Data Processing Agreement

Effective 18 July 2026

This Data Processing Agreement (the “DPA”) governs the processing of personal data by Supry Inc., a Delaware corporation with a registered address at 2035 Sunset Lake Road, Suite B-2, Newark, DE 19702, USA (“Supry”, “we”, “us”, the “Processor”), on behalf of the customer using InboxAgents (“you”, the “Controller”). It is entered into under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and, where applicable, the UK GDPR and the Data Protection Act 2018.

This DPA is incorporated into, and forms part of, the Terms of Service. It takes effect automatically for every Controller that uses the Service, without signature. If your compliance programme requires a countersigned copy, request one at legal-inbox-agents@supry.com and we will provide it. Terms defined in the Terms of Service have the same meaning here.

1. Scope, roles, and what this DPA covers

InboxAgents is API-first email infrastructure that provisions programmatic email inboxes and makes the mail arriving in them available over an API. The current version of the Service is receive-only: no outbound mail is sent through it other than the one-time code used to verify an email address at signup.

You are the Controllerof the personal data contained in mail received into your inboxes (“Customer Personal Data”). You decide which inboxes exist, who is told about them, what is done with the messages, and how long they are kept. This includes the personal data of third parties who send mail to your inboxes — people who have no relationship with Supry and have not agreed to anything with us.

Supry is the Processor of Customer Personal Data. We process it solely to deliver, store, and serve it to you, on your instructions, and for no independent purpose of our own.

Carve-out — where Supry is an independent controller. Supry acts as a controller, not a processor, for the data it holds about you as a customer: account records and profile details, authentication data, billing and payment records, support correspondence, security and abuse-prevention records (including the IP address that requested a signup), and product and website analytics. That processing is governed by our Privacy Policy and by data protection law directly, not by this DPA. Nothing in this DPA makes Supry a processor of that data, and nothing in it makes Supry a controller of Customer Personal Data.

The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I.

2. Processing on documented instructions

We will process Customer Personal Data only on your documented instructions, including in relation to transfers of that data to a third country, unless we are required to process it by Union or Member State law to which we are subject. Where such a legal requirement applies, we will inform you of it before processing, unless that law prohibits the notification on important grounds of public interest.

Your documented instructions consist of: this DPA; the Terms of Service; the configuration you set in the dashboard or through the API (the inboxes you provision, the webhook endpoints and WebSocket subscriptions you enable, the inboxes you delete); the calls your software makes to the API, SDKs, CLI, or MCP server; and any further written instruction you give us at legal-inbox-agents@supry.com. Taken together, these are the complete and final instructions for our processing.

We will tell you if, in our opinion, an instruction infringes the GDPR, the UK GDPR, or another applicable data protection provision. We may suspend the affected processing until the instruction is confirmed, withdrawn, or amended.

An instruction that falls outside the documented functionality of the Service — for example, a request for bespoke processing, bespoke retention behaviour, or data residency in a particular region — may require a separate written agreement, and we may charge for it or decline it where it is not technically feasible. We will say which.

3. No use of Customer Personal Data for AI or machine learning

We commit, as a term of this DPA, that we do not disclose Customer Personal Data to any artificial intelligence or machine-learning provider, and do not use it to train, fine-tune, or evaluate any model, to generate embeddings, or to perform automated classification, summarisation, or profiling. Our systems contain no integration with any large language model or AI service. This commitment is binding and survives for as long as we hold Customer Personal Data.

One clarification, so this is not read as a contradiction. InboxAgents exists to be used by AI agents, and you may connect your own agents to your own inboxes through our API or MCP server using your own credentials and your own model provider. When you do, that is your processing as controller, under your own agreements with that provider. It is not a disclosure by us, and we have no visibility over what your agent does with what it reads. The commitment above concerns Supry’s own conduct as Processor.

