Skip to main content

Privacy and Cookie Policy for mySMTP

Last updated: 1 September 2026

This policy explains how SMTP.dk ApS, trading as mySMTP (“mySMTP”, “we”, “us”), processes personal data and uses cookies in connection with our website, customer portal and SMTP services.

We process personal data in accordance with the EU General Data Protection Regulation (“GDPR”), the Danish Data Protection Act and other applicable laws.

We only use non-essential cookies with your consent.

  1. Data controller and contact details

SMTP.dk ApS is the data controller for personal data relating to website visitors, customers, contacts and users of our platforms.

SMTP.dk ApS, trading as mySMTP
Refshalevej 163A
1432 Copenhagen K
Denmark
Company registration number: 29849439
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
Website: www.mysmtp.com

You are welcome to contact us if you have questions about how we process personal data or if you wish to exercise your rights.

  1. When is mySMTP a controller or processor?

mySMTP is the data controller for personal data that we process for our own purposes. This includes customer administration, billing, support, security, operations and marketing.

When we provide SMTP services and process email data on behalf of a customer, the customer is generally the data controller and mySMTP is the data processor.

Our processing of email data on behalf of the customer is governed by our separate Data Processing Agreement (“DPA”).

  1. Personal data we process

3.1 Website visitors

When you visit our website, we may process technical information such as:

  • IP address
  • Browser and device type
  • Operating system
  • Pages visited and time of visit
  • Referring website
  • Cookie choices and consent status

Necessary technical information is processed to operate and protect the website.

Information used for analytics or marketing is only processed if you have consented to the relevant cookies.

3.2 Account registration and purchase of services

When you create an account or purchase a service, we may process:

  • Name and contact details
  • Address and country
  • Company name and company or VAT number
  • Login and account information
  • Order, payment and billing information
  • Subscription, usage and purchase history
  • IP addresses and domains connected to the account
  • Communications between you and mySMTP

We process this information to create and administer your account, provide the requested services, receive payment and meet our legal obligations.

3.3 Support and other communications

When you contact us, we may process:

  • Name and contact details
  • Customer and account number
  • The content of your enquiry
  • Technical information and relevant log data
  • Any attached documents or screenshots

We use this information to respond to your enquiry, provide support, document our communication and improve our services.

Please do not send sensitive personal data or passwords unless necessary and specifically agreed with us.

3.4 SMTP services and email data

When a customer uses our SMTP services, we may process on the customer’s behalf:

  • Sender and recipient email addresses
  • Sender domains and IP addresses
  • Subject lines and technical email headers
  • Email content during transmission
  • Sending time and delivery status
  • SMTP responses, bounce information and error messages
  • Spam, security and delivery-related information

Email content is processed temporarily to the extent necessary for transmission, security, spam filtering and error handling.

Email content is not stored permanently. However, it may temporarily remain in a mail queue or be processed when necessary for delivery, troubleshooting, security or abuse handling.

The customer is responsible for the recipient data, email content and legal basis for sending the emails. mySMTP processes this data according to the customer’s documented instructions and the applicable DPA.

3.5 Newsletters and marketing

If you subscribe to our newsletter or otherwise consent to marketing, we process your name, email address and information documenting your consent.

We may record email opens and clicks if you have given the necessary consent to such tracking.

You can unsubscribe at any time by using the unsubscribe link in our emails or contacting This email address is being protected from spambots. You need JavaScript enabled to view it..

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

3.6 Security and abuse prevention

We may process account, traffic and technical information to:

  • Prevent spam, phishing and fraud
  • Detect compromised accounts
  • Protect our systems, domains and IP addresses
  • Investigate security incidents and abuse
  • Handle complaints from recipients and email providers
  • Comply with lawful requests from public authorities
  1. Purposes and legal bases

We process personal data for the following purposes and on the following legal bases:

Purpose

Legal basis

Account registration and administration

Performance of a contract, GDPR Article 6(1)(b)

Delivery of requested services

Performance of a contract, Article 6(1)(b)

Billing and accounting

Legal obligation, Article 6(1)(c)

Customer support and communication

Performance of a contract and legitimate interests, Article 6(1)(b) and (f)

Operations, security and abuse prevention

Legitimate interests, Article 6(1)(f)

Legal claims and disputes

Legal obligation and legitimate interests, Article 6(1)(c) and (f)

Newsletters and marketing

Consent, Article 6(1)(a), or legitimate interests where permitted by law

Analytics and marketing cookies

Consent, Article 6(1)(a)

Essential cookies

Legitimate interests or necessity to provide a requested function

Our legitimate interests include operating, protecting and improving our services, providing support, preventing abuse and documenting our activities.

  1. Recipients and data processors

We do not sell personal data or disclose it to third parties for their own marketing purposes.

