Effective Date: September 1, 2026 • Standard Contractual Clauses (SCCs) Included
1
Preamble & Relationship to Main Agreement
This Data Processing Agreement (“DPA”) governs the processing of Personal Data by MAILARCH LTD (trading as “mailarch.io”, Company No. 17444844, registered in England and Wales) (“MailArch”, “Processor”) on behalf of the customer subscribing to or utilizing the MailArch services (“Customer”, “Controller”).
This DPA supplements and is incorporated into the MailArch Terms of Service or any applicable Master Services Agreement (“Principal Agreement”). By connecting your Microsoft 365 tenant or executing a subscription with MailArch, Customer enters into this DPA on behalf of itself and its authorized corporate affiliates.
Automatic Applicability & Enterprise Execution
This DPA applies automatically to all tenants processing Personal Data protected by European, UK, Swiss, or United States data privacy laws. Enterprise customers requiring a countersigned bilateral DPA may request an executed PDF copy by contacting info@mailarch.io.
2
Definitions
Capitalized terms used in this DPA shall have the following meanings:
“Applicable Data Protection Law” means all worldwide data protection and privacy laws applicable to the processing of Personal Data under this Agreement, including the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK Data Protection Act 2018 and UK GDPR (“UK Data Protection Law”), the Swiss Federal Act on Data Protection (“FADP”), and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”).
“Customer Personal Data” means any Personal Data contained within email messages, attachments, headers, or Microsoft 365 directory profiles processed by MailArch on behalf of Customer.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, and “Processing” shall have the meanings given in the GDPR.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 (Module 2: Controller-to-Processor).
“Sub-processor” means any third-party data processor engaged by MailArch to assist in fulfilling its processing obligations under this Agreement.
3
Roles of the Parties & Documented Instructions
Party Roles: The parties acknowledge and agree that with respect to Customer Personal Data, Customer is the Controller (or a processor acting on behalf of third-party controllers) and MailArch is the Processor.
Documented Instructions: MailArch shall process Customer Personal Data solely:
To provide the attachment scanning, offloading, stubbing, and retrieval services as described in the Principal Agreement.
In accordance with Customer’s documented configuration policies configured within the MailArch administration dashboard (e.g., minimum attachment size, age thresholds, excluded file formats).
As required by applicable statutory law to which MailArch is subject, in which case MailArch will notify Customer prior to such processing (unless prohibited by law on important grounds of public interest).
MailArch will immediately inform Customer if, in its reasonable opinion, any instruction received from Customer infringes Applicable Data Protection Law.
4
Confidentiality & Personnel Controls
MailArch ensures that all personnel, contractors, and engineers who have access to or process Customer Personal Data:
Are bound by enforceable written confidentiality commitments or statutory obligations of confidentiality.
Have received rigorous training regarding data security, privacy principles, and least-privilege administrative access.
Are subject to zero-trust access controls, requiring Multi-Factor Authentication (MFA) and just-in-time administrative authorization.
5
Technical & Organizational Measures (TOMs)
MailArch implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or unauthorized disclosure.
Core Security Standards
Encryption at Rest: AES-256 bit encryption on all sovereign storage volumes, databases, and backup archives.
Encryption in Transit: TLS 1.3 enforced across all Microsoft Graph API calls, internal messaging queues, and web download interfaces.
Tenant Isolation: Logical and cryptographic separation between tenant data spaces. Cross-tenant access is architecturally impossible.
Zero-Trust Identity: Single sign-on authentication enforced via Microsoft Entra ID (Azure AD). When a user account is deactivated in Microsoft 365, attachment download permissions cease immediately.
Detailed specifications of our Technical and Organizational Measures are outlined in Annex II of this DPA.
6
Authorized Sub-processors
General Authorization: Customer grants MailArch general written authorization to engage the Sub-processors listed in Annex III to process Customer Personal Data.
Sub-processor Obligations: MailArch imposes data protection terms on each Sub-processor that are no less protective than those set forth in this DPA. MailArch remains fully responsible and liable to Customer for the performance of each Sub-processor’s obligations.
Notice of New Sub-processors: MailArch will notify Customer at least thirty (30) days prior to authorizing any new or replacement Sub-processor via email or in-app notice. Customer may reasonably object to such appointment in writing within fifteen (15) days on objective data protection grounds. If the parties cannot resolve the objection within thirty (30) days, Customer may terminate the affected service without penalty.
7
Assistance with Data Subject Rights
Taking into account the nature of the processing, MailArch shall assist Customer through appropriate technical measures, insofar as possible, to fulfill Customer’s obligation to respond to requests from Data Subjects exercising their statutory rights under Chapter III of the GDPR (e.g., right of access, rectification, erasure, restriction, portability, or objection).
If MailArch receives a request directly from a Data Subject concerning Customer Personal Data, MailArch will prompt the Data Subject to submit their request directly to Customer, and notify Customer without undue delay.
8
Personal Data Breach Notification
MailArch will notify Customer in writing without undue delay and, in any event, within 48 hours of becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The breach notification will include, at minimum:
A description of the nature of the security incident and affected data categories.
