Legal
Data Processing Agreement
Version 1.0 · effective 31 July 2026. Processor terms for customers who submit personal data to WillItInbox.
Parties and processing details
The Processor is Akash Soni, an individual operating WillItInbox from India. Manual execution is required. Email [email protected] to receive a copy completed with both parties' legal names, service addresses, effective date, and signatures. Data subjects include the Controller's users, customers, prospects, recipients, employees, and contractors. Data may include identifiers, email addresses, message and header content, IP and domain evidence, authentication results, validation and bounce evidence, DMARC/TLS reports, webhook data, and support records. Frequency and duration follow the Controller's use, subscription term, and documented retention settings.
1. Scope and roles
This DPA applies when a customer uses WillItInbox to process personal data. The customer is Controller and Akash Soni, an individual operating WillItInbox from India, is Processor. It supplements the Terms and an applicable order. The published page is not a signed agreement: this DPA becomes binding only when incorporated into an executed order or otherwise expressly accepted by both parties.
2. Processing instructions
WillItInbox processes personal data only on the Controller's documented instructions, including those expressed through product configuration and API requests, to provide email validation, deliverability testing, reports, DMARC and domain monitoring, inbox-placement diagnostics, webhooks, support, security, and deletion/export functions. WillItInbox will notify the Controller if an instruction appears to violate applicable data-protection law.
3. Confidentiality and personnel
Personnel and contractors with access to personal data are bound by confidentiality duties, receive access only as needed, and are subject to appropriate security and privacy training.
4. Security
WillItInbox maintains measures appropriate to risk, including encryption in transit, password and API-key hashing, encrypted integration credentials, tenant and project scoping, least-privilege access, MFA support, audit events, webhook signing, rate limits, provider-managed encryption at rest for backups, monitoring, vulnerability remediation, and short default retention for sensitive source data.
5. Data-subject requests
Taking account of the nature of processing, WillItInbox will provide reasonable technical and organizational assistance for access, correction, erasure, restriction, objection, and portability requests. Self-service export and erasure controls are available to authenticated account holders.
6. Security incidents
WillItInbox will notify the Controller without undue delay after confirming a personal-data breach affecting Customer Data and, where feasible, within 24 hours. Notices will include available information needed for the Controller's assessment and 72-hour supervisory-authority deadline, with updates as facts become available.
7. Subprocessors
The Controller grants general authorization for the subprocessors listed below. WillItInbox will impose materially equivalent data-protection obligations and remains responsible for their performance. Material changes will be announced in advance where practicable; the Controller may raise a reasonable data-protection objection.
8. International transfers
For restricted transfers without an adequacy decision, the parties will use the applicable module of the European Commission Standard Contractual Clauses, incorporated by reference, and supplementary measures where required. The Controller authorizes necessary onward transfers under those safeguards.
9. Return and deletion
On termination or documented instruction, WillItInbox will delete or return Customer Data unless law requires retention. Backups are isolated from ordinary use and expire under the backup schedule. Legally required financial records are minimized and anonymized where possible.
10. Information and audits
WillItInbox will provide information reasonably necessary to demonstrate Article 28 compliance. No more than once annually, unless a breach or regulator requires otherwise, the Controller may request relevant audit evidence or conduct a scoped audit on reasonable notice, subject to confidentiality, security, and cost protections.
11. Controller obligations
The Controller is responsible for lawful instructions, notices, legal bases, data accuracy, user permissions, and limiting submitted data to what is necessary. The Controller must not submit unlawful purchased lists, special-category data, or children's data unless expressly agreed with appropriate safeguards.
Annex A · approved subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| OVH US LLC dba OVHcloud | Frontend origin, application, PostgreSQL, Redis, SMTP receiver, encrypted backups, and workers | Primary hosting and backups: Vint Hill, Virginia, USA |
| Cloudflare, Inc. | Authoritative DNS, proxy/CDN, edge security, Email Routing, and cookie-free Web Analytics/Browser Insights | Global |
| SMTP2GO (Sand Dune Mail Ltd) | Transactional account email | Automatic/global routing; fixed account storage region recorded at execution |
Other independent recipients
Dodo Payments acts primarily as an independent controller and Merchant of Record for checkout, payment, tax, fraud-prevention, and invoice data. Google handles sign-in data when a user chooses Google OAuth. Customer-selected webhook, mailbox, SMTP, Slack, and similar integration providers receive data only on the Controller's instructions; they are not WillItInbox subprocessors for this DPA.
The European Commission SCCs apply where required. See the Privacy Policy and email [email protected] for a completed annex or signed copy.