GDPR (for email tools)

GDPR is the EU's General Data Protection Regulation, the law governing how personal data of people in the EU and EEA is collected, stored, and processed. For an email tool it means the contents, sender addresses, and metadata it handles are personal data, so lawful basis, data minimisation, and where the data is hosted all apply.

What the regulation covers

GDPR (Regulation (EU) 2016/679) has applied since May 2018 and sets rules for any organisation that processes the personal data of people in the EU or EEA, wherever that organisation is based. It defines principles — lawful basis, purpose limitation, data minimisation, and storage limitation — and grants individuals rights over their data, such as access, correction, and erasure. A tool that reads or stores email is a data processor or controller under these rules.

Why it matters for AI email tools

Email is dense with personal data: names, addresses, message contents, and often special-category details. An AI assistant that classifies messages or drafts replies processes all of it, and may pass it to model providers acting as sub-processors. That makes three things central — a lawful basis for the processing, transparency about which sub-processors see the data, and data residency (whether the data leaves the EU). Buyers typically also want a data processing agreement (DPA) and the ability to export or delete their data.

How it works in DraftKite

DraftKite is built around GDPR from the ground up and hosts its infrastructure in the EU (Frankfurt). OAuth tokens for connected Gmail and Outlook mailboxes are stored encrypted (AES-256-GCM), and it never sends on your behalf — every reply it writes waits as a draft until a person reviews and sends it, keeping a human in the loop. Assess your own obligations, but the data handling is designed to take them seriously.

Frequently asked questions

If it processes the email of people in the EU or EEA, GDPR applies to that processing regardless of where the tool's company is based. Compliance rests with both the provider (as processor) and the customer (usually the controller), typically formalised in a data processing agreement.

DraftKite hosts its infrastructure in the EU (Frankfurt) and is built around GDPR by design. Connected mailbox tokens are stored encrypted, and it never auto-sends — every draft waits for a person to review and send it.