Data processing agreement.

Version 1.0 · Last updated 6 August 2026 · Forms part of the Terms of Service

This is the Article 28 agreement required whenever one organisation processes personal data on another's behalf. Surve reads your customers' email, so it applies to every account — you do not need to request it, and there is nothing to sign before it takes effect. It is here in full because a compliance officer should be able to read it without emailing sales first.

Who is who. You are the controller: it is your inbox and your relationship with the people who write to you. We are the processor: we act on your instructions and nothing else.

1. Scope

This agreement applies to personal data we process on your behalf under the Terms of Service, for as long as we provide the service. Where UK GDPR and EU GDPR both apply, references are to whichever governs the data in question.

2. Our instructions

We process personal data only on your documented instructions. Your configuration — which mailboxes are connected, the knowledge base, the tone, the routing rules, whether auto-send is on — constitutes those instructions, along with the Terms of Service.

If we believe an instruction breaches data protection law, we will tell you and may decline to act on it. If we are legally required to process data for another reason, we will tell you first unless the law prohibits it.

3. Confidentiality

Everyone we authorise to access personal data is bound by a duty of confidentiality, and access is limited to those who need it to run the service.

4. Security measures

Article 32 requires appropriate technical and organisational measures. Ours are:

5. Sub-processors

You give general authorisation for us to engage the sub-processors listed in the privacy policy. Each is bound by written terms no less protective than this agreement, and we remain liable for their performance.

We will give you at least 30 days' notice before adding or replacing one. If you reasonably object on data protection grounds, you may terminate the affected service without penalty for the remainder of the term.

6. Helping you answer data subjects

If someone contacts us directly about data in your inbox, we will not respond substantively — we will tell them to contact you, and tell you. We will help you meet access, correction, deletion, restriction, objection and portability requests, using the export and erase tools in your account.

7. Breach notification

We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting your data. The notification will describe what happened, the categories and approximate number of people affected, the likely consequences, and what we are doing about it — and will be sent even when the picture is incomplete, with updates as we learn more.

8. Deletion and return

You can export your data at any time. On termination we delete it within 30 days, except where law requires retention (billing records). We will confirm deletion in writing if you ask.

9. Audits

We will make available the information needed to demonstrate compliance with this agreement, and will allow and contribute to an audit no more than once a year, on reasonable notice, at your cost, subject to confidentiality. Where a recognised third-party report would answer your question, we may provide that instead.

10. International transfers

Processing takes place in the EU. Where a sub-processor processes data outside the UK/EEA — currently Anthropic, and Stripe where card payments are used — transfers are made under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with a transfer risk assessment on file.

Annex — details of processing

Subject matterProviding an AI assistant that reads and replies to the controller's business email
DurationFor the term of the agreement, plus the retention periods in the privacy policy
Nature and purposeReading, classifying, summarising, drafting replies to, sending, storing and deleting email
Categories of data subjectAnyone who emails the connected mailbox — customers, enquirers, candidates, suppliers — and the controller's own staff
Categories of personal dataNames, email addresses, telephone numbers where given, message content, and whatever the sender chooses to include
Special category dataNot intentionally processed. Senders may nonetheless include it in free text — for example a recruitment inbox receiving a CV. The controller should assess this and configure sensitive-topic handling accordingly.
FrequencyContinuous, on a five-minute cycle

Contact

Surve
privacy@surve.app