Preparation document — not an executed DPA. We have not published a finalized, signed processing agreement. Do not treat these pages as a GDPR certification or as a substitute for your required contract.
Processing to be covered
The agreement must identify the customer and Cyberpigeon operator, the term, and the documented instructions for storing and transmitting agent email. It must cover account-linked mailbox settings, message bodies, headers, recipients, delivery events and attachment metadata, and the people whose information can appear in them. Special-category and children's data are excluded from the beta unless separately agreed.
Required operational commitments
The final agreement must address authorized personnel and confidentiality; risk-appropriate technical and organizational safeguards; assistance with access, erasure and other rights; incident notification without undue delay; assistance with assessments and regulator enquiries; documented return/deletion on termination; evidence and audit rights; and the handling of instructions that conflict with data protection law.
Subprocessors and transfers
It must identify the applicable Azure and email-provider processing arrangements, the customer authorization mechanism, advance notices and objection handling for changes, and any international transfer safeguards required for the actual data flows. A selected EU compute or sending region alone does not settle these questions.
Implemented technical controls
The current service uses HTTPS, a private database network, managed identities for infrastructure secrets, hashed API/session/recovery tokens, memory-hard password hashing, session revocation, request-origin and CSRF validation, account isolation, scoped agent keys, usage limits, a restricted email preview, data exports, and account closure/erasure processing. Mail is held off until provider setup and account approval. We make no SOC 2, ISO 27001 or GDPR certification claim.
Next step
Contact the operator listed in the privacy notice to agree processing terms before using real third-party personal data. The EDPB's controller and processor guidance explains the roles; the binding obligations are those in applicable law and the agreement you execute.