// introduction
Background
(A) Azla Managers LLC, a limited liability company organized under the laws of the State of Florida, United States ("ephemail", "we", "us"), and the customer that accepts ephemail's Terms of Service (the "Customer", "you") have entered into an agreement under which ephemail provides disposable, programmatic, and test email inboxes and related email-automation services (the "Services", governed by the "Terms of Service").
(B) In providing the Services, ephemail may process Personal Data on behalf of the Customer. This DPA sets out the additional terms required to ensure such processing complies with applicable Data Protection Legislation, including the mandatory clauses of Article 28(3) of the General Data Protection Regulation (EU) 2016/679 ("EU GDPR") and the UK GDPR.
Agreed terms
This DPA is incorporated into and forms part of the Terms of Service. Except as modified here, the Terms of Service remain in full force. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA prevails.
// 1. definitions and interpretation
1. Definitions and interpretation
1.1 In this DPA, the following terms have the meanings set out below:
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, and processing: have the meanings given in the Data Protection Legislation.
CCPA/CPRA: the California Consumer Privacy Act of 2018 (Cal. Civ. Code §§ 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020, together with its implementing regulations, as amended from time to time.
Customer Personal Data: any Personal Data that the Customer provides to, or that is processed by ephemail on the Customer's behalf in connection with, the Services, where ephemail acts as a Processor. Customer Personal Data does not include Personal Data that ephemail processes as a Controller, which is governed by the ephemail Privacy Policy and is outside the scope of this DPA.
Data Protection Legislation: all laws and regulations applicable to the processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the CCPA/CPRA, and other applicable U.S. state privacy laws (including, where applicable, the Florida Digital Bill of Rights), each as amended from time to time.
EU Standard Contractual Clauses ("EU SCCs"): the European Commission's Standard Contractual Clauses for the transfer of Personal Data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914, or such alternative clauses as may be approved from time to time.
UK Addendum: the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as amended or replaced.
Data Privacy Framework ("DPF"): the EU–U.S. Data Privacy Framework, the UK Extension thereto, and the Swiss–U.S. Data Privacy Framework administered by the U.S. Department of Commerce.
Sub-Processor: any third party appointed by or on behalf of ephemail to process Customer Personal Data.
Sub-Processor List: the list of Sub-Processors maintained at https://ephemail.io/sub-processors (as set out in Annex C).
Business Purposes: the provision of the Services under the Terms of Service and any processing reasonably necessary for that purpose.
1.2 This DPA is subject to and incorporated into the Terms of Service.
1.3 Section headings do not affect interpretation. "Including" means "including without limitation."
1.4 Where this DPA references the EU SCCs or UK Addendum, those clauses are incorporated by reference and completed by the information in Annex A, Annex B, Annex C, and Appendix 1.
1.5 If there is any conflict, the order of precedence is: (1) the EU SCCs / UK Addendum (for restricted transfers they govern), (2) this DPA, (3) the Terms of Service.
// 2. roles and processing purposes
2. Roles and processing purposes
2.1 The parties acknowledge that, with respect to Customer Personal Data:
2.1.1 the Customer is the Controller and ephemail is the Processor;
2.1.2 the Customer retains control of the Customer Personal Data and remains responsible for providing all required notices and obtaining all required consents and legal bases for the processing; and
2.1.3 the subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in Annex A.
// 3. ephemail's obligations
3. ephemail's obligations
3.1 ephemail will process Customer Personal Data only to the extent, and in the manner, necessary for the Business Purposes and in accordance with the Customer's documented instructions (including the Terms of Service and this DPA), unless required to do otherwise by applicable law, in which case ephemail will (where legally permitted) inform the Customer first. ephemail will promptly notify the Customer if, in its opinion, an instruction infringes the Data Protection Legislation.
3.2 ephemail will ensure that persons authorized to process Customer Personal Data are subject to a duty of confidentiality.
