DPA
Data Processing Agreement
Effective August 11, 2026
Parties and roles
This DPA is between the organization that authorizes a user to connect a work Gmail account (Customer) and Ordinal Doctrine. Customer is the controller or business for Customer Mail Data; Ordinal Doctrine is its processor or service provider. Each party remains independently responsible for personal data it controls for its own application, account, legal, security and support purposes.
Processing instructions
Customer instructs Ordinal Doctrine to retrieve, synchronize, display, search and send Customer Mail Data only through the product features the authorized user chooses. Ordinal Doctrine will not sell Customer Mail Data, use it for advertising or credit decisions, or train generalized AI models with it. The Terms, this DPA and the authorized user’s actions are Customer’s documented instructions.
People, data and duration
Customer Mail Data may concern Customer personnel, customers, suppliers and other correspondents and may include Gmail addresses, participant names and addresses, message and thread metadata, subjects, bodies, attachment metadata, and attachment bytes handled during a requested transfer. Processing continues until Customer deletes the service data, subject to provider backup expiry and legal retention.
Customer obligations
Customer confirms it has authority and a lawful basis to connect the mailbox, provide required notices, issue lawful instructions and use the service. Customer must not connect personal consumer mailboxes or use the beta for regulated sensitive-data workflows without Ordinal Doctrine’s prior written approval.
Confidentiality and security
Ordinal Doctrine limits access to persons who need it for support, security or legal duties and who are bound by confidentiality. Safeguards include AES-256 encryption at rest for the hosted database, additional AES-GCM encryption for OAuth credentials, HTTPS, secure HttpOnly cookies, access controls, same-origin checks, rate limits and deletion controls. Customer remains responsible for Google account security and appropriate administrator controls.
Subprocessors and international processing
Instructions, supervision and responsibility
Ordinal Doctrine will promptly notify Customer if, in its reasonable opinion, an instruction violates applicable data-protection law and may suspend the affected processing while the parties correct it. Customer may supervise performance through reasonable information requests, require correction of a verified breach and terminate affected processing if it is not corrected. Each party is responsible for damage caused by its breach of this DPA or applicable law, subject only to limitations that the law permits.
Assistance and incidents
Taking account of the processing and information available, Ordinal Doctrine will reasonably assist Customer with data-subject requests, security obligations and legally required assessments. Ordinal Doctrine will notify Customer without undue delay after confirming a breach of Customer Mail Data and provide available information needed for Customer’s response.