Data Processing Agreement
Last updated 6 October 2026. Applies to every company using CySo Mail (the "Customer", controller) and CySo Solutions Ltd (the "Processor").
1. Subject and duration
The Processor processes personal data in the Customer's connected mailboxes only to provide CySo Mail, for as long as the Customer uses it.
2. Instructions
The Processor acts only on the Customer's documented instructions: the settings, approvals and requests made by the Customer's users and their AI apps through the service.
3. Data and people
Email messages, addresses, names and attachments in connected mailboxes, concerning the Customer's staff, clients and correspondents.
4. Confidentiality and security
- Each company's data is stored separately; mailbox passwords are encrypted (AES-256-GCM, a key per password) and never shown to AI apps.
- Email content is not stored by the Processor; it is read from the mail server on request.
- Sending, permanent deletion and new mailboxes require approval by a person of the Customer.
- Access to systems is limited to personnel bound by confidentiality.
5. Sub-processors
- Cloudflare, Inc.: hosting; data stored in the EU jurisdiction.
- Telegram: only if the Customer connects it; delivers approval requests; outside the EU.
- Microsoft / Google: for "Continue with Microsoft/Google" sign-in and, only if a user connects it, for saving attachments into that user's own OneDrive or Google Drive.
The Processor informs Customers of new sub-processors in advance, so they can object.
6. Transfers
Where data leaves the EU (Telegram, Cloudflare's global network), appropriate safeguards such as the EU Standard Contractual Clauses are used.
7. Assistance and breaches
The Processor helps the Customer answer data-subject requests and notifies the Customer without undue delay after becoming aware of a personal data breach.
8. End of service
When a mailbox is disconnected, its password is deleted at once. When the account is closed, the Customer's data is deleted, except where the law requires keeping it.
9. Audits
The Processor makes available the information needed to show compliance with Article 28 GDPR. Contact: legal@cysosolutions.com.