Mailumi

Privacy notice

Who we are

Mailumi is operated by Scadex, trading as Mailumi, a sole proprietorship (eenmanszaak), Stalpaert van der Wielestraat 12, 5344 VR Oss, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 42065103, VAT number NL005468347B34. We are responsible for the personal data described in this notice. Questions about privacy go to privacy@mailumi.com.

What we collect

  • Account details: your email address, a hashed password, your workspace name and your settings.
  • Domains and keys: the domains you add, their DNS records and verification status, and your API keys, which we store only as hashes.
  • Email you send and receive: sender and recipient addresses, subjects, content, attachments, delivery events and webhook attempts.
  • Billing: your plan, Stripe customer and subscription references, and invoices. Card details are entered on Stripe and never reach our servers.
  • Enquiries: what you send us through the contact form or by email.
  • Live chat: when you talk to Mailumi Support, your name, email address, messages and images, the page you started the chat on, your time zone and language and, if you are signed in, your account and workspace. Questions you ask the chat assistant are not stored, unless you then start a chat with a person: they are added to that chat so you do not have to repeat yourself.
  • Security data: the IP address and browser of each sign-in, used to protect accounts and limit abuse.

Why we use it

  • To provide the service you signed up for: your account, sending and receiving email, domains, billing and support (performance of a contract).
  • To keep Mailumi secure and prevent spam and fraud (legitimate interests).
  • To keep billing and tax records (legal obligation).
  • To send you service emails such as address confirmation, password resets, invoices and important changes. We do not send marketing email without your consent.

Email content you process with Mailumi

For the email you send and receive through Mailumi, you decide what is processed and why: you are the controller and we act as your processor, processing that data only to provide the service. The details are in our Data Processing Agreement, which is part of the terms.

Who processes data for us

  • Cloudflare: hosting, and the database and file storage, which are restricted to the European Union.
  • Amazon Web Services (EU, Ireland region): sending and receiving email.
  • Fly.io (Amsterdam): the SMTP server, which passes email sent over SMTP to Mailumi without storing it.
  • Stripe: payments, subscriptions and invoices.
  • Google Public DNS: looking up the public DNS records of the domains you add. Only the domain names are sent.
  • Cloudflare Workers AI: answering the questions you ask the chat assistant.
  • Telegram (Telegram FZ-LLC): Mailumi Support reads and answers live chats in a private Telegram group. Your name, email address, the page you were on, your messages and images and, if you are signed in, your account details pass through Telegram, which may process them outside the European Economic Area.
  • Where a provider processes data outside the European Economic Area, the transfer is protected by the European Commission’s Standard Contractual Clauses or an adequacy decision. Telegram is not covered by these safeguards; live chat messages reach it only because you ask us to answer you in the chat. If you prefer, email support@mailumi.com instead.

How long we keep it

  • Email content and attachments are deleted 30 days after the email is sent or received. Delivery metadata and usage totals are kept while your account exists.
  • Account data is deleted when you close your account, except billing records, which we keep for as long as tax law requires.
  • Live chats and their images are deleted 30 days after the last message, together with the chat’s Telegram topic.
  • The IP address and browser saved with a sign-in are deleted when that session ends, at most 90 days later.

Cookies

  • Mailumi uses one strictly necessary cookie to keep you signed in. We do not use advertising or analytics cookies.
  • When you use the live chat, your browser’s storage keeps your chat and the name and email address you entered, so you can pick up where you left off. Nothing is stored before you open the chat, and clearing your browser data removes it.

Security

Connections use HTTPS. Passwords are hashed with scrypt, API keys and session tokens are stored only as hashes, and access to production systems is restricted.

Your rights

You can ask to access, correct, delete or export your personal data, and object to or restrict how we use it, by writing to privacy@mailumi.com. You can also complain to your local data protection authority.

Changes

If we change this notice in a way that matters, we will tell you by email or in the dashboard before the change takes effect.