[{"data":1,"prerenderedAt":126},["ShallowReactive",2],{"aSsAZfG8-ugqD29LzCcPuWNV7-1XbuJkeCo-tNirhrg":3,"_apollo:default":96},{"page":4,"blog":13},{"__typename":5,"title":6,"slug":7,"subtitle":8,"_seoMetaTags":9,"_allSlugLocales":81,"deal":13,"tapfiliateReferralCode":8,"tapfiliateTapS":8,"footerTheme":87,"seoStructuredData":13,"hideTopNavigation":88,"sections":89},"PageRecord","StartMail Privacy Policy – Your Data, Your Control","privacy","",[10,14,18,21,25,28,31,35,39,43,47,50,53,57,61,65,69,73,77],{"__typename":11,"tag":12,"attributes":13,"content":6},"Tag","title",null,{"__typename":11,"tag":15,"attributes":16,"content":13},"meta",{"property":17,"content":6},"og:title",{"__typename":11,"tag":15,"attributes":19,"content":13},{"name":20,"content":6},"twitter:title",{"__typename":11,"tag":15,"attributes":22,"content":13},{"name":23,"content":24},"description","Learn how StartMail protects your privacy – No tracking, no ads, and full control over your data. Read our privacy policy today!",{"__typename":11,"tag":15,"attributes":26,"content":13},{"property":27,"content":24},"og:description",{"__typename":11,"tag":15,"attributes":29,"content":13},{"name":30,"content":24},"twitter:description",{"__typename":11,"tag":15,"attributes":32,"content":13},{"property":33,"content":34},"og:image","https://www.datocms-assets.com/47413/1664435631-1.png?auto=format&fit=max&w=1200",{"__typename":11,"tag":15,"attributes":36,"content":13},{"property":37,"content":38},"og:image:width","1200",{"__typename":11,"tag":15,"attributes":40,"content":13},{"property":41,"content":42},"og:image:height","701",{"__typename":11,"tag":15,"attributes":44,"content":13},{"property":45,"content":46},"og:image:alt","Why you should protect your emails",{"__typename":11,"tag":15,"attributes":48,"content":13},{"name":49,"content":34},"twitter:image",{"__typename":11,"tag":15,"attributes":51,"content":13},{"name":52,"content":46},"twitter:image:alt",{"__typename":11,"tag":15,"attributes":54,"content":13},{"property":55,"content":56},"og:locale","en",{"__typename":11,"tag":15,"attributes":58,"content":13},{"property":59,"content":60},"og:type","article",{"__typename":11,"tag":15,"attributes":62,"content":13},{"property":63,"content":64},"og:site_name","StartMail",{"__typename":11,"tag":15,"attributes":66,"content":13},{"property":67,"content":68},"article:modified_time","2025-06-10T09:30:02Z",{"__typename":11,"tag":15,"attributes":70,"content":13},{"property":71,"content":72},"article:publisher","https://www.facebook.com/MyStartMail/",{"__typename":11,"tag":15,"attributes":74,"content":13},{"name":75,"content":76},"twitter:card","summary",{"__typename":11,"tag":15,"attributes":78,"content":13},{"name":79,"content":80},"twitter:site","@MyStartMail",[82,86],{"__typename":83,"locale":84,"value":85},"StringNonNullMultiLocaleField","de","datenschutz",{"__typename":83,"locale":56,"value":7},"light",false,[90,93],{"__typename":91,"centeredTitle":88,"subtitle":8,"title":92},"PageHeaderRecord","Privacy Policy",{"__typename":94,"requiredBody":95},"MarkdownSectionRecord","\u003Ch2>StartMail has been developed to Protect your Privacy\u003C/h2>\n\n\u003Cp>Using StartMail, you can protect yourself against unwarranted\nintrusion and mass surveillance and take back your right to\ncommunications privacy. Our core values include &quot;privacy by design&quot;\nand &quot;minimal data retention&quot;.\u003C/p>\n\n\u003Cp>Our core values are:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>\u003Cstrong>Privacy by design.\u003C/strong> Privacy shouldn&#39;t be an afterthought. We\nbuilt StartMail from scratch, and privacy has always been our main\nobjective.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>\u003Cstrong>Encryption made easy.\u003C/strong> Encryption is a must to achieve\nprivacy. While existing encryption solutions for email are\ncumbersome, StartMail makes encryption easy for everyone.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>\u003Cstrong>Optimal security.\u003C/strong> Privacy and security must go hand in\nhand. There is no privacy without security.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>\u003Cstrong>Minimal data retention.\u003C/strong> We store and process as little personal\ninformation about you as possible.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>\u003Cstrong>Transparency of purpose.\u003C/strong> We have no hidden agenda with your\ninformation. If we store your data at all, we always tell you\nexactly why.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>\u003Cstrong>Responsible protection of users&#39; civil rights.