Data processing addendum

Last updated: 2026-07-22. This addendum forms part of the agreement between the customer ("controller") and Canyon Data Insights ("processor"). A signable version is available on request at [email protected]. The summary below describes how it works; it is not a substitute for the executed document.

Roles and scope

For mail we filter on your behalf, you are the controller and Blockjay is the processor. We process personal data only on your documented instructions — namely, to fetch, classify, store, quarantine, restore, and display mail, and to provide reports and support. The subject matter is email filtering; the duration is the term of your account.

Categories of data and data subjects

Sub-processors

We use a limited set of sub-processors, listed and kept current on the sub-processors page. We impose data-protection terms on each and remain responsible for their performance. We will give notice of new sub-processors and a chance to object as set out in the executed addendum.

International transfers

We operate EU-first and region-configurable. Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (and the UK addendum where relevant), together with the data-minimization and zero-retention measures described in our security and privacy pages.

Security measures

We maintain the technical and organizational measures summarized on the security page — AES-256 encryption at rest, per-user/per-org keys held in a key-management service, TLS in transit, row-level tenant isolation, no admin access to content, audited key use, and a log scrubber that keeps bodies and credentials out of logs.

Assistance, rights, and breach

Retention, return and deletion

Valid mail is retained until the data subject or controller deletes it. Quarantined spam is retained for 60 days after capture and then automatically deleted, along with its stored copy. On termination, we return or delete personal data per your instruction, subject to any legal-hold exceptions. Erasure destroys the per-user encryption key so residual ciphertext is unrecoverable.