Data Processing Agreement
Version 1.1, 23 September 2026.
This agreement applies where you use fabricatedemail to receive mail that your own systems send, and that mail contains personal data for which you are the controller under the GDPR. You are the controller; we are the processor. It forms part of the Terms of Service and takes effect when you accept them; no separate signature is needed. If you require a countersigned copy, write to support.
1. Subject matter, duration, nature and purpose
We store the mail sent to the addresses you register, and make it readable through our API, so that your automated tests can assert on it. We process it for no other purpose. Processing lasts for as long as your account exists; each individual message expires 24 hours after it arrives, or earlier when its address expires, and a cleanup that runs every hour deletes expired messages. Deleting an address deletes its mail at once.
2. Types of personal data and categories of data subject
Data: whatever your systems put in the mail they send — typically headers, sender and recipient addresses, subject lines, message bodies, one-time codes and verification links. We do not choose it, and we do not inspect it as a matter of routine; we may inspect a specific message where a report, a platform-safety concern or a legal obligation makes it necessary, as the Acceptable Use Policy describes.
Data subjects: the people your test messages concern — usually your own test accounts and staff. The service is for testing systems you control; sending real people's mail to it is prohibited by the Acceptable Use Policy. Do not use it to process special categories of personal data.
3. Our obligations
- We process personal data only on your documented instructions. Your use of the API is the instruction; the Terms and this agreement are the rest of it. We tell you if we believe an instruction breaches data protection law, and if law requires us to process otherwise, we tell you before doing so unless that law forbids it.
- Everyone with access is bound by confidentiality. Access is limited to the operator, and it is used for support, investigation and maintenance only.
- We keep appropriate technical and organisational security measures (Article 32): encryption in transit, API keys stored only as hashes, access to the production systems restricted to the operator with multi-factor authentication, and short retention as the primary protection — mail expires within 24 hours, and a cleanup that runs every hour deletes it.
- We help you, so far as we reasonably can and given the nature of the processing, with data-subject requests, security-incident notifications, impact assessments and prior consultations.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time.
4. Sub-processors
You give general authorisation for the sub-processors below. We will tell you at least 30 days before adding or replacing one, and you may object on reasonable data-protection grounds — in which case you may end the affected subscription and receive a refund of the unused period.
| Sub-processor | Processing | Location |
|---|---|---|
| Cloudflare | Inbound mail routing, the API, message and address storage | D1 in the EEUR region; Workers at the global edge |
| Microsoft — Azure and Entra | Account store, dashboard, sign-in, logs and metrics | Azure in Sweden Central; Entra External ID on Microsoft's own infrastructure, under its terms |
| Microsoft — Azure Communication Services | Sending service email to account holders | Europe |
| Stripe, including Link | Payments as merchant of record | Stripe's own infrastructure |
Each is engaged under a written contract imposing obligations no less protective than these, and we remain liable to you for their performance.
5. Transfers outside the EEA
Stored mail is held in the European Union. The API executes at the Cloudflare location nearest the caller, so a request may be processed outside the EEA. Any transfer outside the EEA rests on the sub-processor's standard contractual clauses and its own transfer framework.
6. Return and deletion
Mail expires within 24 hours and a cleanup that runs every hour deletes it, so there is normally nothing to return. Deleting your account removes your addresses, the mail held for them, your keys and your account record. Deleted mail can remain for up to 7 days in the restorable history Cloudflare D1 keeps of the database (Time Travel), and Cloudflare keeps its own log of each message's sender, recipient and subject for 31 days. On request before deletion we will export what remains, as described in the Privacy Policy.
7. Audit
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this agreement — including our sub-processors' own certifications and reports, which for a service of this size take the place of an on-site audit.
8. Contact
fabricatedemail-support@blackcurrantsecurity.com. Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement prevails.