This Privacy Policy explains how Lettermint B.V. (“Lettermint”, “we”, “us”, or “our”) collects and processes personal data when you visit our website, create or use a Lettermint account, communicate with us, or otherwise interact with our business.
Lettermint B.V. is a private limited liability company incorporated under the laws of the Netherlands, registered with the Dutch Chamber of Commerce under number 99337711 and having its registered address at Willemsvaart 16 B, 8019 AB Zwolle, the Netherlands.
For privacy questions or requests, contact us at legal@lettermint.co.
1. Scope and our roles
This Privacy Policy applies to personal data for which Lettermint determines the purposes and means of processing. This includes personal data relating to our website, accounts, billing, sales, support, security, product analytics, compliance, and business relationships (“Business Relationship Data”).
When a customer uses Lettermint to send, receive, store, route, or otherwise process email, the customer normally determines the purposes and essential means of that processing. For that personal data, the customer acts as controller and Lettermint acts as processor, or as subprocessor where the customer itself acts as processor. This includes email content, attachments, sender and recipient identifiers, headers, routing information, delivery and engagement events, suppression data, and related technical metadata (“Email Data”).
Our processing of Email Data and other personal data on behalf of customers is governed by our Data Processing Agreement, not primarily by this Privacy Policy.
If you received an email sent through Lettermint and your request concerns the sender’s use of your personal data, you should normally contact the sender or the relevant Lettermint customer first. Section 13 explains this further.
2. Personal data we collect as controller
The personal data we collect depends on how you interact with us.
2.1 Account and identity information
We may collect:
- your name;
- business email address and other business contact details;
- account username or identifier;
- organisation, team, job title, and role information;
- authentication credentials and account-security settings;
- multi-factor authentication and login information;
- account preferences, language, and communication preferences; and
- information about invitations, memberships, permissions, and administrative actions within a Lettermint account.
2.2 Subscription, billing, and payment information
We may collect:
- billing name and address;
- company and tax information;
- subscription, plan, invoice, credit, and payment status;
- transaction references and payment history; and
- limited payment-method information made available to us by our payment provider, such as card brand, expiry information, and the final digits of a payment card.
Full payment-card numbers and card security codes are processed by Stripe. We do not store those full payment details ourselves.
2.3 Sales, support, and communication information
When you contact us, request information, submit a support request, participate in a call, or otherwise communicate with us, we may process:
- your contact details;
- the organisation you represent;
- the content and context of the communication;
- support history, troubleshooting information, and correspondence;
- feedback, survey responses, and product requests; and
- information needed to follow up on a commercial inquiry or manage our relationship with you.
Support communications may contain Email Data or other personal data that our customer controls. To the extent we process that information solely to provide the Services on the customer’s behalf, the Data Processing Agreement applies.
2.4 Technical, usage, and security information
When you visit our website or use the Lettermint application, we may collect:
- IP address;
- browser, operating system, and device characteristics;
- approximate country or region derived from your IP address;
- referring page or URL;
- dates and times of access;
- pages, screens, and product features used;
- session, authentication, and account activity;
- application and API activity;
- technical errors, diagnostic data, and performance information; and
- security, fraud-prevention, and abuse-related signals.
We do not use this information to build advertising profiles or sell behavioural advertising data.
2.5 Marketing preferences
We may process your email address, organisation, communication preferences, consent records, unsubscribe status, and information about relevant interactions with our communications.
2.6 Special categories of personal data
We do not intentionally request special categories of personal data, such as health information, political opinions, religious beliefs, biometric data, or information about racial or ethnic origin, for account administration, billing, sales, or marketing purposes.
Customer content and support communications may nevertheless contain special categories of personal data or personal data relating to criminal convictions and offences. Where Lettermint processes such data on behalf of a customer through the Services, the customer is responsible for ensuring that the processing is lawful and subject to appropriate safeguards, and Lettermint processes the data in accordance with the Data Processing Agreement. If you voluntarily include such information in a direct communication with Lettermint, we process it only where and for as long as necessary to handle the communication, protect legal rights, or comply with law. Please do not provide such information unless it is necessary.
3. Sources of personal data
We obtain personal data:
- directly from you when you create an account, use the Services, make a payment, contact us, or adjust your preferences;
- from your organisation, an account owner, administrator, or colleague when they create or manage an account, invite you, assign permissions, or provide your business contact details;
- automatically from your device, browser, account activity, and use of our website or application;
- from payment, authentication, security, and other service providers where necessary to provide and protect our Services; and
- from customers or other business contacts where they include you in a support, security, contractual, or administrative communication.
