emaia.eu

Last updated: 2026-07-23

Privacy Policy

This Privacy Policy explains how the free test version of emaia.eu processes personal data for its website, hosted mailboxes, inbound and outbound email, transactional email APIs, form submissions, administration, support, security, and privacy-friendly website analytics.

Contact: contact page

Controller and Contact

Boban Acimovic operates emaia.eu privately and is the controller for account, website, support, security, and service-administration processing. No company is presently the controller. For email and other content processed under a customer's instructions, the customer may be the controller and the operator may act as processor, depending on the use. This description of roles does not itself replace any Article 28 data processing agreement required by the GDPR. Business customers must not use the test service for processing that requires such an agreement until an appropriate agreement is available.

You can contact us through the contact page.

Personal Data We Process

Depending on use, we process names, email addresses, account and organization data, authentication and security data, roles, settings, domains and DNS results, mailbox and alias configuration, API and integration configuration, support requests, IP addresses, user agents, request and audit logs, and language or theme preferences. Email processing may include sender and recipient addresses, subjects, headers, message bodies, attachments, routing and delivery metadata, inbound raw messages, outbound queue data, bounces, spam and malware results, and retention settings.

Purposes and Legal Bases

We process data to register and authenticate users, provide and administer requested email services, route and deliver messages, store mail where configured, diagnose delivery, respond to support, secure systems, detect spam, malware and abuse, enforce limits, maintain auditability, improve usability and reliability, and meet legal obligations. Depending on the processing, the legal basis is performance of the free service agreement or pre-contract steps (Article 6(1)(b) GDPR), legitimate interests in secure and reliable operation and aggregate service measurement (Article 6(1)(f)), compliance with law (Article 6(1)(c)), or consent where specifically requested (Article 6(1)(a)).

Cookies and Local Storage

We use only storage needed for requested functions: the secure HttpOnly __Host-emaia-session cookie for login, the emaia-locale cookie and localStorage entry for language, emaia-theme in localStorage for appearance, and emaia-session in localStorage for the current account, organization, expiry, and CSRF-related session metadata. The language cookie lasts up to about 400 days; session storage follows the authenticated session, and localStorage remains until it is replaced, cleared on sign-out where applicable, or removed in the browser. These items can be cleared through browser controls, although login and preferences may then stop working.

We use the open-source Plausible Analytics tracker to understand aggregate website usage. Events are sent to our analytics endpoint at analytics.acim.net. Plausible analytics does not set analytics cookies or persistent identifiers, perform cross-site or cross-device tracking, build advertising profiles, or sell visitor data. It measures aggregate information such as visited pages, referral source, country, browser, operating system, and device type; IP address and user agent are processed transiently to count visits but are not stored as raw analytics values. The service does not inject open-tracking pixels into customer email, and version 1 of the transactional email API rejects provider tracking options. Email pixels and tracked links may engage ePrivacy and data-protection requirements; this product choice does not claim that every form of tracking is categorically unlawful. Customers remain responsible for the lawfulness of external resources or tracking included in their own message content, including required notices, consent or another legal basis. Because there are currently no optional analytics or advertising cookies, there is no separate cookie-settings panel. If optional storage or tracking is introduced, we will disclose it and request consent where required before activation.

Recipients and Subprocessors

Data is available only as needed to the operator and to infrastructure, hosting, network, DNS, email-delivery, security, backup, support, and other operational providers used to run the service. Messages are necessarily transmitted to sending and receiving mail systems selected by addresses and DNS. Plausible analytics events use the operator's configured analytics endpoint. We do not sell personal data or use customer mail content for advertising.

Retention

Retention depends on the feature, customer configuration, operational need, and test-stage limits. Account and configuration data is normally kept while the account is active; mailbox content remains while hosted and not deleted; queued, inbound, delivery, security, audit, and support data is kept only as needed for operation, troubleshooting, abuse prevention, configured retention, or legal obligations. After deletion or termination, residual copies may remain temporarily in logs and backups until their normal rotation. The test service gives no contractual retention or recovery guarantee, so keep independent copies of important data.

Your Rights

Subject to applicable conditions, you may request access, correction, deletion, restriction, portability, or information about your personal data, object to processing based on legitimate interests, and withdraw consent for future processing. You may also complain to a competent data-protection supervisory authority. When a customer controls message data, requests concerning that data may need to be directed to that customer.

Security

We use technical and organizational measures intended to protect confidentiality, integrity, and availability, including authenticated access, scoped authorization, CSRF protection, secure HttpOnly session cookies, TLS in transit where supported, network and database access controls, logging, filtering, updates, and operational safeguards. No system can guarantee absolute security, and a compromise remains possible. The current test environment does not provide application-managed or volume-level encryption at rest for all mailbox data, database data, queued message content, inbound raw messages, or backups. Do not use it for highly sensitive or special-category data without independently assessing the risk.

International Transfers

The service is intended to use European infrastructure where practicable, but email is routed according to recipient domains and may be delivered worldwide. Operational providers or recipients may therefore process data outside Germany or the European Economic Area. Where the operator selects a provider involving a restricted international transfer, appropriate safeguards required by law will be used. Customers remain responsible for transfer rules arising from their chosen recipients, integrations, and processing instructions.

Translations

Localized versions of this Privacy Policy may be automated or machine-assisted. If translated wording is unclear or conflicts with English, the English version controls unless applicable law requires otherwise.

Changes

We will update this notice when material processing, providers, storage, analytics, security measures, or legal requirements change. An authorized organization owner or administrator accepts a combined Terms and Privacy version for the organization. For ordinary material changes, publication and queueing of the notification email start a grace period of at least seven days before the new version takes effect. Urgent legal, security, or abuse-related changes may take effect immediately when reasonably necessary. The version shown applies from its stated effective date.