Privacy and Cookie Policy for mySMTP
Last updated: 1 September 2026
This policy explains how SMTP.dk ApS, trading as mySMTP (“mySMTP”, “we”, “us”), processes personal data and uses cookies in connection with our website, customer portal and SMTP services.
We process personal data in accordance with the EU General Data Protection Regulation (“GDPR”), the Danish Data Protection Act and other applicable laws.
We only use non-essential cookies with your consent.
- Data controller and contact details
SMTP.dk ApS is the data controller for personal data relating to website visitors, customers, contacts and users of our platforms.
SMTP.dk ApS, trading as mySMTP
Refshalevej 163A
1432 Copenhagen K
Denmark
Company registration number: 29849439
Email:
Website: www.mysmtp.com
You are welcome to contact us if you have questions about how we process personal data or if you wish to exercise your rights.
- When is mySMTP a controller or processor?
mySMTP is the data controller for personal data that we process for our own purposes. This includes customer administration, billing, support, security, operations and marketing.
When we provide SMTP services and process email data on behalf of a customer, the customer is generally the data controller and mySMTP is the data processor.
Our processing of email data on behalf of the customer is governed by our separate Data Processing Agreement (“DPA”).
- Personal data we process
3.1 Website visitors
When you visit our website, we may process technical information such as:
- IP address
- Browser and device type
- Operating system
- Pages visited and time of visit
- Referring website
- Cookie choices and consent status
Necessary technical information is processed to operate and protect the website.
Information used for analytics or marketing is only processed if you have consented to the relevant cookies.
3.2 Account registration and purchase of services
When you create an account or purchase a service, we may process:
- Name and contact details
- Address and country
- Company name and company or VAT number
- Login and account information
- Order, payment and billing information
- Subscription, usage and purchase history
- IP addresses and domains connected to the account
- Communications between you and mySMTP
We process this information to create and administer your account, provide the requested services, receive payment and meet our legal obligations.
3.3 Support and other communications
When you contact us, we may process:
- Name and contact details
- Customer and account number
- The content of your enquiry
- Technical information and relevant log data
- Any attached documents or screenshots
We use this information to respond to your enquiry, provide support, document our communication and improve our services.
Please do not send sensitive personal data or passwords unless necessary and specifically agreed with us.
3.4 SMTP services and email data
When a customer uses our SMTP services, we may process on the customer’s behalf:
- Sender and recipient email addresses
- Sender domains and IP addresses
- Subject lines and technical email headers
- Email content during transmission
- Sending time and delivery status
- SMTP responses, bounce information and error messages
- Spam, security and delivery-related information
Email content is processed temporarily to the extent necessary for transmission, security, spam filtering and error handling.
Email content is not stored permanently. However, it may temporarily remain in a mail queue or be processed when necessary for delivery, troubleshooting, security or abuse handling.
The customer is responsible for the recipient data, email content and legal basis for sending the emails. mySMTP processes this data according to the customer’s documented instructions and the applicable DPA.
3.5 Newsletters and marketing
If you subscribe to our newsletter or otherwise consent to marketing, we process your name, email address and information documenting your consent.
We may record email opens and clicks if you have given the necessary consent to such tracking.
You can unsubscribe at any time by using the unsubscribe link in our emails or contacting
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
3.6 Security and abuse prevention
We may process account, traffic and technical information to:
- Prevent spam, phishing and fraud
- Detect compromised accounts
- Protect our systems, domains and IP addresses
- Investigate security incidents and abuse
- Handle complaints from recipients and email providers
- Comply with lawful requests from public authorities
- Purposes and legal bases
We process personal data for the following purposes and on the following legal bases:
|
Purpose |
Legal basis |
|
Account registration and administration |
Performance of a contract, GDPR Article 6(1)(b) |
|
Delivery of requested services |
Performance of a contract, Article 6(1)(b) |
|
Billing and accounting |
Legal obligation, Article 6(1)(c) |
|
Customer support and communication |
Performance of a contract and legitimate interests, Article 6(1)(b) and (f) |
|
Operations, security and abuse prevention |
Legitimate interests, Article 6(1)(f) |
|
Legal claims and disputes |
Legal obligation and legitimate interests, Article 6(1)(c) and (f) |
|
Newsletters and marketing |
Consent, Article 6(1)(a), or legitimate interests where permitted by law |
|
Analytics and marketing cookies |
Consent, Article 6(1)(a) |
|
Essential cookies |
Legitimate interests or necessity to provide a requested function |
Our legitimate interests include operating, protecting and improving our services, providing support, preventing abuse and documenting our activities.
- Recipients and data processors
We do not sell personal data or disclose it to third parties for their own marketing purposes.
