Inovamail Legal
Privacy Policy
Inovamail is built so that we cannot read the content of your end-to-end-encrypted messages and cannot recover your encryption keys. This Policy explains the limited personal data we do process — account, billing, security, and delivery metadata — why we process it, who we share it with, and the rights you have. This summary is for convenience and does not replace the full text below.
1. Introduction & Scope
This Privacy Policy (the “Policy”) describes how [LEGAL ENTITY NAME], operating as Inovamail (“Inovamail”, “we”, “us”, “our”), collects, uses, discloses, and protects personal data in connection with the Inovamail encrypted email service, including the web application, IMAP/SMTP access, mobile and desktop apps, automated workflows and integrations, organization features, and outreach tools (together, the “Service”), and our website at [WEBSITE URL].
This Policy applies to:
- Visitors to our website;
- Account holders — individuals who register for an Inovamail account (an “Account”);
- Members — individuals whose Accounts are created or administered under an organization established in the Service (an “Organization”); and
- Individuals who correspond with us (for example, through support requests).
1.1 Our roles: controller and processor
Data-protection laws distinguish between a controller (who decides why and how personal data is processed) and a processor (who processes it on a controller’s behalf). Inovamail acts in different roles for different data:
- Inovamail as controller. We are the controller (and, under Canadian law, the organization accountable) for personal data relating to your Account, registration, authentication, billing, support, and use of the Service — the categories described in Section 4.
- Inovamail as processor / service provider. Where an Organization uses the Service, the Organization (or its designated customer entity) is the controller of the content, contact data, and other personal data of third parties that it and its Members put into the Service (“Customer Content”), and Inovamail processes that data as a processor/service provider on the Organization’s documented instructions under our Data Processing Agreement (the “DPA”).
- Inovamail as neither. For the content of end-to-end-encrypted messages, we hold only ciphertext we cannot decrypt. We cannot access that content in intelligible form at all (see Sections 2 and 6).
- You as controller. Where you use the Service to process other people’s personal data — for example, addresses you find, upload, or contact using the outreach features described in Section 4.9 (“Outreach Tools”), or recipient data in your automated workflows — you (or your Organization) are the controller of that data and are responsible for having a lawful basis to process it.
This Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
2. Our Privacy Commitment: Zero-Knowledge by Design
Inovamail is engineered on a zero-knowledge, end-to-end-encryption (“E2E”) architecture. In plain terms:
- We cannot read the content of your end-to-end-encrypted messages. Message content and attachments protected by E2E encryption are encrypted using keys that are themselves protected by secrets (such as your passphrase) that we never hold in usable form. What we store is ciphertext that is unintelligible to us.
- We cannot recover your keys. Encrypted backups of your account keys are encrypted such that only you can unlock them. If you lose your passphrase, recovery codes, and any other recovery methods you have set up, neither you nor we can decrypt your data, and it is permanently lost.
- We do not mine your messages. We do not scan the content of your messages for advertising, profiling, or marketing purposes. We do not build advertising profiles from your correspondence, and we serve no third-party advertising in the Service.
- We minimize what we must hold. We collect and retain only the data reasonably necessary to operate, secure, and bill for the Service, to route and deliver mail, and to comply with law.
Your responsibility: because of the zero-knowledge design, you must safeguard your passphrase, recovery codes, and any exported keys. We have no “master key” and no reset mechanism that can restore access to your encrypted data. Loss of your credentials and recovery methods means permanent, irreversible loss of the data they protect.
Section 6 explains in more detail what this architecture means — and does not mean — for your data.
3. Who Is Responsible for Your Data & How to Reach Us
The controller of the personal data described in this Policy (except Customer Content, for which the relevant Organization or user is the controller) is:
[LEGAL ENTITY NAME] (operating as Inovamail)
a company registered in Canada
Registered office: [REGISTERED ADDRESS]
Privacy contact: [PRIVACY EMAIL]
Privacy Officer / Data Protection Officer: [DPO NAME/CONTACT]. This person is also our designated privacy officer for the purposes of the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”) and the person in charge of the protection of personal information for the purposes of Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25.