\u003C/strong> We believe\ncommunications privacy is a fundamental right. StartMail protects\nyour email against unauthorized and unconstitutional intrusions.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>\u003Cstrong>Transparency about our solutions and remaining threat vectors.\u003C/strong>\n100% privacy or security does not exist. We strive to be as open and\nclear as possible about what our solution can and cannot offer.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Cp>Definitions of the capitalized terms are included in the \u003Ca href=\"/terms-of-service\">Terms of\nService\u003C/a>.\u003C/p>\n\n\u003Ch2>We put you Back in Control\u003C/h2>\n\n\u003Cp>We are fully transparent about which data we process and why. We put\nyou back in the driver&#39;s seat when it comes to your data.\u003C/p>\n\n\u003Cp>Your inbox and other personal information are yours even though we\nhelp you by securing it and making it accessible through our\nuser-friendly interface. Exactly which part of your data is processed\nby us and why, depends on how you are using our Website and the\nStartMail Service.\u003C/p>\n\n\u003Ch3>1. Visiting our Website\u003C/h3>\n\n\u003Cp>When you visit the Website, the following details are automatically\nprocessed:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>Your IP address → to allow effective troubleshooting and abuse\ncontrol.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Browser and operating system type and version → to display the\nWebsite in the right format for your browser and operating system.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Browser language settings → to show you the Website in the right\nlanguage.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Country (based on IP-address), date and time → to know in which\ncountries and at what moments our marketing efforts appear to be\neffective.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Origin of your visit (such as whether you directly typed the Website\nURL or accessed the Website through a search engine query or link\nfrom another website) → to assess the success of our search engine\noptimization and information outreach efforts.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Clicked links and visited (parts of) pages on our Website → to help\nus get an idea of which of our pages appear to be effective to\ninform our visitors.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Cp>In our weblogs we store the browser user agent, pages visited, IP\naddress and timestamp for a maximum of 7 days after which they are\ndeleted.\u003C/p>\n\n\u003Cp>All other information is processed in a self-hosted analytics tool and\nstored anonymized, in order to analyze usage trends.\u003C/p>\n\n\u003Ch3>2. Signing up for an Account\u003C/h3>\n\n\u003Cp>Additionally, when signing up for the StartMail Service you may be\nasked to provide:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>A name that you choose (optional and may be an alias or pseudonym,\nbut see also our \u003Ca href=\"/terms-of-service\">Terms of Service\u003C/a>, → to be\nable to address you when we communicate with you.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Your desired email address (required), → to provide you with your\nStartMail email address.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>A password (required), → to provide authentication for your Account.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>A Verification Email Address, → This address is used to send you an\nactivation link to activate your StartMail trial account. To\nmaintain the integrity of the StartMail service, StartMail must take\nmeasures to avoid the automatic creation of accounts by\nspammers. This is because if spammers use StartMail to send\nmessages, StartMail&#39;s IP addresses can become blocked by major mail\nproviders such as Gmail, Yahoo, Outlook, etc.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>A Recovery Email Address (optional, see also our Term of Service), →\nto communicate with you in the event that you need to recover access\nto your StartMail Account should you ever lose your password.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>A promotional code (optional, if you have one), → to give you the\nbenefit of a promotional offer. Your preference as to whether you\nwould like to subscribe to our newsletter(s), → to send you our\nnewsletters only if you want to receive them.