Data Processing Agreement
Effective 4 October 2026
In short: when email passes through GhostParse, you (our customer) decide what happens to it and we only process it on your instructions. We don't store email content (bodies, subjects or attachments): it passes through to you and is gone. We keep a short delivery log of metadata, and we use only the sub-processors listed below. Email is processed on servers in the United Kingdom. This agreement forms part of our Terms and applies automatically: there's nothing to sign.
1. Parties and scope
This Data Processing Agreement ("DPA") is between WILDYE LIMITED, a company registered in England and Wales ("WILDYE LIMITED", "we", the processor) and the customer who has accepted our Terms ("you", the controller). It applies to personal data we process on your behalf when providing the Service, as required by Article 28 of the UK GDPR and, where it applies, the EU GDPR ("Data Protection Law").
Personal data about you as our user (your login, team and account details) is covered by our Privacy Policy, where we are the controller, not by this DPA.
2. Details of the processing
| Subject matter | Receiving email for your domains and addresses, and delivering it to the webhook URLs and other destinations you set (such as Slack, Microsoft Teams, Google Sheets, Zapier, Make or n8n). |
|---|---|
| Duration | For as long as you use the Service, then as set out in section 9. |
| Nature and purpose | Receiving, parsing, authenticating (SPF, DKIM, DMARC), optionally scanning for spam and viruses, optionally extracting fields with your parsers, and delivering email to you; keeping a delivery log so you can see what happened. |
| Personal data | Whatever the emails contain: typically names, email addresses, message content and attachments, and technical data such as IP addresses in headers. Delivery log: Message-ID, the sender's domain, recipient addresses at your domains, size, spam score and outcome. |
| Special category data | Only if senders include it in their emails. You decide whether your addresses should receive it. |
| Data subjects | People who send email to your addresses, and anyone named in those emails. |
3. Our obligations
We will:
- process the personal data only on your documented instructions, which are these Terms, this DPA and how you configure the Service (your domains, addresses, webhook URLs and settings), unless the law requires otherwise, in which case we'll tell you first unless the law forbids that;
- tell you straight away if we think an instruction breaks Data Protection Law;
- make sure everyone authorised to process the data is bound by confidentiality;
- take the security measures in section 6;
- help you, taking into account the nature of the processing, to respond to requests from data subjects exercising their rights, and to meet your obligations on security, breach notification, data protection impact assessments and prior consultation;
- delete the personal data at the end of the Service as set out in section 9;
- make available the information you need to show compliance with Article 28, and allow for and contribute to audits as set out in section 8.
4. Your obligations
You are responsible for having a lawful basis to receive the email you route through the Service, for the instructions you give us, and for what you do with the email once it reaches your webhook.
5. Sub-processors
You give general authorisation for us to use the sub-processors below. We impose data protection obligations on each of them equivalent to those in this DPA and remain liable for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| WILDYE LIMITED | Servers that run the Service and its database | United Kingdom |
The destinations you set up (your webhooks and services such as Slack, Microsoft Teams, Google Sheets, Zapier, Make or n8n) are not our sub-processors. We deliver email to them on your instructions, and you choose them under your own terms with each provider.
Spam and virus scanning (where enabled) run on our own servers; no email is sent to a third party for scanning. We'll announce changes to this list on this page at least 30 days in advance. If you object on reasonable data protection grounds, tell us at hello@wildye.com; if we can't resolve the objection, you may stop using the affected feature or close your account.
6. Security
- No storage of email content: email you receive is parsed in memory and delivered to you; its content (body, subject, attachments) is never written to our database, logs or backups. If your webhook is unavailable, we don't hold the email: we ask the sending server to retry later, so it stays with the sender until you can take it.
- Encryption: TLS for the dashboard, API and webhooks (HTTPS), and opportunistic TLS (STARTTLS) for SMTP. Webhook secrets, DKIM keys and 2FA secrets are encrypted at rest; passwords, API keys and session identifiers are stored only as hashes.
- Integrity: every webhook is signed with HMAC-SHA256 (Standard Webhooks) and timestamped, so you can prove it came from us, unchanged, and reject replays. Each event has a stable id that stays the same if it's delivered again, so you can process it exactly once.
- Access control: role-based access for your team, optional or enforced 2FA, an audit log of account activity, and least-privilege access for our staff.
- Network protection: webhooks can't be pointed at private networks; databases are not exposed to the internet.
- Resilience: undelivered email is deferred so the sending server retries, an optional backup webhook URL, and a public status page.
7. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own obligations, and keep you updated as we learn more.
8. Audits
We'll answer reasonable written questions about our compliance with this DPA. If that isn't enough to show compliance, or a regulator requires it, you (or an independent auditor bound by confidentiality) may audit us once a year on 30 days' notice, during business hours and without disrupting the Service, at your cost.
9. Deletion and return
Email content isn't stored, so there is nothing to return or delete. Delivery log metadata is deleted automatically after 90 days. When you delete your account, all of this is deleted with it, unless the law requires us to keep it.
10. International transfers
We process email on servers in the United Kingdom. We transfer personal data outside the UK (or, for EU customers, the EEA) only where Data Protection Law allows it, for example to a country covered by adequacy regulations, or with the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, in place.
11. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law doesn't allow that. If this DPA conflicts with the Terms on data protection, this DPA wins.
12. Contact
WILDYE LIMITED, a company registered in England and Wales. Email: hello@wildye.com.