When we receive personal data indirectly, we use it only for purposes compatible with the context in which it was provided and as permitted by applicable law.
4. How and why we use personal data
We process Business Relationship Data for the following purposes and legal bases.
| Purpose | Personal data generally involved | Legal basis |
|---|---|---|
| Creating and administering accounts and providing the Services to an individual customer | Account, identity, subscription, usage, and support information | Performance of a contract or steps taken before entering into a contract |
| Managing users, permissions, and contacts of a business customer | Account, identity, role, authentication, and organisation information | Our legitimate interest in administering and providing the Services to business customers |
| Processing subscriptions, invoices, payments, credits, and refunds | Billing, payment, tax, transaction, and account information | Performance of a contract and compliance with legal obligations |
| Providing customer support and responding to inquiries | Contact, account, support, communication, and relevant technical information | Performance of a contract or our legitimate interest in providing effective support and managing customer relationships |
| Operating, maintaining, monitoring, and improving the Services | Technical, diagnostic, usage, feedback, and product information | Our legitimate interest in maintaining reliable Services, understanding product use, and improving functionality and user experience |
| Securing accounts and infrastructure and preventing fraud, spam, abuse, and other misuse | Account, authentication, IP, activity, security, technical, support, and abuse-related information | Our legitimate interest in protecting customers, recipients, our infrastructure, and the integrity and reputation of the Services; legal obligation where applicable |
| Communicating operational, contractual, security, or policy information | Account, contact, subscription, and communication information | Performance of a contract, legal obligation, or our legitimate interest in administering the relationship and keeping users informed |
| Sending marketing and promotional communications | Business contact details, preferences, consent, and communication history | Consent where required, or our legitimate interest in promoting relevant business services where permitted by applicable law |
| Managing opt-outs and communication preferences | Contact details, preferences, consent, and suppression records | Legal obligation and our legitimate interest in respecting and demonstrating communication choices |
| Meeting legal, regulatory, compliance, accounting, and tax requirements | Account, billing, payment, communication, security, and transaction information | Compliance with legal obligations and our legitimate interest in demonstrating compliance |
| Establishing, exercising, or defending legal rights and handling disputes | Information relevant to the claim, dispute, investigation, or request | Our legitimate interest in protecting and enforcing legal rights |
Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the rights and freedoms of the affected individuals. You may object to processing based on legitimate interests as described in Section 12.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that took place lawfully before withdrawal.
5. Information required to use the Services
Certain account, authentication, business contact, and billing information is required to create and administer an account, provide a paid subscription, process payment, secure the Services, or comply with legal obligations.
If you do not provide required information, we may be unable to create or maintain your account, process a transaction, provide the relevant Services, or respond to a request.
Information requested for optional surveys, product feedback, or non-essential marketing is voluntary.
6. Artificial intelligence-assisted processing
Lettermint uses artificial intelligence-assisted natural-language processing for limited internal purposes:
- triaging and drafting responses to support requests; and
- detecting, investigating, and handling suspected abuse of the Services.
We currently use Mistral AI for this processing. We minimise the information submitted and use a European processing region for this service.
Mistral AI is contractually restricted and configured so that personal data, prompts, and generated output submitted by Lettermint are not used for model training, fine-tuning, research, feedback-based improvement, advertising, or other independent purposes of Mistral AI.
AI-generated output is reviewed by authorised Lettermint personnel and is not, by itself, the sole basis for a permanent account suspension, termination, or another materially adverse action. We may apply temporary automated measures where reasonably necessary to contain an immediate security, abuse, legal, or deliverability risk, but those measures are subject to prompt human review.
We do not use this AI-assisted processing to make decisions about individuals that produce legal effects or similarly significantly affect them.
Where the processed information is Business Relationship Data, Lettermint acts as controller under this Privacy Policy. Where the information is Email Data or other customer-controlled personal data processed on behalf of a customer, the Data Processing Agreement applies and the AI provider acts as a subprocessor.
7. Cookies, analytics, and similar technologies
Our marketing website does not set cookies. We may collect limited website analytics in a cookieless manner without storing a cookie on your device.
Within the Lettermint application:
- Stripe may use cookies or similar technologies where necessary for secure payment processing and fraud prevention;
- PostHog may use cookies or comparable identifiers for product analytics; and
- our self-hosted error-monitoring tooling processes limited technical and diagnostic information to help us maintain application reliability.