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Payment method information. (see 3. Paying for an Account below)\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Information collected as a result of you answering prompts, such as\nimage labeling data, text converted from audio files played to you,\n→ in order for us to protect our website from spam and abuse, we use\nhCaptcha. Intuition Machines can deduce if we are dealing with a\nlegitimate website visitor or a robot. We have a legitimate interest\nto know this. For more information, please read hCaptcha&#39;s \u003Ca href=\"https://www.hcaptcha.com/privacy\">Privacy\nStatement\u003C/a>.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Ch3>3. Paying for an Account\u003C/h3>\n\n\u003Cp>StartMail offers a paid subscription service which can be paid for\nwith various online payment methods. To facilitate payment and to\nmanage the customers&#39; subscription, StartMail works with third-party\npayment providers and a subscription management provider.\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>For payment processing, StartMail relies on third parties such as\nStripe and Paypal to process payment details such as credit card\ninformation to process your payments or refunding such payments. In\naccordance with Payment Card Industry Security Standards (PCI DSS),\nwhich our payment and subscriptions providers all adhere to, they are\nnot permitted to use your information for anything other than\nprocessing your payment.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>For subscription management, StartMail relies on Chargebee to manage\ncustomer lifecycle operations such as managing trials, assigning\ncredits, issuing refunds and making mid-cycle subscription\nchanges. Our subscription management provider processes data only as\nour &#39;processor&#39; (as intended in the GDPR). Through our data processing\nagreement, we have bound this provider to only process data in order\nto provide their services to us and not for other purposes. In\naddition, we pseudonymize your data before providing it to our\nsubscription management provider.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Cp>\u003Cbr>\u003C/p>\n\n\u003Cp>StartMail necessarily must share some information with these\nthird-party data processors to provide the StartMail Service\u003C/p>\n\n\u003Cp>The legal basis of this processing is the performance of the contract\nbetween you and StartMail.\u003C/p>\n\n\u003Cp>In order to protect your privacy, StartMail will minimize the type and\namount of data which is being shared with our data processors so you\ncan make use of the StartMail service without sharing more of your\nprivate information than necessary.\u003C/p>\n\n\u003Cp>For example: For StartMail to manage your subscription through\nChargebee, a unique and random identifier is generated and shared with\nChargebee. This unique identifier enables StartMail to link your\nStartMail e-mail address to your subscription at Chargebee but not the\nother way around. Chargebee only receives this unique identifier and\nas a result Chargebee cannot directly link the payment details to the\nemail address you have registered at StartMail. This provides an\nadditional safeguard to protect your privacy. For additional privacy,\nStartMail also offers \u003Ca href=\"https://support.startmail.com/hc/en-us/articles/360006620637-Payment-methods\">anonymous payment\nmethods\u003C/a>.\nPlease send a message to \u003Ca href=\"mailto:support@startmail.com\">support@startmail.com\u003C/a> to\nreceive more information on how to perform such a payment.\u003C/p>\n\n\u003Ch4>Information required for Payment, billing and subscription information\u003C/h4>\n\n\u003Cp>The specialized payment and subscription providers\n\u003Ca href=\"https://stripe.com/docs/security\">Stripe\u003C/a>,\n\u003Ca href=\"https://www.paypal.com/nl/home\">Paypal\u003C/a> and\n\u003Ca href=\"https://www.chargebee.com/security/pci/\">Chargebee\u003C/a> have been\ncarefully chosen to responsibly process payment details and billing\ninformation which is used to manage your subscription. These companies\nhave strict security standards, as laid down in the \u003Ca href=\"https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard\">Payment Card\nIndustry Security Standards (PCI\nDSS)\u003C/a>,\nwith which they are fully compliant. These providers store account\npayment details under a unique identifier but cannot connect the payment\ndata to the account email address. The StartMail system also works\nwith this unique identifier and has no direct access to Stripe&#39;s system --\neffectively separating the two systems.