Legal
Data processing agreement
This data processing agreement ("DPA") forms part of the terms of service between the customer ("Controller") and Mobiweb AI Ltd ("Processor") for Mobiweb AI Mail, and applies to personal data the Processor processes on the Controller's behalf. It is intended to meet Article 28 of the GDPR and the UK GDPR, and the DIFC Data Protection Law 2020.
1. Subject matter and details
| Purpose | Generating email drafts, replies, summaries, rewrites and translations requested by the Controller's users. |
|---|---|
| Nature | Transient processing in memory; content is not stored. |
| Data subjects | The Controller's users and the senders, recipients and people mentioned in the emails they process. |
| Categories of data | Names, email addresses, and any personal data contained in the email text the user chooses to process. The Controller should avoid processing special categories of data where not needed. |
| Duration | For each request, the time needed to produce the answer (seconds). Account and usage data: as described in the privacy policy. |
2. Processor obligations
- Process personal data only on the Controller's documented instructions, which are these terms and the use of the service by its users.
- Ensure that authorised personnel are bound by confidentiality.
- Implement the technical and organisational measures in Annex 1.
- Assist the Controller with data subject requests, security, breach notification and impact assessments, taking into account the nature of the processing.
- Notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting the Controller's data.
- Delete or return personal data at the end of the service; email content is not stored in the first place.
- Make available information needed to demonstrate compliance and allow for audits, primarily by providing documentation and answers to security questionnaires.
3. Sub-processors
The Controller authorises the sub-processors listed on the sub-processors page. The Processor will give at least 30 days' notice of new sub-processors; the Controller may object on reasonable grounds and, if the objection cannot be resolved, terminate the affected service.
4. International transfers
Where personal data is transferred from the EU/EEA or the UK to the Processor, the parties agree to the European Commission's standard contractual clauses (Module 2, controller to processor) and the UK International Data Transfer Addendum, incorporated by reference. [Annex details and DIFC transfer basis to be confirmed by counsel.]
Annex 1. Technical and organisational measures
- Encryption in transit (TLS 1.2 or later) between the add-in, our servers and the AI provider.
- No storage or logging of email content; automated test before every release that logs contain no content.
- Pseudonymisation of email addresses, links and international phone numbers before AI processing.
- AI processing on Amazon Bedrock in the EU, configured not to store inputs or outputs.
- Authentication of every request with Microsoft Entra ID tokens; tenant isolation of account data.
- Least-privilege Outlook permission (ReadWriteItem); the add-in cannot read the rest of the mailbox.
- Restricted, named administrative access to production; daily database backups.
- Treatment of incoming email as untrusted input; escaping of AI output before insertion.