4. Confidentiality of personnel

We limit access to Customer Personal Data to the personnel who need it to provide, secure, or support the Service. Every person we authorise to process Customer Personal Data is bound by a written obligation of confidentiality, or is under an appropriate statutory obligation of confidentiality. That obligation survives the end of their engagement with us. We ensure such personnel are aware of the confidential nature of the data and process it only on our instructions.

5. Security of processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement appropriate technical and organisational measures under Article 32 GDPR. Those measures are set out in Annex II.

We describe those measures precisely and we do not claim measures we have not implemented. Supry holds no SOC 2 report, no ISO 27001 certification, and no other third-party security certification or attestation. If your risk assessment requires one, you should take that into account before using the Service.

We may update the measures in Annex II from time to time, provided the updated measures do not materially reduce the overall level of security.

6. Sub-processors

General authorisation. You give us a general written authorisation to engage sub-processors to assist in providing the Service. The sub-processors engaged as at the effective date of this DPA are listed in Annex III, with their processing purpose and location.

Flow-down.We engage each sub-processor under written data protection terms — in most cases the sub-processor’s own data processing agreement — that impose obligations providing at least equivalent protection to those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, Supry remains fully liable to you for the performance of that sub-processor’s obligations.

Notice of change and right to object. Before we add a new sub-processor, or replace an existing one, in a way that affects the processing of Customer Personal Data, we will notify you by email to your account address, or by a notice in the dashboard, at least thirty (30) days in advance. You may object on reasonable data protection grounds by writing to legal-inbox-agents@supry.com within that period. If you object, we will work with you in good faith to find a reasonable alternative — for example, by making the relevant feature optional or by using a different provider. If no such alternative can be found within a reasonable time, you may terminate the affected part of the Service, or the Service in full, without penalty, and we will refund any fees prepaid for the period after termination.

Where a change is required urgently to protect the security or availability of the Service, we may make it with shorter notice and will inform you as soon as reasonably practicable; your right to object under this section is unaffected.

7. Assistance with data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR — access, rectification, erasure, restriction, portability, and objection.

In practice, the Service itself is the primary means of that assistance: the API lets you list, read, and export the threads and messages you hold, and delete an inbox together with all of its stored mail. The API does not currently support deleting an individual message or thread; where a request cannot be met through the API, write to legal-inbox-agents@supry.com and we will assist, including by locating, exporting, or deleting specific data on your instruction.

If a data subject contacts us directly with a request concerning Customer Personal Data, we will not respond to it substantively on your behalf. We will acknowledge the person, identify the relevant Controller, and either refer the person to you or forward the request to you, so that you can act on it as controller. Where we are legally permitted to tell the person which Controller holds their data, we will.

8. Assistance with security, breaches, DPIAs, and prior consultation

Taking into account the nature of the processing and the information available to us, we will assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR.

Article 32 — security. We will provide the information described in Annex II, and reasonable further information about our security measures, so that you can assess their appropriateness for your processing.

Articles 33 and 34 — personal data breaches. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notification will describe, to the extent then known to us, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of that at once, we will provide it in phases as it becomes available. We will provide the information reasonably available to us to help you meet your own 72-hour notification obligation to a supervisory authority, but the assessment of whether a breach is notifiable, and any notification to authorities or data subjects, remains yours as Controller. We do not commit to a fixed notification deadline shorter than the standard above.

Articles 35 and 36 — DPIAs and prior consultation. Where you carry out a data protection impact assessment, or consult a supervisory authority in advance, relating to your use of the Service, we will provide reasonable assistance and the information about the Service that is available to us and necessary for that purpose.

9. International transfers

All processing of Customer Personal Data under this DPA takes place in the United States. We do not currently offer EU, UK, or other regional data residency, and there is no configuration that keeps Customer Personal Data inside the EEA or the UK. Every sub-processor listed in Annex III is located in the United States.

