Privacy Policy

Last updated:

This policy explains what personal data Email Marketing handles and why. The important distinction: for your own account we are the controller, and for the contact lists you upload we are only the processor, you decide what happens to that data.

1. Two different roles

Under the GDPR we act in two capacities, and it matters which one applies:

  • Controller: for the personal data of our own customers, the account you create, your billing details, your support messages and how you use the product. We decide why and how that data is processed, and this policy governs it.
  • Processor: for the contact data you upload into your workspace. You decide who is on your list and what you send them; we only process it to provide the Service, on your documented instructions. Your own privacy notice governs that relationship with your recipients.

2. Data we collect as controller

CategoryExamplesWhy
AccountName, email address, workspace name, roleTo create and secure your account and workspace
AuthenticationSession identifiers, sign-in timestampsTo keep you signed in and detect suspicious access
BillingPlan, invoices, company and tax detailsTo take payment and meet accounting obligations
UsageCampaigns sent, feature use, audit log entriesTo operate the Service, enforce limits and investigate abuse
SupportMessages you send us and our repliesTo answer you and improve the product
TechnicalA salted hash of your IP address, browser user agentSecurity and abuse prevention. We do not store raw IP addresses from the contact form

3. Data we process on your behalf

When you import contacts or send a campaign, we process the personal data of your recipients strictly to deliver the Service:

  • Contact details you upload: email address, name, company and any custom fields you define.
  • Consent records: status, timestamp and source, so you can demonstrate a lawful basis.
  • Delivery events: whether a message was sent, delivered, opened, clicked, bounced, marked as spam or unsubscribed.
  • Suppression records: addresses that must never be mailed again from your workspace.

We do not sell this data, do not use it to build profiles for our own purposes, and do not use it to train AI models. When you use AI campaign generation, only the brief you write is sent to our AI subprocessor, never your contact list.

5. How long we keep data

  • Account data: for as long as your account is open, then up to 12 months after closure so you can reactivate, unless you ask us to erase it sooner.
  • Contact data: until you delete it. You control this: deletion and anonymization are available in the product at any time.
  • Raw delivery events: retained according to your workspace’s retention setting (400 days by default, configurable), then purged automatically. Aggregated statistics are kept so historical reporting survives.
  • Suppression records: kept indefinitely by design. Deleting the record that someone unsubscribed would risk mailing them again.
  • Billing records: for the period required by tax law.
  • Contact form messages: up to 24 months.

6. Subprocessors

We use the following processors to run the Service. Each is bound by a data processing agreement, and we remain responsible to you for their handling of the data.

ProviderPurposeLocation
SupabasePostgreSQL database, file storage, queuesEU (project region)
ClerkAuthentication, organizations and session managementEU / US
Amazon Web Services (SES)Outbound email delivery and delivery event notificationsUnited States (us-east-1)
OpenAIAI campaign copy generation (only the brief you submit)US
AWS AmplifyApplication hosting and CDNUnited States / global edge

We give notice before adding a subprocessor that processes customer data, so you have the opportunity to object. Email contact@eviasoft.cloud to be notified of changes or to request our data processing agreement.

7. International transfers

Your contacts, campaigns and delivery history are stored in the European Union. Two parts of the service process data outside the European Economic Area: email delivery (Amazon SES, United States) and AI campaign generation (OpenAI, United States, and only the brief you write, never your contact list).

Those transfers rely on Standard Contractual Clauses together with supplementary technical measures, including encryption in transit and at rest. The subprocessor table above states the region for each provider.

8. Security

  • Data is encrypted in transit (TLS) and at rest.
  • Every workspace is isolated at the database level by row-level security, so one customer’s queries cannot reach another’s data even if application code is at fault.
  • Access is role-based, and privileged actions are recorded in an audit log.
  • Credentials and API keys are never exposed to the browser.
  • We will notify you without undue delay, and within 72 hours where the GDPR requires it, if a breach affects your data.

9. Your rights

If we are the controller of your data, you have the right to access it, correct it, erase it, restrict or object to processing, and receive it in a portable format. To exercise any of these, email contact@eviasoft.cloud. We respond within one month.

The product implements several of these directly: you can export every contact with its consent trail as CSV, and anonymize a contact so their personal data is removed while aggregate history stays valid.

10. US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you may have additional rights over the account data for which we are the controller (see Data we collect as controller above). Depending on your state, these can include the right to:

  • Know what personal data we hold about you and request a copy of it.
  • Correct inaccurate personal data.
  • Delete your personal data, subject to legal retention requirements.
  • Opt out of the sale or “sharing” of personal data and of targeted advertising. We do not sell personal data and do not use it for cross-context behavioural advertising, so there is nothing to opt out of today.
  • Not be discriminated against for exercising these rights.

To exercise any of these rights, email contact@eviasoft.cloud. We will verify your request using the information tied to your account before acting on it, and will not charge a fee unless the request is manifestly excessive.

11. If you received an email sent through us

We are the processor, not the controller, of that data: the sender decides who is on their list. The fastest way to stop receiving messages is the unsubscribe link in the email, which takes effect immediately and adds you to a permanent suppression list for that sender.

For access or erasure you should contact the sender directly, as they control the data. If you cannot identify or reach them, write to contact@eviasoft.cloud and we will forward your request and assist the sender in responding.

12. Children

The Service is not intended for children. We do not knowingly collect data from anyone under 16, and we delete such data if we become aware of it.

13. Changes

We update this policy as the Service changes. Material changes are announced by email or in the dashboard before they take effect, and the “last updated” date above always reflects the current version.

14. Contact and complaints

Controller: EVIA SOFTWARE SRL, Str. Decebal 5A, Bl. S10, Sc. A, Et. 3, Ap. 12, 240265 Râmnicu Vâlcea, Vâlcea, Romania. Data protection contact: contact@eviasoft.cloud (contact@eviasoft.cloud).

If you are unhappy with our response you may complain to your local supervisory authority, or to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro where we are established.