The Customer is the data controller. NAM Consult (CBE 0717.544.038), publisher of MailRich, is the data processor within the meaning of Article 28 of the GDPR. The processor only processes data on the documented instructions of the controller.
The purpose of the processing is the provision of the MailRich Service. Its nature consists of collecting, hosting, organizing, consulting and transmitting emails and associated data, for the purpose of managing and overseeing the Customer's mailboxes. The processing lasts for the duration of the contract.
The processor refrains from reusing the Customer's data for its own purposes. In particular, the content of the Customer's emails is not used to train artificial intelligence models, except with the Customer's express agreement and on anonymized data. The assistance features produce proposals subject to human validation.
The Customer authorizes the use of sub-processors (cloud hosting provider, artificial intelligence provider, email sending service, alerts channel). The processor maintains an up-to-date list, imposes on each of them obligations equivalent to this agreement, and informs the Customer of any addition or replacement, the Customer having a right of reasoned objection. To date, hosting is provided by Vercel Inc. (United States, edge distribution), governed by standard contractual clauses. The complete and up-to-date list of sub-processors (hosting, artificial intelligence, email sending, alerts channel) and their location is maintained by the publisher and provided to the Customer on request as well as upon each addition or replacement.
At the end of the contract, at the Customer's choice, the processor returns the data in a usable format and then deletes it, or deletes it directly, unless there is a legal retention obligation. The Service allows effective deletion of the data.
The data is preferably hosted in the European Union. Any transfer outside the EU is governed by a valid mechanism (adequacy decision or standard contractual clauses), accompanied, where applicable, by a transfer impact assessment.
The processor notifies the Customer of any personal data breach without undue delay after becoming aware of it, and provides it with the relevant information to enable, where applicable, its notification to the supervisory authority.