Legal

Privacy Policy

Last updated:

This Privacy Policy explains how Lettermint B.V. (“Lettermint”, “we”, “us”, or “our”) collects and processes personal data when you visit our website, create or use a Lettermint account, communicate with us, or otherwise interact with our business.

Lettermint B.V. is a private limited liability company incorporated under the laws of the Netherlands, registered with the Dutch Chamber of Commerce under number 99337711 and having its registered address at Willemsvaart 16 B, 8019 AB Zwolle, the Netherlands.

For privacy questions or requests, contact us at legal@lettermint.co.

1. Scope and our roles

This Privacy Policy applies to personal data for which Lettermint determines the purposes and means of processing. This includes personal data relating to our website, accounts, billing, sales, support, security, product analytics, compliance, and business relationships (“Business Relationship Data”).

When a customer uses Lettermint to send, receive, store, route, or otherwise process email, the customer normally determines the purposes and essential means of that processing. For that personal data, the customer acts as controller and Lettermint acts as processor, or as subprocessor where the customer itself acts as processor. This includes email content, attachments, sender and recipient identifiers, headers, routing information, delivery and engagement events, suppression data, and related technical metadata (“Email Data”).

Our processing of Email Data and other personal data on behalf of customers is governed by our Data Processing Agreement, not primarily by this Privacy Policy.

If you received an email sent through Lettermint and your request concerns the sender’s use of your personal data, you should normally contact the sender or the relevant Lettermint customer first. Section 13 explains this further.

2. Personal data we collect as controller

The personal data we collect depends on how you interact with us.

2.1 Account and identity information

We may collect:

  • your name;
  • business email address and other business contact details;
  • account username or identifier;
  • organisation, team, job title, and role information;
  • authentication credentials and account-security settings;
  • multi-factor authentication and login information;
  • account preferences, language, and communication preferences; and
  • information about invitations, memberships, permissions, and administrative actions within a Lettermint account.

2.2 Subscription, billing, and payment information

We may collect:

  • billing name and address;
  • company and tax information;
  • subscription, plan, invoice, credit, and payment status;
  • transaction references and payment history; and
  • limited payment-method information made available to us by our payment provider, such as card brand, expiry information, and the final digits of a payment card.

Full payment-card numbers and card security codes are processed by Stripe. We do not store those full payment details ourselves.

2.3 Sales, support, and communication information

When you contact us, request information, submit a support request, participate in a call, or otherwise communicate with us, we may process:

  • your contact details;
  • the organisation you represent;
  • the content and context of the communication;
  • support history, troubleshooting information, and correspondence;
  • feedback, survey responses, and product requests; and
  • information needed to follow up on a commercial inquiry or manage our relationship with you.

Support communications may contain Email Data or other personal data that our customer controls. To the extent we process that information solely to provide the Services on the customer’s behalf, the Data Processing Agreement applies.

2.4 Technical, usage, and security information

When you visit our website or use the Lettermint application, we may collect:

  • IP address;
  • browser, operating system, and device characteristics;
  • approximate country or region derived from your IP address;
  • referring page or URL;
  • dates and times of access;
  • pages, screens, and product features used;
  • session, authentication, and account activity;
  • application and API activity;
  • technical errors, diagnostic data, and performance information; and
  • security, fraud-prevention, and abuse-related signals.

We do not use this information to build advertising profiles or sell behavioural advertising data.

2.5 Marketing preferences

We may process your email address, organisation, communication preferences, consent records, unsubscribe status, and information about relevant interactions with our communications.

2.6 Special categories of personal data

We do not intentionally request special categories of personal data, such as health information, political opinions, religious beliefs, biometric data, or information about racial or ethnic origin, for account administration, billing, sales, or marketing purposes.

Customer content and support communications may nevertheless contain special categories of personal data or personal data relating to criminal convictions and offences. Where Lettermint processes such data on behalf of a customer through the Services, the customer is responsible for ensuring that the processing is lawful and subject to appropriate safeguards, and Lettermint processes the data in accordance with the Data Processing Agreement. If you voluntarily include such information in a direct communication with Lettermint, we process it only where and for as long as necessary to handle the communication, protect legal rights, or comply with law. Please do not provide such information unless it is necessary.

