Corresso All legal documents

Data processing agreement

Effective [not yet set]

To keep a copy, print this page or save it as a PDF from your browser’s print dialog.

This data processing agreement (“DPA”) is part of the agreement between your business, as controller, and [not yet set], CVR [not yet set], as processor, for the Corresso service. It governs all personal data we process on your behalf. It is concluded in writing when you accept our terms of service; GDPR art. 28(9) allows that to be done electronically.

1. The standard contractual clauses

The standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (OJ L 199, 7.6.2021, p. 18) — “the Clauses” — are incorporated into this DPA by reference and form its body. The Commission has decided that they meet the requirements of GDPR art. 28(3) and (4) for contracts between controllers and processors.

We do not modify the Clauses. This page makes the choices they leave open and fills in their Annexes, as Clause 2(a) allows, and adds a few terms of its own — about notice, objections, transfers and the end of the agreement — which Clause 2(b) allows because they do not contradict the Clauses. If anything on this page, in our terms of service or in any other agreement between us contradicts the Clauses, the Clauses prevail (Clause 4).

2. The choices the Clauses leave open

Some sub-processors give us less time than that when they change their own sub-processors: Postmark gives us 7 days and Anthropic gives us 15 days to object. When such a notice reaches us, we pass it on to you as soon as we receive it, and you may object within the time it leaves.

If you object on reasonable grounds relating to data protection, we look for a solution with you. If there is none, you may end the agreement for the affected part of the service, without penalty, before the change takes effect.

3. Transfers outside the EU and EEA

Corresso runs in the EU, at Hetzner in Germany. Where each sub-processor handles the data, and on what basis:

By accepting this DPA you instruct us to make these transfers (Clause 7.8(a)). Where a sub-processor relies on the Commission’s standard contractual clauses for a transfer, we and it use them as Clause 7.8(b) provides.

This DPA does not itself cover transfers of personal data from us to you; the Clauses say as much of themselves (Clause 1(f)). If your business is established outside the EU and EEA, tell us before you accept it, so that the right transfer clauses can be added.

4. Your instructions

Your documented instructions (Clause 7.1) are our terms of service, this DPA, and what your people do in Corresso: the settings they choose and the messages they send. We tell you immediately if we think an instruction infringes data protection law (Clause 7.1(b)).

5. Personal data breaches

We notify you of a personal data breach concerning your data without undue delay after we become aware of it, with the information Clause 9.2 lists, by email to your organisation’s owners.

6. When the agreement ends

At your choice, we delete your personal data and confirm to you that we have done so, or return it to you and delete our copies, within 30 days after the agreement ends — unless Union or Danish law requires us to keep it — and delete it from our backups within one further backup cycle (Clause 10(d)). Until then, the Clauses continue to apply.

Annex I — List of parties

Controller

Processor

Annex II — Description of the processing

Categories of data subjects

Categories of personal data

Sensitive data

The processing is not intended for special categories of personal data or for data about criminal offences. Messages contain whatever their senders write, however, and may include such data. The safeguards in Annex III apply to every message alike: access only for your own staff, through their own accounts; access by us only as Annex III describes; and no use for any purpose of ours.

Nature of the processing

Storing, displaying, organising, searching and deleting messages and notes; sending the messages your people approve through our email delivery sub-processor, and recording what happened to them; showing information from services you connect; and, once AI drafting is switched on with notice, writing draft replies for your people to review.

Purpose

To provide Corresso to you: so your staff can read, organise, assign and answer your business’s email, and send the replies and service messages they approve.

Duration

For as long as the agreement lasts, and afterwards for the up to 30 days needed to return or delete the data, and one further backup cycle for backups.

Receiving email into Corresso from your mailboxes is not yet switched on. When it is, we will update this Annex and, where it involves a new sub-processor, give you notice as section 2 describes.

Processing by sub-processors

For each, the subject matter and nature of the processing are the purpose and the personal data shown, and its duration is that of the agreement.

Hetzner Online GmbH

Active
Purpose
Hosting: the servers that run Corresso and hold its database
Personal data
Everything Corresso stores: accounts, conversations, notes and drafts
Where
Germany (EU)
Address
Industriestr. 25, 91710 Gunzenhausen, Germany
Transfer safeguard
None needed: the data stays in the EU

AC PM, LLC (Postmark)

Active
Purpose
Delivering the email a person sends from Corresso, and reporting back what happened to it
Personal data
Outgoing messages (sender, recipients, subject and text) and whether each was delivered, bounced or marked as spam
Where
USA (Deft’s data centre outside Chicago, and Amazon Web Services)
Address
1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA
Transfer safeguard
EU-U.S. Data Privacy Framework (AC PM LLC is covered by ActiveCampaign, LLC’s certification), with the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as the alternative
Keeps data
Keeps sent messages for up to 45 days (its default), and addresses that bounced, complained or unsubscribed on a suppression list until they are removed

Anthropic Ireland, Limited, and Anthropic, PBC

Not yet active

Engaged only when this service is switched on, and not before every customer has had 30 days’ notice.

Purpose
Writing draft replies for a person to review, edit and send
Personal data
The text of the conversation a draft is written for, and the draft it returns
Where
USA (Anthropic, PBC)
Address
Anthropic Ireland, Limited: 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland. Anthropic, PBC: 548 Market St, PMB 90375, San Francisco, CA 94104, USA
Transfer safeguard
EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Anthropic is not certified under the EU-U.S. Data Privacy Framework.

Annex III — Technical and organisational measures

Encryption

Separation between customers

Access and identification

A person sends every message

Data minimisation and retention

Availability and restore

Testing and review

Logging

Helping you (Clauses 8 and 9)