Draft — pending legal review before launch. Structure is final; binding wording will be confirmed by counsel. Enterprise customers may request a counter-signed copy.
Data Processing Agreement
Last updated: June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and The Agentic Group (“Processor”, operator of Inbox) and applies where the Processor processes Personal Data on the Controller’s behalf. It reflects the requirements of the EU/UK GDPR, India’s Digital Personal Data Protection Act 2023 (DPDP), and the CCPA/CPRA.
1. Roles & scope
For the customer’s own account data, The Agentic Group is a controller. For the personal data contained in the customer’s support messages and connected store data, the customer is the Controller and The Agentic Group is the Processor, processing only on documented instructions to provide the Service.
2. Nature & purpose of processing
Receiving inbound support messages; retrieving read-only order context; generating AI-drafted replies; sending replies the Controller approves; and providing analytics. Processing lasts for the term of the agreement.
3. Categories of data & data subjects
Personal Data: end-customer names, email addresses, message content, and order/shipping details the Controller connects. Data subjects: the Controller’s customers and end users. The Processor does not require special-category data and asks Controllers not to send it.
4. Sub-processors
The Controller authorizes the Processor to engage the sub-processors listed at /inbox/legal/subprocessors. The Processor remains responsible for its sub-processors and will give notice before adding a new one that processes Personal Data, allowing a reasonable opportunity to object.
5. Security measures
The Processor maintains technical and organizational measures appropriate to the risk, including database-level tenant isolation (row-level security), encryption of OAuth tokens at rest, signature-verified webhooks, strict transport security and security headers, optional two-factor authentication, least-privilege access, and automated dependency and secret scanning. Details: our security practices.
6. International transfers
Where Personal Data is transferred across borders, the Processor relies on an appropriate transfer mechanism (e.g. the EU Standard Contractual Clauses and the UK Addendum) and applies supplementary measures as needed. The current hosting regions are stated in the sub-processor list.
7. Data-subject requests
The Processor will assist the Controller, taking into account the nature of processing, to respond to data-subject requests (access, correction, deletion, portability, objection). The Controller can export and delete its data self-serve from account settings, or contact privacy_inbox@theagenticgroup.dev.
8. Personal-data breach
The Processor will notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a Personal Data breach affecting the Controller’s data, with the information needed to meet the Controller’s own notification obligations.
9. Audits
On reasonable request and subject to confidentiality, the Processor will make available the information necessary to demonstrate compliance with this DPA, including relevant security documentation.
10. Deletion & return
On termination, the Processor will delete or return the Controller’s Personal Data within a reasonable period, except where retention is required by law. Account deletion triggers a 30-day grace period followed by permanent erasure.
11. Liability & precedence
Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms on the subject of data protection, this DPA prevails.
12. Contact
Privacy & DPA requests: privacy_inbox@theagenticgroup.dev. Legal: legal_inbox@theagenticgroup.dev.
See also our Privacy Policy, Sub-processors, and Terms.