Cirrux Data Processing Agreement
Effective date: 17 August 2026.
This Data Processing Agreement ("DPA") governs our processing of personal data on your behalf under Article 28 of the GDPR. It applies automatically to every business customer as part of our Terms of Service, so there is nothing you need to request or sign before it is in force. If your procurement process needs a countersigned copy on paper, email help@cirrux.co and we will send one.
If you use Cirrux as an individual rather than on behalf of an organisation, this DPA does not apply to you: we are the controller of your data, and our Privacy Policy is the document that describes it.
Contents
- Parties and precedence
- Scope, roles and duration
- Processing on your instructions
- Confidentiality
- Security
- Sub-processors
- Data subject requests
- Assistance with your own obligations
- Personal data breaches
- Return and deletion
- Audits
- International transfers and government requests
- Liability, term and law
- Annex I: details of the processing
- Annex II: technical and organisational measures
- Annex III: sub-processors
1. Parties and precedence
This DPA is between Werk Slim B.V., trading as Cirrux, Larenseweg 136, 1222 HM Hilversum, the Netherlands, registered with the Dutch Chamber of Commerce under number 77760026 (the "Processor", "we", "us") and the organisation that has entered into the Terms of Service with us (the "Controller", "you").
It forms part of the Agreement. Where this DPA and the Terms of Service or the Privacy Policy disagree about the processing of personal data on your behalf, this DPA prevails. Terms defined in the GDPR, such as controller, processor, personal data, processing and personal data breach, carry their GDPR meaning here.
2. Scope, roles and duration
- You are the controller of the personal data contained in your workspace, which includes the content of mailboxes, calendars, contacts and Drive, and the personal data of your members. You decide why and how it is processed, and you are responsible for having a lawful basis for it.
- We are the processor of that data. We process it to provide the service, and for nothing else.
- For a limited set of data we are ourselves the controller rather than your processor: account and authentication records, billing data, security and abuse-prevention data, and the operational logs we need to run and defend the platform. Our Privacy Policy governs that processing.
- This DPA runs for as long as we process personal data on your behalf, which is the duration of the Agreement plus the retention period in section 10.
Annex I describes the subject matter, nature and purpose of the processing, the categories of data subjects and the types of personal data.
3. Processing on your instructions
- We process personal data only on your documented instructions, including for transfers to a third country. The Agreement, this DPA, and your and your members' use of the service through its interfaces are your documented instructions. You may issue further instructions in writing, and if they require work beyond the service as offered, we may charge for it or decline where it is not technically feasible.
- We will tell you if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law, and we may suspend that instruction until it is resolved.
- We do not sell your data, use it for advertising, use it to profile anyone, or use it to train AI models, ours or anyone else's. This is a contractual commitment, not only a policy statement.
- Automated processing that is inherent to the service does happen, and you instruct us to carry it out: filtering inbound mail for spam and malware, running the filter rules your members configure, indexing content so your members can search it, and handling the routing metadata that mail delivery requires. No person at Cirrux reads your content except where you or a member asks support to look into a specific problem, or where the law compels us.
4. Confidentiality
Everyone we allow to process your personal data is bound by a written duty of confidentiality that survives the end of their engagement, has been briefed on their obligations, and is granted access only to the extent their work requires. Administrative actions taken on customer accounts are logged.
5. Security
We implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 of the GDPR.
We may change these measures over time, and we will not reduce the overall level of security while this DPA is in force.
6. Sub-processors
- You give us a general authorisation to engage sub-processors. The ones we use today are listed in Annex III, with what each of them receives.
- Before adding or replacing a sub-processor that processes your content, we give at least 30 days' notice. We email every administrator of every affected workspace, so there is no notification list to join and nothing you need to do to stay informed, and we update Annex III with the date of the change.
- If you reasonably object to a new sub-processor on data protection grounds within those 30 days, tell us and we will work with you to find a solution. If we cannot, you may terminate the affected part of the service and we will refund the unused part of any prepaid fees.
