Ruber

Legal

Data processing agreement

Where you use Ruber to run mail for other people — your staff, your clients, your users — you are the controller of their personal data and Sukses360 Ltd is your processor. This document is the agreement that relationship requires. It applies automatically to every account and does not need to be signed separately.

Last updated

01Why this exists

Article 28 of the UK GDPR requires a written contract between a controller and a processor, covering a specific list of things. Most providers make you ask for one. Publishing it means you can read it before you sign up rather than after, and it means every customer has the same terms.

This supplements the terms of service. Where the two conflict on the handling of personal data, this document wins.

02What is being processed

Message contents are unbounded by nature. Anybody can send anything to an address, including special category data, and no provider controls what arrives. That is a property of email rather than of this service, and it is worth stating because a schedule listing neat categories would be misleading.

  • Subject matter: providing mailboxes and mail delivery on domains you control.
  • Duration: for as long as your account is open, plus the short period afterwards described under deletion.
  • Nature and purpose: receiving, filtering, storing, transmitting and displaying email, and operating the accounts and domains that make that possible.
  • Types of personal data: the contents of messages, which may contain anything the sender chose to write; message metadata; mailbox and account identifiers; and connection logs including IP addresses.
  • Categories of data subject: your staff, your customers, and anybody who sends mail to an address you operate.

03Our obligations

  • We process personal data only on your documented instructions, including on transfers, unless a law requires otherwise — in which case we tell you before processing, where that law permits.
  • Everyone with access is under an obligation of confidentiality.
  • We take appropriate technical and organisational security measures. What those are today, and what they are not yet, is published on the security page rather than described here in the abstract.
  • We assist you with data subject requests, and with your obligations on security, breach notification and impact assessments, to the extent our position makes that possible.
  • We make available the information you need to demonstrate compliance with Article 28.

04Subprocessors

You give general authorisation for us to use the subprocessors listed on the subprocessors page. Each is bound by terms no less protective than these.

We publish changes to that list before a new subprocessor begins handling customer data, so that you have the opportunity to object. If you object on reasonable data-protection grounds and we cannot accommodate it, you may terminate.

05Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available at the time, and we follow up as more becomes known. We do not wait for a complete picture before telling you, because your own notification clock starts before ours finishes.

06International transfers

Mailbox contents are stored in the European Union. Where a subprocessor processes data outside the UK or EEA, that transfer relies on the UK International Data Transfer Addendum or on standard contractual clauses, together with any additional measures the transfer requires.

07Deletion and return

Because the mailbox is reachable over IMAP throughout, you can export your data yourself at any point without asking us — that is the return mechanism, and it does not depend on our cooperation at the moment you need it most.

On termination we delete personal data within a reasonable period, except where a law requires us to keep it. Tell us if you need deletion confirmed in writing.

08Audit

We provide the information reasonably needed to demonstrate compliance, and will respond to a security questionnaire. We do not currently hold SOC 2 or ISO 27001, and there is no third-party audit report to share — the security page says so plainly rather than leaving it to be discovered here.

On-site audits are considered case by case, on reasonable notice, at your cost, and subject to not compromising other customers.

Sukses360 Ltd

Trading as Ruber. Registered in England and Wales, company number 16587307. Registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

Questions: hello@ruber.me