If you are established in the EEA, the UK, or Switzerland, or your processing is otherwise subject to the GDPR or UK GDPR, your use of the Service therefore involves a transfer of personal data to a third country. For those transfers, the parties incorporate by reference the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are deemed executed between you as data exporter and Supry Inc. as data importer. For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018.

For the purposes of those clauses: the optional docking clause does not apply; the supervisory authority is that of the Member State in which the data exporter is established; the parties select the option requiring the data importer’s general written authorisation for sub-processors, with the notice period set out in section 6; the governing law and forum are those specified in the clauses themselves rather than in the Terms of Service; and Annexes I, II and III of this DPA serve as the corresponding annexes to the clauses. Where the clauses conflict with any other term of this DPA or the Terms of Service, the clauses prevail.

We will notify you if we receive a legally binding request from a public authority for disclosure of Customer Personal Data, unless we are prohibited from doing so, and we will challenge requests we consider unlawful where there is a reasonable basis to do so.

10. Retention, deletion, and return

We want to be direct rather than reassuring here, because the position is unusual. The Service does not delete Customer Personal Data automatically. There is no time-to-live on stored messages, no expiry on stored attachments or raw MIME, and no retention ceiling or storage lifecycle rule that ages content out. Customer Personal Data is retained for as long as you keep it in the Service.

Deletion happens when you delete an inbox through the dashboard or API, which removes the threads, messages, and attachments it holds, or when you ask us to delete data by writing to legal-inbox-agents@supry.com. There is currently no self-serve account deletion in the dashboard: account-level deletion requests are handled manually by us. We commit to actioning a written deletion request, and confirming back to you, within 30 days of receipt.

At the end of the provision of the Service, and at your choice, we will delete or return all Customer Personal Data and delete existing copies, unless Union, Member State, or other applicable law requires us to store it. Customer Personal Data is retained for sixty (60) days after termination so that an accidental or reconsidered cancellation can be reversed and any outstanding export can be completed. You should tell us in writing during that period if you want the data returned rather than deleted; if you have not told us otherwise by the end of the sixty days, we will delete it. Return is effected through your own export via the API while your account remains accessible, or, on request, by an export we produce for you.

Residual copies may persist in routine backups after deletion from live systems. Those copies are not accessible for ordinary processing, remain subject to this DPA, and expire in the ordinary backup cycle.

11. Demonstrating compliance; audits

We will make available to you the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

Because Supry holds no third-party audit report or certification, this obligation is discharged in the following ways: by this DPA and the descriptions in its Annexes; by our Privacy Policy; and by our responding to reasonable written security and privacy questionnaires. We will respond to such a questionnaire within a reasonable time, normally 30 days, and no more than once in any twelve-month period unless a personal data breach has occurred or a supervisory authority requires otherwise.

Where that information is genuinely insufficient for you to demonstrate compliance, you may request an on-site or remote inspection. Such an inspection must be requested at least 30 days’ in advance, take place during business hours, be limited to matters relevant to the processing of your Customer Personal Data, be conducted so as not to disrupt the Service, and be subject to confidentiality obligations. The auditor must not be a competitor of Supry. You bear your own costs and, where an inspection requires more than a nominal amount of our time, our reasonable costs. We may exclude from an inspection any information belonging to another customer or that would compromise the security of the Service.

Nothing in this section limits the audit and inspection rights of a data exporter or supervisory authority under the Standard Contractual Clauses incorporated by section 9.

12. Controller obligations and warranties

You warrant that you have a lawful basis for the processing you instruct, that the personal data you cause to be processed has been collected in compliance with applicable law, and that you have provided any notices and obtained any consents required — including, where the law requires it, towards the third parties who send mail to your inboxes. You are responsible for the accuracy, quality, and legality of Customer Personal Data and for the means by which you acquired it.

You are responsible for the security of your own credentials, for the scope of the API keys you issue, and for the endpoints to which you direct webhooks or WebSocket streams. Enabling webhook or real-time delivery causes full message content to be transmitted to the destination you configure; that transmission is carried out on your instruction.

