Skip to content

Data Processing Addendum

For customers who need a signed processor agreement. This is the full text; the download link below is the same document in a form you can attach to a procurement ticket.

Last updated

Download this DPA (plain text) — or email [email protected] for a counter-signed copy.

This Addendum forms part of the Terms of Service between NVS Ventures ("Koltrix", the Processor) and the customer who has accepted those terms ("you", the Controller). It applies where Koltrix processes personal data on your behalf, and it takes precedence over the Terms of Service to the extent of any conflict about data protection.

"GDPR" means Regulation (EU) 2016/679 and, for the United Kingdom, the UK GDPR and the Data Protection Act 2018. "DPDP Act" means India's Digital Personal Data Protection Act, 2023. "Personal data", "controller", "processor", "processing" and "data subject" have the meanings given in the GDPR; "Data Fiduciary" and "Data Processor" have the meanings given in the DPDP Act.

1. Roles

You are the controller of the personal data contained in the mail and contacts in your workspace. Koltrix is your processor for that data, and processes it only on your documented instructions.

Koltrix is a controller in its own right for the account data of your users — names, login credentials, billing status and usage counters — which it processes as described in its Privacy Policy. This Addendum does not cover that processing.

2. Subject matter, duration, nature and purpose

Subject matter: the provision of a hosted email service comprising a team inbox, a transactional sending API, an SMTP relay and optional AI features.

Duration: for as long as your workspace exists, plus the retention periods set out in section 9.

Nature and purpose: receiving, storing, indexing, classifying, transmitting and deleting electronic mail and related data at your instruction.

3. Types of personal data and categories of data subject

Types of personal data: email addresses, display names, message subjects, message bodies, attachments, mail headers including IP addresses of sending servers, contact records, and any personal data your correspondents choose to include in a message.

  • Categories of data subject: your employees and contractors; your customers and prospects; anyone who sends mail to an address in your workspace.

Because the content of inbound mail is chosen by the sender, it may contain special categories of personal data. Koltrix does not solicit such data and processes it only as part of message content.

4. Your instructions

Koltrix processes personal data only on your documented instructions, which consist of this Addendum, the Terms of Service, and your use of the product's features and settings.

Koltrix will tell you if, in its opinion, an instruction infringes the GDPR, the DPDP Act or other applicable data protection law. Koltrix may process personal data where required to do so by law, and will inform you first unless the law prohibits it.

5. Confidentiality

Koltrix ensures that everyone authorised to process your personal data is bound by confidentiality obligations, and limits access to those who need it to operate or support the service.

6. Security

Koltrix implements appropriate technical and organisational measures, which currently include:

  • a separate database schema per workspace, so no query can reach another customer's data
  • encryption in transit for all web traffic, and opportunistic TLS for SMTP in both directions
  • API keys stored as hashes and scoped to individual permissions
  • expiring sessions and CSRF protection on cookie-authenticated requests
  • rate limiting on authentication, search, AI and image-proxy endpoints
  • remote images in mail fetched through a proxy so recipients' IP addresses are not disclosed to senders
  • automated dependency vulnerability scanning on every build
  • access to production restricted to named individuals

Koltrix does not hold a SOC 2, ISO 27001 or comparable certification, and does not represent that it does. Its security posture, including what is not implemented, is published at https://koltrix.com/security.

7. Subprocessors

You give Koltrix general authorisation to engage subprocessors. The current list is published at https://koltrix.com/legal/subprocessors and is as follows at the date of this Addendum:

  • OVHcloud — Servers, network and storage for the entire service (Frankfurt, Germany (European Union))
  • Cloudflare — DNS, TLS termination and protection against denial-of-service attacks (Global edge network)
  • OpenRouter (TypeSafe's Jev model) — Spam scoring and message classification (Provider-operated infrastructure)
  • OpenRouter (Google Gemini and DeepSeek models) — AI summaries and draft replies (Provider-operated infrastructure)
  • Dodo Payments — Merchant of record: payment processing, invoicing, sales tax and GST (Provider-operated infrastructure)

Koltrix will give at least 14 days' notice by email or in the product before adding or replacing a subprocessor. You may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, your sole and exclusive remedy is to stop using the affected service and cancel the subscription; fees already paid are not refunded.

Koltrix imposes data protection obligations on each subprocessor no less protective than those in this Addendum, and remains liable to you for their performance.

