SekurMailThese Business Terms apply to organizations (companies) that create a SekurMail organization, verify a domain, and add members. They supplement the Terms of Service; where they conflict for business use, these Business Terms control. The Data Processing Addendum in Part B applies where SekurMail processes personal data on the organization's behalf, and controls for that subject (Section B6).
An organization is created by an admin, verified by proving control of a domain (via a DNS record), and may add members (seats). The organization is the account holder and is responsible for its admins' and members' use of the Service, for authority to add each member, and for its own compliance obligations toward its members and personnel.
SekurMail is end-to-end encrypted, and this does not change for organizations. Specifically, as the Service exists today:
The organization and its admins must: have authority and any legally required consent to add members and to send messages to the organization; use the Service consistent with the Acceptable Use Policy; manage seats and offboarding; and not misrepresent the organization's data-access capabilities to its members. The organization is responsible for actions taken under its admin credentials.
Business plans are billed per the plan you select (per-seat and/or usage-based). Fees are handled via our payment processor (Stripe) and/or invoicing. Late amounts may incur suspension. Fees are non-refundable except as required by law or expressly stated.
Either party may terminate per the plan terms. We may suspend for non-payment or AUP violations. On termination, members lose organization access; encrypted data on members' devices remains subject to end-to-end-encryption realities (we cannot recover keys).
The warranty disclaimers, liability cap (greater of trailing-12-month fees or US$100), and indemnification in the Terms of Service apply to business use. The organization additionally indemnifies SekurMail against claims by its members or personnel arising from the organization's configuration or use of the Service.
Texas governing law and the arbitration/venue provisions of the Terms of Service apply, unless a signed enterprise agreement states otherwise.
This DPA applies where, and to the extent, SekurMail processes personal data on behalf of the organization (“Customer”) as a processor (or “service provider” under U.S. state law), and Customer is the controller.
For personal data Customer routes through the Service (e.g., member identifiers, routing metadata, billing contacts), SekurMail processes it only to provide the Service, per Customer's documented instructions and these terms. For end-to-end-encrypted message content, SekurMail is not a meaningful processor of the plaintext — it cannot access it.
SekurMail will: (a) process personal data only on Customer's documented instructions and as needed to provide the Service or comply with law; (b) ensure personnel are bound by confidentiality; (c) implement appropriate technical and organizational security measures (including the end-to-end encryption central to the Service); (d) assist Customer, taking into account the nature of processing, with data-subject requests and with security/breach/DPIA obligations; (e) notify Customer without undue delay of a personal-data breach it becomes aware of; and (f) at Customer's choice, delete or return personal data at the end of the relationship, subject to the retained-data carve-outs (security/audit log, watermark records, legal-hold evidence) described in the Privacy Policy and any legal retention obligations.
Customer authorizes the subprocessors listed in the Privacy Policy (Stripe, SMS/email couriers, AWS, push providers, TURN). SekurMail will impose data-protection terms on subprocessors and remains responsible for their performance, and will give notice of new subprocessors with a chance to object.
Where applicable, the parties will rely on Standard Contractual Clauses or another valid transfer mechanism for transfers of EEA/UK/Swiss personal data.
SekurMail will make available information reasonably necessary to demonstrate compliance and allow audits per agreed terms. As a service provider under the CCPA/CPRA, SekurMail will not sell or share personal data or use it outside the direct business relationship. Deletion is subject to the carve-outs above.
If this DPA conflicts with the Business Terms or Terms of Service on personal-data processing, this DPA controls for that subject.
Contact for data-protection matters: privacy@sekurmail.com / legal@sekurmail.com.