13. Liability, term, and governing law

This DPA takes effect when you first use the Service, or on the effective date above if later, and continues for as long as we process Customer Personal Data on your behalf. The obligations in sections 3, 4, 9, 10, and 11 survive its termination for as long as we hold Customer Personal Data.

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except to the extent applicable law does not permit that, and except that nothing in the Terms of Service limits a data subject’s rights or either party’s liability under the Standard Contractual Clauses.

This DPA is governed by the laws of the State of Delaware, USA, consistent with the Terms of Service, save that the Standard Contractual Clauses and the UK Addendum are governed by the law they themselves specify. If any provision of this DPA is held invalid or unenforceable, the remainder stays in force. In the event of a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service and the Privacy Policy, in each case in respect of the processing of Customer Personal Data.

We may update this DPA where necessary to reflect changes in law, in our sub-processors, or in the Service. Material changes will be notified in accordance with the change process in the Terms of Service. The effective date at the top of this page always reflects the current version.

Annex I

Description of the processing

Parties. Data exporter and controller: the customer using InboxAgents. Data importer and processor: Supry Inc., 2035 Sunset Lake Road, Suite B-2, Newark, DE 19702, USA, contactable at legal-inbox-agents@supry.com.

Subject matter. The provision of InboxAgents, API-first email infrastructure that gives software agents and applications their own programmatic email inboxes.

Nature and purpose of the processing.Receiving, parsing, storing, and making available inbound email on the Controller’s behalf, through a REST API, official SDKs, a command-line interface, an MCP server, webhooks, and WebSocket streams. Processing operations include receipt, parsing of MIME structure, storage of message content and attachments, indexing and retrieval, transmission to Controller-configured endpoints and subscribers, and deletion on the Controller’s instruction. The Service is receive-only; it does not send mail on the Controller’s behalf.

Types of personal data. Whatever a sender puts in a message is stored intact — nothing is redacted, stripped, or minimised. For each message this includes:

  • the sender email address;
  • every recipient address, including To, Cc, Bcc and Reply-To;
  • the subject line;
  • the plain-text body and the HTML body;
  • the complete set of MIME headers;
  • attachments, including their filenames and content types, and their decoded contents;
  • message identifiers and timestamps;
  • the complete raw MIME source of the message.

Because the content of a message is entirely determined by its sender, personal data of any type may be present, including special categories of data under Article 9 GDPR. The Service is not designed or held out as suitable for special category data, applies no additional safeguards to it, and the Controller is responsible for whether its inboxes are used in a way that attracts such data.

Categories of data subjects. Two groups, which are worth distinguishing:

  • the Controller’s personnel and end users who hold, operate, or are named as recipients on the inboxes; and
  • any third party who sends email to one of those inboxes. These people have no relationship with Supry, have not agreed to anything with either party, and have not consented to their message being stored by us. Most of the personal data processed under this DPA belongs to this group. The Controller is responsible for the lawfulness of receiving that mail and for any transparency owed to those senders.

Frequency of the transfer.Continuous, as mail arrives and as the Controller’s software reads it.

Duration of the processing. For as long as the Controller maintains the data in the Service. There is no automatic deletion, no time-to-live, and no retention ceiling. Data is deleted when the Controller deletes an inbox, which removes the threads, messages, and attachments it holds, or on written request to the contact above, actioned within 30 days. After termination, data is retained for 60 days and then deleted. See section 10.

Transfers to sub-processors. As set out in Annex III, for the purposes and durations stated there.

Competent supervisory authority. For the purposes of the Standard Contractual Clauses, the supervisory authority of the EEA Member State in which the data exporter is established, or as otherwise determined under Clause 13.

Annex II

Technical and organisational measures

The measures below are the measures actually implemented. Measures we have not implemented are named as such, so that you can assess the risk accurately rather than favourably.

