Privacy Policy
Last updated:
This policy explains how [OPERATOR NAME, ADDRESS, ID] (“we”) processes personal data as a controller when you visit our website or use your Frontmail account. When we process the content of emails you send through Frontmail, we act as your processor under the Data Processing Agreement.
1. Data we process
| Category | Examples | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Account data | name, email, password hash, organisation, role, language | providing the account and the Service | contract (Art. 6(1)(b)) |
| Security data | IP address, device and session information, MFA settings, audit log | securing accounts, preventing abuse | legitimate interest (Art. 6(1)(f)) |
| Billing data | billing address, VAT ID, invoices, payment status (card data is handled by Stripe) | billing and tax obligations | contract, legal obligation (Art. 6(1)(b), (c)) |
| Usage data | API requests, message metadata, credit consumption | operating the Service, usage dashboards, support | contract, legitimate interest |
| Communication | support messages, product and billing notifications | support, service communication | contract, legitimate interest |
| Marketing (optional) | email address, consent timestamp | newsletters and product news | consent (Art. 6(1)(a)) |
| Website analytics (optional) | aggregated page views | improving the website | consent (Art. 6(1)(a)) |
2. Recipients and sub-processors
We use carefully selected providers: Amazon Web Services (hosting, email for system notifications; EU region eu-central-1), Stripe (payments), Cloudflare (DNS, bot protection), Google Cloud (usage analytics; [REGION TO CONFIRM]) and [ANALYTICS PROVIDER, if enabled]. A current list is kept in the DPA. Some providers may process data outside the EEA on the basis of Standard Contractual Clauses or an adequacy decision.
3. Retention
- Account data: for the life of the account, then deleted within 30 days of closure (backups roll off within [35] days).
- Message history: according to your plan (7–180 days).
- Invoices and accounting records: as required by tax law ([10 years in the Czech Republic – confirm]).
- Security logs: up to [90] days.
4. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time. You can export or delete your data from the dashboard or write to privacy@frontmail.dev. You may lodge a complaint with a supervisory authority – in the Czech Republic the Office for Personal Data Protection (ÚOOÚ).
5. Security
We encrypt data in transit and at rest; provider credentials are protected with envelope encryption (AWS KMS). Access is limited to staff who need it.
6. Cookies
See our Cookie Policy.
7. Changes
We will announce material changes on this page and, where appropriate, by email.
8. Contact
Data protection contact: privacy@frontmail.dev. [Data protection officer, if appointed.]