Legal · Last updated 25 September 2026
Data Processing Agreement
Contents
- 1. Definitions and interpretation
- 2. Scope, roles and duration
- 3. Nature and purpose of processing
- 4. Categories of data and data subjects
- 4A. Warmerly's obligations as processor
- 4B. Customer obligations
- 5. Sub-processors
- 6. International transfers
- 7. Security
- 8. Personal data breaches
- 9. Data subject requests
- 10. Information and audit
- 11. Deletion and return
- 12. Liability and precedence
- 13. Term, termination and changes
- 14. Governing law and jurisdiction
- 15. Contact
- Annex 1: Description of the processing
- Annex 2: Technical and organisational measures
- Annex 3: Sub-processors
This Data Processing Agreement ("DPA") is made between the Customer and Warmerly ("Warmerly", "we", "us"). It forms part of our Terms of Service (the "Terms") and applies whenever we process personal data on the Customer's behalf in providing the service. The Customer accepts it by accepting the Terms, and no separate signature is needed for it to bind both parties. If the Customer wants a countersigned copy for its records, we will provide one on request (section 15).
1. Definitions and interpretation
Terms used but not defined here (including "controller", "processor", "data subject", "personal data breach", "processing" and "supervisory authority") have the meanings given in Data Protection Law. In this DPA:
- "Customer" means the person or organisation that has agreed to the Terms, including for every workspace it owns or pays for.
- "Customer Personal Data" means personal data that we process on the Customer's behalf in providing the service, as described in Annex 1. It does not include the data described in section 2.3, for which we are a controller.
- "Data Protection Law" means, as applicable to the processing, the UK GDPR, the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), the Swiss Federal Act on Data Protection, and the laws that implement or supplement them, as amended or replaced.
- "EU SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, and "IDTA" means the International Data Transfer Agreement issued under the same section.
- "Sub-processor" means a third party we engage that processes Customer Personal Data on our behalf.
- "Warmerly" means the provider of the service, a sole trader established in the United Kingdom (not a limited company).
Headings are for convenience only. "Including" means including without limitation. A reference to a section is to a section of this DPA unless it says otherwise.
2. Scope, roles and duration
2.1 Warmerly as processor. For Customer Personal Data, the Customer is the controller and Warmerly is its processor. This covers the Customer's connected and hosted mailboxes and their contents, campaigns and the people they are sent to, imported lists and custom fields, connected LinkedIn, WhatsApp, Instagram and other channel accounts, transactional email the Customer sends through our API, records the Customer takes out of our lead database into its own workspace, and anything else the Customer uploads to or creates in the service.
2.2 Customers who are themselves processors. Where the Customer processes personal data for its own clients (for example an agency running client workspaces), the Customer is a processor and Warmerly is its sub-processor. The Customer warrants that its client has authorised our appointment on the terms of this DPA, including the sub-processors in section 5. The Customer remains our only point of contact: we take instructions from, and give notices to, the Customer alone, and the Customer is responsible for passing them on to its client.
2.3 Warmerly as independent controller. We act as a controller, not as the Customer's processor, for:
- account, authentication, billing, support and security data about the Customer's users, as described in our Privacy Policy;
- our business-contact database and the records produced by our email finder, as described in our Prospect Privacy Notice. Once the Customer exports a record, or adds it to its own workspace, campaign or list, the Customer is the controller of that copy (see our Lead Database Use Terms) and we process that copy as its processor;
- data about how the service is used, and aggregated or de-identified information we derive from the service under section 14.2 of the Terms; and
- the operation of the warmup network, as set out in section 2.4.
Where we act as a controller, we do so under our own privacy notices and Data Protection Law, and this DPA does not apply to that processing.