Encryption

  • All traffic to and between the Service’s components is encrypted in transit using TLS.
  • At rest, data is protected by the default encryption applied by our infrastructure providers: server-side encryption on AWS S3 object storage, and disk encryption on the Supabase database. No additional application-level encryption is applied. Message bodies, subjects, and headers are stored as ordinary plaintext database columns, readable by anyone with authorised access to the database.

Access control and tenant isolation

  • Customer data is isolated at the database level using PostgreSQL row-level security, so a query executed in the context of one account cannot reach another account’s rows.
  • API keys are stored only as SHA-256 hashes; we never hold the plaintext key and cannot recover one. Keys carry granular permission scopes and can be revoked at any time, with revocation effective for subsequent requests.
  • One-time signup codes are stored hashed, expire after ten minutes, and are attempt-limited.
  • Downloads of attachments and raw message source are served through pre-signed links that expire after fifteen minutes.
  • Access to production data is restricted to authorised personnel, each bound by confidentiality obligations under section 4. At the Service’s current scale that is a small number of individuals.

Integrity of the ingest pipeline

  • The inbound webhook endpoint verifies the cryptographic signature of every notification it receives and pins the expected topic identifier. It is fail-closed: if the expected configuration is absent, inbound processing is rejected rather than accepted unverified.
  • Per-IP rate limiting is applied to the public signup endpoint to resist automated account creation.

Purpose limitation

  • Customer Personal Data is not disclosed to any AI or machine-learning provider and is not used for training, fine-tuning, embeddings, classification, or profiling — a binding commitment under section 3.
  • Customer Personal Data is not sold, is not shared for advertising purposes, and is not combined across customers.
  • Product and web analytics receive event metadata and account identifiers only, never message content.

Measures not in place

Stated plainly so that no reader infers more than exists. Supry holds no SOC 2 report, no ISO 27001 certification, and no other third-party security attestation, and does not publish penetration test reports. There is no application-level encryption of message content, no automated retention or deletion, no customer-managed encryption keys, and no regional data residency option. We do not currently operate a formal, documented access-review or security-training programme. The Service is in public beta and carries no service level agreement or uptime commitment.

Annex III

Authorised sub-processors

The following sub-processors are authorised as at the effective date of this DPA. All are located in the United States. Changes are subject to the notice and objection rights in section 6.

Sub-processorPurposeData processedLocation
SupabaseDatabase and authenticationAll stored message content, headers, and inbox configurationUnited States (us-east-1)
Amazon Web Services (SES, S3, SNS)Email receipt, object storage, delivery notificationsAll inbound mail, raw MIME, attachmentsUnited States (us-east-1)
VercelApplication and API hostingAll Customer Personal Data transits Vercel as the application host; retained runtime logs contain request metadata onlyUnited States
Fly.ioReal-time WebSocket event deliveryFull message content transits this relayUnited States (iad)
StripePayment processingAccount email address only. No Customer Personal DataUnited States
SvixDelivery of webhooks to Controller endpointsFull message payload, including bodies, headers and sender addressesUnited States
PostHogProduct analyticsEvent metadata and account identifiers. No message contentUnited States
Google Analytics 4Web and application analyticsUsage events and an application user identifier. No message contentUnited States

Two entries deserve emphasis, because both carry full message content and both are enabled by the Controller. Webhook delivery through Svix transmits the complete message payload — bodies, headers, sender addresses — to the endpoint the Controller configures. Real-time streaming through Fly.io means full message content transits that relay. Stripe, PostHog, and Google Analytics receive no message content of any kind.

Signature and contact

No signature is required: this DPA applies automatically to every Controller using the Service, as part of the Terms of Service. If you need a countersigned copy for your records, or wish to give a written instruction, object to a sub-processor, or request deletion, write to us.

Supry Inc.
2035 Sunset Lake Road, Suite B-2
Newark, DE 19702, USA
legal-inbox-agents@supry.com