Privacy Policy
Last updated:
This policy explains what personal data Email Marketing handles and why. The important distinction: for your own account we are the controller, and for the contact lists you upload we are only the processor, you decide what happens to that data.
1. Two different roles
Under the GDPR we act in two capacities, and it matters which one applies:
- Controller: for the personal data of our own customers, the account you create, your billing details, your support messages and how you use the product. We decide why and how that data is processed, and this policy governs it.
- Processor: for the contact data you upload into your workspace. You decide who is on your list and what you send them; we only process it to provide the Service, on your documented instructions. Your own privacy notice governs that relationship with your recipients.
2. Data we collect as controller
| Category | Examples | Why |
|---|---|---|
| Account | Name, email address, workspace name, role | To create and secure your account and workspace |
| Authentication | Session identifiers, sign-in timestamps | To keep you signed in and detect suspicious access |
| Billing | Plan, invoices, company and tax details | To take payment and meet accounting obligations |
| Usage | Campaigns sent, feature use, audit log entries | To operate the Service, enforce limits and investigate abuse |
| Support | Messages you send us and our replies | To answer you and improve the product |
| Technical | A salted hash of your IP address, browser user agent | Security and abuse prevention. We do not store raw IP addresses from the contact form |
3. Data we process on your behalf
When you import contacts or send a campaign, we process the personal data of your recipients strictly to deliver the Service:
- Contact details you upload: email address, name, company and any custom fields you define.
- Consent records: status, timestamp and source, so you can demonstrate a lawful basis.
- Delivery events: whether a message was sent, delivered, opened, clicked, bounced, marked as spam or unsubscribed.
- Suppression records: addresses that must never be mailed again from your workspace.
We do not sell this data, do not use it to build profiles for our own purposes, and do not use it to train AI models. When you use AI campaign generation, only the brief you write is sent to our AI subprocessor, never your contact list.
4. Legal bases
- Contract: to provide the Service you have signed up for, account management, sending, reporting and support.
- Legitimate interests: securing the Service, preventing abuse and spam, and improving the product, balanced against your rights.
- Legal obligation: accounting, tax and responding to lawful requests.
- Consent: where we ask for it explicitly, such as optional product emails. You can withdraw it at any time.
5. How long we keep data
- Account data: for as long as your account is open, then up to 12 months after closure so you can reactivate, unless you ask us to erase it sooner.
- Contact data: until you delete it. You control this: deletion and anonymization are available in the product at any time.
- Raw delivery events: retained according to your workspace’s retention setting (400 days by default, configurable), then purged automatically. Aggregated statistics are kept so historical reporting survives.
- Suppression records: kept indefinitely by design. Deleting the record that someone unsubscribed would risk mailing them again.
- Billing records: for the period required by tax law.
- Contact form messages: up to 24 months.
6. Subprocessors
We use the following processors to run the Service. Each is bound by a data processing agreement, and we remain responsible to you for their handling of the data.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | PostgreSQL database, file storage, queues | EU (project region) |
| Clerk | Authentication, organizations and session management | EU / US |
| Amazon Web Services (SES) | Outbound email delivery and delivery event notifications | United States (us-east-1) |
| OpenAI | AI campaign copy generation (only the brief you submit) | US |
| AWS Amplify | Application hosting and CDN | United States / global edge |
We give notice before adding a subprocessor that processes customer data, so you have the opportunity to object. Email contact@eviasoft.cloud to be notified of changes or to request our data processing agreement.
7. International transfers
Your contacts, campaigns and delivery history are stored in the European Union. Two parts of the service process data outside the European Economic Area: email delivery (Amazon SES, United States) and AI campaign generation (OpenAI, United States, and only the brief you write, never your contact list).
Those transfers rely on Standard Contractual Clauses together with supplementary technical measures, including encryption in transit and at rest. The subprocessor table above states the region for each provider.
8. Security
- Data is encrypted in transit (TLS) and at rest.
- Every workspace is isolated at the database level by row-level security, so one customer’s queries cannot reach another’s data even if application code is at fault.
- Access is role-based, and privileged actions are recorded in an audit log.
- Credentials and API keys are never exposed to the browser.
- We will notify you without undue delay, and within 72 hours where the GDPR requires it, if a breach affects your data.
9. Your rights
If we are the controller of your data, you have the right to access it, correct it, erase it, restrict or object to processing, and receive it in a portable format. To exercise any of these, email contact@eviasoft.cloud. We respond within one month.
The product implements several of these directly: you can export every contact with its consent trail as CSV, and anonymize a contact so their personal data is removed while aggregate history stays valid.
10. US state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you may have additional rights over the account data for which we are the controller (see Data we collect as controller above). Depending on your state, these can include the right to:
- Know what personal data we hold about you and request a copy of it.
- Correct inaccurate personal data.
- Delete your personal data, subject to legal retention requirements.
- Opt out of the sale or “sharing” of personal data and of targeted advertising. We do not sell personal data and do not use it for cross-context behavioural advertising, so there is nothing to opt out of today.
- Not be discriminated against for exercising these rights.
To exercise any of these rights, email contact@eviasoft.cloud. We will verify your request using the information tied to your account before acting on it, and will not charge a fee unless the request is manifestly excessive.
11. If you received an email sent through us
We are the processor, not the controller, of that data: the sender decides who is on their list. The fastest way to stop receiving messages is the unsubscribe link in the email, which takes effect immediately and adds you to a permanent suppression list for that sender.
For access or erasure you should contact the sender directly, as they control the data. If you cannot identify or reach them, write to contact@eviasoft.cloud and we will forward your request and assist the sender in responding.
12. Children
The Service is not intended for children. We do not knowingly collect data from anyone under 16, and we delete such data if we become aware of it.
13. Changes
We update this policy as the Service changes. Material changes are announced by email or in the dashboard before they take effect, and the “last updated” date above always reflects the current version.
14. Contact and complaints
Controller: EVIA SOFTWARE SRL, Str. Decebal 5A, Bl. S10, Sc. A, Et. 3, Ap. 12, 240265 Râmnicu Vâlcea, Vâlcea, Romania. Data protection contact: contact@eviasoft.cloud (contact@eviasoft.cloud).
If you are unhappy with our response you may complain to your local supervisory authority, or to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro where we are established.
