mailbud.app

Data Processing Agreement

The contractual detail behind how we handle your mailbox, written to be read, not just signed.

Last updated: 18 August 2026

This Data Processing Agreement (DPA) forms part of the agreement between you (the “Controller”) and Nahayat.io (the “Processor”) for the mailbud service. It applies to personal data contained in the email we process on your behalf. It is written in plain language on purpose: a DPA nobody can read is not much of a safeguard.

1. Subject and roles

You are the controller of the personal data in your mailbox, both your own and that of everyone who writes to you. We act as your processor when we read and file that email on your instructions, which are expressed as the categories you configure in mailbud.

2. Nature and purpose of processing

We process the subject, sender and a bounded portion of the body of your incoming email for one purpose: deciding which of your folders each message belongs in, and moving it there. We use it for nothing else. We do not use it to train AI models, and we do not build shared or cross-customer models from it.

3. Categories of data and data subjects

The data may include any personal data present in your email, and relates to you and to the people who correspond with you. You decide which mailbox is connected, and you can disconnect it at any time from your Microsoft account.

4. Where processing happens

Entirely within the EU. Mailbox content is stored on our own servers in the Netherlands and classified by Mistral AI in France, over its EU endpoint. No mailbox content is transferred outside the EEA, so no Chapter V transfer mechanism is required for it. Where a sub-processor listed in section 6 that does not receive mailbox content processes data outside the EEA, appropriate safeguards such as Standard Contractual Clauses apply.

5. Security measures

  • Encryption per account. Mailbox content is encrypted at rest with AES-256-GCM under a data key unique to your account. One key never unlocks another customer’s data.
  • Ciphertext bound to its owner. Each encrypted value is cryptographically tied to the account and table it belongs to, so it cannot be relocated between accounts and still be read.
  • Derived data protected too. The numeric vectors we use to learn from your corrections are transformed under a secret unique to your account, rather than stored as the model produced them.
  • No send permission. We hold read and move permissions only. mailbud is technically incapable of sending, replying to or forwarding your mail.
  • Credentials. Microsoft OAuth tokens are encrypted at rest, alongside mail content, under the same per-account key. We never receive or store your password.
  • Access control. Row-level security is enabled throughout the database and there is no public data API. Every query is scoped to a single account.
  • Logging discipline. Our operational logs record identifiers only, never subjects, message bodies or the addresses you correspond with.

6. Sub-processors

You authorise the following sub-processors. We will inform you before adding any new sub-processor that touches mailbox content, giving you a reasonable opportunity to object.

  • Microsoft (EU): hosts your mailbox; accessed through the official Graph API under your own consent.
  • Mistral AI SAS (Paris, France): classifies mailbox content, on its EU endpoint. The only sub-processor that receives mailbox content.
  • Stripe: payment and subscription processing. Receives billing data only.
  • WeFact (Netherlands): invoicing and bookkeeping. Billing data only.
  • Resend: delivery of our own transactional emails to you. Receives your email address and our message text only.
  • Cloudflare: website delivery and protection. No mailbox content.

There is no hosting sub-processor for the application or database: that infrastructure is ours, in the Netherlands.

7. Retention

We commit to windows rather than to “as long as necessary”:

  • Classification history: content erased after 30 days. The record of the decision is retained without the text of your mail.
  • Review queue items: deleted 30 days after resolution, or after 180 days if never resolved.
  • Confirmed corrections: the most recent 200 per category are retained.
  • Internal job records: deleted within a few days.

8. Return and deletion

You can delete your account yourself, at any time, from your settings. Doing so disconnects the mailbox, deletes the stored tokens and all mail data, and then destroys the encryption key for your account. Because the key is gone, any residual copy in a backup is rendered permanently unreadable rather than merely deleted from the live database, a stronger guarantee than deletion alone can offer.

The folders mailbud created in your Outlook, and the mail within them, remain yours and are not modified on deletion.

Paid invoices are retained for seven years, as Dutch tax law requires. They contain billing data only and never mailbox content. This is the sole category of data that survives an erasure request, and it is retained because the law compels it.

9. Assistance and breach notification

We will assist you in responding to requests from data subjects, and will notify you without undue delay, and in any case within 72 hours of becoming aware, of any personal data breach affecting your data, together with what we know and what we are doing about it.

10. Audit and instructions

We process personal data only on your documented instructions. On reasonable request we will provide the information needed to demonstrate compliance with this DPA. Our staff are bound by confidentiality.

11. Contact

For any data protection matter, including exercising a data subject right or reporting a concern, contact [email protected]. See also our Privacy Policy.