- One exception, for emergencies. If a sub-processor has to be added or replaced immediately, because the incumbent has failed or because waiting would create a security or continuity risk, we may make the change first and notify you as soon as we can rather than 30 days ahead. Your right to object under the previous point still applies from the moment we notify you. We will not use this to shortcut an ordinary, planned change.
- We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. Data subject requests
- Where a data subject contacts us directly about data we process on your behalf, we will not respond to the substance ourselves. We will refer them to you and tell you promptly.
- We assist you in meeting your obligation to respond to requests under Articles 12 to 23 of the GDPR, taking into account the nature of the processing.
- In practice most requests need no assistance from us at all. Administrators can access, correct and delete member data themselves, and IMAP, CalDAV, CardDAV and plain file downloads give you a complete, portable copy of the content in a workspace at any time, without asking us and at no cost.
8. Assistance with your own obligations
Taking into account the nature of the processing and the information available to us, we assist you in complying with your obligations under Articles 32 to 36 of the GDPR: security of processing, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation.
9. Personal data breaches
- We notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf.
- The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned as far as we can establish them, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we cannot provide all of it at once, we provide it in phases without further undue delay.
- Notifying a supervisory authority or the affected data subjects is your decision and your obligation as controller. We will give you what you need to make it.
10. Return and deletion
- You can export your content yourself, at any time and without our involvement, over IMAP, CalDAV, CardDAV and ordinary file downloads. There is no export we need to grant you and no fee for leaving.
- After the Agreement ends we keep the workspace for 30 days, so you can reactivate or export it, and then delete it permanently. If you ask us to delete it sooner, we do.
- Deletion destroys the workspace's encryption keys, so the stored objects can no longer be decrypted. It is not a flag in a database. Backups made with Cirrux Backup are deleted within 48 hours.
- We keep personal data beyond these periods only where EU or member state law requires it, for example the seven-year retention of invoices under Dutch tax law, and we keep it only for that purpose.
- We will confirm deletion in writing on request.
11. Audits
- We make available to you all information necessary to demonstrate compliance with Article 28 of the GDPR. Ask at help@cirrux.co and we will answer security and data protection questionnaires, and share the documentation we hold.
- You may audit our compliance, or appoint an independent auditor to do so, once per twelve months, on 30 days' written notice, during business hours, without unreasonable disruption to our operations, and subject to confidentiality. A supervisory authority may audit at any time the law allows.
- An audit may not include access to any other customer's data, to systems where such access would compromise the security of other customers, or to penetration testing of production without our written agreement on scope and timing.
- You bear your own costs. We bear ours for the first audit in any twelve-month period, and may charge a reasonable fee for additional or repeat audits.
12. International transfers and government requests
- Your content is stored and processed in the European Union, in Frankfurt, Germany. We do not transfer it outside the EEA for the ordinary operation of the service.
- Where a sub-processor in Annex III is established outside the EEA, or has a parent company that is, any resulting transfer or support access takes place under the European Commission's standard contractual clauses, or under an adequacy decision where one applies.
- If we receive a legally binding request from a public authority for personal data we process on your behalf, we will notify you before responding unless the law prohibits it. Where prohibited, we will use reasonable efforts to obtain a waiver of the prohibition and to challenge the request. We disclose only the minimum the request covers, and we do not give any authority direct or unfettered access to your data.
13. Liability, term and law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA takes effect when you accept the Terms and ends when we have deleted the personal data we process on your behalf in line with section 10. Dutch law governs it, and disputes go to the court named in the Terms.
We may update this DPA to reflect changes in law, the service, or our sub-processors. Where a change is material we give at least 30 days' notice, and the sub-processor notice in section 6 applies to changes in Annex III.
14. Annex I: details of the processing
- Subject matter: our provision of the Cirrux service, being email, calendars, contacts and file storage, together with the sync, backup, import and API features you choose to use.
