Data Processing Agreement — Email Archive
WebsitePublisher.ai · Version 2.0 · 3 September 2026
This agreement applies to the Email Archive add-on. By ordering the add-on you accept it. It supplements the WebsitePublisher.ai Terms of Service; where the two conflict, this agreement prevails for the processing of archived mail.
Parties
Controller (the "Customer"): the holder of the WebsitePublisher.ai account under which an email archive is created. Where an account belongs to a team, the team member who creates an archive is the Controller for that archive. Nobody else on the account has access to it.
Processor ("M25"): M25, Brandemaat 78, 7943 EX Meppel, the Netherlands, Chamber of Commerce 04072374, VAT NL001629875B23, trading as WebsitePublisher.ai.
Privacy contact: privacy@websitepublisher.ai
1. Subject and duration
1.1 M25 processes personal data solely to provide the Email Archive service (the "Service") and solely on the Customer's documented instructions. Use of the Service constitutes such instruction.
1.2 This agreement runs for as long as the Customer holds an active Email Archive plan. It ends when that plan ends, except for the provisions that by their nature survive (articles 8, 9 and 11).
2. Nature and purpose of the processing
2.1 M25 processes:
- the full content of the mailboxes the Customer connects, including attachments
- the associated metadata: sender, recipients, timestamps, folders, size
2.2 M25 performs the following operations on that data:
| a | Retrieval over IMAP, read-only |
| b | Storage of messages in their original form |
| c | Indexing for search, including full message content |
| d | Computing vector representations for semantic search |
| e | Summarising messages per context using a language model |
| f | Proposing draft replies using a language model, only when a user asks for one |
| g | Making messages available to AI assistants the Customer connects |
2.3 M25 never writes to the Customer's mailbox. The connection is technically read-only. Messages are not modified, moved or deleted at the source.
2.4 M25 never sends email on the Customer's behalf. A draft reply is text. Sending is done by the Customer in their own mail client.
2.5 M25 does not use the data for its own purposes. In particular: not to train or improve models, not for analysis across customers, and not for product development based on the content.
3. Customer responsibilities
3.1 The Customer warrants that they have a lawful basis for archiving and processing the correspondence concerned.
3.2 The Customer acknowledges that a mailbox may contain special categories of personal data — health, financial, data about minors — because a mailbox by its nature holds everything the Customer receives. M25 does not and cannot filter this. The Customer assesses before connecting a mailbox whether it contains such data and whether they have a basis for it.
3.3 The Customer informs data subjects where required and handles their requests, using the tools described in article 7.
3.4 When the Customer connects an external AI assistant to their archive, messages retrieved by that assistant leave M25's platform and go to the assistant's provider. The Customer chooses that provider and is responsible for the consequences, including any transfer outside the EEA. M25 points this out in this agreement and in the documentation.
4. Security
4.1 M25 takes appropriate technical and organisational measures (art. 32 GDPR), including:
- encrypted transport to storage and across internal connections
- internal message services that are not publicly reachable and are protected by a shared key with rotation support
- archive ownership checked on every retrieval, so that messages from another archive cannot be requested
- attachments with a risky content type are not served inline
- every AI operation, including local ones, is logged so that it is demonstrable whether data left the platform
- automated tests on scoping and access with every change
4.2 AI processing takes place on M25's own hardware. Vectors, summaries and draft replies do not leave the platform.
4.3 Fallback to a cloud language model is disabled. If M25's own hardware is unavailable, the processing is not performed rather than routed elsewhere. Enabling a cloud fallback happens only at the Customer's request and makes that provider a sub-processor.
4.4 Access by M25. M25 is a sole proprietorship. Its owner has technical access to all archives; separation of duties is not possible. M25 commits to:
| a | access message content only for incident investigation or at the Customer's request |
| b | record every such access with time and reason |
| c | inform the Customer afterwards of any access to message content that was not at their request |
5. Sub-processors
5.1 The Customer gives general authorisation for the engagement of sub-processors. M25 informs the Customer at least thirty days before a change, after which the Customer may object and terminate.