\u003C/p>\n\n\u003Ch4>Privacy Policies\u003C/h4>\n\n\u003Ch5>Chargebee\u003C/h5>\n\n\u003Cp>The information that you provide through Chargebee is subject to the\n\u003Ca href=\"https://www.chargebee.com/privacy/\">Chargebee Privacy Policy\u003C/a>. A\nrandom e-mail pseudonym is generated when you register at StartMail\nwhich will be shared with Chargebee to help you and StartMail manage\nyour subscription. This for example allows you to receive an invoice\nwithout Chargebee knowing your account name.\u003C/p>\n\n\u003Ch5>Stripe\u003C/h5>\n\n\u003Cp>The information that you provide through Stripe such as your credit\ncard number, credit card expiration date, card security code is\nsubject to \u003Ca href=\"https://stripe.com/en-nl/privacy\">the Stripe Privacy\nPolicy\u003C/a>.\u003C/p>\n\n\u003Ch5>PayPal\u003C/h5>\n\n\u003Cp>StartMail supports PayPal as a payment processing provider. You can\nfind their privacy policy\n\u003Ca href=\"https://www.paypal.com/uk/legalhub/privacy-full\">here:\u003C/a> To make\npayments as easy and user-friendly as possible, StartMail sends your\nname and e-mail address to Paypal during a payment process. All this\ninformation would be requested by the provider anyway.\u003C/p>\n\n\u003Ch3>4. Location of data\u003C/h3>\n\n\u003Ch4>StartMail\u003C/h4>\n\n\u003Cp>The StartMail databases (containing customer emails which are stored\nin encrypted user vaults) are located in data centers in the\nNetherlands. Payment and subscription details are stored in the\n(cloud) servers used by our payment and subscription management\nproviders, outside of the EU. See below for more information.\u003C/p>\n\n\u003Ch4>Stripe\u003C/h4>\n\n\u003Cp>Stripe&#39;s data (credit card information for payment processing) is\nhosted solely in data centers in the US. Under EU data protection law,\nthere is no requirement to localize, i.e., to store data in the\nEU. However, when data is transferred to a non-EU country that does\nnot offer the same level of data protection as the European Union&#39;s\nGeneral Data Protection Regulation (GDPR), a data transfer mechanism\nhas to be implemented to ensure this protection. Stripe&#39;s existing\nmeasures include the EU Commission&#39;s approved Standard Contractual\nClauses (SCCs) to accommodate international data transfers.\u003C/p>\n\n\u003Ch4>Chargebee\u003C/h4>\n\n\u003Cp>Chargebee has their main servers located in the US. To facilitate\nthis, StartMail and Chargebee have a Data Processing Addendum (DPA)\nfor the transfer of data outside of the EU. StartMail uses\npseudonymization to ensure that our subscription management provider\ncannot relate your subscription information to your e-mail\naddress. Chargebee&#39;s existing measures include the EU Commission&#39;s\napproved Standard Contractual Clauses (SCCs) to accommodate\ninternational data transfers.\u003C/p>\n\n\u003Ch4>Paypal\u003C/h4>\n\n\u003Cp>Please see \u003Ca href=\"https://www.paypal.com/uk/webapps/mpp/ua/privacy-full\">Paypal&#39;s privacy\nstatement\u003C/a>\nto understand how they manage your payment details. Paypal&#39;s existing\nmeasures include the EU Commission&#39;s approved Standard Contractual\nClauses (SCCs) to accommodate international data transfers.\u003C/p>\n\n\u003Ch3>5. Using the StartMail Service\u003C/h3>\n\n\u003Cp>All of your email messages are stored in a secure User Vault on our\nservers. All information in the vault is encrypted (see \u003Ca href=\"#startmail-gives-you-ironclad-data-protection\">StartMail\nGives You Ironclad Data Protection\u003C/a> on how we use encryption to protect your data). Everything you can see through the regular user interface (your inbox\nand folders, including spam folder, but excluding contacts) is stored,\nand is stored safely in the User Vault.\u003C/p>\n\n\u003Cp>\u003Cbr>\nAdditionally, the following is also stored in the User Vault:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>personalized spam preferences of the User as part of the self-learning\nprocess of the spam filter\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>a search index, which allows an efficient email search functionality  \u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Cp>\u003Cbr>\nWhen you use the StartMail Service to send an email, your IP address\nis not included in the header of the email. Instead our IP address is\nshown.\u003Cbr>\n\u003Cbr>\nStartMail stores 7 days worth of logs. These include metadata like remote email server IP addresses, and SMTP sender and recipient addresses for emails sent and received. We use the logs for detecting and troubleshooting operational issues like problems with the webmail application, emails not being delivered and fighting spam and phishing.