Skip to content

/ Legal

Privacy policy.

What we collect, why we collect it, where it lives, and what rights you have over it. Written to be read rather than to satisfy a checklist.

Last updated: 2026-05-25

01 — Summary

We provide managed email delivery infrastructure. To do that, we process two distinct categories of personal data: the data of the people who work at customer organizations (the named contacts who interact with us), and the data inside the email customers send through our infrastructure (recipient addresses, message content, engagement events). We treat both with care, we minimize what we collect, and we transit message content without reading it.

If you want the short version: we collect what we need to operate the service, we don't sell anything to anyone, we run dedicated infrastructure for our customers, and we offer EU, US, or LATAM termination so your data can sit where your customers' rules require.

02 — Our roles under data-protection law

For data we collect directly about you — when you contact us, sign a service agreement, or interact with this website — we act as the data controller. For data inside the email our customers send through our infrastructure, we act as a data processor on behalf of the customer, who is the controller for that mail.

This distinction matters because it determines who has obligations to whom. For controller activities we follow this policy directly. For processor activities we operate under the terms of our Data Processing Agreement with the customer, which mirrors the protections customers expect under GDPR-style regimes.

03 — What we collect

From people who reach out or become customers: name, work email, company, role, the contents of any message you send us, and — if you become a customer — billing details and the named contacts authorized to interact with us about your account.

From mail customers send through our infrastructure: the technical metadata required to deliver mail (sender, recipient, headers, timestamps, delivery and engagement events) and the message content itself in transit. Message content is processed only to the extent needed to deliver it; we do not analyze content for our own purposes.

From this website: minimal technical logs (IP address, user agent, pages requested) to operate the site and detect abuse. We don't use third-party advertising or analytics that profile visitors across sites.

04 — How we use it

To respond to you when you contact us. To deliver and operate the service if you become a customer. To monitor and protect the infrastructure against abuse. To meet legal, tax, and audit obligations. To communicate operationally with named customer contacts — service updates, security advisories, billing — but not for marketing without explicit consent.

We do not sell personal data, we do not share it with advertisers, and we do not use customer mail content to improve any model or to build any aggregated product.

05 — Sub-processors

We use a small number of sub-processors to operate the service — cloud infrastructure providers, billing, support tooling. A current list is available on request and to active customers, and we notify customers in advance of material additions so they can object before the change takes effect, as required by our Data Processing Agreement.

We disclose personal data to sub-processors only as needed to operate the service, under contractual terms that bind them to equivalent protections.

06 — Data residency

Customers can choose where their sending infrastructure terminates — EU, US, or LATAM — which determines where mail metadata and content transit. The choice is made during scoping and is part of the service architecture. If you have specific residency requirements driven by your own customers' rules, raise them on the discovery call and we'll architect accordingly.

07 — Retention

We retain account and billing data for as long as the account is active and for a period afterward as required by tax and audit obligations. Message logs are retained for the window agreed in the service contract — typically longer than the 30-day or 45-day caps common in self-serve platforms — and configurable to your compliance needs.

Message content in transit is processed only as long as needed to deliver and is not stored permanently.

08 — Your rights

Where applicable law gives you rights over personal data we hold about you — to access, correct, port, delete, or restrict processing — you can exercise those rights by contacting us using the details below. We respond within the timeframes the applicable law requires, typically within 30 days.

For data we process on behalf of a customer (the email content they sent), your first point of contact is the customer; we'll support them in fulfilling your request as their processor.

09 — Cookies

This site uses strictly necessary cookies for basic functionality. We don't run third-party advertising cookies or cross-site tracking. If we add any analytics, we'll do so with clear disclosure and a consent mechanism for jurisdictions that require one.

10 — Changes to this policy

We update this policy when our practices change or when the law requires us to. Material changes are flagged at the top of the page and, for active customers, communicated directly. The "last updated" date at the top reflects the most recent revision.

11 — Contact

Privacy questions, requests, or concerns can be sent to privacy@emaildeliveryplatform.com. We read and respond to each one.