3.3 Taking into account the nature of the processing, ephemail will assist the Customer (at the Customer's cost, by appropriate technical and organizational measures and insofar as is reasonably possible) in fulfilling the Customer's obligations to respond to Data Subject requests and to comply with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation.
3.4 ephemail will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA.
3.5 ephemail will comply with the CCPA/CPRA obligations set out in Section 16.
// 4. ephemail personnel
4. ephemail personnel
4.1 ephemail will take reasonable steps to ensure that any individual it authorizes to process Customer Personal Data:
4.1.1 is subject to confidentiality obligations; and
4.1.2 is informed of the confidential nature of the Customer Personal Data and their data-protection responsibilities.
// 5. security
5. Security
5.1 ephemail will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
5.2 The Customer acknowledges that the measures in Annex B are appropriate for the Customer Personal Data processed under the Services.
// 6. personal data breach
6. Personal Data Breach
6.1 ephemail will notify the Customer without undue delay, and where feasible no later than seventy-two (72) hours after becoming aware, of any Personal Data Breach affecting Customer Personal Data.
6.2 Such notification will, to the extent then known and as it becomes available, include: (a) a description of the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the breach and mitigate its effects; and (d) a contact point for more information.
6.3 ephemail will reasonably cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of the breach.
6.4 ephemail will not notify any third party of a Personal Data Breach concerning Customer Personal Data without first obtaining the Customer's written consent, except where required by law. As between the parties, the Customer has the sole right to determine whether to notify affected Data Subjects, regulators, or others.
6.5 Subject to the limitation of liability in the Terms of Service, ephemail will bear reasonable, documented expenses associated with its obligations under this Section 6, unless the breach arose from the Customer's instructions, negligence, willful default, or breach of this DPA, in which case the Customer will bear those expenses.
// 7. international transfers
7. International transfers
7.1 The Customer authorizes ephemail to transfer Customer Personal Data outside the United Kingdom, the European Economic Area ("EEA"), or Switzerland where necessary to provide the Services, provided such transfer is carried out in compliance with the Data Protection Legislation.
7.2 Where ephemail transfers Customer Personal Data from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, the transfer is governed by the appropriate safeguards below:
7.2.1 the EU SCCs (Module Two, controller-to-processor, and where applicable Module Three, processor-to-processor) for transfers subject to the EU GDPR, as completed in Appendix 1 and Annex A;
7.2.2 the UK Addendum to the EU SCCs for transfers subject to the UK GDPR; and
7.2.3 the EU SCCs as supplemented for Swiss transfers (with references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner).
7.3 The parties agree that execution of this DPA constitutes execution of the EU SCCs and the UK Addendum where they apply, and that the signatures to this DPA apply to those clauses.
7.4 To the extent ephemail self-certifies under the EU–U.S. Data Privacy Framework, the UK Extension, and the Swiss–U.S. Data Privacy Framework, it will process Customer Personal Data transferred in reliance on the DPF in accordance with the DPF Principles.
7.5 If a transfer mechanism in this Section ceases to provide a lawful basis for the transfer, the parties will cooperate in good faith to implement an alternative lawful mechanism.
// 8. sub-processors
8. Sub-Processors
8.1 ephemail may appoint a Sub-Processor to process Customer Personal Data only if:
8.1.1 the Sub-Processor is listed in the Sub-Processor List (Annex C), or the Customer is given an opportunity to object within seventy-two (72) hours after ephemail provides written notice of a new Sub-Processor;
8.1.2 ephemail enters into a written contract with the Sub-Processor imposing data protection obligations substantially equivalent to those in this DPA; and
8.1.3 ephemail maintains control over the Customer Personal Data entrusted to the Sub-Processor.
8.2 The Customer's continued use of the Services after the 72-hour notice period without written objection constitutes approval of the new Sub-Processor.
8.3 If the Customer objects on reasonable data-protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected Services as its sole remedy.