EU representative (Article 27 of the EU General Data Protection Regulation (“GDPR”)): [EU REPRESENTATIVE].
UK representative (Article 27 of the UK GDPR): [UK REPRESENTATIVE].
You may contact our representatives in respect of GDPR / UK GDPR matters instead of, or in addition to, contacting us directly.
4. Personal Data We Collect
We collect the following categories of personal data. Where indicated, a category is provided by you; otherwise it is generated automatically when you use the Service. We do not intentionally collect sensitive personal data (such as health, biometric, or precise geolocation data) for our own purposes; if your encrypted content includes such data, we cannot read it.
| Category | What it includes | Source | Notes |
|---|---|---|---|
| 4.1 Account & registration data | Your chosen Inovamail email address(es) and aliases, display name, account settings and preferences, plan tier, language, custom domain names you connect, and any optional recovery email address you provide. | You | Required to create and operate your Account. |
| 4.2 Authentication & security data | Credential verifiers (we do not store your passphrase itself in readable form), two-factor authentication configuration, recovery-code status (not the plaintext codes once issued), key-verification records, app-password and API-key identifiers, session tokens, and login history (timestamps, IP address, approximate location derived from IP, device/client identifiers). | You / automatic | Used to authenticate you and to detect account compromise and abuse. |
| 4.3 Billing data | Plan and subscription details, invoices, transaction history, billing name and address, tax information where required, and limited payment tokens or references. | You / payment processor | Payments are handled by a third-party PCI-DSS-compliant payment processor. We do not receive or store your full card number or card security code. See Subprocessors. |
| 4.4 Usage, log, device & technical data | Server and application logs (IP address, timestamps, protocol events, error reports), device and client information (browser or app type and version, operating system), feature-usage events (for example, that a workflow ran — not the content it handled), storage consumption, and rate-limit counters. | Automatic | Used to operate, secure, debug, and improve the Service and to enforce plan limits and our Acceptable Use Policy. |
| 4.5 Message metadata (envelope / transport data) | The routing information that email protocols require to deliver mail: sender and recipient addresses, message timestamps, message size, delivery status, mail routing headers, spam/abuse signals, and quarantine or challenge status under Fortress mode. | Automatic | No email provider can end-to-end encrypt this transport metadata, because mail systems need it to route and deliver messages. We process it only for delivery, security, anti-abuse, and troubleshooting. See Section 6. |
| 4.6 Message content (end-to-end encrypted) | The body content and attachments of your messages, and your encrypted key material. | You (as ciphertext) | Inaccessible to us. E2E-encrypted content is stored only as ciphertext we cannot decrypt. Messages exchanged with external services that do not support end-to-end encryption are necessarily processed transiently in the course of transmission so they can be delivered; stored message content in your Account is protected by zero-knowledge encryption. |
| 4.7 Support communications | Messages you send to our support, privacy, legal, or abuse addresses, and any information you choose to include in them. | You | Do not include passphrases or decrypted message content in support requests; we will never ask for your passphrase. |
| 4.8 Cookies & local storage | Strictly necessary cookies and similar local-storage technologies used for sign-in, session management, security, and preferences. | Automatic | Described in full in our Cookie Policy. See Section 12. |
| 4.9 Organization data | If you create or belong to an Organization: the Organization’s name and settings, Member account identifiers and addresses, roles and permissions, and administrative activity records. | You / Organization admin | Organization administrators can see and manage Member account data and certain metadata — see Section 7.3. |
| 4.10 Outreach Tools data | Email addresses and related publicly available information that you locate through the Outreach Tools or upload to the Service, and your sending activity using those tools. | You / public web at your direction | You are the controller of this data. We process it only on your instructions, as a processor/technical intermediary. See the callout below. |
Outreach Tools — your obligations. When you use the Outreach Tools to discover publicly available email addresses or to contact people, you are the data controller and the sole sender of that outreach. You are responsible for ensuring you have a lawful basis — and any consent required by CASL, CAN-SPAM, the GDPR/ePrivacy rules, and all other applicable laws — for every address you collect and every message you send. Your use of these features is governed by our Acceptable Use Policy and Anti-Spam Policy. We do not guarantee that any discovered address is accurate, deliverable, or lawful for you to contact.