We may share personal data with suppliers and processors where necessary for:

  • Hosting and data centre operations
  • Payment processing
  • Accounting and billing
  • Customer service and support
  • Email communications
  • Security, monitoring and abuse prevention
  • Analytics, where consent has been given
  • Legal advice and compliance with official requests

Our processors may only process personal data according to our instructions and must protect it in accordance with applicable law.

An updated list of relevant subprocessors is available here:

[Insert link to subprocessor list]

  1. Transfers outside the EU/EEA

We aim to host and process personal data within the EU/EEA.

If a supplier processes personal data outside the EU/EEA, we ensure that a valid transfer mechanism is in place. This may include an adequacy decision by the European Commission or the European Commission’s Standard Contractual Clauses.

You may contact us for further information about the applicable transfer mechanisms.

  1. Retention and deletion

We only retain personal data for as long as necessary for the purpose for which it was collected or as required by law.

As a general rule:

  • SMTP traffic logs and technical metadata are normally retained for up to 30 days
  • Email content is not stored permanently but may temporarily remain in a mail queue
  • Account and subscription information is retained while the customer relationship remains active
  • Inactive accounts may be deleted after 12 months of inactivity and prior notice
  • Invoices and accounting records are retained for the period required by applicable accounting law
  • Support communications are retained for as long as necessary for support, documentation and potential legal claims
  • Records of marketing consent are retained for as long as necessary to document the consent
  • Information concerning abuse, security incidents and disputes may be retained for longer where necessary for documentation or legal claims
  • Data contained in backups is deleted or overwritten according to our backup procedures

Information may be retained for longer where necessary to establish, exercise or defend a legal claim.

  1. Information security

We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure.

These measures may include:

  • Access controls
  • Encrypted communications
  • Monitoring and logging
  • Spam and malware filtering
  • System updates and maintenance
  • Backup and recovery procedures
  • Restricted access for employees and suppliers

However, no internet-based service can be guaranteed to be completely secure.

  1. Your rights

Subject to applicable data protection law, you may have the right to:

  • Access the personal data we process about you
  • Have inaccurate or incomplete information corrected
  • Have personal data deleted where the relevant conditions are met
  • Restrict the processing of your personal data
  • Object to processing based on legitimate interests
  • Object to direct marketing
  • Receive certain data in a structured and machine-readable format
  • Withdraw your consent
  • Submit a complaint to a supervisory authority

These rights may be limited by applicable law, the rights of others or our need to document and defend legal claims.

To exercise your rights, please contact This email address is being protected from spambots. You need JavaScript enabled to view it.. We may request proof of identity where necessary to ensure that personal data is not disclosed to an unauthorised person.

  1. Complaints

If you are dissatisfied with how we process your personal data, you are welcome to contact us first.

You may also submit a complaint to:

The Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Website: www.datatilsynet.dk

If you are located in another EU/EEA country, you may also have the right to complain to your local data protection authority.

  1. Cookies and similar technologies

Cookies are small data files stored on your computer, phone or other device. We may also use similar technologies, including pixels, local storage and technical identifiers.

We use these technologies to:

  • Operate the website and customer portal
  • Remember your choices and settings
  • Protect login functions and prevent abuse
  • Analyse website traffic and usage
  • Measure the effectiveness of our communications and marketing
  1. Cookie categories

12.1 Essential cookies

Essential cookies support basic functions such as navigation, login, security, session management and recording cookie choices.

These cookies may be used without consent because they are necessary to provide the website or a function expressly requested by the user.

12.2 Functional cookies

Functional cookies remember choices and settings that are not strictly necessary for the website’s basic operation.

These cookies are only used with your consent unless a specific cookie is necessary to provide a function you have requested.

12.3 Analytics cookies

Analytics cookies help us understand how visitors use our website, including which pages are visited and whether technical errors occur.

These cookies are only used with your consent.

12.4 Marketing cookies

Marketing cookies may be used to measure campaigns, track activity across websites or provide more relevant advertising.

These cookies are only used with your consent.

  1. Cookie declaration

The current list of cookies, providers, purposes and expiry periods is available through our cookie settings or cookie declaration:

[Insert link to cookie settings or automatic cookie declaration]

The list is updated when our cookies or suppliers change.

  1. Cookie consent and preferences

When you first visit our website, you can accept all non-essential cookies, reject them or select specific categories.

Non-essential cookies are not placed until you have given your consent.

You can change or withdraw your consent at any time through:

[Insert link or button: “Cookie settings”]

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

You can also delete cookies through your browser settings. If you block essential cookies, parts of the website or customer portal may not function correctly.

  1. Automated decision-making

We do not use personal data to make automated decisions that produce legal effects or similarly significantly affect you.

We may use automated security and spam controls to identify and restrict suspected abuse. These controls may result in temporary restrictions or suspension, which may be reviewed by our support team.

  1. Changes to this policy

We may update this policy when our services, suppliers, technologies or legal obligations change.

The current version will always be available on mySMTP.com and will show the date of the latest update.

If we make material changes, we may notify registered customers by email or through our platform.