3. Sources of personal data

We obtain personal data:

  • directly from you when you create an account, use the Services, make a payment, contact us, or adjust your preferences;
  • from your organisation, an account owner, administrator, or colleague when they create or manage an account, invite you, assign permissions, or provide your business contact details;
  • automatically from your device, browser, account activity, and use of our website or application;
  • from payment, authentication, security, and other service providers where necessary to provide and protect our Services; and
  • from customers or other business contacts where they include you in a support, security, contractual, or administrative communication.

When we receive personal data indirectly, we use it only for purposes compatible with the context in which it was provided and as permitted by applicable law.

4. How and why we use personal data

We process Business Relationship Data for the following purposes and legal bases.

PurposePersonal data generally involvedLegal basis
Creating and administering accounts and providing the Services to an individual customerAccount, identity, subscription, usage, and support informationPerformance of a contract or steps taken before entering into a contract
Managing users, permissions, and contacts of a business customerAccount, identity, role, authentication, and organisation informationOur legitimate interest in administering and providing the Services to business customers
Processing subscriptions, invoices, payments, credits, and refundsBilling, payment, tax, transaction, and account informationPerformance of a contract and compliance with legal obligations
Providing customer support and responding to inquiriesContact, account, support, communication, and relevant technical informationPerformance of a contract or our legitimate interest in providing effective support and managing customer relationships
Operating, maintaining, monitoring, and improving the ServicesTechnical, diagnostic, usage, feedback, and product informationOur legitimate interest in maintaining reliable Services, understanding product use, and improving functionality and user experience
Securing accounts and infrastructure and preventing fraud, spam, abuse, and other misuseAccount, authentication, IP, activity, security, technical, support, and abuse-related informationOur legitimate interest in protecting customers, recipients, our infrastructure, and the integrity and reputation of the Services; legal obligation where applicable
Communicating operational, contractual, security, or policy informationAccount, contact, subscription, and communication informationPerformance of a contract, legal obligation, or our legitimate interest in administering the relationship and keeping users informed
Sending marketing and promotional communicationsBusiness contact details, preferences, consent, and communication historyConsent where required, or our legitimate interest in promoting relevant business services where permitted by applicable law
Managing opt-outs and communication preferencesContact details, preferences, consent, and suppression recordsLegal obligation and our legitimate interest in respecting and demonstrating communication choices
Meeting legal, regulatory, compliance, accounting, and tax requirementsAccount, billing, payment, communication, security, and transaction informationCompliance with legal obligations and our legitimate interest in demonstrating compliance
Establishing, exercising, or defending legal rights and handling disputesInformation relevant to the claim, dispute, investigation, or requestOur legitimate interest in protecting and enforcing legal rights

Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the rights and freedoms of the affected individuals. You may object to processing based on legitimate interests as described in Section 12.

Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that took place lawfully before withdrawal.

5. Information required to use the Services

Certain account, authentication, business contact, and billing information is required to create and administer an account, provide a paid subscription, process payment, secure the Services, or comply with legal obligations.

If you do not provide required information, we may be unable to create or maintain your account, process a transaction, provide the relevant Services, or respond to a request.

Information requested for optional surveys, product feedback, or non-essential marketing is voluntary.

6. Artificial intelligence-assisted processing

Lettermint uses artificial intelligence-assisted natural-language processing for limited internal purposes:

  • triaging and drafting responses to support requests; and
  • detecting, investigating, and handling suspected abuse of the Services.

We currently use Mistral AI for this processing. We minimise the information submitted and use a European processing region for this service.

Mistral AI is contractually restricted and configured so that personal data, prompts, and generated output submitted by Lettermint are not used for model training, fine-tuning, research, feedback-based improvement, advertising, or other independent purposes of Mistral AI.

AI-generated output is reviewed by authorised Lettermint personnel and is not, by itself, the sole basis for a permanent account suspension, termination, or another materially adverse action. We may apply temporary automated measures where reasonably necessary to contain an immediate security, abuse, legal, or deliverability risk, but those measures are subject to prompt human review.

We do not use this AI-assisted processing to make decisions about individuals that produce legal effects or similarly significantly affect them.

Where the processed information is Business Relationship Data, Lettermint acts as controller under this Privacy Policy. Where the information is Email Data or other customer-controlled personal data processed on behalf of a customer, the Data Processing Agreement applies and the AI provider acts as a subprocessor.

7. Cookies, analytics, and similar technologies

Our marketing website does not set cookies. We may collect limited website analytics in a cookieless manner without storing a cookie on your device.

Within the Lettermint application:

  • Stripe may use cookies or similar technologies where necessary for secure payment processing and fraud prevention;
  • PostHog may use cookies or comparable identifiers for product analytics; and
  • our self-hosted error-monitoring tooling processes limited technical and diagnostic information to help us maintain application reliability.