We may share personal data with suppliers and processors where necessary for:
- Hosting and data centre operations
- Payment processing
- Accounting and billing
- Customer service and support
- Email communications
- Security, monitoring and abuse prevention
- Analytics, where consent has been given
- Legal advice and compliance with official requests
Our processors may only process personal data according to our instructions and must protect it in accordance with applicable law.
An updated list of relevant subprocessors is available here:
[Insert link to subprocessor list]
- Transfers outside the EU/EEA
We aim to host and process personal data within the EU/EEA.
If a supplier processes personal data outside the EU/EEA, we ensure that a valid transfer mechanism is in place. This may include an adequacy decision by the European Commission or the European Commission’s Standard Contractual Clauses.
You may contact us for further information about the applicable transfer mechanisms.
- Retention and deletion
We only retain personal data for as long as necessary for the purpose for which it was collected or as required by law.
As a general rule:
- SMTP traffic logs and technical metadata are normally retained for up to 30 days
- Email content is not stored permanently but may temporarily remain in a mail queue
- Account and subscription information is retained while the customer relationship remains active
- Inactive accounts may be deleted after 12 months of inactivity and prior notice
- Invoices and accounting records are retained for the period required by applicable accounting law
- Support communications are retained for as long as necessary for support, documentation and potential legal claims
- Records of marketing consent are retained for as long as necessary to document the consent
- Information concerning abuse, security incidents and disputes may be retained for longer where necessary for documentation or legal claims
- Data contained in backups is deleted or overwritten according to our backup procedures
Information may be retained for longer where necessary to establish, exercise or defend a legal claim.
- Information security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure.
These measures may include:
- Access controls
- Encrypted communications
- Monitoring and logging
- Spam and malware filtering
- System updates and maintenance
- Backup and recovery procedures
- Restricted access for employees and suppliers
However, no internet-based service can be guaranteed to be completely secure.
- Your rights
Subject to applicable data protection law, you may have the right to:
- Access the personal data we process about you
- Have inaccurate or incomplete information corrected
- Have personal data deleted where the relevant conditions are met
- Restrict the processing of your personal data
- Object to processing based on legitimate interests
- Object to direct marketing
- Receive certain data in a structured and machine-readable format
- Withdraw your consent
- Submit a complaint to a supervisory authority
These rights may be limited by applicable law, the rights of others or our need to document and defend legal claims.
To exercise your rights, please contact
- Complaints
If you are dissatisfied with how we process your personal data, you are welcome to contact us first.
You may also submit a complaint to:
The Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Website: www.datatilsynet.dk
If you are located in another EU/EEA country, you may also have the right to complain to your local data protection authority.
- Cookies and similar technologies
Cookies are small data files stored on your computer, phone or other device. We may also use similar technologies, including pixels, local storage and technical identifiers.
We use these technologies to:
- Operate the website and customer portal
- Remember your choices and settings
- Protect login functions and prevent abuse
- Analyse website traffic and usage
- Measure the effectiveness of our communications and marketing
- Cookie categories
12.1 Essential cookies
Essential cookies support basic functions such as navigation, login, security, session management and recording cookie choices.
These cookies may be used without consent because they are necessary to provide the website or a function expressly requested by the user.
12.2 Functional cookies
Functional cookies remember choices and settings that are not strictly necessary for the website’s basic operation.
These cookies are only used with your consent unless a specific cookie is necessary to provide a function you have requested.
12.3 Analytics cookies
Analytics cookies help us understand how visitors use our website, including which pages are visited and whether technical errors occur.
These cookies are only used with your consent.
12.4 Marketing cookies
Marketing cookies may be used to measure campaigns, track activity across websites or provide more relevant advertising.
These cookies are only used with your consent.
- Cookie declaration
The current list of cookies, providers, purposes and expiry periods is available through our cookie settings or cookie declaration:
[Insert link to cookie settings or automatic cookie declaration]
The list is updated when our cookies or suppliers change.
- Cookie consent and preferences
When you first visit our website, you can accept all non-essential cookies, reject them or select specific categories.
Non-essential cookies are not placed until you have given your consent.
You can change or withdraw your consent at any time through:
[Insert link or button: “Cookie settings”]
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
You can also delete cookies through your browser settings. If you block essential cookies, parts of the website or customer portal may not function correctly.
- Automated decision-making
We do not use personal data to make automated decisions that produce legal effects or similarly significantly affect you.
We may use automated security and spam controls to identify and restrict suspected abuse. These controls may result in temporary restrictions or suspension, which may be reviewed by our support team.
- Changes to this policy
We may update this policy when our services, suppliers, technologies or legal obligations change.
The current version will always be available on mySMTP.com and will show the date of the latest update.
If we make material changes, we may notify registered customers by email or through our platform.