8.4 ephemail remains fully liable to the Customer for the performance of each Sub-Processor's data-protection obligations.
8.5 The current Sub-Processors are listed in Annex C.
// 9. data subject requests and complaints
9. Data Subject requests and complaints
9.1 ephemail will, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as reasonably possible, to respond to requests by Data Subjects to exercise their rights under the Data Protection Legislation, including rights of access, rectification, erasure, restriction, portability, and objection.
9.2 ephemail will promptly notify the Customer if it receives a request or complaint from a Data Subject, regulator, or other third party relating to Customer Personal Data, and will not respond except on the Customer's documented instructions or as required by law.
9.3 ephemail will not disclose Customer Personal Data to any third party except as instructed by the Customer, as permitted under this DPA, or as required by law.
// 10. term and termination
10. Term and termination
10.1 This DPA takes effect on the Effective date and remains in force for as long as (a) the Terms of Service remain in effect, or (b) ephemail retains any Customer Personal Data in its possession or control (the "Term").
10.2 Provisions that by their nature should survive termination (including Sections 6, 11, 12, 14, 16, and 17) survive.
// 11. data return and destruction
11. Data return and destruction
11.1 During the Term, ephemail will, on the Customer's written request, provide the Customer with a copy of, or access to, the Customer Personal Data in ephemail's possession.
11.2 On expiry or termination of the Terms of Service, ephemail will, at the Customer's written direction, securely delete or return all Customer Personal Data in its possession or control within thirty (30) days, and delete existing copies, unless applicable law requires continued storage.
11.3 Where ephemail is required by law to retain any Customer Personal Data, it will inform the Customer of the legal requirement (to the extent permitted) and protect the data for as long as it is retained.
11.4 Customer Personal Data is considered deleted where it is put beyond further use by ephemail. The Services are designed so that disposable inbox data and associated messages are deleted automatically on expiry of the inbox and routine logs are cleared within thirty (30) days.
// 12. records
12. Records
12.1 ephemail will maintain records of its processing of Customer Personal Data sufficient to demonstrate compliance with this DPA and the Data Protection Legislation.
12.2 ephemail will make such records available to the Customer on reasonable written request.
// 13. audit
13. Audit
13.1 ephemail will permit the Customer (or its authorized third-party auditor bound by confidentiality) to audit ephemail's compliance with this DPA on reasonable prior written notice, no more than once per calendar year and at the Customer's expense, provided audits do not unreasonably disrupt ephemail's operations. ephemail may satisfy audit requests by providing relevant third-party certifications, reports, or questionnaires.
13.2 The once-per-year limit does not apply where an audit is required by a competent supervisory authority.
// 14. warranties
14. Warranties
14.1 ephemail warrants that it will process Customer Personal Data in compliance with this DPA and that the persons it authorizes to process Customer Personal Data are reliable and subject to appropriate confidentiality and training.
14.2 The Customer warrants that (a) it has a lawful basis and has provided all required notices for the processing it instructs, and (b) its instructions comply with the Data Protection Legislation.
// 15. notices
15. Notices
15.1 Notices under this DPA must be in writing and sent to the other party's designated contact.
15.2 ephemail's contact for data protection and notices under this DPA is: privacy@ephemail.io (with a copy to legal@ephemail.io).
15.3 The Customer's contact is the email address associated with the Customer's account, unless otherwise specified.
15.4 Notices are deemed received on delivery (if by courier), or on the next business day after sending (if by email, absent a delivery-failure notice).
// 16. ccpa/cpra compliance
16. CCPA/CPRA compliance
16.1 This Section applies to processing of Personal Data subject to the CCPA/CPRA. For that processing, ephemail acts as a "Service Provider" and the Customer is the "Business" (as those terms are defined in the CCPA/CPRA).
16.2 ephemail will process Personal Data only for the limited and specified Business Purposes set out in this DPA and the Terms of Service, and will not process it for any other purpose.