5. How We Use Personal Data & Our Legal Bases
We use personal data only for the purposes below. For individuals in the European Economic Area, the UK, or other jurisdictions with equivalent requirements, we identify the legal basis under Article 6 GDPR / UK GDPR for each purpose. In Canada, we rely on your express or implied consent for these identified purposes, as permitted by PIPEDA and Quebec Law 25, and on statutory exceptions where applicable.
| Purpose | Examples | GDPR legal basis |
|---|---|---|
| Provide and operate the Service | Creating and maintaining your Account; routing, delivering, and storing mail; syncing across IMAP/SMTP and apps; running your configured workflows and integrations; operating Organization features; enforcing plan limits. | Performance of a contract (Art. 6(1)(b)). |
| Secure the Service and prevent abuse | Authentication and session security; detecting and blocking spam, phishing, fraud, account takeover, and abuse; operating Fortress mode quarantine and sender challenges; rate limiting (including on Outreach Tools); investigating violations of our Terms and policies. | Legitimate interests (Art. 6(1)(f)) — protecting the Service, our users, and third parties; performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) where security measures are required by law. |
| Billing and account administration | Processing subscriptions and payments through our payment processor; invoicing; tax and accounting records; fraud prevention in payments; handling refunds under our Refund Policy. | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax/accounting records. |
| Communicate with you | Service, security, and transactional notices (which you cannot opt out of while you hold an Account); responses to support requests; product and marketing communications only with the consent required by applicable law (including CASL), always with a working unsubscribe mechanism. | Performance of a contract (Art. 6(1)(b)) for service notices; consent (Art. 6(1)(a)) or legitimate interests (Art. 6(1)(f)) for marketing, as applicable law permits. |
| Comply with law | Responding to valid legal process consistent with our Law Enforcement Guidelines; meeting record-keeping, tax, sanctions, and reporting obligations; establishing, exercising, or defending legal claims. | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) for legal claims. |
| Improve the Service | Debugging; capacity planning; understanding feature usage in aggregated or de-identified form that no longer identifies you. We do not use the content of your messages for these purposes — we cannot read it. | Legitimate interests (Art. 6(1)(f)). |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms, particularly given the privacy-protective design of the Service; you may request further information about this balancing, and you may object as described in Section 11. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. We do not use personal data for purposes incompatible with those listed above without notifying you and, where required, obtaining your consent.
6. What Encryption Means for Your Data
6.1 Content versus metadata
End-to-end encryption protects the content of messages — bodies, attachments, and the keys that protect them. It cannot, for any provider, protect the transport metadata that mail systems require to function: sender and recipient addresses, timestamps, message sizes, and routing information (Section 4.5). We limit our processing of that metadata to delivery, security, anti-abuse, billing-relevant measurement (such as storage used), and troubleshooting. Messages exchanged with external providers that do not support end-to-end encryption necessarily transit in the form those providers support; our security-enforcement features (such as requiring E2E for outbound mail and disallowing plaintext fallback) let you restrict this at your option.
6.2 Consequences for recovery
- We cannot reset or recover your passphrase or private keys. Encrypted key backups can be unlocked only by you.
- If you lose all of your credentials and recovery methods, your encrypted data is permanently unrecoverable, by design. We are not able to make exceptions, no matter the circumstances, because the capability to do so does not exist in our systems.
6.3 Consequences for requests about your data
- When you exercise an access or portability right (Section 11), we can provide the personal data we hold in intelligible form — account, billing, usage, and metadata records. E2E-encrypted content can only be provided as the ciphertext we store, or accessed by you directly through your own Account and keys.
