RocketMail
ProductPricingSecurityIntegrations
Sign inContact
Legal

Data Processing Agreement

The Article 28 terms under which RocketMail processes personal data on a customer's behalf.

CompanyMARTECHSOL LTD
Company number16554162
Last updated11 August 2026
On this page
  1. The parties and what this is
  2. Subject matter, duration, nature and purpose
  3. We act only on your instructions
  4. Confidentiality of our people
  5. Security measures
  6. Subprocessors
  7. Helping you answer data subjects
  8. Personal data breaches
  9. Return and deletion
  10. Audits
  11. International transfers
  12. Liability and precedence
01

The parties and what this is.

This Data Processing Agreement forms part of the agreement between MARTECHSOL LTD (company number 16554162, of 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom), the Processor, and the customer subscribing to RocketMail, the Controller.

It applies whenever we process personal data on your behalf, and it takes precedence over anything inconsistent in the rest of the agreement.

Terms such as personal data, processing, data subject, controller, and processor have the meanings given in the UK GDPR and the Data Protection Act 2018.

02

Subject matter, duration, nature and purpose.

Subject matter. Providing RocketMail: reading a mailbox and a CRM to rank conversations, summarise threads, draft replies, and propose CRM updates.

Duration. For as long as you have an account, plus the deletion period in section 09.

Nature and purpose. Collection, storage, structuring, analysis, and retrieval by automated means, including submission to a language model provider at the moment an output is generated.

Categories of data subject. Your personnel, and the people they correspond with by email, which includes customers, prospects, and their advisers.

Categories of personal data. Names, email addresses, job titles, employer, the full content of email messages including anything the correspondents chose to put in them, and CRM records such as company, deal value, and stage.

Special category data. Not requested and not required. Because we process whole message bodies, special category data may be present if your correspondents put it there. We treat all message content to the same standard and do not separate or infer on it.

03

We act only on your instructions.

We process personal data only on your documented instructions, which are these terms, the configuration you choose in the product, and anything else you tell us in writing.

Where the law requires us to process for another reason, we will tell you first unless that law forbids it.

If we think an instruction breaches data protection law, we will tell you. We will not quietly comply with something we believe is unlawful.

04

Confidentiality of our people.

Everyone we authorise to process your data is bound by a written confidentiality obligation that survives their engagement with us, and is trained on handling customer data.

Access to production data is granted only where there is a specific reason, for a limited period, and is logged. Nobody at this company reads customer mail in the course of ordinary work.

05

Security measures.

We implement appropriate technical and organisational measures under Article 32. The specific measures in place today are:

  • Encryption in transit on every connection, and at rest for all stored data.
  • Envelope encryption of credentials. A master key held in a key management service wraps a per-organisation data key, which encrypts each OAuth token with AES-256-GCM. The additional authenticated data binds the ciphertext to the organisation, user, purpose, and provider, so a credential row copied into another tenant cannot be decrypted.
  • Tenant isolation enforced by the database. Row level security is enabled and forced on every table holding customer data, so a query that fails to scope itself returns an error rather than another customer's rows.
  • Least privilege on mail. We hold no scope permitting us to send email.
  • Human approval before any write to your CRM.
  • Separate database roles for the application and for migrations, with the application role unable to bypass row level security.
  • Logging of access to production, and of every AI call with its prompt version and model.

The security page describes these in more depth, including the controls we have not implemented yet.

06

Subprocessors.

You give us general authorisation to engage subprocessors. Each is bound by written terms that are no less protective than these, and we remain liable to you for their performance.

The subprocessors engaged today are:

  • Neon (managed PostgreSQL, running on Amazon Web Services, us-east-1): all customer data at rest.
  • Amazon Web Services (infrastructure and key management underlying the above): all customer data at rest.
  • Google Cloud KMS (holds the master key that wraps each organisation's data key, us-east1): no customer data, key material only. The key never leaves the service, so this subprocessor cannot read anything it protects.
  • OpenAI (language model inference and embeddings, zero retention, no training on submitted data): message text and CRM field values at the moment an output is generated.

Your mail provider and your CRM are not our subprocessors. They are your own systems, which you have instructed us to connect to, and your relationship with them is direct.

We will give you 30 days' notice before adding or replacing a subprocessor. If you object on reasonable data protection grounds within that period we will work with you to find an alternative, and if we cannot, you may terminate the affected part of the service without penalty for the remainder of the term.

07

Helping you answer data subjects.

If a data subject contacts us directly about data we process for you, we will not respond on your behalf. We will tell you promptly and point them to you.

Taking account of the nature of the processing, we will help you meet your obligations to respond to requests for access, correction, erasure, restriction, portability, and objection, by giving you the tools to export and delete data, and by acting on your instructions where the tools do not reach.

We will also help you with data protection impact assessments and prior consultation, with the information available to us.

08

Personal data breaches.

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data.

The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, the measures we have taken, and a named contact. Where we do not have all of that at first, we will send what we have and follow up rather than wait.

We will not make a public statement identifying you without your agreement, unless we are legally required to.

09

Return and deletion.

On termination, and at your choice, we will return or delete the personal data we process for you. Our default is deletion.

Live systems are cleared within 30 days of termination. Backups are on a rolling window and the data is removed as that window cycles, within 90 days. It is not restored to live systems in the meantime.

We may keep data where UK or EU law requires, and where we do, we keep it only for that purpose and continue to protect it under these terms.

Deleting our copy does not affect your mailbox or your CRM. Those remain yours and untouched, and we never held the only copy of anything.

10

Audits.

We will make available the information needed to demonstrate compliance with Article 28, and will allow and contribute to audits by you or an auditor you appoint.

In practice: we will answer a security questionnaire within three business days, and will take an architecture call. An on-site or on-system audit may be requested once in any twelve month period, on 30 days' notice, at your cost, subject to confidentiality, and arranged so it does not compromise other customers' data.

11

International transfers.

Personal data is stored in the United States by default. Where personal data is transferred out of the United Kingdom we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply.

You instruct us to make those transfers, and to enter into the relevant clauses with our subprocessors on your behalf. Copies are available on request.

Enterprise customers can pin storage to a single region.

12

Liability and precedence.

Each party's liability under this DPA is subject to the limitations in the main agreement. Nothing here limits a data subject's rights.

If any provision of this DPA conflicts with the rest of the agreement, this DPA prevails on matters of data protection. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.

Questions, objections to a subprocessor, and audit requests go to hello@rocketmail.ai.

RocketMail

The mail client your sales team closes from. Ranks every thread by the revenue at stake, drafts replies in each rep's own writing, and keeps the CRM current from what buyers actually said.

Product
  • Ranked inbox
  • Draft in voice
  • CRM sync
  • Integrations
Company
  • Pricing
  • Security
  • Contact
Legal
  • Terms
  • Privacy
  • DPA
  • Subprocessors
© MARTECHSOL LTD. RocketMail is a product of MARTECHSOL LTD, registered in England and Wales, company number 16554162.Cleared for launch