Further details are available in our Cookie Policy.

Where applicable law requires consent for non-essential cookies or similar technologies, we will request that consent before using them.

8. How we share personal data

We do not sell personal data. We do not disclose personal data to advertisers for behavioural advertising.

We may share personal data with the following categories of recipients where necessary for the purposes described in this Privacy Policy:

8.1 Service providers

We use service providers for activities such as:

  • payment processing and fraud prevention, including Stripe;
  • product analytics, including PostHog;
  • AI-assisted support and abuse handling, including Mistral AI;
  • security and compliance management, including Vanta and Aikido;
  • accounting and financial administration, including Exact, Denovit, and our accountant;
  • internal collaboration and issue management, including Slack and Linear; and
  • software development, version control, and deployment, including GitHub.

Providers may process only the personal data reasonably necessary for their role and are subject to contractual, confidentiality, security, and data-protection requirements as applicable.

Our current provider information is available on our Subprocessors page. That page distinguishes providers involved in delivering the Services from providers used for general business operations.

8.2 Professional advisers

We may disclose relevant information to lawyers, auditors, accountants, insurers, consultants, and other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations.

We may disclose personal data where required by law, a court, or a competent authority, or where reasonably necessary to:

  • comply with a binding legal request;
  • protect the rights, safety, and security of Lettermint, our customers, recipients, or others;
  • investigate fraud, abuse, security incidents, or unlawful activity; or
  • establish, exercise, or defend legal claims.

8.4 Corporate transactions

If Lettermint is involved in a merger, acquisition, restructuring, financing, insolvency, or transfer of all or part of its business or assets, relevant personal data may be disclosed to prospective or actual parties and their advisers, subject to appropriate confidentiality and data-protection safeguards.

9. International data transfers

Lettermint is established in the Netherlands.

Email Data hosted, stored, routed, or processed as part of Lettermint’s core email-delivery infrastructure remains within the European Union (EU). In the ordinary course of providing the Services, emails are transmitted to recipient systems selected by the customer. Those recipient systems may be located outside the EU, including outside the European Economic Area (EEA). Such customer-directed delivery is distinct from Lettermint hosting or internally processing Email Data outside the EU.

Some providers used for billing, collaboration, development, and other business operations may process Business Relationship Data outside the EEA. Depending on the provider and destination, we rely on safeguards such as:

  • an adequacy decision adopted by the European Commission;
  • the European Commission’s Standard Contractual Clauses;
  • supplementary contractual, organisational, or technical safeguards; or
  • another valid transfer mechanism available under applicable data-protection law.

You may request further information about the safeguards relevant to your personal data by contacting legal@lettermint.co. We may redact commercially confidential or security-sensitive information from copies of contractual safeguards where permitted by law.

10. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including providing the Services, maintaining security and accountability, meeting legal obligations, and establishing or defending legal claims.

Different categories of data have different retention periods or criteria:

Data categoryRetention period or criteria
Account, profile, organisation, and subscription dataRetained while the account or business relationship is active. After termination, we retain only the information reasonably necessary to close the relationship, complete billing and administration, maintain security and accountability, comply with law, or handle disputes. Remaining information is deleted or anonymised when no longer needed.
Customer-controlled data after terminationData that remains available through the Services may be retrieved for the period stated in the Terms and Conditions and is then deleted in accordance with the Data Processing Agreement, unless retention is legally required.
Data subject to confirmed account deletionWhere an authorised user confirms permanent account deletion after being informed of its consequences, we treat this as an instruction to delete the associated customer-controlled data rather than retain it for retrieval. Account and service data that is not required for billing, legal compliance, security, fraud prevention, or dispute handling is deleted from active systems without undue delay.
Application, delivery, technical, and security logsNormally retained for no more than 14 days, unless selected records are required for an active security, abuse, deliverability, compliance, or legal investigation. Retention of customer-controlled Email Data and delivery data is additionally governed by the Data Processing Agreement and applicable product settings.
Backup copiesResidual copies are automatically overwritten or deleted within our documented rolling backup-retention cycle, which does not exceed 14 days. Backups are access-restricted and are not used for ordinary processing. If a backup is restored, applicable deletion instructions and retention rules are reapplied without undue delay.
Billing, invoice, accounting, and tax recordsRetained for the applicable statutory accounting and tax-retention period.
Support and customer-success communicationsRetained for as long as necessary to resolve and document the request, support the customer relationship, maintain security and service continuity, and address reasonably anticipated disputes or legal obligations. Records are deleted or anonymised when no longer needed.
Sales inquiries and prospective-customer communicationsRetained while the inquiry or potential relationship remains active and for a limited follow-up period where a business relationship may reasonably develop. Data is then deleted or anonymised unless a longer period is required for legal or compliance purposes.
Marketing preferences and suppression recordsRetained until consent is withdrawn or an objection is made. A minimal suppression record may be retained afterwards to ensure that the opt-out continues to be respected.
Security, abuse, incident, or legal evidenceRetained for as long as reasonably necessary to investigate and remediate the matter, demonstrate compliance, protect the Services, or establish, exercise, or defend legal claims.