2.4 The warmup network. Enrolling a mailbox in warmup is an instruction to us to send and receive warmup messages between that mailbox and other mailboxes enrolled in the network. Those are other customers' mailboxes and mailboxes we operate ourselves, such as ready-warmed mailboxes before they are sold. For the Customer's own mailbox and the warmup messages in it, we act as the Customer's processor. We decide how the network works: which mailboxes exchange mail, and the content, timing and handling of warmup messages. We use the resulting activity records to run, protect and measure the network and to produce aggregated deliverability statistics, and for those purposes we act as an independent controller. Other participating customers see the Customer's mailbox address, display name and signature in the warmup mail they receive (section 4). They are not our sub-processors, and our Warmup Network Participation Terms forbid them from using that information for any other purpose.
2.5 Duration. This DPA applies for as long as we process Customer Personal Data. That is the term of the Terms plus the deletion periods in section 11.
3. Nature and purpose of processing
We process Customer Personal Data only to provide, secure and support the service under the Terms. That covers:
- authentication, and encrypted storage of mailbox OAuth tokens and IMAP/SMTP credentials;
- sending and receiving warmup mail through the Customer's enrolled mailboxes;
- sending outreach campaigns through the Customer's mailboxes and connected accounts, and recording delivery, open, click, reply, bounce and unsubscribe events;
- reading, storing and displaying the contents of the Customer's connected mailboxes and connected LinkedIn, WhatsApp and Instagram accounts in the Warmerly inbox, and sending push notifications about new messages to the Customer's mobile devices where the Customer has turned them on;
- hosting mailboxes the Customer orders from us (including OneMail mailboxes and the free mailbox), and sending transactional email the Customer submits through our API;
- sending message extracts, campaign context and business-contact information to an AI provider in order to classify messages, draft replies, generate personalised campaign content and answer the Customer's questions in the support assistant;
- scheduling and publishing content to social accounts the Customer connects;
- computing health and deliverability metrics, and providing the dashboard, API and MCP server;
- backups, security monitoring, abuse prevention and error tracking; and
- access by Warmerly staff where needed to resolve an issue the Customer has raised or to investigate a credible abuse report. That access is audit-logged and time-limited (Annex 2).
Annex 1 describes the processing in full.
4. Categories of data and data subjects
- The Customer's users and team members, to the extent their data is Customer Personal Data (for example their names and roles within a workspace).
- Warmup participants: the addresses, display names and signatures in the headers and bodies of warmup mail, used only to send, receive and handle warmup messages. Because warmup is real mail between real mailboxes, the Customer's mailbox address, display name and signature are visible to the other participating mailboxes it exchanges warmup mail with (section 2.4).
- Campaign recipients and leads: name, business email address, employer, job title, LinkedIn or other profile details, any custom fields the Customer uploads, the content sent to them, and their engagement with it (opens, clicks, replies, bounces and unsubscribes).
- Correspondents in the Customer's mailboxes and connected accounts: anyone who appears in the Customer's inbox or sent mail, or in its LinkedIn, WhatsApp or Instagram conversations, including their name, address, number or handle and the full content of those messages. This category is broad and is not limited to people connected with Warmerly.
- Recipients of the Customer's transactional email: email address, the content the Customer submits, and delivery, bounce and complaint events.
- People who appear in content the Customer publishes through connected social accounts.
Our business-contact database is not Customer Personal Data. We are its controller (section 2.3), and our Prospect Privacy Notice covers it.
The service is not designed for special category data (Article 9), criminal offence data (Article 10) or data about children, and the Customer must not use it to process them. If the content of the Customer's mail or messages nonetheless contains such data, the Customer is responsible for having a lawful basis and any condition the law requires.
4A. Warmerly's obligations as processor
- Documented instructions. We process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country or an international organisation. The Customer's instructions are the Terms, this DPA, the Customer's configuration and use of the service (for example the mailboxes it connects, the campaigns it launches and the features it turns on), and any other written instruction we agree to. Additional instructions that fall outside the service as described in the Terms need our agreement and may be charged for. If the law of the UK, the EU or an EU member state requires us to process Customer Personal Data other than on the Customer's instructions, we will tell the Customer about that legal requirement before processing, unless that law prohibits us from doing so on important grounds of public interest.
- Infringing instructions. We will tell the Customer promptly if, in our opinion, an instruction infringes Data Protection Law. We may suspend acting on that instruction until the Customer confirms or changes it. We are not obliged to carry out a legal review of the Customer's instructions.
