DPA

Data Processing Agreement

Effective August 11, 2026

Parties and roles

This DPA is between the organization that authorizes a user to connect a work Gmail account (Customer) and Ordinal Doctrine. Customer is the controller or business for Customer Mail Data; Ordinal Doctrine is its processor or service provider. Each party remains independently responsible for personal data it controls for its own application, account, legal, security and support purposes.

Processing instructions

Customer instructs Ordinal Doctrine to retrieve, synchronize, display, search and send Customer Mail Data only through the product features the authorized user chooses. Ordinal Doctrine will not sell Customer Mail Data, use it for advertising or credit decisions, or train generalized AI models with it. The Terms, this DPA and the authorized user’s actions are Customer’s documented instructions.

People, data and duration

Customer Mail Data may concern Customer personnel, customers, suppliers and other correspondents and may include Gmail addresses, participant names and addresses, message and thread metadata, subjects, bodies, attachment metadata, and attachment bytes handled during a requested transfer. Processing continues until Customer deletes the service data, subject to provider backup expiry and legal retention.

Customer obligations

Customer confirms it has authority and a lawful basis to connect the mailbox, provide required notices, issue lawful instructions and use the service. Customer must not connect personal consumer mailboxes or use the beta for regulated sensitive-data workflows without Ordinal Doctrine’s prior written approval.

Confidentiality and security

Ordinal Doctrine limits access to persons who need it for support, security or legal duties and who are bound by confidentiality. Safeguards include AES-256 encryption at rest for the hosted database, additional AES-GCM encryption for OAuth credentials, HTTPS, secure HttpOnly cookies, access controls, same-origin checks, rate limits and deletion controls. Customer remains responsible for Google account security and appropriate administrator controls.

Subprocessors and international processing

Customer authorizes OpenAI OpCo, LLC and its listed infrastructure subprocessors, including Cloudflare, Ltd., to host and operate the service. Current locations and links are listed in the Privacy Policy. Google is the mailbox provider selected by Customer. Each subprocessor must be bound to data-protection duties no less protective than the applicable duties in this DPA, and Ordinal Doctrine remains responsible for its subprocessors to the extent required by law. Before a new subprocessor handles Customer Mail Data, Ordinal Doctrine will request Customer approval where required by applicable law and otherwise give advance notice and an opportunity to object.

Instructions, supervision and responsibility

Ordinal Doctrine will promptly notify Customer if, in its reasonable opinion, an instruction violates applicable data-protection law and may suspend the affected processing while the parties correct it. Customer may supervise performance through reasonable information requests, require correction of a verified breach and terminate affected processing if it is not corrected. Each party is responsible for damage caused by its breach of this DPA or applicable law, subject only to limitations that the law permits.

Assistance and incidents

Taking account of the processing and information available, Ordinal Doctrine will reasonably assist Customer with data-subject requests, security obligations and legally required assessments. Ordinal Doctrine will notify Customer without undue delay after confirming a breach of Customer Mail Data and provide available information needed for Customer’s response.

Return, deletion and audit

Customer retains original Gmail as its return copy. Customer may delete active application data in Mail accounts; the product attempts to revoke each connected Google authorization before deleting the local OAuth credentials and reports any revocation failures for manual removal. Ordinal Doctrine will confirm a manual email deletion request to the verified requester. Provider backups are governed separately as described in the Privacy Policy. On reasonable written request, Ordinal Doctrine will provide information necessary to demonstrate compliance with this DPA; audits must protect other customers, security and confidential information.

Order of terms and contact

This DPA controls over conflicting Terms for Customer Mail Data. Mandatory data-protection law remains controlling. Contact andrea@nprit.co.kr.