Data Processing Agreement
Version 1.0, 2 September 2026.
This agreement applies where you use fabricatedemail to receive mail that your own systems send, and that mail contains personal data for which you are the controller under the GDPR. You are the controller; we are the processor. It forms part of the Terms of Service and takes effect when you accept them; no separate signature is needed. If you require a countersigned copy, write to support.
To be completed before launch. This agreement must name the company as processor — registered name, address, organisation number and contact address — in the wording confirmed with the company's accountant.
1. Subject matter, duration, nature and purpose
We store the mail sent to the addresses you register, and make it readable through our API, so that your automated tests can assert on it. We process it for no other purpose. Processing lasts for as long as your account exists; each individual message is deleted 24 hours after it arrives, or when its address expires or is deleted, whichever comes first.
2. Types of personal data and categories of data subject
Data: whatever your systems put in the mail they send — typically headers, sender and recipient addresses, subject lines, message bodies, one-time codes and verification links. We do not choose it and we do not inspect it.
Data subjects: the people your test messages concern — usually your own test accounts and staff. The service is for testing systems you control; sending real people's mail to it is prohibited by the Acceptable Use Policy. Do not use it to process special categories of personal data.
3. Our obligations
- We process personal data only on your documented instructions. Your use of the API is the instruction; the Terms and this agreement are the rest of it. We tell you if we believe an instruction breaches data protection law, and if law requires us to process otherwise, we tell you before doing so unless that law forbids it.
- Everyone with access is bound by confidentiality. Access is limited to the operator, and it is used for support, investigation and maintenance only.
- We keep appropriate technical and organisational security measures (Article 32): encryption in transit, API keys stored only as hashes, access to the production systems restricted to the operator with multi-factor authentication, and short retention as the primary protection — mail exists for 24 hours.
- We help you, so far as we reasonably can and given the nature of the processing, with data-subject requests, security-incident notifications, impact assessments and prior consultations.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time.
4. Sub-processors
You give general authorisation for the sub-processors below. We will tell you at least 30 days before adding or replacing one, and you may object on reasonable data-protection grounds — in which case you may end the affected subscription and receive a refund of the unused period.
| Sub-processor | Processing | Location |
|---|---|---|
| Cloudflare | Inbound mail routing, the API, message and address storage | D1 in the EEUR region; Workers at the global edge |
| Microsoft — Azure and Entra | Account store, dashboard, sign-in, logs and metrics | Sweden Central; see the Privacy Policy for the sign-in tenant |
| Microsoft — Azure Communication Services | Sending service email to account holders | Sweden Central |
| Stripe, including Link | Payments as merchant of record | Stripe's own infrastructure |
Each is engaged under a written contract imposing obligations no less protective than these, and we remain liable to you for their performance.
5. Transfers outside the EEA
Stored mail is held in the European Union. The API executes at the Cloudflare location nearest the caller, so a request may be processed outside the EEA. Any transfer outside the EEA rests on the sub-processor's standard contractual clauses and its own transfer framework.
6. Return and deletion
Mail is deleted automatically 24 hours after it arrives, so there is normally nothing to return. Deleting your account removes your addresses, the mail held for them, your keys and your account record. On request before deletion we will export what remains, as described in the Privacy Policy.
7. Audit
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this agreement — including our sub-processors' own certifications and reports, which for a service of this size take the place of an on-site audit.
8. Contact
fabricatedemail-support@blackcurrantsecurity.com. Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement prevails.