Data Processing Addendum
In one sentence: for the content of the mailboxes you connect, you are the controller and CopperMailer is your processor, acting only on your instructions, under Article 28 GDPR.
1. Parties and scope
- This Addendum is between the customer identified in the account (“Controller”) and JC Establishment LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States (“Processor”).
- It applies to processing of personal data contained in Customer Data by the Processor in the course of providing the Service.
- Terms defined in the Terms of Service have the same meaning here. “GDPR” means Regulation (EU) 2016/679 and, where relevant, the UK GDPR as incorporated by the European Union (Withdrawal) Act 2018.
- In case of conflict between this Addendum and the Terms of Service on data protection matters, this Addendum prevails.
2. Details of processing (Art. 28(3))
| Subject matter | Provision of AI-assisted email reply automation. |
|---|---|
| Duration | For as long as the Controller’s account remains open, plus the deletion periods in clause 10. |
| Nature and purpose | Receiving, storing, indexing, analysing and generating responses to email; routing, tagging, escalation, analytics, backup, support and security operations. |
| Types of personal data | Names, email addresses, telephone numbers, postal addresses, order and account references, message content and attachments, IP addresses and technical metadata: whatever the Controller’s correspondents include in their messages. |
| Categories of data subject | The Controller’s customers, prospects, suppliers, employees and any other person who emails a connected mailbox. |
| Special categories | Not intended. The Controller must not deliberately route special-category or criminal-offence data through the Service without first agreeing additional safeguards in writing. Where such data arrives incidentally in an inbound message, the Processor applies the same technical and organisational measures. |
3. Processor obligations
The Processor shall:
- process personal data only on documented instructions from the Controller, including as to international transfers, unless required otherwise by EU or Member State law, in which case it will inform the Controller before processing, unless that law prohibits it on important grounds of public interest. Use of the Service in accordance with the documentation constitutes documented instruction;
- immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law;
- ensure that persons authorised to process the data are bound by confidentiality obligations that survive the end of their engagement, and are trained on data protection before access is granted;
- implement the technical and organisational measures in Annex A (clause 11) in accordance with Article 32;
- respect the conditions on sub-processing in clause 4;
- assist the Controller, by appropriate technical and organisational measures and insofar as possible, in fulfilling requests from data subjects exercising their rights under Chapter III;
- assist the Controller in complying with Articles 32 to 36 (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of processing and the information available;
- at the Controller’s choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless retention is required by law;
- make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits under clause 8.
4. Sub-processors
- The Controller grants a general written authorisation for the Processor to engage sub-processors.
- The current list is published in Annex B, below, and forms part of this Addendum.
- The Processor will notify the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the account’s notification address and by updating that page. Customers may subscribe to change notifications at privacy@coppermailer.com.
- The Controller may object on reasonable data-protection grounds within 30 days of notice. The parties will discuss in good faith; if no resolution is found, the Controller may terminate the affected part of the Service without penalty and receive a prorated refund of the unused prepaid fees.
- The Processor imposes on every sub-processor, by written contract, data protection obligations no less protective than those in this Addendum, and remains fully liable to the Controller for the sub-processor’s performance.
5. International transfers
- The Processor’s default hosting region is the United States. On request before onboarding, a workspace can be provisioned in the EU region (Germany) so that Customer Data is stored at rest within the European Economic Area.
- Where personal data is transferred outside the EEA, the Processor relies on Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses, which are incorporated into this Addendum by reference: Module Two (controller to processor) between the Controller and the Processor, and Module Three (processor to processor) between the Processor and its sub-processors.
- For the purposes of the SCCs: the docking clause applies; clause 9 option 2 (general written authorisation, 30 days) applies; clause 11 optional independent dispute resolution does not apply; clause 17 selects the law of Ireland; clause 18(b) selects the courts of Ireland. Annexes I, II and III are populated by clauses 2, 11 and Annex B respectively.
- The Processor is established in the United States and is the data importer under the SCCs. We have not appointed an Article 27 representative in the European Union, because we do not currently target the Service at consumers in the EEA; if that changes we will appoint one and name it here before doing so. EEA and UK customers can reach our privacy team directly at privacy@coppermailer.com.
- Transfer impact assessments are maintained and available on request. Supplementary measures include encryption in transit and at rest, pseudonymisation where feasible, and a policy of challenging overbroad government access requests and notifying the Controller unless legally prohibited.
- UK transfers use the UK International Data Transfer Addendum to the SCCs; Swiss transfers use the SCCs with the adaptations required by the FDPIC.
6. Data subject requests
- The Service provides self-service tools to search, export, correct and delete individual records, so the Controller can normally answer requests without our help.
- If a data subject contacts the Processor directly, the Processor will not respond substantively but will refer the request to the Controller without undue delay, and in any case within 5 business days.
- Additional assistance beyond the self-service tools is provided free of charge for reasonable volumes.
7. Personal data breach
- The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data.
- The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, to the extent known, with updates as the investigation progresses.
- The Processor will not notify a supervisory authority or data subjects on the Controller’s behalf unless instructed to do so in writing.
- Notification is not an admission of fault or liability.
8. Audit rights
- The Processor makes available its security documentation and completes customer security questionnaires free of charge. It holds no third-party audit report and no penetration test summary today; both will be offered here once they exist.