The approximate number of Data Subjects and mailbox accounts impacted.
The name and contact details of MailArch’s security officer or privacy contact.
The likely consequences of the incident and remediation measures implemented or proposed.
MailArch will take immediate and reasonable steps to contain and mitigate the effects of the incident and cooperate fully with Customer’s regulatory notification duties under Articles 33 and 34 of the GDPR.
9
Data Protection Impact Assessments (DPIAs)
MailArch shall provide reasonable assistance to Customer with any data protection impact assessments (DPIAs) and prior consultations with competent supervisory authorities required under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and information available to MailArch.
10
Deletion, Return & 30-Day Grace Period
Post-Termination Re-hydration Window
Upon termination of the Principal Agreement, MailArch provides an automated thirty (30) day post-termination grace period during which Customer may export all archived attachment binaries or initiate automated re-hydration back into Exchange Online.
Following the expiration of the 30-day grace period, MailArch shall securely delete and cryptographically overwrite all existing copies of Customer Personal Data from production object storage and database repositories, unless Applicable Data Protection Law requires continued statutory retention.
11
Audits & Compliance Demonstrations
MailArch shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits conducted by Customer or an independent auditor mandated by Customer.
To satisfy audit requests while preserving multi-tenant security, MailArch may provide its SOC 2 reports, third-party security penetration test summaries, and compliance attestations. Any on-site audit shall occur during normal business hours, upon at least thirty (30) business days written notice, and subject to reasonable confidentiality procedures.
12
International Cross-Border Data Transfers
Data Residency First: MailArch enforces regional sovereign data storage boundaries based on Customer’s configured storage region (Belgium EU, London UK, Frankfurt DE, Iowa US, South Carolina US, Taiwan APAC). Customer Personal Data is not transferred outside the designated geographical boundary.
Standard Contractual Clauses: Where a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of data protection occurs, the parties agree that:
The EU SCCs (Module 2: Controller-to-Processor) are hereby incorporated by reference, with Customer as “data exporter” and MailArch as “data importer”.
For UK transfers, the UK International Data Transfer Addendum to the EU SCCs applies.
For Swiss transfers, references to the GDPR shall be deemed to reference the Swiss Federal Act on Data Protection (FADP).
13
California Consumer Privacy Act (CCPA / CPRA) Addendum
With respect to Personal Information subject to the CCPA/CPRA, MailArch certifies that it acts solely as a “Service Provider” and:
Shall not “sell” or “share” Customer Personal Information (as those terms are defined under the CCPA/CPRA).
Shall not retain, use, or disclose Customer Personal Information for any purpose other than for the business purposes specified in the Principal Agreement.
Shall not retain, use, or disclose Customer Personal Information outside of the direct business relationship between MailArch and Customer.
Shall not combine Customer Personal Information with personal information received from or on behalf of any other party, except as permitted by the CCPA and regulations.
I
Annex I: Processing Details & Data Categories
Subject Matter
Automated cloud-native attachment offloading, storage, indexing, and stubbing for Microsoft 365 Exchange Online mailboxes.
Duration
Duration of the Principal Agreement plus thirty (30) days for re-hydration/data export.
Nature & Purpose
Reading attachments via Microsoft Graph API, archiving files in encrypted sovereign cloud storage, replacing messages with lightweight stubs, and authenticating user downloads via Microsoft Entra ID.
Categories of Data Subjects
Employees, contractors, partners, customers, and third-party correspondents who send or receive emails to/from Customer’s Microsoft 365 mailboxes.
Customer determines what files users transmit via corporate email. MailArch does not systematically scan for or filter special category data; all files are encrypted uniformly with AES-256.
II
Annex II: Technical & Organizational Measures (TOMs)
Pseudonymization & Encryption: AES-256 symmetric encryption for data at rest; TLS 1.3 enforced for data in transit with forward secrecy.
Confidentiality & Integrity: Principle of least privilege, strict RBAC, automated code analysis, multi-tenant database isolation.
Resilience & Availability: Multi-zone replication across sovereign data centers, automated health checks, 99.9% uptime target.
Access Control: MFA required for all engineering personnel, zero shared credentials, centralized Microsoft Entra ID SAML/OIDC SSO.
Auditing & Logging: Comprehensive audit trails logging message ID, user identity, file hash, timestamp, and IP address for all attachment interactions.
III
Annex III: Authorized Sub-processors
Sub-processor
Service Provided
Processing Location
Google Cloud Platform (Google LLC)
Sovereign cloud compute, serverless runners, and regional object storage buckets
Designated Customer Storage Region (Belgium, London, Frankfurt, US, APAC)
Microsoft Corporation (Azure & Entra ID)
OAuth identity verification, Graph API synchronization, and optional customer BYOS storage
Customer Tenant Region
Stripe Payments Europe, Ltd.
Payment tokenization and billing recurring subscription charges
Ireland / United States (Billing details only; no email contents)
Processor Entity: MAILARCH LTD (Company No. 17444844, registered in England and Wales)
Registered Office: 31 Courtfield Rise, West Wickham, England, BR4 9BD