 to 17:00 Mountain Time (17:00 to 01:00 CET)

© 2026 JC Establishment LLC. All rights reserved. CopperMailer is a trading name of JC Establishment LLC, a Wyoming limited liability company