- Nature and purpose: hosting, storing, transmitting, receiving, indexing, filtering, backing up, encrypting and deleting personal data so your members can use the service, and providing support when you ask for it.
- Duration: the term of the Agreement, plus the retention period in section 10.
- Categories of data subjects: your members, and any person whose personal data appears in the content they send, receive, create or store. In an email service that includes people who never contracted with either of us, such as the senders and recipients your members correspond with.
- Types of personal data: names, email addresses, phone numbers, postal addresses, message content and attachments, calendar events and their participants, contact records, files and their contents, profile images, IP addresses, device and browser information, and authentication and usage metadata.
- Special categories: we do not ask for special category data, and the service is not designed around it. Because your members control what they write and store, such data may nonetheless be present. We apply the measures in Annex II to all content alike, and you remain responsible for deciding whether the service is appropriate for the data you put into it.
15. Annex II: technical and organisational measures
- Encryption in transit: TLS for the web apps and API, for IMAP, SMTP, CalDAV and CardDAV, and opportunistic TLS when handing mail to another provider.
- Encryption at rest: message bodies, attachments and files are held in encrypted object storage. Every object gets its own 256-bit key and is encrypted with AES-256-GCM, and that key is wrapped with a master key belonging to your workspace, so destroying the workspace keys renders the stored bytes unreadable.
- Access control: two-factor authentication and passkeys are available to every member, and an administrator can require passkeys for the whole workspace. Access to production systems is limited to the people who operate them, and administrative actions on customer accounts are logged.
- Abuse and intrusion resistance: authentication is rate limited, repeated failures and unusual activity are detected and acted on, inbound mail is filtered for spam and phishing, and attachments are scanned for malware by our own scanner rather than a third-party service.
- Segregation: data is separated per workspace, and workspace encryption keys are not shared between customers or between categories of content.
- Availability and resilience: redundant infrastructure, monitored continuously, with backups held in the same EU region as the primary data.
- Logging: operational events are recorded as structured logs and deleted automatically on a schedule that depends on severity, from 3 days for debug entries to 30 days for errors.
- Secure development: changes are reviewed before release, dependencies are pinned and monitored for known vulnerabilities, and secrets are held in a managed secret store rather than in code.
- Incident response: a defined process for detecting, escalating and communicating security incidents, including the notification duties in section 9.
- Data location: all processing of content takes place in the European Union.
16. Annex III: sub-processors
The sub-processors we engage today, and what each of them receives. This annex was last changed on 17 August 2026.
Exoscale (Akenes SA, Switzerland)
- Purpose
- hosting and object storage, in its DE-FRA1 data centre in Frankfurt
- Data received
- All customer content and account data. This is where the service runs.
- Location
- Frankfurt, Germany
Stripe (Stripe Payments Europe, Ltd., Ireland)
- Purpose
- payments and invoicing
- Data received
- Billing data only: name, billing address, VAT number, payment method and invoices. Never content.
- Location
- Ireland
Sentry (Functional Software, Inc., on its EU instance)
- Purpose
- error monitoring
- Data received
- Technical error reports and an account identifier. Reports from the apps send no personal information beyond that identifier, and they are proxied through our own servers rather than sent directly from the browser.
- Location
- European Union
Moneybird (Moneybird B.V., the Netherlands)
- Purpose
- bookkeeping
- Data received
- The name, email address and country on an invoice, and its amount and date. No content.
- Location
- The Netherlands
seven.io (seven communications GmbH & Co. KG, Germany)
- Purpose
- SMS delivery
- Data received
- A phone number and a verification code, and only for accounts that add a recovery phone number.
- Location
- Germany
Apple (Apple Inc., United States)
- Purpose
- sending push notifications to the native Drive client
- Data received
- A device token and a signal that something changed. No file names and no contents.
- Location
- United States, under standard contractual clauses
Google and Microsoft are not sub-processors. Where you ask us to sync or back up an account you hold with them, we act on your instruction to read that account, and their own terms govern what they do with it.