- When we receive legal demands, we can only ever disclose what we actually possess in intelligible form. We cannot decrypt E2E-encrypted content for anyone — including governments, courts, or law enforcement — because we do not have the keys. See Section 7.2 and our Law Enforcement Guidelines.
- Deletion of encrypted content may be effected in whole or in part by cryptographic erasure (destruction of the relevant encryption keys), which renders the ciphertext permanently unreadable.
Legal notice: statements in this Policy that we “cannot” access, decrypt, recover, or produce E2E-encrypted content are statements about the technical architecture of the Service. They are not a promise to resist valid legal process; they mean that compliance with such process can never yield decrypted content, because we do not possess the means to decrypt it.
7. How We Disclose & Share Personal Data
We do not disclose personal data except as described in this Section.
7.1 Sub-processors and service providers
We use a limited number of vetted third-party providers (for example, infrastructure hosting, payment processing, and support tooling) to operate the Service. They may process personal data only on our documented instructions, under contracts imposing confidentiality, security, and data-protection obligations consistent with this Policy and, where applicable, the DPA. The current list is published on our Subprocessors page, which we update when providers change.
7.2 Legal process and law enforcement
We may disclose personal data where we believe in good faith that disclosure is required by applicable law or valid legal process (such as a Canadian court order or a lawful order binding on us), or is necessary to protect the rights, property, or safety of Inovamail, our users, or the public, or to detect, prevent, or address fraud, security, or technical issues. Our practices for handling government and law-enforcement requests — including our requirement of valid legal process, our policy of narrow interpretation, and, where lawful, notice to affected users — are set out in our Law Enforcement Guidelines. Because of the zero-knowledge design, any disclosure is limited to data we hold in intelligible form (such as the categories in Sections 4.1–4.5); we cannot produce decrypted E2E content (Section 6.3).
7.3 Organization administrators
If your Account exists under an Organization, the Organization’s administrators can access and manage your Account within the Service — including your account profile and address information, membership, roles, settings, and certain usage and message metadata visible in administrative tooling — and may be able to suspend, modify, or delete your Account. The Organization, not Inovamail, is the controller of that administration. If you use an Organization-provided Account, direct privacy questions about the Organization’s practices to the Organization.
7.4 Business transfers
If Inovamail is involved in a merger, acquisition, financing, reorganization, insolvency proceeding, or sale of all or part of its business or assets, personal data may be disclosed to and transferred as part of that transaction, subject to confidentiality obligations and to the successor’s commitment to honour protections materially consistent with this Policy. We will notify you (for example, by email or in-Service notice) of any such transaction that changes the controller of your personal data.
7.5 Aggregated and de-identified data
We may create and use aggregated or de-identified data that can no longer reasonably be linked to you (for example, overall usage statistics). We commit to maintaining such data in de-identified form and not attempting to re-identify it, except as permitted by law to test the effectiveness of de-identification.
7.6 We do not sell or “share” personal data
No sale, no ad-sharing. We do not sell personal data, and we do not “share” personal data for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”), and we have not done so in the preceding 12 months. We do not engage in cross-context behavioural advertising, do not permit third-party advertising trackers in the Service, and do not process personal data for targeted advertising as defined in comparable US state privacy laws.
8. International Data Transfers
We store and process Service data in [HOSTING LOCATIONS]. Because our sub-processors and our users are located in multiple countries, personal data may be transferred to, and processed in, countries other than your own, which may have different data-protection laws.
Where we transfer personal data internationally, we use lawful transfer mechanisms and appropriate safeguards, including:
- Adequacy decisions. The European Commission has recognized Canada’s PIPEDA as providing adequate protection for personal data transferred to commercial organizations subject to it, and the UK recognizes Canada as adequate on a corresponding basis; we rely on these adequacy findings where they apply.
- Standard Contractual Clauses. For transfers from the EEA not covered by an adequacy decision, we use the European Commission’s Standard Contractual Clauses (“SCCs”), supplemented where appropriate by additional technical and organizational measures.