Where personal data is subject to a legal hold or mandatory retention obligation, we may retain it for the required period and restrict it from unrelated processing.

11. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration, or disclosure.

Our measures include, as appropriate, access controls, encryption, logging and monitoring, vulnerability management, secure development practices, incident response, backups, supplier management, and personnel confidentiality and training.

Further information about our security programme is available through our Trust Center.

No method of transmission or storage is completely risk-free. You are responsible for maintaining the security of your credentials, devices, integrations, and account configuration and for notifying us promptly if you suspect unauthorised account access.

12. Your privacy rights

Depending on applicable law and the circumstances, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • receive certain personal data in a structured, commonly used, and machine-readable format and transmit it to another controller;
  • object to processing based on our legitimate interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time where processing is based on consent; and
  • receive information about, and where applicable challenge, solely automated decisions that produce legal effects or similarly significantly affect you.

These rights are not absolute. We may decline or limit a request where an exemption applies, where we are legally required to retain information, or where fulfilling the request would adversely affect the rights and freedoms of others.

To exercise your rights, contact legal@lettermint.co. Account users may also use available account and data-export functionality within the Services.

We may request information necessary to verify your identity and authority before fulfilling a request. We will respond within the period required by applicable law and will inform you if an extension is permitted and necessary.

Direct marketing

You may unsubscribe from marketing emails at any time by using the unsubscribe link in the message or by contacting us. Service, security, billing, and other non-promotional communications necessary to administer your account or relationship may continue.

13. Requests concerning emails sent by our customers

If you received an email sent through Lettermint, the sender or relevant Lettermint customer is normally the controller responsible for deciding why your personal data is processed and for responding to your request.

Requests concerning matters such as:

  • why an email was sent to you;
  • consent or another legal basis used by the sender;
  • correction or deletion of an address in the sender’s systems;
  • marketing preferences or unsubscribe requests; or
  • the sender’s retention or use of your information

should normally be directed to the sender.

If you send such a request to Lettermint, we may ask for information necessary to identify the relevant customer or message and forward the request to that customer. We will assist our customer in accordance with the Data Processing Agreement where required.

This does not prevent you from contacting Lettermint directly about processing for which Lettermint itself acts as controller, such as our own account, website, billing, support, security, or marketing activities.

14. Children

The Lettermint account and administration Services are intended for businesses and professional users and are not directed at children.

We do not knowingly permit children to create or administer a business account. Customer emails and other customer content may nevertheless contain personal data relating to children. In those circumstances, the relevant customer acts as controller and is responsible for ensuring that the processing is lawful. Lettermint processes the data in accordance with the customer’s instructions and the Data Processing Agreement.

15. Complaints

Please contact us first at legal@lettermint.co so that we can investigate and address your concern.

You also have the right to lodge a complaint with a competent data-protection authority. Because Lettermint is established in the Netherlands, the Dutch supervisory authority is the Autoriteit Persoonsgegevens. You may also contact the supervisory authority in the EEA country where you live, work, or believe an infringement occurred.

Information about the Autoriteit Persoonsgegevens is available at autoriteitpersoonsgegevens.nl.

16. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, regulatory guidance, our Services, providers, or processing activities. We will update the revision date when changes are made.

Where a change materially affects the purposes of processing, categories of personal data, recipients, international transfers, retention practices, or the way individuals can exercise their rights, we will provide appropriate notice, for example by email or through an in-application notification. Minor editorial, formatting, or non-material corrections may be published without separate notice.

17. Contact

For questions, concerns, or privacy requests, contact:

Lettermint B.V.
Willemsvaart 16 B
8019 AB Zwolle
The Netherlands

Email: legal@lettermint.co