⚡️ New Release ⚡️InboxPilot gets smarter every time you edit an email draft
Try it yourself
Impress logo with a purple exclamation mark icon followed by the word 'impress' in black lowercase letters.
How it works
Solutions
Website Chatbot
Engage customers on your website
Email Agent
Automate your inbox
Read Case Studies
Learn how InboxPilot streamlined email handling for different teams.
Read here
Resources
Help Center
Step-by-step guides
FAQ
Answers to common questions
Blog
Articles and stories
Case Studies
How companies use InboxPilot
Changelog
Latest product updates
Security
Data & Privacy practices
Contact
Pricing
Sign in
Sign in
Get started
Legal

Data Processing Agreement

InboxPilot, Inc.  ·  GDPR & CCPA compliant

Automatic acceptance

This DPA is automatically incorporated into the InboxPilot Terms of Service. By using our Service, you acknowledge and agree to be bound by its terms. No separate signature is required for the DPA to be effective.

Requesting a signed DPA

If your organization requires a signed DPA for compliance purposes, follow these steps:

1. Download the DPA

Download the PDF version of the DPA document using the button above.

2. Complete required information

Fill in your organization's details including company name, address, and authorized signatory information.

3. Sign the document

Have an authorized signatory sign the completed DPA on behalf of your organization.

4. Send to InboxPilot

Email the signed DPA to support@inboxpilot.co. Upon receipt, it will supersede the automatically incorporated DPA and become the legally binding version for your organization.

Section 1
Definitions and interpretation

This Data Processing Agreement ("Agreement") forms part of the InboxPilot Terms of Service ("Principal Agreement") between the Customer (the "Controller") and InboxPilot, Inc. (the "Processor"). In the event of a conflict between this Agreement and the Principal Agreement, the terms of this Agreement shall prevail with respect to the processing of personal data.

  • Controller Personal Data — any personal data processed by Processor on behalf of Controller under the Services.
  • Applicable Data Protection Laws — GDPR, CCPA/CPRA, and other applicable privacy laws.
Section 2
Scope and duration

This DPA applies to all Controller Personal Data processed under the Main Agreement. It terminates automatically upon termination of the Main Agreement.

Section 3
Processing instructions

Processor shall process Controller Personal Data only on Customer's documented instructions (including the Main Agreement and this DPA), unless required by law.

purpose

data subjects

personal data

retention

Generate AI email responses

Email recipients, support contacts

Names, email addresses, message content, IDs

Subscription term + 30 days

Train custom AI models

Users uploading data

FAQs, documents, sample emails

Until deletion or termination

Website chatbot

Site visitors

Chat logs, IP, browser

90 days (logs)

Aggregated analytics

All users

Anonymized usage data

Indefinite

Section 4
Data subject rights & cooperation

Processor shall assist Customer by appropriate technical and organizational measures in responding to data subject requests. Processor shall forward any data subject request received directly to Customer without undue delay and shall not respond except on Customer's instruction.

Section 5
Security of processing

Processor implements and maintains the security measures described in Annex II below. All personnel processing Controller Personal Data are subject to confidentiality obligations.

Section 6
Sub-processors

Customer grants general authorization to engage the sub-processors listed in Annex I. Processor shall inform Customer of any new sub-processor 30 days in advance via email. Customer may object on reasonable data protection grounds within 14 days. The Processor remains fully liable for sub-processor performance.

Section 7
Data breach

Processor shall notify Customer within 24 hours of becoming aware of a personal data breach, including all details required under GDPR Art. 33(3).

Section 8
Audits & DPIA

Processor shall make available all information necessary to demonstrate GDPR Art. 28 compliance. Customer may audit once per year with 30 days' notice, at Customer's cost unless material non-compliance is found. Processor may satisfy audits via SOC 2 Type II or equivalent certification.

Section 9
International transfers

Data is processed in the United States. The Standard Contractual Clauses (Module 2: Controller to Processor) in Annex III apply and are incorporated by reference.

‍

SCC choices:

  • Clause 7 (Docking): Applies
  • Clause 9(a): Option 2 — 30 days
  • Clause 17: Delaware law
  • Clause 18(b): New Castle County, Delaware courts

TO BE CONTINUED

Questions, concerns, or complaints

If you have questions, concerns, or complaints regarding Terms of Service or our data practices, please contact us:

InboxPilot

2810 N Church St PMB 16104
Wilmington, Delaware 19802-4447

privacy@inboxpilot.co

Thank you for choosing InboxPilot. We are committed to ensuring your privacy and providing a secure platform.

Impress logo with a purple exclamation mark icon followed by the word 'impress' in black lowercase letters.
Product
Email Agent
Website Chatbot
AI Labeling
AI Drafting
AI Sorting
Email Actions
Pricing
Resources
Blog
Case Studies
FAQ
Changelog
Security
Company
About
Contact
Privacy Policy
Terms of Service
DPA
Compare
inboxpilot vs Fyxer AI
inboxpilot vs Superhuman
inboxpilot vs Shortwave
inboxpilot vs Gemini
inboxpilot vs Copilot
inboxpilot vs Zapier
Ask About InboxPilot
OpenAI logo with an interwoven geometric design inside a purple circle.Black abstract starburst shape centered on a purple circular background.Diamond shape with a rainbow gradient inside a purple circle background.Black gift box with a bow icon inside a purple circle.
© 2026 InboxPilot, Inc. All rights reserved.