Before you connect an AI email tool to a business inbox, check five things under GDPR: where the data is hosted, what the tool actually processes, whether connection tokens are encrypted at rest, whether a Data Processing Agreement (DPA) is in place, and whether a person approves every outgoing message. If a vendor can't answer all five clearly, treat that as your answer.
1. Where is the data actually hosted
GDPR does not forbid using AI tools with EU customer data, but it does require you to know where that data lives and under whose jurisdiction. An AI email assistant reads live inbox content — sender, subject, body — so hosting location is not a footnote, it is one of the first questions to ask. Look for an explicit answer such as "EU-hosted" with a named data center, not a vague "compliant" badge. DraftKite hosts on Supabase infrastructure in Frankfurt, Germany — connected mailboxes, classifications, and drafts all stay on EU servers.
2. What the tool processes — and what it doesn't need to
A second, related question: does the tool need your entire mailbox history, or only new messages as they arrive? Broad, standing access to years of email is a bigger processing footprint than it needs to be for classifying and drafting new mail. Confirm the tool only reads what it needs to do its job — sender, subject, and body of new messages — and doesn't quietly ingest your full archive unless you deliberately opt in (for example, adding past emails to a knowledge base for tone-matching).
Ask for the scopes, not just the pitch
OAuth permission screens (Google's or Microsoft's) list the exact scopes an app is requesting before you grant access. Read that screen. It's a more reliable source than a vendor's marketing page for exactly what the tool can touch.
3. Are connection tokens encrypted at rest
Connecting an inbox issues an OAuth token, not your password — that part is standard and safe with any reputable vendor. What varies is how that token is stored afterwards. A token stored in plain text in a database is a single breach away from full inbox access for every connected account. Ask whether refresh and access tokens are encrypted at rest (AES-256 is the accepted baseline) and whether the encryption key is managed separately from the database itself. DraftKite encrypts every stored token this way, and the same encryption wraps any API key you connect for other integrations.
4. Is there a signed Data Processing Agreement
Under GDPR, any vendor that processes personal data on your behalf while you remain the data controller is a data processor, and you need a Data Processing Agreement (DPA) with them — this is a legal requirement, not a nice-to-have. A serious AI email vendor will have a standard DPA ready to sign (often incorporating the EU Standard Contractual Clauses) before you connect a real business inbox. If a vendor can't produce one, or treats the request as unusual, that's a compliance gap you'd be inheriting.
5. Does a human approve every message before it sends
This is the control measure that matters most in practice, and it's often overlooked in a pure data-flow compliance check. An AI tool that reads inbox content and auto-sends replies removes the one safeguard that catches a wrong price, a misread request, or a reply sent to the wrong thread. Human review before send isn't just good practice — it's the difference between an assistant and an unsupervised system acting on personal data in your name. DraftKite never sends automatically: every classification and reply sits as a Gmail or Outlook draft until you review and send it yourself.
A quick checklist before you connect a business inbox
- EU hosting confirmed with a named region — not just a "GDPR-friendly" claim
- Access limited to what's needed for classifying and drafting new mail
- OAuth scopes reviewed on the provider's own consent screen
- Refresh and access tokens encrypted at rest, not stored in plain text
- A signed Data Processing Agreement in place before go-live
- Every outgoing reply requires human approval — nothing auto-sends
None of this replaces your own organization's compliance review. Treat this as a starting checklist, not a substitute for legal advice specific to your data and industry.
DraftKite is built around these five points: EU-hosted in Frankfurt, encrypted tokens, a standard DPA on request, and every draft waiting for your approval before it goes anywhere. Start the 7-day free trial — no card required — and check the answers yourself before you connect a real inbox.