16.3 ephemail will not "sell" or "share" Personal Data (as those terms are defined in the CCPA/CPRA).
16.4 ephemail will not retain, use, or disclose Personal Data outside the direct business relationship with the Customer, except as permitted by the CCPA/CPRA.
16.5 ephemail will not combine Personal Data received from the Customer with Personal Data from other sources, except as permitted by the CCPA/CPRA.
16.6 ephemail will provide the same level of privacy protection required of Businesses under the CCPA/CPRA and will comply with applicable obligations.
16.7 ephemail will notify the Customer if it determines it can no longer meet its CCPA/CPRA obligations.
16.8 The Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
16.9 ephemail will assist the Customer in responding to verifiable consumer requests under the CCPA/CPRA, taking into account the nature of the processing.
// 17. governing law
17. Governing law
17.1 Except for the EU SCCs and UK Addendum (which are governed by the laws set out in those clauses and in Appendix 1), this DPA is governed by the law specified in the Terms of Service and, absent such specification, by the laws of the State of Florida, United States, without regard to conflict-of-laws principles. The parties submit to the courts located in [county], Florida for disputes arising under this DPA, except where the Data Protection Legislation requires otherwise.
// annex a — details of processing
Annex A — Details of processing
Part 1 — Role of the parties
The Customer is the Controller and ephemail is the Processor of the Customer Personal Data.
Part 2 — Particulars of processing
- Subject matter: ephemail's processing of Customer Personal Data as necessary to provide the Services under the Terms of Service.
- Duration: the Term, plus the wind-down period in Section 11.
- Nature and purpose: receiving, storing, parsing, displaying, forwarding, and making available via API/web inbound email messages and related metadata sent to email addresses created or controlled through the Services; authentication checks (SPF/DKIM/DMARC); spam classification; optional AI extraction of one-time codes, links, and summaries; analytics on the Customer's own usage.
- Categories of Personal Data: any Personal Data contained in inbound email messages and metadata directed to the Customer's inboxes — which may include sender and recipient email addresses, names, message subject and body content, attachments, IP/header information, and any Personal Data the senders choose to include. Account data (Customer's name, email, billing contact) is processed by ephemail as a Controller and is outside this DPA.
- Special categories: ephemail does not intend or require the processing of special categories of Personal Data; the Customer should not direct such data to the Services unless appropriate safeguards are in place.
- Categories of Data Subjects: the Customer's authorized users and staff; and the senders and subjects of email received at the Customer's inboxes.
- Retention: disposable inbox data is deleted on inbox expiry; other Customer Personal Data is retained for the applicable plan's retention window and deleted or returned per Section 11; routine logs are cleared within 30 days.
// annex b — technical and organizational security measures
Annex B — Technical and organizational security measures
ephemail maintains measures appropriate to the Services, including:
- Encryption in transit: TLS/SSL for all web, API, and SMTP connections.
- Sandboxed rendering: inbound HTML email is rendered only inside a sandboxed iframe and is never executed against the application, mitigating XSS/injection.
- Tokenized API access: API keys are never stored in plaintext — only a salted hash and a short non-secret prefix are retained; keys are scoped and revocable.
- Row-Level Security: database access is governed by row-level security policies so tenants can access only their own data.
- Least-privilege transport services: the inbound/outbound mail services have no direct database credentials and interact only through narrowly scoped, authenticated server-to-server functions guarded by a rotating shared secret.
- Encrypted secrets: application secrets, signing keys (including outbound DKIM private keys), and credentials are stored in an encrypted secrets vault.
- Signed, time-limited storage URLs: raw message and attachment files are stored in private object storage and exposed only via signed, expiring URLs.
- Access control: administrative access is restricted, authenticated, and limited to personnel who require it.
- Automated data expiry: disposable inboxes and their messages are automatically deleted on expiry; retention windows are enforced programmatically.
