Envelope

Data Processing Agreement

Last updated: 26 June 2026

1. Scope and definitions

This Data Processing Agreement ("DPA") forms part of the Envelope Terms of Service between Envelope ("Processor") and the customer ("Controller") and applies where the Controller uses the Envelope Service to process personal data subject to applicable data protection law, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the UK GDPR, the California Consumer Privacy Act ("CCPA"), or equivalent legislation in the Controller's jurisdiction.

  • Controller — the customer who determines the purposes and means of processing personal data using the Service
  • Processor — Envelope, acting on the Controller's documented instructions
  • Data subjects — individuals whose personal data is processed through the Service (typically the Controller's end users and team members)
  • Personal data — any information relating to an identified or identifiable natural person processed in connection with the Service

2. Nature and purpose of processing

Envelope processes personal data solely to provide the Service as described in the Terms of Service. Processing activities include:

  • Storing and managing team design workspaces, agent configurations, and exported spec files created by the Controller
  • Encrypting and storing credentials (API keys, secrets) in the credentials vault
  • Sending transactional emails (magic link authentication) to data subjects
  • Managing billing and subscription records

Envelope processes only the categories of personal data provided by the Controller and does not collect additional personal data beyond what is necessary to provide the Service.


3. Controller's instructions

Envelope will process personal data only on documented instructions from the Controller, including as set out in this DPA and the Terms of Service. If Envelope is required to process personal data for any other purpose by applicable law, Envelope will notify the Controller before such processing unless the law prohibits such notification.


4. Confidentiality

Envelope ensures that persons authorised to process personal data are subject to appropriate confidentiality obligations. Access to personal data is limited to personnel and sub-processors who need access to provide the Service.


5. Security

Envelope implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction, including:

  • AES-256 encryption of credentials at rest, with keys stored separately from encrypted data
  • TLS 1.2+ encryption of all data in transit
  • Encryption at rest for the underlying PostgreSQL database
  • Access controls limiting personal data access to authorised personnel only
  • Regular security review of infrastructure and dependencies

A full description of our security measures is available at openenvelope.org/trust.


6. Sub-processors

The Controller provides general authorisation for Envelope to engage the following sub-processors. Envelope will notify the Controller of any intended changes to this list and provide an opportunity to object before the change takes effect.

| Sub-processor | Purpose | Location | |---|---|---| | Replit, Inc. | Hosting, compute, managed database | United States | | Stripe, Inc. | Payment processing | United States | | Resend, Inc. | Transactional email delivery | United States | | GitHub, Inc. | OAuth sign-in (when used) | United States | | Google LLC | OAuth sign-in (when used) | United States | | Plausible Analytics | Privacy-friendly site analytics (no personal data) | European Union |

Each sub-processor is subject to data processing terms that impose data protection obligations equivalent to those in this DPA. Envelope remains liable for the acts and omissions of its sub-processors.


7. International transfers

Some sub-processors are located in the United States. Where personal data is transferred from the UK or EEA to the United States, Envelope relies on appropriate transfer mechanisms including the UK International Data Transfer Agreement (UK IDTA) or EU Standard Contractual Clauses (SCCs) as applicable. Envelope will provide information about applicable transfer mechanisms on request.


8. Data subject rights

Envelope will assist the Controller in responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection) to the extent technically feasible given the nature of the Service. The Controller is responsible for responding to data subjects directly. Envelope will notify the Controller promptly if it receives a data subject request relating to the Controller's data.


9. Data breach notification

In the event of a personal data breach affecting the Controller's data, Envelope will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. Notification will include, where available: a description of the breach, the categories and approximate number of data subjects affected, the categories and approximate volume of personal data records concerned, and the measures taken or proposed to mitigate the breach.


10. Data protection impact assessments

Envelope will provide reasonable assistance to the Controller in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities where required by applicable law, taking into account the nature of processing and the information available to Envelope.


11. Audit rights

Envelope will make available to the Controller all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or a mandated third-party auditor, provided that such audits: (a) are conducted on reasonable notice of not less than 30 days; (b) are conducted during normal business hours; (c) do not disrupt Envelope's operations or compromise the security or data of other customers; and (d) occur no more than once per calendar year unless required by a supervisory authority.


12. Retention and deletion

Upon termination or expiry of the Terms of Service, Envelope will, at the Controller's election, delete or return all personal data processed on the Controller's behalf within 30 days, except to the extent that applicable law requires continued retention.


13. Governing law

This DPA is governed by applicable data protection law in the relevant jurisdiction. Any disputes arising from or in connection with this DPA will first be addressed through good faith negotiation. Where formal resolution is required, the parties agree to submit to the jurisdiction of courts competent for the matter.


14. Contact

To request a countersigned copy of this DPA, or for any questions about data processing, contact us at [email protected].