Data Processing Addendum (summary)
Last updated 26 September 2026Effective 26 September 2026
Scope
This summary applies where an organisation (the "customer") provides Viremail accounts to its staff or members. In that case the customer is the controller of the personal data in those mailboxes, and Svayam Incarnation Limited acts as its processor under Article 28 of UK GDPR. A full Data Processing Addendum is available on request via the contact details on our website.
Processing details
| Item | Description |
|---|---|
| Subject matter | Providing email, calendar, contacts, notes, tasks, chat and calling services |
| Duration | For the term of the customer agreement, plus the deletion period below |
| Nature and purpose | Storing, transmitting, filtering, indexing and displaying data to provide the service |
| Data subjects | Customer's users and the people they correspond with |
| Personal data | Account data, message content and metadata, contacts, calendar data, notes, chats, security logs |
| Special category data | Not intended, but may be present in message content at the customer's discretion |
Our commitments
- Process personal data only on the customer's documented instructions.
- Ensure staff with access are bound by confidentiality.
- Apply appropriate technical and organisational security measures (see our Security Overview).
- Use sub-processors only with the customer's general authorisation, and give notice of changes so the customer can object.
- Help the customer respond to data subject requests and meet its security, breach notification and impact assessment obligations.
- Notify the customer without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the service, unless the law requires us to keep it.
- Make available information needed to demonstrate compliance, and allow for reasonable audits.
Sub-processors
Mail and account data are hosted on our own servers. Limited data passes through the third parties listed in our Privacy Policy, including Cloudflare (network and security).
Full sub-processor list: [Sub-processor list with locations (to be added)]
International transfers
Where personal data is transferred outside the UK, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum.