Data Processing Agreement
Last updated: 2026-08-14. This DPA forms part of the Terms of Service and applies automatically to every Business and Enterprise account — there is nothing to request and nothing to sign. If your procurement process needs a countersigned copy, email support@outlookdog.com.
The short version
For almost everything OutlookDog does, there is no personal data for us to process on your behalf: we never store your email. Message content is processed in the moment and discarded, and taught rules live in your own mailbox, not on our servers. The one thing we genuinely hold for a business customer is the team roster — the names and email addresses of the people you assign seats to. This agreement is about that.
1. Parties and roles
This DPA is between Speraj LLC ("OutlookDog", "we"), and the organization that holds the Business or Enterprise subscription ("Customer", "you").
Roles differ by data type, and the distinction matters:
- You are the controller and we are the processor for your team roster — the member names, email addresses and seat assignments you enter when managing your team. We process it only to run the service for you.
- We are the controller for the account and billing metadata we need to operate as a business: the account owner's name and email, subscription state, and anonymous usage counts. That is covered by our Privacy Policy, not by this DPA.
- Neither role applies to message content, because we do not retain any. See section 3.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the OutlookDog Outlook add-in and its account, roster and billing functions. Duration: for as long as your subscription is active, plus the deletion window in section 8. Nature and purpose: hosting and administering seat entitlements so the right people in your organization have access.
Categories of data subject: your employees, contractors and other people you assign a seat to. Categories of personal data: name, work email address, seat and role assignment, and subscription status. Special categories: none — the service is not designed for, and must not be used to process, special-category data under GDPR Art. 9.
3. Message content is not retained
When someone uses an AI action, the relevant message text is sent for processing at that moment and is not written to our storage. With OutlookDog's managed AI, it goes to Azure OpenAI under Microsoft's enterprise terms: not used to train models, and held by Microsoft for up to 30 days for abuse monitoring, or not at all where abuse monitoring is disabled. With bring-your-own-key, message text goes directly from the add-in to the AI provider you chose and never reaches our systems at all — in that mode your relationship is with that provider, under whatever terms you agreed with them, and this DPA does not cover it.
Taught rules are stored in the user's own Outlook mailbox settings, not on our servers.
4. Our obligations
- Documented instructions. We process roster data only to provide the service, and otherwise only on your documented instructions, unless required by law — in which case we will tell you first unless the law forbids it.
- Confidentiality. Everyone with access is bound by confidentiality obligations.
- No secondary use. We do not sell your data, and we do not use it to train AI models.
- Assistance. We will help you respond to data-subject requests, and with security, breach notification and impact assessments, taking into account the nature of the processing and the information available to us.
5. Security
Measures are described in full on our Security page. In summary: TLS in transit; encryption at rest for the data we do store; token-verified API access that fails closed; least privilege, with administrative access to production limited to the founder and protected by multi-factor authentication; and monitored, automated backups with a documented disaster-recovery plan.
We are not SOC 2 certified and have not applied. We say so plainly here for the same reason we say it on the Security page: a security questionnaire is the wrong place to discover it.
6. Subprocessors
You give general authorization for the subprocessors below. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected subscription and receive a pro-rata refund.
- Microsoft Azure — hosting, storage and Azure OpenAI (all processing).
- Azure Communication Services — sends account and support email; receives email addresses, never message content.
- Stripe — payments, as merchant of record. We never see card numbers.
- Google Web Risk — link-safety checks; receives URLs only, never message content or user identity.
Each subprocessor is bound by data-protection terms no less protective than these.
7. International transfers
We operate in Microsoft Azure. Where personal data is transferred out of the EEA, the UK or Switzerland, the transfer relies on the EU Standard Contractual Clauses (and the UK Addendum or Swiss equivalent where applicable), which are incorporated into this DPA by reference, together with our subprocessors' own transfer mechanisms. If you need a specific data region for your deployment, raise it with us before purchase — we will tell you honestly whether we can commit to it.
8. Return and deletion
You can remove roster members at any time from your account page, and download or permanently delete your data yourself from the same place. On termination, we delete roster data within 30 days, except where we must retain records to meet a legal obligation — billing records being the usual case.
9. Audit
On reasonable written request, no more than once a year (or after a personal-data breach affecting you), we will provide the information needed to demonstrate compliance with this DPA and respond to a reasonable security questionnaire. Where information alone is insufficient, we will cooperate with an audit conducted by you or an independent auditor you appoint, at your cost, on reasonable notice and without disrupting the service.
10. Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the nature of the breach, the likely consequences, the measures taken, and a contact point — and we will keep you updated as we learn more.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of roster data, this DPA prevails.
Questions
Email support@outlookdog.com. If your security review needs a questionnaire completed, send it over — that is included with Enterprise and we will do it for Business customers too.
