Data processing agreement.
This is the Article 28 agreement required whenever one organisation processes personal data on another's behalf. Surve reads your customers' email, so it applies to every account — you do not need to request it, and there is nothing to sign before it takes effect. It is here in full because a compliance officer should be able to read it without emailing sales first.
- 1. Scope
- 2. Our instructions
- 3. Confidentiality
- 4. Security measures
- 5. Sub-processors
- 6. Helping you answer data subjects
- 7. Breach notification
- 8. Deletion and return
- 9. Audits
- 10. International transfers
- Annex — details of processing
1. Scope
This agreement applies to personal data we process on your behalf under the Terms of Service, for as long as we provide the service. Where UK GDPR and EU GDPR both apply, references are to whichever governs the data in question.
2. Our instructions
We process personal data only on your documented instructions. Your configuration — which mailboxes are connected, the knowledge base, the tone, the routing rules, whether auto-send is on — constitutes those instructions, along with the Terms of Service.
If we believe an instruction breaches data protection law, we will tell you and may decline to act on it. If we are legally required to process data for another reason, we will tell you first unless the law prohibits it.
3. Confidentiality
Everyone we authorise to access personal data is bound by a duty of confidentiality, and access is limited to those who need it to run the service.
4. Security measures
Article 32 requires appropriate technical and organisational measures. Ours are:
- Encryption — TLS in transit. Mailbox credentials are held on access-restricted servers with restrictive file permissions, and encryption at rest is being implemented.
- Tenant isolation — every stored record is scoped to one customer and every query is filtered by it. This is enforced in code and covered by tests that fail the build if isolation breaks.
- Least privilege — the service holds only the mailbox scopes it needs, and you can revoke access at any time from your own provider.
- Prompt-injection defence — inbound mail is treated as data, never as instructions. Attempts to manipulate the AI through message content are detected, receive a fixed safe reply, and are held for a human.
- Output controls — a screen on every outgoing message blocks financial promises and strips links to domains you have not approved.
- Rate limiting and a kill switch — per-sender, per-domain and global send caps, plus an incident stop that halts all sending immediately and fails closed if it cannot be read.
- Data minimisation — attachments are not stored; message bodies are truncated; secrets are never returned to the user interface.
- Automatic deletion — a nightly purge removes handled messages 45 days after resolution.
5. Sub-processors
You give general authorisation for us to engage the sub-processors listed in the privacy policy. Each is bound by written terms no less protective than this agreement, and we remain liable for their performance.
We will give you at least 30 days' notice before adding or replacing one. If you reasonably object on data protection grounds, you may terminate the affected service without penalty for the remainder of the term.
6. Helping you answer data subjects
If someone contacts us directly about data in your inbox, we will not respond substantively — we will tell them to contact you, and tell you. We will help you meet access, correction, deletion, restriction, objection and portability requests, using the export and erase tools in your account.
7. Breach notification
We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting your data. The notification will describe what happened, the categories and approximate number of people affected, the likely consequences, and what we are doing about it — and will be sent even when the picture is incomplete, with updates as we learn more.
8. Deletion and return
You can export your data at any time. On termination we delete it within 30 days, except where law requires retention (billing records). We will confirm deletion in writing if you ask.
9. Audits
We will make available the information needed to demonstrate compliance with this agreement, and will allow and contribute to an audit no more than once a year, on reasonable notice, at your cost, subject to confidentiality. Where a recognised third-party report would answer your question, we may provide that instead.
10. International transfers
Processing takes place in the EU. Where a sub-processor processes data outside the UK/EEA — currently Anthropic, and Stripe where card payments are used — transfers are made under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with a transfer risk assessment on file.
Annex — details of processing
| Subject matter | Providing an AI assistant that reads and replies to the controller's business email |
|---|---|
| Duration | For the term of the agreement, plus the retention periods in the privacy policy |
| Nature and purpose | Reading, classifying, summarising, drafting replies to, sending, storing and deleting email |
| Categories of data subject | Anyone who emails the connected mailbox — customers, enquirers, candidates, suppliers — and the controller's own staff |
| Categories of personal data | Names, email addresses, telephone numbers where given, message content, and whatever the sender chooses to include |
| Special category data | Not intentionally processed. Senders may nonetheless include it in free text — for example a recruitment inbox receiving a CV. The controller should assess this and configure sensitive-topic handling accordingly. |
| Frequency | Continuous, on a five-minute cycle |
Contact
Surve
privacy@surve.app