Further details are available in our Cookie Policy.
Where applicable law requires consent for non-essential cookies or similar technologies, we will request that consent before using them.
8. How we share personal data
We do not sell personal data. We do not disclose personal data to advertisers for behavioural advertising.
We may share personal data with the following categories of recipients where necessary for the purposes described in this Privacy Policy:
8.1 Service providers
We use service providers for activities such as:
- payment processing and fraud prevention, including Stripe;
- product analytics, including PostHog;
- AI-assisted support and abuse handling, including Mistral AI;
- security and compliance management, including Vanta and Aikido;
- accounting and financial administration, including Exact, Denovit, and our accountant;
- internal collaboration and issue management, including Slack and Linear; and
- software development, version control, and deployment, including GitHub.
Providers may process only the personal data reasonably necessary for their role and are subject to contractual, confidentiality, security, and data-protection requirements as applicable.
Our current provider information is available on our Subprocessors page. That page distinguishes providers involved in delivering the Services from providers used for general business operations.
8.2 Professional advisers
We may disclose relevant information to lawyers, auditors, accountants, insurers, consultants, and other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations.
8.3 Authorities and legal recipients
We may disclose personal data where required by law, a court, or a competent authority, or where reasonably necessary to:
- comply with a binding legal request;
- protect the rights, safety, and security of Lettermint, our customers, recipients, or others;
- investigate fraud, abuse, security incidents, or unlawful activity; or
- establish, exercise, or defend legal claims.
8.4 Corporate transactions
If Lettermint is involved in a merger, acquisition, restructuring, financing, insolvency, or transfer of all or part of its business or assets, relevant personal data may be disclosed to prospective or actual parties and their advisers, subject to appropriate confidentiality and data-protection safeguards.
9. International data transfers
Lettermint is established in the Netherlands.
Email Data hosted, stored, routed, or processed as part of Lettermint’s core email-delivery infrastructure remains within the European Union (EU). In the ordinary course of providing the Services, emails are transmitted to recipient systems selected by the customer. Those recipient systems may be located outside the EU, including outside the European Economic Area (EEA). Such customer-directed delivery is distinct from Lettermint hosting or internally processing Email Data outside the EU.
Some providers used for billing, collaboration, development, and other business operations may process Business Relationship Data outside the EEA. Depending on the provider and destination, we rely on safeguards such as:
- an adequacy decision adopted by the European Commission;
- the European Commission’s Standard Contractual Clauses;
- supplementary contractual, organisational, or technical safeguards; or
- another valid transfer mechanism available under applicable data-protection law.
You may request further information about the safeguards relevant to your personal data by contacting legal@lettermint.co. We may redact commercially confidential or security-sensitive information from copies of contractual safeguards where permitted by law.
10. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including providing the Services, maintaining security and accountability, meeting legal obligations, and establishing or defending legal claims.
Different categories of data have different retention periods or criteria:
| Data category | Retention period or criteria |
|---|---|
| Account, profile, organisation, and subscription data | Retained while the account or business relationship is active. After termination, we retain only the information reasonably necessary to close the relationship, complete billing and administration, maintain security and accountability, comply with law, or handle disputes. Remaining information is deleted or anonymised when no longer needed. |
| Customer-controlled data after termination | Data that remains available through the Services may be retrieved for the period stated in the Terms and Conditions and is then deleted in accordance with the Data Processing Agreement, unless retention is legally required. |
| Data subject to confirmed account deletion | Where an authorised user confirms permanent account deletion after being informed of its consequences, we treat this as an instruction to delete the associated customer-controlled data rather than retain it for retrieval. Account and service data that is not required for billing, legal compliance, security, fraud prevention, or dispute handling is deleted from active systems without undue delay. |
| Application, delivery, technical, and security logs | Normally retained for no more than 14 days, unless selected records are required for an active security, abuse, deliverability, compliance, or legal investigation. Retention of customer-controlled Email Data and delivery data is additionally governed by the Data Processing Agreement and applicable product settings. |
| Backup copies | Residual copies are automatically overwritten or deleted within our documented rolling backup-retention cycle, which does not exceed 14 days. Backups are access-restricted and are not used for ordinary processing. If a backup is restored, applicable deletion instructions and retention rules are reapplied without undue delay. |
| Billing, invoice, accounting, and tax records | Retained for the applicable statutory accounting and tax-retention period. |
| Support and customer-success communications | Retained for as long as necessary to resolve and document the request, support the customer relationship, maintain security and service continuity, and address reasonably anticipated disputes or legal obligations. Records are deleted or anonymised when no longer needed. |
| Sales inquiries and prospective-customer communications | Retained while the inquiry or potential relationship remains active and for a limited follow-up period where a business relationship may reasonably develop. Data is then deleted or anonymised unless a longer period is required for legal or compliance purposes. |
| Marketing preferences and suppression records | Retained until consent is withdrawn or an objection is made. A minimal suppression record may be retained afterwards to ensure that the opt-out continues to be respected. |
| Security, abuse, incident, or legal evidence | Retained for as long as reasonably necessary to investigate and remediate the matter, demonstrate compliance, protect the Services, or establish, exercise, or defend legal claims. |
Where personal data is subject to a legal hold or mandatory retention obligation, we may retain it for the required period and restrict it from unrelated processing.
11. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration, or disclosure.
Our measures include, as appropriate, access controls, encryption, logging and monitoring, vulnerability management, secure development practices, incident response, backups, supplier management, and personnel confidentiality and training.
Further information about our security programme is available through our Trust Center.
No method of transmission or storage is completely risk-free. You are responsible for maintaining the security of your credentials, devices, integrations, and account configuration and for notifying us promptly if you suspect unauthorised account access.
12. Your privacy rights
Depending on applicable law and the circumstances, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- receive certain personal data in a structured, commonly used, and machine-readable format and transmit it to another controller;
- object to processing based on our legitimate interests;
- object at any time to processing for direct marketing;
- withdraw consent at any time where processing is based on consent; and
- receive information about, and where applicable challenge, solely automated decisions that produce legal effects or similarly significantly affect you.
These rights are not absolute. We may decline or limit a request where an exemption applies, where we are legally required to retain information, or where fulfilling the request would adversely affect the rights and freedoms of others.
To exercise your rights, contact legal@lettermint.co. Account users may also use available account and data-export functionality within the Services.
We may request information necessary to verify your identity and authority before fulfilling a request. We will respond within the period required by applicable law and will inform you if an extension is permitted and necessary.
Direct marketing
You may unsubscribe from marketing emails at any time by using the unsubscribe link in the message or by contacting us. Service, security, billing, and other non-promotional communications necessary to administer your account or relationship may continue.
13. Requests concerning emails sent by our customers
If you received an email sent through Lettermint, the sender or relevant Lettermint customer is normally the controller responsible for deciding why your personal data is processed and for responding to your request.
Requests concerning matters such as:
- why an email was sent to you;
- consent or another legal basis used by the sender;
- correction or deletion of an address in the sender’s systems;
- marketing preferences or unsubscribe requests; or
- the sender’s retention or use of your information
should normally be directed to the sender.
If you send such a request to Lettermint, we may ask for information necessary to identify the relevant customer or message and forward the request to that customer. We will assist our customer in accordance with the Data Processing Agreement where required.
This does not prevent you from contacting Lettermint directly about processing for which Lettermint itself acts as controller, such as our own account, website, billing, support, security, or marketing activities.
14. Children
The Lettermint account and administration Services are intended for businesses and professional users and are not directed at children.
We do not knowingly permit children to create or administer a business account. Customer emails and other customer content may nevertheless contain personal data relating to children. In those circumstances, the relevant customer acts as controller and is responsible for ensuring that the processing is lawful. Lettermint processes the data in accordance with the customer’s instructions and the Data Processing Agreement.
15. Complaints
Please contact us first at legal@lettermint.co so that we can investigate and address your concern.
You also have the right to lodge a complaint with a competent data-protection authority. Because Lettermint is established in the Netherlands, the Dutch supervisory authority is the Autoriteit Persoonsgegevens. You may also contact the supervisory authority in the EEA country where you live, work, or believe an infringement occurred.
Information about the Autoriteit Persoonsgegevens is available at autoriteitpersoonsgegevens.nl.
16. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, regulatory guidance, our Services, providers, or processing activities. We will update the revision date when changes are made.
Where a change materially affects the purposes of processing, categories of personal data, recipients, international transfers, retention practices, or the way individuals can exercise their rights, we will provide appropriate notice, for example by email or through an in-application notification. Minor editorial, formatting, or non-material corrections may be published without separate notice.
17. Contact
For questions, concerns, or privacy requests, contact:
Lettermint B.V.
Willemsvaart 16 B
8019 AB Zwolle
The Netherlands
Email: legal@lettermint.co