- Confidentiality. We ensure that everyone we authorise to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and has access only to the extent needed for their role.
- Security. We take the measures required by Article 32, as described in section 7 and Annex 2.
- Sub-processors. We engage sub-processors only on the conditions in section 5.
- Data subject rights. Taking into account the nature of the processing, we assist the Customer by appropriate technical and organisational measures, as far as possible, to respond to requests from data subjects to exercise their rights (section 9).
- Compliance with Articles 32 to 36. Taking into account the nature of the processing and the information available to us, we assist the Customer with its obligations on security of processing, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation with the supervisory authority. We do this mainly by providing this DPA, Annex 2, our Sub-processors page and the information in section 8, and by answering reasonable written questions.
- Deletion or return. At the end of the service we delete or return Customer Personal Data as set out in section 11.
- Information and audit. We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in section 10.
- Requests from authorities. If a public authority asks us for Customer Personal Data, we will direct it to the Customer where we can, and tell the Customer about the request unless the law prohibits us. We will disclose only what we are legally required to disclose.
4B. Customer obligations
- The Customer is responsible for the lawfulness of the Customer Personal Data it provides, connects or collects through the service, and of its instructions. That includes having a lawful basis for each processing activity, meeting the requirements of electronic marketing law, and giving data subjects any notice the law requires, including notice that we process their data as the Customer's processor.
- The Customer is responsible for the accuracy and quality of that data and for the means by which it was obtained.
- The Customer's instructions must comply with Data Protection Law, and following them must not cause us to breach it.
- The Customer has assessed the measures in section 7 and Annex 2 and agrees they give a level of security appropriate to the risk of its processing.
- The Customer is responsible for configuring the service securely on its side, including managing its users, their roles and API keys, and choosing which mailboxes and accounts to connect.
5. Sub-processors
5.1 Current sub-processors. The Customer authorises us to use the following sub-processors. Annex 3 incorporates this list, and our Sub-processors page sets out the same list with the data categories, location and date added for each.
- OVH SAS (Germany, United Kingdom): servers for the application, the main database and our hosted-mailbox mail servers.
- Cloudflare, Inc. (United States, with a global network): DNS, DDoS protection and CDN, bot checks on sign-up and support forms, R2 object storage for uploaded images and files, registration and DNS for domains ordered through OneMail, and status-page failover.
- Microsoft Corporation / Microsoft Ireland Operations Ltd. (Azure regions in Sweden and Germany): the primary AI provider for the AI features in section 3 (Azure OpenAI, Sweden Central region), and storage of encrypted database backups (Azure Blob Storage, Germany West Central region).
- OpenRouter, Inc. (United States): fallback routing of AI requests to model providers when the primary AI provider fails.
- Google LLC / Google Ireland Ltd. (United States / Ireland): Gemini models reached through OpenRouter when it is used as the fallback, Google Analytics 4 on our website (consent-gated), and delivery of mobile push notifications to Android devices.
- Backblaze, Inc. (United States company): storage of message bodies and attachments for mailboxes we host (OneMail and the free mailbox).
- Stripe Payments Europe, Ltd. (Ireland, with a US parent): billing and payment processing.
- Resend, Inc. (United States): delivery of Warmerly's own service and account email, and receipt of mail sent to our support address.
- Amazon Web Services EMEA SARL (Sweden, eu-north-1): Amazon SES, delivery of customer transactional email and its bounce/complaint event notifications.
- Unipile SAS (France): LinkedIn account connection, messaging and sync.
- Meta Platforms, Inc. (United States): Instagram account connection and messaging, where the Customer connects an Instagram account.
- Zernio (outside the UK/EEA): connection of social accounts and scheduling and publishing of content to them, where the Customer uses content scheduling.
- 650 Industries, Inc. (Expo) (United States): delivery of push notifications to the Warmerly mobile app.
- PostHog, Inc. (United States): product analytics, error monitoring and session replay (consent-gated).
