What the regulation covers
GDPR (Regulation (EU) 2016/679) has applied since May 2018 and sets rules for any organisation that processes the personal data of people in the EU or EEA, wherever that organisation is based. It defines principles — lawful basis, purpose limitation, data minimisation, and storage limitation — and grants individuals rights over their data, such as access, correction, and erasure. A tool that reads or stores email is a data processor or controller under these rules.
Why it matters for AI email tools
Email is dense with personal data: names, addresses, message contents, and often special-category details. An AI assistant that classifies messages or drafts replies processes all of it, and may pass it to model providers acting as sub-processors. That makes three things central — a lawful basis for the processing, transparency about which sub-processors see the data, and data residency (whether the data leaves the EU). Buyers typically also want a data processing agreement (DPA) and the ability to export or delete their data.
How it works in DraftKite
DraftKite is built around GDPR from the ground up and hosts its infrastructure in the EU (Frankfurt). OAuth tokens for connected Gmail and Outlook mailboxes are stored encrypted (AES-256-GCM), and it never sends on your behalf — every reply it writes waits as a draft until a person reviews and sends it, keeping a human in the loop. Assess your own obligations, but the data handling is designed to take them seriously.