Effective Date: September 1, 2026 • Last Revised: September 7, 2026
1
Acceptance of Terms
These Terms of Service (“Terms”, “Agreement”) constitute a legally binding agreement between MAILARCH LTD (trading as “mailarch.io”, Company No. 17444844, registered in England and Wales) (“MailArch”, “we”, “us”, or “our”) and the business entity, organization, or person (“Customer”, “you”, or “your”) accessing or using the MailArch platform, services, software, website, and APIs.
By clicking “Connect with Microsoft 365”, creating an account, authorizing Microsoft Entra ID consent, or otherwise accessing the service, you affirm that:
You have read, understood, and agreed to be bound by this Agreement.
You have full legal authority to bind your organization or Microsoft 365 tenant to these Terms.
You will comply with all applicable local, national, and international laws and regulations.
If you do not have such authority or do not agree with any part of these Terms, you must not accept this Agreement and must not access or use MailArch.
2
Service Description & Cloud Architecture
MailArch provides an automated, cloud-native email attachment offloading and stubbing platform purpose-built for Microsoft 365 Exchange Online environments.
The service functions through cloud-to-cloud Microsoft Graph API automation:
Mailbox Analysis: Enumerates Microsoft 365 mailboxes and calculates attachment storage volume, storage quotas, and candidate emails according to customer-configured policies.
Attachment Offloading: Safely transfers email attachment binaries meeting specified size and age criteria from Exchange Online mailboxes to secure, sovereign cloud object storage.
Lightweight Stubbing: Modifies target email messages in Exchange Online by removing the bulky attachment binary and inserting a lightweight, cryptographically signed HTML stub and retrieval link.
Desktop Search Preservation: Preserves original metadata and provides indexable summaries to ensure full-text search capability remains seamless in Outlook Desktop, Web, and Mobile.
3
Microsoft 365 Authentication & Permissions
MailArch operates on the principle of least privilege using Microsoft Entra ID (Azure Active Directory) OAuth 2.0 consent:
Read-Only Analysis Mode: Uses User.Read.All and Reports.Read.All to aggregate tenant mailbox utilization without accessing email message bodies or attachments.
Active Offloading Mode: Requires explicit administrator consent for Mail.ReadWrite and offline_access to read attachment binaries, transfer them to sovereign storage, and replace them with stub references in background execution queues.
You represent and warrant that your administrator has valid tenant-level administrative authority to grant these Microsoft Graph API permissions on behalf of all affected mailbox users. You may revoke MailArch’s Microsoft Entra ID Enterprise Application permissions at any time directly through the Microsoft Entra Admin Center.
4
Scope of Use & Strict Attachment-Only Restriction
MailArch is engineered strictly as an email attachment offloading and archiving pipeline for Microsoft 365 mailboxes.
Strict File Scope & Authorized Use Guardrail
Storage capacity and API bandwidth provided by MailArch are strictly reserved for legitimate email attachments processed automatically via your authorized Microsoft Graph API integration. Using MailArch as a general-purpose file hosting repository, media distribution network (CDN), FTP endpoint, backup target for unassociated files, or arbitrary object storage is strictly prohibited and constitutes a material breach of this Agreement.
You further agree not to:
Circumvent or attempt to circumvent authentication mechanisms, download token signatures, or rate limits.
Reverse engineer, decompile, or disassemble any part of the MailArch service or software.
Use the service to process, store, or transmit malicious code, malware, spyware, or unlawful material.
Interfere with or disrupt the integrity or performance of MailArch services or underlying cloud infrastructure.
5
Fair Use Policy, Capacity Tiers & Ingestion Limits
Subscriptions are structured into capacity tiers designed for SMBs, MSPs, and enterprises:
Tier
Included Storage
Mailbox Capacity
Target Environment
Starter
1 TB Archive Storage
Up to 3 Active Mailboxes
Solo practitioners & small offices
Growth
3 TB Archive Storage
Up to 15 Active Mailboxes
Growing businesses & targeted teams
Business Pro
10 TB Archive Storage
Up to 250 Active Mailboxes
Full SMB tenants & medium businesses
Enterprise / Custom
Custom Capacity / BYOS
250+ Mailboxes
Dedicated MSAs, custom DPAs, SLAs
Ingestion Queue & Microsoft Graph Throttling Controls
To prevent Microsoft Graph API 429 throttling and ensure smooth, non-disruptive mailbox synchronization, MailArch employs automated rate smoothing and daily batch quotas (default 1,000 emails/day per tenant, configurable up to 5,000/day). Customer agrees to adhere to scheduled ingestion queues during initial historical mailbox migrations.
Tenants exceeding 250 active mailboxes must be provisioned under an Enterprise agreement with custom throughput planning and security architecture.
6
Customer Data Ownership & Limited Processing License
Zero Customer Data Ownership Claimed
As between Customer and MailArch, Customer retains 100% exclusive ownership, right, title, and interest in and to all emails, attachments, metadata, and files processed or stored (“Customer Data”). MailArch claims zero proprietary rights in your content.
Customer grants MailArch only a limited, non-exclusive, worldwide, royalty-free license to access, encrypt, transmit, store, and re-hydrate Customer Data solely to the extent necessary to perform the attachment offloading and stubbing services requested by Customer.
MailArch will never monetize, sell, distribute, train artificial intelligence models on, or disclose Customer Data to third parties, except as strictly required by law or as expressly authorized under your Data Processing Agreement (DPA).
7
Security, Encryption & Sovereign Data Residency
MailArch adheres to zero-trust enterprise security practices:
Encryption: Customer Data is encrypted at rest using AES-256 and in transit using TLS 1.3 across all communication channels.