The providers of the mailboxes and platforms the Customer chooses to connect (for example Google Workspace, Microsoft 365, LinkedIn or WhatsApp) act under the Customer's own agreements with them and are not our sub-processors, except where they are listed above. The same applies to the mail servers of the people the Customer sends to.
5.2 General authorisation. The Customer gives us general written authorisation to engage sub-processors, on the conditions in this section.
5.3 Flow-down and responsibility. Before a sub-processor processes Customer Personal Data, we put in place a written contract that imposes data protection obligations no less protective than those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, we remain liable to the Customer for its performance of those obligations, subject to section 12.
5.4 Notice of changes. We will give at least 15 days' notice before a new sub-processor starts processing Customer Personal Data, by updating our Sub-processors page and by emailing anyone who has asked to be notified as described on that page. The Customer agrees that this is the notice required by Article 28(2) and by Clause 9(a) of the EU SCCs. If we have to replace a sub-processor urgently to keep the service secure or running, we may do so with shorter notice, give notice as soon as reasonably practicable, and the right to object below still applies.
5.5 Objections. The Customer may object to a new sub-processor on reasonable data protection grounds by emailing privacy@warmerly.com within the notice period, with its reasons. We will discuss the objection in good faith and may propose a change to the service, or to the Customer's configuration, that avoids the sub-processor. If we cannot resolve the objection within 30 days, the Customer may terminate the affected part of the service by written notice, and we will refund any prepaid fees for that part covering the period after termination. That is the Customer's only remedy for an objection. If the Customer does not object within the notice period, it is treated as having accepted the new sub-processor.
6. International transfers
6.1 Where data is processed. Warmerly is established in the United Kingdom. Our main application servers and database are in Germany, with hosted-mailbox mail servers in the United Kingdom, and our database backups are stored in Germany. Our primary AI provider processes requests in Sweden, and our transactional email sub-processor (Amazon SES) also processes requests in Sweden. Several sub-processors in section 5 are established outside the UK and EEA, or may process data in the United States.
6.2 Transfers from the Customer to Warmerly. For a Customer established in the UK, transferring Customer Personal Data to us is not a restricted transfer. For a Customer established in the EEA or Switzerland, the transfer to us relies on the adequacy decision for the United Kingdom issued by the European Commission, or the equivalent Swiss recognition. If that decision ceases to apply, the EU SCCs are incorporated into this DPA for those transfers, as set out in section 6.4: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor.
6.3 Onward transfers to sub-processors. We will not transfer Customer Personal Data, or allow a sub-processor to transfer it, to a country outside the UK and EEA unless the transfer is covered by a mechanism that Data Protection Law recognises. That means an adequacy decision or regulations (including, where the recipient is certified, the EU-US Data Privacy Framework and its UK Extension), or the EU SCCs (Module Three for EEA-origin data), the UK Addendum or the IDTA, as the sub-processor's data processing terms provide. We also use encryption in transit and data minimisation as supplementary measures. A copy of the relevant safeguards is available on request, with commercial terms removed.
6.4 How the EU SCCs apply. Where this DPA incorporates the EU SCCs:
- the Customer is the data exporter and Warmerly is the data importer, and signing or accepting the Terms counts as signing the EU SCCs;
- the optional docking clause in Clause 7 applies;
- for Clause 9(a), Option 2 (general written authorisation) applies, with the notice period in section 5.4;
- the optional wording in Clause 11(a) does not apply;
- for Clause 13, the competent supervisory authority is the one identified in Annex 1, part C;
- for Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland;
- for Clause 18(b), disputes are resolved by the courts of Ireland; and
- Annexes I and II of the EU SCCs are completed by Annexes 1 and 2 of this DPA, and the sub-processor list for Annex III is in section 5 and Annex 3.
6.5 The UK Addendum. Where a transfer of Customer Personal Data is restricted under the UK GDPR and no other mechanism applies, the UK Addendum is incorporated into this DPA. Table 1 is completed with the details in Annex 1, part A. Table 2 is completed by selecting the EU SCC modules and clauses described in section 6.4. Table 3 is completed by Annexes 1 to 3. For Table 4, either party may end the UK Addendum as set out in its Section 19.