- Network protections: rate limiting and abuse detection on public endpoints and mail intake; IP-based throttling.
- Email authentication: SPF, DKIM, and DMARC evaluation on inbound mail and DKIM signing on outbound mail.
- PCI-compliant billing: payment card data is handled by a PCI-DSS-compliant third-party payment processor; ephemail does not store full card numbers.
- Reputable infrastructure: hosting and managed data services are provided by infrastructure vendors maintaining recognized certifications (e.g., SOC 2, ISO 27001, PCI DSS); see Annex C.
- Backups and recovery: managed database backups with point-in-time recovery via the hosting provider.
- Vulnerability management: dependency and configuration review as part of the development lifecycle.
// annex c — list of sub-processors
Annex C — List of Sub-Processors
The current Sub-Processors engaged by ephemail are listed below and maintained at https://ephemail.io/sub-processors.
| Sub-Processor | Purpose | Processing location |
|---|---|---|
| Supabase (hosted on Amazon Web Services) | Managed database, authentication, object storage, edge functions | United States |
| Amazon Web Services, Inc. | Underlying cloud infrastructure for the managed backend | United States |
| Fly.io (The Fly.io Corporation) | Hosting of the inbound/outbound mail transport services | United States |
| Cloudflare, Inc. | DNS and network/edge services | Global / United States |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| OpenAI, L.L.C. / Anthropic, PBC | AI extraction of one-time codes, links, and summaries (only if enabled) | United States |
// appendix 1 — eu standard contractual clauses
Appendix 1 — EU Standard Contractual Clauses
The EU SCCs (Commission Implementing Decision (EU) 2021/914), Module Two (controller-to-processor) and, where applicable, Module Three (processor-to-processor), are incorporated into this DPA by reference and completed as follows.
Clause-specific selections:
- Clause 7 (Docking clause): included.
- Clause 9 (Sub-processors): Option 2, general written authorization, with the 72-hour notice period in Section 8 of this DPA.
- Clause 11 (Redress): the optional independent-dispute-resolution language is not selected.
- Clause 17 (Governing law): the EU SCCs are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction): the courts of Ireland.
SCC Annex I
A. List of Parties
- Data exporter: the Customer (name, address, and contact as set out in the Customer's account / order form). Role: Controller.
- Data importer: Azla Managers LLC dba ephemail, [registered address], Florida, United States. Contact: contact@ephemail.io. Role: Processor.
B. Description of the transfer — as set out in Annex A, Part 2 (categories of Data Subjects and Personal Data, nature and purpose of processing, retention).
C. Competent supervisory authority — the supervisory authority of the EEA member state in which the data exporter is established or, where the exporter is not established in the EEA, the Irish Data Protection Commission as the supervisory authority of the member state whose law governs the SCCs.
SCC Annex II — Technical and organizational measures: as set out in Annex B of this DPA.
SCC Annex III — List of Sub-Processors: as set out in Annex C of this DPA.
// appendix 2 — uk international data transfer addendum
Appendix 2 — UK International Data Transfer Addendum
For Customer Personal Data subject to the UK GDPR, the UK Addendum to the EU SCCs is incorporated by reference and completed as follows:
- Table 1 (Parties): as in Appendix 1, SCC Annex I.A above.
- Table 2 (Selected SCCs, Modules and Clauses): EU SCCs as completed in Appendix 1; Module Two and, where applicable, Module Three; docking clause included; general authorization for sub-processors.
- Table 3 (Appendix Information): Annex 1A → Table 1; Annex 1B → Annex A, Part 2; Annex II → Annex B; Annex III → Annex C.
- Table 4 (Ending the Addendum): only the data importer (ephemail) may end the Addendum as set out in its Mandatory Clauses.
- Governing law / forum of the UK Addendum: the laws and courts of England and Wales, as required by the ICO Mandatory Clauses.
The ICO's Mandatory Clauses (version B.1.0) apply and are incorporated by reference.