\u003C/p>\n\n\u003Ch3>6. Support\u003C/h3>\n\n\u003Cp>You may visit our support section or send us feedback or a support\nrequest. StartMail processes personal data to offer you support. For\nthis purpose, we use the information provided by you, such as your\nemail address and your feedback or request. We need this information\nfor the performance of a contract: to respond to your feedback or\nsupport request.\u003C/p>\n\n\u003Cp>We use Zendesk to power our support section and process your feedback\nor support request. Zendesk is a global company with its head office\nin the United States. We and Zendesk have taken appropriate safeguards\nto protect your personal data when using Zendesk to handle your\nsupport request. For example, Zendesk has implemented binding\ncorporate rules (BCRs) which have been approved by the appropriate\nprivacy supervisory authority. In addition, we have made use of the\noption to bind Zendesk to standard contractual clauses made by the\nEuropean Commission in order to protect your privacy.\u003C/p>\n\n\u003Cp>Nevertheless, If you do not want Zendesk to be used to handle your\nsupport inquiry, then you can send an e-mail to\n\u003Ca href=\"mailto:support-alt@startmail.com\">support-alt@startmail.com\u003C/a>. Note that it may take slightly longer for\nan agent to pick up your request. We store any communications up to a\nmaximum of two years.\u003C/p>\n\n\u003Ch3>7. Subscribing to our newsletter\u003C/h3>\n\n\u003Cp>On our support form, we may offer the option to subscribe to our\nnewsletter. If you have subscribed, you may receive our newsletters\nuntil you have unsubscribed. You can unsubscribe at any time.\u003C/p>\n\n\u003Ch3>8. Deleted is Deleted\u003C/h3>\n\n\u003Cp>When you delete an email, it is immediately deleted from your secure\nuser vault. As part of our backup strategy a (fully encrypted) copy\nwill remain for the maximum retention period of three days.\u003C/p>\n\n\u003Cp>Your Account will be stored for as long as our Agreement remains in\nforce. When an Agreement is fully terminated, all data contained in\nthe Account, including all emails, will be deleted permanently.\u003C/p>\n\n\u003Ch3>9. Viewing and Amending your Personal Data\u003C/h3>\n\n\u003Cp>If you have any questions about our Privacy Policy or if you have\nquestions about viewing, amending or deleting your personal data, you\ncan contact us at: \u003Ca href=\"mailto:legal@startmail.com\">legal@startmail.com\u003C/a>.\u003C/p>\n\n\u003Ch2>No Tracking or Advertising -- Guaranteed\u003C/h2>\n\n\u003Cp>StartMail is an ad-free service. StartMail does not collect or share\nany data with a third party for advertisement or tracking purposes\nwithin its application. We only use cookies to the extent that this is\nnecessary to provide you with a smooth and user-friendly experience,\nand to understand how our Website is used in general.\u003C/p>\n\n\u003Cp>Other webmail providers collect and use your personal data to display\npersonalized ads to you. As a result, you pay for your webmail with\nyour privacy. We think your privacy is worth more than gold. We\ntherefore don&#39;t track your behavior online and we don&#39;t build any\npersonal profiles of you. The StartMail Service is strictly ad-free.\u003C/p>\n\n\u003Ch3>What (tracking) cookies are and what they can do\u003C/h3>\n\n\u003Cp>A cookie is a small file that is stored on a computer (such as a PC,\nsmartphone or tablet) when visiting a website. Cookies are very useful\nto enable a smooth and user-friendly experience on a website, for\nexample to prevent that visitors would have to supply their login\ndetails again for every action on the website, or to remember the\ncontents of a shopping basket. However, so-called &#39;tracking cookies&#39;\ncan also be used to track users across multiple websites and to build\npersonalized profiles for advertising or other purposes, negatively\naffecting privacy.\u003C/p>\n\n\u003Cp>StartMail will set cookies for the following purposes; First of all,\nwe want to better understand how our StartMail product is used so that\nwe can improve the service. And secondly, we want to evaluate the\neffectiveness of our marketing efforts aimed at attracting new\nStartMail users. \u003Ca href=\"https://support.startmail.com/hc/en-us/articles/360006636657\">Click\nhere\u003C/a>\nfor a complete and up-to-date overview of the cookies used by\nStartMail.