6.6 Switzerland. For transfers subject to Swiss law, the EU SCCs apply with these changes: references to the EU GDPR are read as references to the Swiss Federal Act on Data Protection, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and data subjects habitually resident in Switzerland may bring claims in Switzerland.
6.7 Precedence. If the EU SCCs, the UK Addendum or the IDTA conflict with this DPA or the Terms, they prevail to the extent of the conflict.
6.8 Transfers the Customer makes. When the Customer directs the service to send mail or messages to recipients in other countries, or connects a mailbox or platform whose provider is abroad, the resulting transfers are made on the Customer's instructions and are the Customer's responsibility.
7. Security
We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. Annex 2 lists the measures in place today. In summary:
- mailbox OAuth tokens and IMAP/SMTP credentials are encrypted at rest with AES-256-GCM;
- passwords are hashed with Argon2id;
- web, app and API traffic is encrypted in transit with TLS;
- role-based access control applies within workspaces and to Warmerly staff, and staff access to a Customer's account is audit-logged;
- database and administrative ports are firewalled off the public internet and reachable only over a private network;
- authentication and other abuse-sensitive endpoints are rate limited; and
- the production database is backed up nightly and continuously archived, encrypted, to a separate provider.
We may update the measures in Annex 2 over time, provided the overall level of security is not reduced.
Warmerly is a small business and states its security posture accurately: we do not currently hold SOC 2, ISO 27001, or any other third-party certification, and we do not currently commission annual third-party penetration testing. We will update this section if that changes.
8. Personal data breaches
We will notify the Customer without undue delay (and within 72 hours where feasible) after confirming a personal data breach affecting Customer Personal Data. We will notify the account owner's email address, with enough detail to enable the Customer to meet its own obligations to notify the supervisory authority and data subjects. As far as it is available, that includes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to deal with it and reduce its effects, and a contact point for more information. Information may be provided in stages as it becomes available.
We will take reasonable steps to contain and investigate the breach and reduce its effects. Unless the law requires otherwise, we will not notify the Customer's data subjects or supervisory authority about a breach on the Customer's behalf without first consulting the Customer. Notifying or responding to a breach is not an admission of fault or liability. This section does not apply to unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, failed log-in attempts or denial-of-service attacks.
9. Data subject requests
We will help the Customer respond to requests from data subjects to exercise their rights within the statutory timeframes. The Customer can deal with most requests itself using the service: finding and deleting campaign leads, deleting campaigns, disconnecting mailboxes, and adding addresses to its suppression list. Where it cannot, we will help on request to privacy@warmerly.com. If we receive a request directly from one of the Customer's data subjects, we will not respond to it ourselves except to tell the requester to contact the Customer, and we will pass the request to the Customer where we can identify it. Assistance beyond what the service provides may be charged at our reasonable rates, unless the request arises from our own breach of this DPA.
10. Information and audit
10.1 Information. We make available to every Customer the information needed to demonstrate our compliance with Article 28: this DPA, Annex 2, our Sub-processors page and our Trust and Security page, together with reasonable written answers to specific questions sent to privacy@warmerly.com.
10.2 Remote audit. Customers on Agency or higher plans may request a remote audit of Warmerly's security posture once per calendar year, by giving 30 days' notice. We will answer a pre-agreed security questionnaire and provide reasonable written evidence of the measures in section 7 and Annex 2. We cannot provide certification or audit reports we do not hold.
10.3 Further audits. Any Customer may carry out a further audit, including an inspection, where the information above is not enough to demonstrate our compliance with this DPA, where a supervisory authority requires it, or after a personal data breach affecting that Customer's data. Such an audit must be carried out by the Customer or an independent auditor it mandates, who is not our competitor and who is bound by confidentiality. It must take place on at least 30 days' written notice, during normal UK business hours, no more than once in any 12 months (unless a supervisory authority requires more), and in a way that does not disrupt the service, compromise security, or give access to other customers' data. The Customer bears its own costs and pays our reasonable costs of assisting, except where the audit shows a material breach of this DPA by us.