AI features involve sending message content to third parties. If you do not want that, AI can be disabled for the whole workspace in settings, and no message content is then sent to any AI subprocessor.

8. International transfers

Koltrix is established in India and operates infrastructure as described in its Privacy Policy. Where processing involves a transfer of personal data out of the European Economic Area, the United Kingdom or Switzerland, the parties adopt the European Commission's standard contractual clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this Addendum by reference.

  • Clause 7 (docking) applies.
  • Clause 9: option 2, general written authorisation, with the 14 days' notice in section 7.
  • Clause 11: the optional independent dispute resolution body does not apply.
  • Clause 17: the clauses are governed by the law of Ireland.
  • Clause 18(b): disputes are resolved before the courts of Ireland.
  • Annexes I, II and III are populated by sections 2, 3, 6 and 7 of this Addendum.

For UK transfers, the UK International Data Transfer Addendum to the standard contractual clauses applies.

9. Retention and deletion

Koltrix retains personal data for as long as your workspace exists. On deletion of a workspace, data is recoverable for seven days and is then deleted from production systems.

A workspace whose trial or subscription lapses becomes read-only, and its data is deleted 30 days later after three warning emails to the workspace owner.

Deleted individual messages are removed from Trash after thirty days.

Backups, once in operation, are retained on a rolling basis and overwritten within 35 days; personal data deleted from production persists in backups only until those are overwritten.

You may export all workspace data at any time from the product, in MBOX form for mail and CSV for contacts and lists. Koltrix will, on request, delete or return personal data at the end of the service.

10. Assistance

Koltrix will assist you, taking into account the nature of the processing and the information available to it, with:

  • responding to requests from data subjects to access, correct, delete, restrict, object to or port their data — the product's own export and deletion tools are provided for this purpose
  • your obligations to keep processing secure (GDPR Article 32)
  • notifying a personal data breach to a supervisory authority and to affected data subjects (Articles 33 and 34)
  • data protection impact assessments and prior consultation (Articles 35 and 36)

Assistance that goes beyond the product's own export, deletion and settings tools, and that requires significant engineering or support time, may be charged at Koltrix's then-current reasonable rates, which Koltrix will quote before starting.

If Koltrix receives a request directly from one of your data subjects, it will not respond to it itself beyond acknowledging receipt, and will forward the request to you promptly.

11. Personal data breaches

Koltrix will notify you without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach affecting your personal data. The notification will describe what happened, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed.

As controller, you are responsible for deciding whether to notify a supervisory authority or data subjects, and for doing so. Koltrix will not do so on your behalf unless you ask it to. Koltrix's notification is not an acknowledgement of fault or liability.

12. Audit

Koltrix will make available the information needed to demonstrate compliance with this Addendum, and will contribute to audits conducted by you or an auditor you appoint.

In the first instance Koltrix will answer a reasonable security questionnaire, no more than once a year, without charge. An on-site audit may be conducted only where a supervisory authority requires it or following a personal data breach affecting your data, no more than once in any 12 months, on at least 30 days' written notice, during business hours, under a written confidentiality agreement, in a way that does not compromise other customers' data or Koltrix's systems, and at your own cost, including the reasonable time Koltrix spends supporting it.

13. Liability

Each party's liability under or in connection with this Addendum, whether in contract, tort or otherwise, is subject to the limitations and exclusions in the Terms of Service and counts towards, rather than adding to, the aggregate limit stated there, except where applicable data protection law does not permit that.

You will indemnify Koltrix against claims, fines and costs arising from your instructions being unlawful, from your lack of a lawful basis or required notices for the processing you instruct, or from your breach of section 14.

14. Your responsibilities as controller

You are responsible for the lawfulness of the personal data you put into Koltrix and of your instructions, including having a valid legal basis, giving data subjects the notices the law requires, and obtaining any consent needed to send them mail.

  • You decide whether to enable AI features, and configure them, knowing that enabling them sends limited message content to the AI subprocessors.
  • You are responsible for the security of your own credentials, API keys and devices, and for who you grant access to your workspace.
  • You must not instruct Koltrix to process special categories of data, or data about children, in a way the service is not designed for.
  • You are responsible for exporting your data before it is deleted under the retention periods in section 9.

15. Term and contact

This Addendum takes effect when you accept the Terms of Service and continues for as long as Koltrix processes personal data on your behalf.

Data protection queries, including a request to sign a counter-signed copy of this Addendum: [email protected].