Tenant Isolation: Customer Data is isolated using per-tenant cryptographic namespaces. Cross-tenant access is architecturally segregated.
Single Sign-On Authentication: Attachment download and re-hydration endpoints authenticate users via Microsoft Entra ID SSO. When a user is disabled or offboarded in Microsoft 365, their access to archived attachments terminates immediately.
Sovereign Data Residency: Customer selects their jurisdictional storage region upon tenant setup (e.g., Belgium EU europe-west1, London UK europe-west2, Frankfurt DE europe-west3, Iowa US us-central1, South Carolina US us-east1, Taiwan APAC asia-east1). Customer Data is never relocated outside the chosen region.
Regulatory Compliance: The platform is designed to support customer compliance with EU GDPR, UK Data Protection Act 2018, SEC Rule 17a-4 / CFTC (WORM object locking where enabled), and Microsoft Purview litigation holds.
8
Bring Your Own Storage (BYOS)
Enterprise customers and Managed Service Providers with dedicated Azure commitments (MACC) may opt for Bring Your Own Storage (BYOS).
Under BYOS, attachments are transferred directly into Azure Blob storage containers hosted within Customer’s or MSP’s own cloud subscription.
Customer retains primary physical custody and billing responsibility for the underlying cloud storage container.
Customer is responsible for maintaining necessary IAM permissions and bucket lifecycle policies required for MailArch to read and write stubs.
Free Discovery Scans & Trials: MailArch may offer a free mailbox scanning period or trial to assess potential storage savings. No payment credentials are required to execute a read-only assessment scan.
Subscription Fees: Paid subscriptions are billed in advance on a recurring monthly or annual basis in the designated currency (USD, EUR, or GBP) via credit card or approved invoice.
Price Adjustments: We reserve the right to revise subscription fees upon at least thirty (30) days prior written notice. Continued use following the effective date of a price adjustment constitutes acceptance.
Cancellation: You may cancel your subscription at any time through your dashboard or by notifying support@mailarch.io. Cancellations take effect at the conclusion of the current prepaid billing period. Pre-paid subscription fees are non-refundable except where required by applicable statutory law.
10
Termination, Data Export & 30-Day Grace Period
Either party may terminate this Agreement if the other party materially breaches any provision and fails to cure such breach within thirty (30) days of receiving written notice.
30-Day Re-hydration & Data Export Guarantee
Upon termination or cancellation of your subscription, MailArch provides a thirty (30) day post-termination grace period during which your archived attachments remain intact. Customer may request a bulk export archive or execute an automated re-hydration process to restore offloaded attachments directly back into Exchange Online mailboxes.
Following the expiration of the 30-day grace period, MailArch will permanently delete all stored Customer Data and cryptographic keys from our production storage systems in accordance with standard cryptographic wiping practices, unless otherwise required by statutory retention obligations.
11
Service Availability, SLAs & Third-Party Dependencies
MailArch targets 99.9% monthly service availability for attachment retrieval endpoints.
Third-Party Platform Dependencies: MailArch relies on third-party cloud infrastructure (Google Cloud Platform, Microsoft Azure) and the Microsoft Graph API. Customer acknowledges that MailArch cannot be held liable for temporary service interruptions, throttling, or performance degradation caused directly by:
Microsoft 365, Exchange Online, or Microsoft Graph API outages or upstream rate throttling.
Internet transit routing failures or public DNS disruptions outside MailArch’s reasonable control.
Customer-side configuration errors, administrative permission revocations, or expired Entra ID credentials.
Scheduled maintenance windows communicated at least 48 hours in advance.
12
Warranty Disclaimer & Limitation of Liability
EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICE IS PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS. TO THE MAXIMUM EXTENT PERMITTED BY LAW, MAILARCH DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
EXCEPT FOR WILLFUL MISCONDUCT OR INDEMNIFICATION OBLIGATIONS UNDER SECTION 13, EACH PARTY’S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL BE LIMITED TO THE TOTAL FEES PAID BY CUSTOMER TO MAILARCH UNDER THIS AGREEMENT DURING THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO LIABILITY.
13
Indemnification
By MailArch: MailArch will defend and indemnify Customer against third-party claims alleging that the core MailArch software directly infringes a valid patent, copyright, or trademark, provided Customer promptly notifies MailArch in writing, grants sole control of defense, and cooperates reasonably.
By Customer: Customer will defend and indemnify MailArch against third-party claims arising out of Customer’s breach of Section 4 (Scope of Use), unauthorized access to tenant mailboxes, or violation of applicable data privacy laws in connection with Customer Data processed through the service.
14
Governing Law & Dispute Resolution
This Agreement and any disputes arising out of or related to it shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflict of law principles. For United States entities where required by public procurement guidelines, this Agreement shall be construed in accordance with the laws of the State of Delaware.
The parties agree to first seek informal resolution of any dispute in good faith for a period of thirty (30) days. Any unresolved dispute shall be submitted to the exclusive jurisdiction of the competent courts located within the agreed jurisdiction.
15
Modifications to Terms
We may update these Terms from time to time to reflect enhancements to our service, changes in technology, or legal requirements. If we make material changes, we will provide at least thirty (30) days prior notice via email to tenant administrators or through a prominent notice on our website.
Your continued use of MailArch after the effective date of the revised Terms constitutes your binding acceptance of the changes.
16
Contact & Legal Notices
If you have questions, inquiries regarding enterprise DPAs, custom Service Level Agreements, or legal notices concerning these Terms, please contact our legal and compliance team:
Legal Entity: MAILARCH LTD (Company No. 17444844, registered in England and Wales)
Registered Office: 31 Courtfield Rise, West Wickham, England, BR4 9BD