10.4 Confidentiality. Information we provide under this section, and the results of any audit, are our confidential information. The Customer may use them only to assess our compliance with this DPA and may share them only with its advisers, its auditors and a supervisory authority.
11. Deletion and return
11.1 Return. During the term, the Customer can retrieve Customer Personal Data using the export features and API in the service. If the Customer asks in writing, no later than 30 days after termination, we will also provide a copy of Customer Personal Data that the service does not let it export, in a commonly used machine-readable format.
11.2 Deletion. On termination, we delete Customer Personal Data on the schedule set out in section 8 of our Privacy Policy. In summary: mailbox credentials immediately when a mailbox is disconnected, synced mailbox contents within 30 days of disconnection, and remaining account data within 90 days.
11.3 Exceptions. We may keep Customer Personal Data where UK, EU or member state law requires us to store it, and only for as long as it requires. Addresses on our platform-wide suppression list (hard bounces and erasure requests) are kept after termination so that they continue to be honoured, and the Customer instructs us to do so. The Customer's own workspace unsubscribe list is deleted with the workspace; the Customer should export it first if it needs it. Copies in our encrypted backups are not deleted one by one. They expire as the backups age out, currently within about 50 days (35-day retention, then up to 14 days of soft deletion). Until they expire, they remain protected under this DPA and are used only to recover from a loss of data.
11.4 Confirmation. We will confirm deletion in writing on request.
12. Liability and precedence
Each party's liability arising out of or relating to this DPA, including the EU SCCs and UK Addendum where they apply, is subject to the limitations and exclusions in our Terms of Service, and counts towards the same aggregate cap. This does not limit either party's liability to data subjects under the EU SCCs or UK Addendum, or any liability that cannot be limited under Data Protection Law. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. On everything else, the Terms prevail. Section 6.7 sets out when the transfer clauses prevail.
13. Term, termination and changes
This DPA starts when the Customer accepts the Terms. It ends when the Terms end, but continues to apply for as long as we hold any Customer Personal Data. It cannot be terminated separately from the Terms, except as set out in section 5.5. We may update this DPA where a change in law, guidance from a supervisory authority, or a change to the service requires it. We will notify material changes in the same way as changes to the Terms, and no change will reduce the overall protection this DPA gives Customer Personal Data. Changes to the sub-processor list follow section 5 instead.
14. Governing law and jurisdiction
This DPA, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it, is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction. The exceptions are the EU SCCs, which are governed by the law and courts set out in section 6.4, and any case where Data Protection Law requires otherwise.
15. Contact
For questions about this DPA, to request a countersigned copy, or to send any notice under it, email privacy@warmerly.com.
Annex 1: Description of the processing
A. List of parties
- Data exporter: the Customer. Contact: the account owner's email address. Activities: use of the service under the Terms. Role: controller, or processor on behalf of its clients (section 2.2).
- Data importer: Warmerly, a sole trader established in the United Kingdom. Contact: privacy@warmerly.com. Activities: providing the service under the Terms. Role: processor, or sub-processor where the Customer is a processor.
B. Description of the transfer and processing
- Categories of data subjects: as listed in section 4. These are the Customer's users and team members, warmup participants, campaign recipients and leads, correspondents in connected mailboxes and accounts, recipients of transactional email, and people who appear in published content.
- Categories of personal data: names; email addresses; phone numbers and messaging handles for connected accounts; employer, job title and profile details; custom fields the Customer uploads; the content of email, messages and posts; message metadata (headers, timestamps, delivery status); engagement events (opens, clicks, replies, bounces, unsubscribes); and technical data (IP address, user agent) where it appears in engagement tracking.
- Special categories of data: none intended (section 4). No additional safeguards apply beyond those in Annex 2.
- Frequency of the transfer: continuous, for the duration of the service.
- Nature of the processing: collection, recording, organisation, storage, retrieval, consultation, use, transmission (sending and receiving mail and messages), analysis (including by AI models), restriction, erasure and destruction.