5.2 Sub-processors at the date of this version:
| Party | Role | Location | Access to archive content |
|---|---|---|---|
| Hetzner Online GmbH | Object storage and servers | Germany | Yes — stores the messages |
| DigitalOcean LLC | Servers and load balancer | Netherlands (Amsterdam) | Processing in transit, no storage |
| Resend, Inc. | Transactional email (notifications to the Customer) | United States | No — receives only the Customer's email address |
| Mollie B.V. | Payment processing | Netherlands | No |
| OpenRouter, Inc. | Cloud language models | United States | Only if the Customer enables the fallback in 4.3 — off by default |
5.3 M25 imposes on every sub-processor the same obligations as in this agreement.
6. Transfers outside the EEA
6.1 M25 processes and stores within the EEA, except for:
- the fallback in article 4.3, only if enabled by the Customer
- transfers resulting from an AI assistant the Customer connects (article 3.4), for which the Customer is responsible
- transactional email via Resend (article 5.2), which carries no archive content
6.2 Where M25 transfers data outside the EEA, appropriate safeguards apply, such as the European Commission's standard contractual clauses.
7. Data subject rights
7.1 M25 enables the Customer to respond to data subject requests through the Service itself:
- search by sender, to find everything from or to an address
- view any archived message
- remove, at three levels: a single message, everything from or to one email address, or the entire archive
7.2 Removal is permanent and covers the search index, the message record, attachments, any context the message belonged to, and the stored original. Removed messages do not return on a later sync; a removal record blocks re-import. Context summaries that may still quote a removed message are cleared and rebuilt.
7.3 Every removal is logged: who requested it, when, what was selected, and how many messages were affected. That log is the Customer's evidence that a request was carried out. Log entries are kept for five years. The selector (the email address used) is retained in readable form for twelve months and as a hash thereafter.
7.4 If M25 itself receives a request from a data subject, M25 refers them to the Customer and informs the Customer without undue delay.
8. Retention and deletion
8.1 M25 retains the data for as long as the Customer keeps the archive.
8.2 The Customer can empty the archive at any time using the tools in article 7. On request, M25 confirms deletion in writing; the confirmation is based on the removal log.
8.3 After the Email Archive plan ends, M25 deletes all archived data within ninety days, unless a statutory retention obligation prevents this. The Customer keeps access until the end of the paid period and can empty the archive themselves before then.
8.4 Before the plan ends, the Customer may request a copy of the archived messages. M25 provides this in a standard mailbox format within a reasonable period; M25 may charge a reasonable fee for the work involved.
9. Data breaches
9.1 M25 informs the Customer of a personal data breach affecting the Customer's archive without undue delay and no later than forty-eight hours after becoming aware of it, at the email address on the account.
9.2 The notification states what happened, which data and how many messages are affected as far as known, what M25 has done, and what M25 recommends the Customer do.
9.3 M25 supports the Customer in any notification to a supervisory authority or to data subjects.
10. Audit
10.1 M25 makes available to the Customer the information necessary to demonstrate compliance with article 28 GDPR, including this agreement, the sub-processor list, the removal log for their archive, and on request the data protection impact assessment and the record of processing activities for the Service.
10.2 The Customer may have an audit carried out once per year, or more often after a breach, by an independent auditor bound by confidentiality, at the Customer's expense and with at least thirty days' notice.
11. Liability
11.1 Each party is liable for its own breaches of this agreement and of the GDPR.
11.2 M25's total liability under this agreement is limited to the amount the Customer paid for the Email Archive plan in the twelve months preceding the event, except in cases of intent or gross negligence.
12. Final provisions
12.1 M25 may amend this agreement. Material changes are announced at least thirty days in advance at the email address on the account. If the Customer does not agree, they may end the Email Archive plan before the change takes effect.
12.2 Dutch law applies. Disputes are brought before the competent court in the Netherlands.
12.3 The current version of this agreement, the data protection impact assessment and the record of processing activities are available at websitepublisher.ai/legal and on request via privacy@websitepublisher.ai.
Version 2.0 replaces version 1.0 (draft, 1 September 2026). Changes: converted from a signed document to click-through acceptance; Controller defined as the archive owner; privacy contact set; articles 7 and 8 updated to reflect the removal tooling as built; sub-processor locations completed; fallback provider named.
Website