Privacy Policy – Tame-Box
Last updated: February 2025 | Publisher: Tame Box
1. Introduction
This Privacy Policy describes how Tame-Box, an Outlook add-in published by Tame Box, collects, uses, and protects the personal data of its users. This policy applies exclusively to the Tame-Box add-in and the services it provides, not to any website.
Tame-Box is an AI-powered Outlook add-in that automatically labels unread emails, provides summaries of open emails, suggests replies, and proposes calendar event additions based on email content.
2. Data We Process
To deliver its features, Tame-Box processes the following data:
- Email content: subject, body, sender, and recipients of emails you open or that are scanned for labeling.
- Microsoft account information: your name and email address, provided via Microsoft OAuth.
- Calendar data: when you choose to add an event, the relevant information is submitted to your Microsoft calendar.
- Technical logs: anonymized error and usage logs for the purpose of service maintenance.
Tame-Box does not store your emails. Email content is transmitted to our AI provider for processing and is not retained beyond the duration of the request. Technical logs may contain metadata but never full email content.
3. How We Use Your Data
- To label unread emails based on their content
- To generate email summaries and suggested replies
- To propose and add calendar events
- To maintain and improve the Tame-Box service
We do not use your data for advertising or sell it to third parties.
4. AI Processing – Third-Party Subprocessor
Email content is sent to Google Gemini (Google LLC) for AI-based analysis. Google acts as a subprocessor under our agreement. Email data is processed in transit and is not retained by Google for model training under our enterprise agreement. For more information, see Google Cloud Data Processing Addendum.
5. Legal Basis for Processing (GDPR)
We process your data based on the following legal grounds:
- Performance of a contract (Art. 6(1)(b) GDPR): processing necessary to provide the Tame-Box service you subscribed to.
- Legitimate interest (Art. 6(1)(f) GDPR): technical logs for service maintenance and security.
6. Data Retention
Email content is not stored. Technical logs are retained for a maximum of 30 days and then deleted automatically. Account information is retained for the duration of your subscription and deleted within 30 days of account termination.
7. Your Rights (GDPR)
As a data subject under the GDPR, you have the following rights:
- Right of access: request a copy of the data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your personal data.
- Right to restriction: request that we limit how we use your data.
- Right to data portability: receive your data in a machine-readable format.
- Right to object: object to processing based on legitimate interests.
To exercise any of these rights, contact us at: contact@tame-box.com. We will respond within 30 days.
You also have the right to lodge a complaint with the French data protection authority: CNIL – www.cnil.fr.
8. Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. All data in transit is encrypted using TLS.
9. International Transfers
Processing by Google Gemini may involve transfer of data outside the European Economic Area. Such transfers are governed by Standard Contractual Clauses as defined by the European Commission.
10. Changes to This Policy
We may update this Privacy Policy. When we do, we will notify you via the Tame-Box add-in interface or by email. Continued use of Tame-Box after notification constitutes acceptance of the updated policy.
11. Contact
Email: contact@tame-box.com
Website: https://tame-box.com