- The Controller may request an audit no more than once in any 12-month period, on 30 days’ written notice, during business hours, without unreasonably disrupting the Processor’s operations, and subject to confidentiality. Where a recognised third-party report addresses the scope, that report satisfies the request.
- Additional audits, or audits following a confirmed material breach, may be conducted more frequently; the Controller bears reasonable costs of audits it initiates beyond the annual allowance.
9. Confidentiality and staff
Access to Customer Data by Processor personnel is limited to what is necessary to operate and support the Service, granted on a least-privilege basis, logged, and reviewed whenever a role changes. Support staff access production Customer Data only against a documented support request from the Controller. All personnel are bound by written confidentiality undertakings before access is granted.
10. Return and deletion
- The Controller may export Customer Data at any time in CSV and JSON.
- On termination, Customer Data remains available for export for 30 days, is then deleted from production systems, and rotates out of encrypted backups within a further 60 days.
- Earlier deletion is available on written request to privacy@coppermailer.com.
- The Processor may retain data where required by EU or Member State law, in which case it continues to protect it and processes it only for the purpose requiring retention.
- A certificate of deletion is issued on request.
11. Annex A: technical and organisational measures
- Encryption. TLS 1.2+ in transit; AES-256 at rest for databases, object storage and backups; keys managed in a hosted KMS with rotation.
- Access control. Mandatory MFA on all administrative accounts; role-based permissions; least privilege; access reviewed whenever a role changes and revoked immediately on departure.
- Tenant isolation. Logical separation of Customer Data with tenant identifiers enforced at the data-access layer and tested automatically.
- Network. Private subnets, security groups, WAF, DDoS protection, no public database endpoints, bastion-free administrative access via short-lived credentials.
- Application security. Peer-reviewed code, dependency scanning, static analysis and secret scanning in CI, prompt-injection defences and output filtering. External penetration testing is planned but has not yet been commissioned.
- Logging and monitoring. Centralised, append-only audit logs held in managed storage; alerting on anomalous access; 12-month retention.
- Resilience. Automated encrypted daily backups, retained 30 days; multi-availability-zone deployment. Restores are tested before being relied on. We do not publish an RPO or RTO figure, because we have not yet run the failure drills that would let us stand behind one.
- Incident response. Documented plan with defined severities; automated alerting; written post-incident reviews sent to affected customers. There is no 24×7 on-call rotation.
- Vendor management. Security review before onboarding a sub-processor and annually thereafter.
- People. Written confidentiality undertakings for everyone with production access, documented onboarding and offboarding, and security training before access is granted.
- Data minimisation. Optional PII redaction before model inference; customer-configurable retention within a 12-month ceiling; no use of Customer Data for training shared or third-party models.
12. Liability and general
- Each party’s liability under this Addendum is subject to the limitations in clause 18 of the Terms of Service, except where the GDPR provides otherwise.
- This Addendum is governed by the laws of the State of Wyoming, United States, without prejudice to clause 5.3.
- If any provision is invalid, the remainder continues in force.
- Signature: this Addendum is incorporated by reference into the Terms of Service and requires no separate signature. A signed copy can be issued on request to legal@coppermailer.com.
13. Annex B: current sub-processors
Every party listed here is bound by a written data-processing agreement with obligations no less protective than those in this Addendum.
Change notice. We announce new or replacement sub-processors at least 30 days before they start processing, by email to your account notification address and by updating this Annex. To subscribe to notifications, email privacy@coppermailer.com with the subject “subprocessor updates”. You may object under clause 4.4 above.
Infrastructure and platform
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Application hosting, databases, object storage, backups | All Customer Data | USA (us-east-1) by default; Frankfurt (eu-central-1) for workspaces provisioned in our EU region | SCCs for EU-origin data held in the USA |
| Cloudflare, Inc. | CDN, WAF, DDoS protection, DNS | IP addresses, request metadata | Global edge | SCCs |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery: receipts, alerts, notifications | Recipient email address, message content | USA | SCCs |
AI model providers
| Sub-processor | Purpose | Data processed | Location | Training / retention |
|---|---|---|---|---|
| Anthropic PBC | Reply generation, classification, summarisation, embeddings for knowledge-base retrieval | Message content and knowledge sources sent for inference | USA, with EU endpoints where available | Commercial API terms: submitted data is not used to train models. Retention is per Anthropic’s published API policy. |
Business operations
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Stripe, Inc. / Stripe Payments Europe Ltd | Payment processing, invoicing, tax calculation, fraud prevention | Billing name, address, email, VAT number, card token; card details captured directly by Stripe | Ireland / USA | SCCs + DPF; independent controller for payments |
| Sentry (Functional Software, Inc.) | Error monitoring; PII scrubbing enabled | Stack traces, technical metadata, scrubbed request context | USA, EU region for EU workspaces | SCCs |
Affiliates
JC Establishment LLC has no parent, no subsidiaries and no affiliated companies. Nothing is processed by a related entity, because there is no related entity. If that ever changes, this Annex is updated with 30 days’ notice.
Optional integrations you control
If you connect Google Workspace, Microsoft 365, HubSpot, Shopify, Zapier or your own IMAP server, those platforms process your data under your own agreement with them. They are not our sub-processors; you are their customer and we act on your instruction to exchange data with them.
Change history
This is the first published version of this Annex, so there is nothing to report yet. Every future addition, replacement or removal will be recorded here with its date, and we will not backfill entries for periods before this Annex existed.