- UK transfers. For transfers from the UK, we use the UK International Data Transfer Agreement or the UK Addendum to the SCCs, as applicable.
- Quebec and other assessments. Where required (including under Quebec Law 25 for communications of personal information outside Quebec), we conduct transfer or privacy impact assessments before transferring personal data.
You may request a summary of, or a copy of the relevant portions of, our transfer safeguards by contacting [PRIVACY EMAIL] (commercially sensitive terms may be redacted). Note that E2E-encrypted content remains encrypted wherever it is stored — the zero-knowledge protections in Section 2 do not vary by storage location.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in Section 5, and we determine retention periods using these criteria:
- whether the data is needed to provide your Account and the Service (most data is kept for the life of the Account);
- legal, tax, and accounting obligations that require minimum retention (for example, billing and transaction records);
- security and anti-abuse needs (logs and abuse signals are kept for limited periods proportionate to their purpose);
- the need to establish, exercise, or defend legal claims, or to comply with a litigation hold or preservation order (a “legal hold”); and
- whether the data has been aggregated or de-identified (in which case it is no longer personal data).
9.1 Account closure and deletion
When you close your Account (or an Organization deletes a Member Account), we delete or de-identify the personal data associated with it within a reasonable period, except data we must retain under the criteria above. Deletion of encrypted content may be effected by cryptographic erasure (Section 6.3). Copies of messages you have sent to other people reside in the recipients’ mailboxes and systems and are outside our control.
9.2 Backups
Deleted data may persist for a limited additional period in encrypted backups maintained for disaster recovery, until those backups are rotated or expire in the ordinary course. Backup copies are protected by the same or equivalent safeguards and are not used to restore data you have deleted, except where restoration of an entire system is necessary and residual data is then re-deleted.
9.3 Legal holds
Where we are subject to a legal hold or a lawful preservation demand, we retain the specified data for the duration required, notwithstanding a deletion request, and delete it when the hold ends.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against loss, theft, and unauthorized access, use, disclosure, alteration, and destruction, appropriate to the sensitivity of the data. These include:
- Encryption. End-to-end and zero-knowledge encryption of message content and account keys; encryption of data in transit; encryption of stored data.
- Access controls. Least-privilege, role-based access for personnel; authentication controls including two-factor authentication; logging and monitoring of administrative access.
- Account security features. Two-factor authentication with recovery codes, key verification, app passwords/API keys for protocol access, strong-passphrase enforcement, password-protected messages, and the security-enforcement and Fortress-mode features described in the Service.
- Organizational measures. Personnel confidentiality obligations, security review of sub-processors, and documented incident-response procedures.
No system is perfectly secure, and we cannot guarantee absolute security; you are responsible for maintaining the confidentiality of your credentials and recovery methods (Section 2). We ask security researchers to report vulnerabilities through our Security & Vulnerability Disclosure page.
10.1 Breach notification
If a breach of security safeguards involving personal data occurs, we will act in accordance with applicable law, including: notifying the Office of the Privacy Commissioner of Canada and affected individuals of any breach creating a real risk of significant harm, and maintaining required breach records, under PIPEDA; notifying the Commission d’accès à l’information du Québec and affected persons of confidentiality incidents presenting a risk of serious injury, and recording incidents in our incident register, under Quebec Law 25; and notifying the competent supervisory authority without undue delay (and, where feasible, within 72 hours) and affected data subjects where required, under the GDPR / UK GDPR. Where we act as a processor, we will notify the affected Organization as provided in the DPA.
11. Your Rights & Choices
You have rights over your personal data. Which rights apply depends on where you live, but we extend the core rights below — access, correction, and deletion — to all users regardless of location. Where Inovamail is a processor for an Organization, we will refer your request to the Organization (the controller) and assist it as required; if you are a Member, you may also raise requests with your Organization administrator directly.
11.1 If you are in Canada (PIPEDA and provincial laws)
- Access — request access to the personal information we hold about you and information about how it has been used and disclosed.
- Correction — challenge the accuracy and completeness of your information and have it amended as appropriate.