- Purpose of the processing: providing, securing and supporting the service, as described in section 3.
- Retention: for the term, then as set out in section 11 and section 8 of our Privacy Policy.
- Transfers to sub-processors: the subject matter, nature and duration are as above, limited to each sub-processor's function listed in section 5 and on our Sub-processors page.
C. Competent supervisory authority
For the EU SCCs: the supervisory authority of the EU member state where the Customer is established. If the Customer is not established in the EU but has appointed a representative under Article 27(1) EU GDPR, it is the authority of the member state where the representative is established. Otherwise, it is the authority of the member state where the data subjects concerned are located. For the UK GDPR and the UK Addendum, it is the Information Commissioner's Office.
Annex 2: Technical and organisational measures
These are the measures in place at the date at the top of this page. They are described as they actually operate, not as aspirations.
Encryption
- Mailbox OAuth tokens, IMAP/SMTP passwords and the credentials of mailboxes we host are encrypted at rest with AES-256-GCM, using a key held outside the database.
- Account passwords are hashed with Argon2id. API keys, email verification tokens and password reset tokens are stored only as SHA-256 hashes.
- The website, app and API are served over TLS, with HTTP Strict Transport Security. Mail to and from other mail servers uses TLS where the other server supports it.
- Database backups are encrypted before they leave our servers (section below).
Access control
- Sessions are recorded server-side and can be revoked. Logging out revokes the session, changing or resetting a password revokes the user's other sessions, and sessions expire after 30 days.
- Log-in, sign-up and other abuse-sensitive endpoints are rate limited, and sign-up is protected by a bot check.
- Within a workspace, users have owner, admin or member roles. Access to a workspace's data requires membership of that workspace.
- Third-party apps connecting to our MCP server use OAuth 2.1 with PKCE (S256 only), and the Customer can revoke a grant at any time.
- Access to our admin tools requires a staff account. Staff hold one of six roles, each limited to the capabilities it needs.
- Staff access to a Customer's account (impersonation) needs a role permitted to do it. It is recorded in an audit log, expires within 24 hours, and ends by revoking the session it used.
- Security-relevant events are recorded in an audit log, including log-ins and failed log-ins, password and email changes, API key creation and revocation, member and role changes, and mailbox connections.
Network and infrastructure
- Servers are hosted in OVH data centres, and we rely on OVH's physical and environmental security controls.
- The production database accepts connections only on a private network (Tailscale). Database and administrative ports are blocked from the public internet by host firewall rules. The only public ports are those for the website (80 and 443) and for mail.
- Public web traffic passes through Cloudflare for DDoS protection.
Availability and recovery
- The production database and our mail servers' databases are backed up nightly. Each backup is encrypted (AES-256) with a key held off-server and uploaded to Microsoft Azure storage in Germany. Our servers hold write-only credentials, so a compromised server cannot read or delete existing backups. Backups are kept for 35 days.
- The production database's write-ahead log is also archived continuously, encrypted, to the same storage (at least every five minutes), which allows point-in-time recovery.
- An automated check alerts us if a backup fails or has not completed on schedule.
- Message bodies of mailboxes we host are stored separately in Backblaze B2 object storage.
Monitoring and data minimisation
- Errors in the app and in our background workers are tracked, and our mail servers are health-checked automatically, with alerts to us.
- Only the data needed for a feature is sent to an AI provider. Our primary AI provider does not use it for training, and requests sent through OpenRouter may be routed only to upstream providers that do not retain prompts.
- Retention periods are set out in section 8 of our Privacy Policy.
Organisation
- Warmerly is a sole trader. Production access is limited to the operator and any staff or contractors we authorise. They are bound by confidentiality and given only the role they need.
- Personal data breaches are handled as set out in section 8.
- We do not hold SOC 2, ISO 27001 or any other third-party certification, and we do not commission annual third-party penetration testing (section 7).
Annex 3: Sub-processors
The sub-processors the Customer has authorised are those listed in section 5.1, as updated under section 5.4. Our Sub-processors page gives the purpose, the data categories, the location and the date added for each.