\u003C/p>\n\n\u003Ch3>We use only anonymous data to try to improve our services\u003C/h3>\n\n\u003Cp>We collect only strictly anonymous statistics from our\ndomain. Anonymous data is collected only in order to get an idea about\nwhat pages are effective in informing our users about the StartMail\nService, and to improve the user interface. For example, we count the\ntotal number of times each page is being visited and we may get some\ninsight into which pages or features are usually accessed\nconsecutively, but we never know who has visited which pages and when.\u003C/p>\n\n\u003Cp>We use an open source statistical measurement tool for this, called\nMatomo. We run this very lightweight tool on our own infrastructure to\nprevent anybody snooping the data, and we have specifically configured\nit for minimal data collection to ensure that no personal data is\nrecorded at any time.\u003C/p>\n\n\u003Ch3>StartMail blocks remote content by default, to protect your privacy\u003C/h3>\n\n\u003Cp>Some emails contain remote content (such as images, which may even be\ninvisible). If such remote content is loaded automatically, this\nenables the sender to know when the e-mail was opened, because the\nsender can detect when its content was loaded and by whom.\u003C/p>\n\n\u003Cp>To protect your privacy, StartMail prevents any remote content to be\nloaded automatically when you open an email. It is possible to\nexplicitly choose to always load such content automatically in your\nSettings. Please note that you should still be careful to avoid\nopening any attachments or clicking on any links in any email, unless\nyou trust the sender and the content.\u003C/p>\n\n\u003Ch2>\u003Ca id=\"startmail-gives-you-ironclad-data-protection\">\u003C/a>StartMail gives you Ironclad Data Protection\u003C/h2>\n\n\u003Cp>We use state-of-the-art technical and organizational security measures\nto protect your data.\u003C/p>\n\n\u003Cp>\u003Cstrong>On the Technical Side\u003C/strong>, we use state-of-the-art cryptography to\nprotect your data. For example:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>Traffic between the User and our servers is encrypted with TLS, and\nperfect forward secrecy is applied.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>We only store passwords in hashed form on our servers.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Your StartMail inbox and its folders are stored in your own\nencrypted User Vault. Your User Vault is only opened when you\nlogin. Without the account password or a recovery key the vault is\ninaccessible when it is closed.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>When you are logged out of StartMail, your entire inbox is\nencrypted. When you are logged in, your unencrypted emails are\nunencrypted, but all of your PGP-encrypted emails are still\nencrypted unless you open an \u003Ca href=\"/encrypted-email\">encrypted email\u003C/a> by submitting your\nPGP-passphrase.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Users can encrypt emails via OpenPGP.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>The users&#39; key-pair is stored in the User Vault. Additionally, the\nprivate key is encrypted by means of the passphrase. Without the\npassphrase the private key can&#39;t be decrypted or used.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>We only use validated encryption algorithms that are considered safe\nby respected cryptographers.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Cp>For more detailed information about our technical security measures,\nplease read our \u003Ca href=\"/whitepaper\">Security White Paper\u003C/a>.\u003C/p>\n\n\u003Cp>\u003Cstrong>On the Organizational Side\u003C/strong> we have strict protocols in place to\nensure the safety of your data. For example:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>At each level, access to our systems is restricted to authorized\nstaff with a legitimate need to know. This access is tightly limited\nand is only for the purpose of providing the StartMail Service to\nyou.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Any individual, who is given access to the StartMail system, is\nrequired to sign a confidentiality agreement.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>No third party, contractor, or sub-contractor of StartMail is given\naccess to the system, except for the purpose of enabling us to\nprovide the StartMail Service to you. All such parties must sign a\ndata processing agreement, containing confidentiality provisions and\nstringent security protocols.