- Withdraw consent — withdraw consent to collection, use, or disclosure at any time, subject to legal or contractual restrictions and reasonable notice; withdrawal may mean we can no longer provide some or all of the Service.
- Quebec (Law 25) — if you are in Quebec, you additionally have rights to rectification, to cessation of dissemination or de-indexing in certain circumstances, to receive computerized personal information you provided to us in a structured, commonly used technological format (data portability), and to be informed of and have observations heard regarding certain automated decisions (Section 14).
- Complain — challenge our compliance with our Privacy Officer (Section 3), and complain to the Office of the Privacy Commissioner of Canada (OPC) or, in Quebec, the Commission d’accès à l’information du Québec (CAI) (Section 17).
11.2 If you are in the EEA or the UK (GDPR / UK GDPR)
- Access (Art. 15) — obtain confirmation of processing and a copy of your personal data;
- Rectification (Art. 16) — have inaccurate data corrected and incomplete data completed;
- Erasure (Art. 17) — have your data deleted in the circumstances the law provides;
- Restriction (Art. 18) — restrict processing in certain circumstances;
- Portability (Art. 20) — receive data you provided to us in a structured, commonly used, machine-readable format and transmit it to another controller;
- Objection (Art. 21) — object to processing based on legitimate interests, and object at any time to direct marketing (which we will always honour);
- Withdraw consent (Art. 7(3)) — at any time, without affecting prior processing; and
- Complain — lodge a complaint with your local data protection authority in the EEA or with the UK Information Commissioner’s Office (ICO) (Section 17).
Please note the effect of encryption on access and portability requests described in Section 6.3: we can only provide E2E-encrypted content as ciphertext, though you can export your own data through your Account.
11.3 If you are in the United States (CCPA/CPRA and comparable state laws)
- Right to know / access — the categories and specific pieces of personal information we collect, the purposes, and the categories of recipients (this Policy, especially Sections 4, 5, and 7, serves as our notice at collection);
- Right to delete — subject to statutory exceptions;
- Right to correct — inaccurate personal information;
- Right to opt out of sale or sharing — we do not sell or share personal information (Section 7.6), so there is nothing to opt out of; if that ever changed, we would provide the required notices and opt-out mechanisms first;
- Right to limit use of sensitive personal information — we use any sensitive personal information (such as log-in credentials) only for the purposes permitted without a right to limit (for example, providing the Service and maintaining security);
- Non-discrimination — we will not discriminate against you for exercising your rights;
- Authorized agents — you may use an authorized agent to submit requests; we may require proof of the agent’s authority and verification of your identity; and
- Appeal — if we decline a request and your state provides an appeal right, you may appeal by replying to our decision or writing to [PRIVACY EMAIL] with the subject “Privacy Appeal”; if your appeal is denied, you may contact your state Attorney General.
11.4 How to exercise your rights
- Self-service. Much of your data can be accessed, corrected, exported, or deleted directly in your Account settings, which is usually the fastest route.
- By request. Email [PRIVACY EMAIL] (or our DPO, [DPO NAME/CONTACT]) describing the right you wish to exercise and the jurisdiction you are in.
- Identity verification. To protect your data — especially given the sensitivity of an email account — we must verify that a request comes from the account holder (or a verified authorized agent). We will typically verify through your authenticated Account or your registered email address, and may request additional information proportionate to the sensitivity of the request. We cannot fulfil requests we cannot verify, and verification data is used only for that purpose. Because we cannot decrypt E2E content, we also cannot use content to verify identity.
- Timelines. We respond without undue delay and within the period required by applicable law: generally 30 days under PIPEDA and Quebec Law 25, one month under the GDPR / UK GDPR (extendable by two further months for complex or numerous requests, with notice), and 45 days under the CCPA/CPRA and comparable state laws (extendable by a further 45 days with notice). Where the law permits, we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests, or decline them with an explanation.
