Data Processing Addendum
Last updated: 2026-07-26
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Computer Repair Ltd (company no. 07013303), registered in England and Wales, registered office 14 Belton Road, London, E7 9PF, trading as JoinedInbox ("we", "us", the processor), and the customer who has subscribed to the service ("you", the controller).
It applies where you use the service to process personal data for which you are the controller — in practice, wherever the mail you aggregate contains information about other people. It applies in full to Teams customers and to any business use of the service.
Words defined in the Terms of Service — in particular owner, member and account — have the same meaning here.
Where this DPA conflicts with the Terms of Service on the subject of data protection, this DPA prevails.
1. Subject matter and duration
Subject matter. Aggregation of the email accounts you connect: fetching copies of mail from mailboxes you nominate, storing and indexing them, making them available to you and to the members you authorize, and sending mail on your behalf through those accounts' own servers.
Duration. For as long as your subscription is active, followed by the retention windows set out in the Terms of Service, after which the data is permanently deleted.
2. Nature and purpose of processing
We process the data solely to provide the service: storage, retrieval, indexing for search, display, transmission, and the organizational features you use (labels, tasks, notes, assignment).
We do not mine, profile, analyse or monetize the content, do not use it to train any model, and do not disclose it to anyone except the subprocessors listed in Section 6 and as required by law.
3. Types of personal data and categories of data subject
Categories of data subject: you; the members you create; and the correspondents who send mail to, or receive mail from, the mailboxes you connect.
Types of personal data: whatever is present in the mail you choose to aggregate. Because email is unstructured, this is determined by you and not by us, and may include names, email addresses, contact details, message content, attachments, and any other information your correspondents include. It also includes the sign-in identities of the members you create, and the notes and task metadata your team adds.
You should not use the service to process special category data unless you have satisfied yourself that it is lawful for you to do so.
4. Your instructions
We process personal data only on your documented instructions. Your configuration of the service — which mailboxes are connected, who has access, what is deleted, whether deletion-from-source is enabled — constitutes those instructions, together with the Terms of Service and this DPA.
We will tell you if, in our opinion, an instruction infringes applicable data protection law. If we are required by law to process data otherwise than on your instructions, we will inform you before doing so unless the law forbids it.
5. Confidentiality and personnel
Access to the production systems is restricted to the personnel who need it to operate the service, who are bound by confidentiality obligations. The service is operated by a small team, and access is limited accordingly.
6. Subprocessors
You give general authorization for us to engage the subprocessors listed below. We remain fully liable for their performance.
- Stripe — payment processing and subscription billing.
- Hostinger — transactional email sending (our own service notices), domain and DNS. Does not carry your aggregated mail.
- Browser push services (Google, Mozilla, Apple) — delivery of browser notifications, only where a user has enabled them. Notification payloads are encrypted to the recipient browser.
- Uptime and job monitoring providers — receive service status only, not personal data.
The hosting itself is not subcontracted: the service runs on hardware we own and control, physically located in Lithuania.
We will give you notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected subscription and receive a pro-rata refund of any prepaid, unused fees.
7. Security measures
- Connected mailbox credentials are encrypted at rest with AES-256-GCM, with the key held only in the server environment and excluded from all backups.
- Account passwords are hashed with argon2id.
- All traffic to the service is encrypted with TLS; session cookies are secure and HTTP-only.
- Each customer's data is held in its own separate database, and access is scoped per user on the server side — a member can reach only the mailboxes granted to them.
- Authentication and other sensitive endpoints are rate-limited.
- Backups are encrypted and held in multiple copies across separate machines, on a rolling 7 daily / 4 weekly / 6 monthly retention.
8. Assistance to you
Taking into account the nature of the processing, we will assist you:
- With data subject requests. The service's built-in export and deletion tools are designed so you can satisfy access, portability and erasure requests yourself, immediately. Where a request reaches us directly, we will refer it to you rather than answer it, unless you instruct otherwise.
- With security, breach notification and impact assessments, by providing the information reasonably available to us.
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available to us at the time and further detail as our investigation progresses.
10. Deletion and return
You can export a complete copy of your data at any time using the built-in export, and can delete your account and all its data at any time.
On termination, data is deleted according to the retention windows in the Terms of Service, and you are emailed the exact deletion date beforehand. Residual copies in encrypted backups age out on the retention schedule in Section 7, which may take up to approximately six months; they are not accessed in the meantime.
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA and respond to your reasonable written questions. Given the size of the service, we do not offer on-site audits by default; where an audit is legally required, the parties will agree a proportionate approach in advance, at your cost.
12. International transfers
The service is hosted on our own hardware in Lithuania, within the EEA. Where a subprocessor listed in Section 6 transfers data outside the UK or EEA, that transfer is made under the safeguards that subprocessor maintains, such as standard contractual clauses or an adequacy decision.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
Contact
Data protection questions about this DPA: ernie@vaitex.co.uk, or write to Computer Repair Ltd, 14 Belton Road, London, E7 9PF.