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Ch3>Compliance with Legitimate Requests by Authorities\u003C/h3>\n\n\u003Cp>While we respect and try to protect your privacy to the best of our\nabilities, your use of StartMail does not place you above the law. But\nneither do we place authorities above the law. We have a strong belief\nin the Rule of Law of the Netherlands. ONLY if we receive a request\nfrom Dutch judicial authorities to hand over information about one of\nour Users, we will have our lawyers check the validity of the request\nand determine whether we are obliged to comply. We will NOT comply\nwith such requests unless we are convinced that the request is legally\nvalid and we believe that it is undeniably our legal obligation to\ncomply.\u003C/p>\n\n\u003Cp>We will NOT comply with requests from any authorities other than Dutch\nauthorities. If we receive a request from any foreign government, we\nwill refuse to comply and will instead instruct the requestor to place\na formal request to the Dutch authorities for mutual assistance.\u003C/p>\n\n\u003Cp>StartMail will never cooperate with any voluntary surveillance\nprograms. Under the strong laws that protect the right to privacy in\nEurope, European governments cannot legally force service providers\nlike StartMail to implement a blanket-spying program on their users.\u003C/p>\n\n\u003Ch3>Requests by Private Third Parties\u003C/h3>\n\n\u003Cp>We will NOT comply with any requests from private third parties to\nprovide information about our Users, unless we would receive a valid\nDutch court order and we believe it is undeniably our legal obligation\nto comply.\u003C/p>\n\n\u003Ch3>We will not reduce your rights without your explicit consent\u003C/h3>\n\n\u003Cp>We may change our Privacy Policy from time to time. Any changes to our\nPrivacy Policy will be posted on this page, and we will provide a more\nprominent notice, such as an email message, if we believe a change\nsignificantly affects your privacy.\u003C/p>\n\n\u003Ch2>StartMail complies with the World&#39;s toughest Privacy Laws\u003C/h2>\n\n\u003Cp>StartMail is based in The Netherlands, Europe, where privacy laws and\nregulations are among the strictest in the world.\u003C/p>\n\n\u003Cp>For example, we do the following to comply with the General Data\nProtection Regulation, which is widely renowned as one of the\nstrongest privacy laws in the world and gives you \u003Ca href=\"https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_en\">formidable legal\nrights\u003C/a>:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>clearly state our identity as a &#39;controller&#39; of your personal data and\nhow you can contact us with questions or requests about your privacy;\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>clearly explain for what legitimate purposes and interests and under\nwhich legal basis we process personal data, as we do in this privacy\npolicy;\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>clearly state which kinds of parties may need to receive your personal\ndata from us and why;\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>first request your express consent to the processing of your personal\ndata in cases where your consent is required, giving you the right to\nwithdraw your consent at any time;\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>do everything we can to prevent that we would process more personal\ndata than necessary for our legitimate purposes, or store it for\nlonger than necessary;\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>implement appropriate security measures to protect your personal data,\nand demand the same of any party processing personal data on our\ninstructions;\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>respect your right to request inspection of your personal data and\nhave them corrected or deleted, or to restrict our processing of it.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Ch3>Legal basis for processing your data\u003C/h3>\n\n\u003Cp>The following legal grounds apply to process your personal data:\u003C/p>\n\n\u003Cul>\n\u003Cli>\u003Cp>Your consent. By using the StartMail Service, you consent to our\nprocessing of your data as part of the StartMail Service.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Necessary to perform a contract with you or take steps before\nentering into a contract with you at your request. By signing up for\nthe StartMail Service, you request us to prepare your contract. Once\nyour contract has been entered into, we may process your data as\nnecessary to perform our contract with you (providing the StartMail\nService to you).\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Our legitimate interest, to provide the StartMail Service to you in\nthe best way we can.\u003C/p>\u003C/li>\n\u003Cli>\u003Cp>Our legal obligations, for example our obligation to store invoices\nfor tax purposes.