12. Cookies, Analytics & Tracking
We use cookies and similar local-storage technologies sparingly and in a privacy-first way. Details — including each cookie’s purpose and duration and how to manage them — are in our Cookie Policy. In summary:
- We use strictly necessary cookies and local storage for sign-in, session security, and remembering your preferences.
- We do not use third-party advertising cookies, cross-site trackers, or social-media pixels in the Service.
- Any analytics we use are minimal, configured to limit personal data, and described in the Cookie Policy; where consent is required for non-essential cookies, we obtain it.
- The Service is designed to protect you from tracking by others, too: external images in messages are blocked by default (defeating common tracking pixels), and our security-enforcement features reduce metadata leakage.
13. Children’s Privacy
The Service is not directed to children and may not be used by anyone under the minimum age set out in the eligibility section (Section 2) of our Terms of Service. We do not knowingly collect personal data from anyone under that age. If you believe a child under the applicable minimum age has created an Account or that we have collected such a child’s personal data, contact us at [PRIVACY EMAIL] and we will take prompt steps to delete the data and close the Account.
14. Automated Decision-Making & Profiling
We do not use your personal data to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR / UK GDPR, and we do not build behavioural or advertising profiles of you.
Anti-abuse systems. Like all email providers, we use automated systems to protect the Service: spam and abuse filtering, anomaly and fraud detection, rate limiting (including on the Outreach Tools), and Fortress-mode quarantining and sender challenges. These systems operate on metadata, technical signals, and sending behaviour — not on the content of E2E-encrypted messages, which we cannot read. Automated signals may result in a message being quarantined or refused, a sending limit being applied, or an Account being flagged or temporarily restricted pending review. Significant account actions (such as suspension or termination for abuse) involve human review, and you may contest any automated outcome and obtain human review by contacting [SUPPORT EMAIL] or, for abuse-related decisions, [ABUSE EMAIL]. If you are in Quebec, this section also serves as the notice of automated processing contemplated by Law 25, and you may submit observations to the person in charge identified in Section 3.
15. Third-Party Links & Integrations
The Service and our website may contain links to third-party websites, and the Service allows you to connect third-party applications and services through integrations, automated workflows, custom domains, and IMAP/SMTP clients. When you enable an integration or connect a third-party client, you direct us to exchange data with that third party, and the third party’s own terms and privacy policy — not this Policy — govern its handling of your data. Data you send to a third party (including message content decrypted on your device or delivered to an external mail service) leaves our zero-knowledge environment. We are not responsible for the privacy practices of third parties; review their policies before connecting them, and disconnect integrations you no longer use in your Account settings.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in the Service, law, or our practices. When we do, we will post the updated Policy at this page and revise the “Last updated” date and Version above. For material changes, we will give you reasonable advance notice — such as by email to your Account address or a prominent in-Service notice — before the changes take effect, and where applicable law requires consent for a new purpose of processing, we will obtain it. The archived prior version is available on request. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy, except where the law requires more; if you do not agree, you must stop using the Service and may close your Account.
17. How to Contact Us & How to Complain
Questions, concerns, requests, and complaints about privacy should be directed first to us — most issues are resolved fastest this way:
- Privacy team: [PRIVACY EMAIL]
- Privacy Officer / DPO: [DPO NAME/CONTACT]
- Post: [LEGAL ENTITY NAME], [NOTICE ADDRESS]
If you are not satisfied with our response, you have the right to complain to a supervisory authority:
- Canada: the Office of the Privacy Commissioner of Canada (OPC) — www.priv.gc.ca;
- Quebec: the Commission d’accès à l’information du Québec (CAI) — www.cai.gouv.qc.ca;
- EEA: the data protection authority of your habitual residence, place of work, or the place of the alleged infringement (a directory is maintained by the European Data Protection Board at edpb.europa.eu); you may also contact our EU representative, [EU REPRESENTATIVE];
- UK: the Information Commissioner’s Office (ICO) — ico.org.uk; you may also contact our UK representative, [UK REPRESENTATIVE];
- US: your state Attorney General, including for appeals under state privacy laws (Section 11.3).