\u003C/p>\u003C/li>\n\u003C/ul>\n\n\u003Ch3>Your rights with respect to your data\u003C/h3>\n\n\u003Cp>You may ask us at any time to access, correct or erase your data. You\nmay also request us to keep your information but block it from further\nprocessing. You can submit any such request by using our contact\ndetails below.\u003C/p>\n\n\u003Cp>If you inform us that you withdraw your consent to process your\ninformation, we will delete your information, unless we are legally\nrequired to keep it (e.g. invoices, as explained below under retention\nperiods).\u003C/p>\n\n\u003Ch3>Retention periods\u003C/h3>\n\n\u003Cp>\u003Cu>Invoices\u003C/u>\u003C/p>\n\n\u003Cp>We store invoices for 7 years, or whichever period may be prescribed\nunder applicable tax law.\u003C/p>\n\n\u003Cp>\u003Cu>E-mail account\u003C/u>\u003C/p>\n\n\u003Cp>If you have subscribed to the StartMail Service, your Account will be\nstored for as long as our Agreement remains in force. When an\nAgreement is fully terminated, all data contained in the Account,\nincluding all emails, will be deleted permanently.\u003C/p>\n\n\u003Ch3>Dutch Data Protection Authority\u003C/h3>\n\n\u003Cp>We are always here to help. If you have any feedback or complaint\nabout our services in general, or more specifically about how your\nprivacy is protected when you use our services, please let us know via\nthe contact details below. In accordance with EU privacy laws and\nregulations, you have the right to lodge a complaint with the national\nsupervisory authority responsible for the protection of personal data\nif you think we have unlawfully processed your personal data. For the\nNetherlands, this supervisory authority is the \u003Cem>Dutch Data Protection\nAuthority\u003C/em>, which you can \u003Ca href=\"https://autoriteitpersoonsgegevens.nl/\">contact\nhere\u003C/a>.\u003C/p>\n\n\u003Ch2>Our company and contact information\u003C/h2>\n\n\u003Cp>\u003Cem>Still have privacy questions?\u003C/em>\u003C/p>\n\n\u003Cp>With this privacy policy we have done our utmost to inform you as well\nas possible about your privacy while using our services. We hope that\nyou agree that your privacy is in good hands with us. StartMail.com is\nowned and operated by StartMail BV, Boulevard 11, 3707 BK Zeist, The\nNetherlands. Representative for the Privacy Policy is Robert\nE.G. Beens. You can contact us at \u003Ca href=\"mailto:privacypolicy@startmail.com\">privacypolicy@startmail.com\u003C/a>.\u003C/p>\n\n\u003Cp>Last Modified: September 24th, 2020\u003C/p>\n\n\u003Cp>Effective: October 1st, 2020\u003C/p>\n\n\u003Cp>Privacy. It&#39;s not just our policy - it&#39;s our mission.\u003C/p>\n",{"ROOT_QUERY":97},["null","__typename",98,"page({\"filter\":{\"slug\":{\"eq\":\"privacy\"}},\"locale\":\"en\"})",99,"blog({\"filter\":{\"slug\":{\"eq\":\"privacy\"}},\"locale\":\"en\"})",13],"Query",["null","__typename",5,"title",6,"slug",7,"subtitle({\"markdown\":true})",8,"_seoMetaTags",100,"_allSlugLocales",120,"deal",13,"tapfiliateReferralCode",8,"tapfiliateTapS",8,"footerTheme",87,"seoStructuredData",13,"hideTopNavigation",88,"sections",123],[101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119],["null","__typename",11,"tag",12,"attributes",13,"content",6],["null","__typename",11,"tag",15,"attributes",16,"content",13],["null","__typename",11,"tag",15,"attributes",19,"content",13],["null","__typename",11,"tag",15,"attributes",22,"content",13],["null","__typename",11,"tag",15,"attributes",26,"content",13],["null","__typename",11,"tag",15,"attributes",29,"content",13],["null","__typename",11,"tag",15,"attributes",32,"content",13],["null","__typename",11,"tag",15,"attributes",36,"content",13],["null","__typename",11,"tag",15,"attributes",40,"content",13],["null","__typename",11,"tag",15,"attributes",44,"content",13],["null","__typename",11,"tag",15,"attributes",48,"content",13],["null","__typename",11,"tag",15,"attributes",51,"content",13],["null","__typename",11,"tag",15,"attributes",54,"content",13],["null","__typename",11,"tag",15,"attributes",58,"content",13],["null","__typename",11,"tag",15,"attributes",62,"content",13],["null","__typename",11,"tag",15,"attributes",66,"content",13],["null","__typename",11,"tag",15,"attributes",70,"content",13],["null","__typename",11,"tag",15,"attributes",74,"content",13],["null","__typename",11,"tag",15,"attributes",78,"content",13],[121,122],["null","__typename",83,"locale",84,"value",85],["null","__typename",83,"locale",56,"value",7],[124,125],["null","__typename",91,"centeredTitle",88,"subtitle",8,"title",92],["null","__typename",94,"body({\"markdown\":true})",95],1775572982172]