Draft — pending legal review. This text describes how Zomail works today but has not yet been reviewed by counsel. Placeholders in [brackets] will be completed before final publication.
Privacy Policy
This policy explains how [COMPANY LEGAL NAME] ("Zomail", "we") handles personal data when organisations and their users use Zomail Cloud, the Zomail mobile apps for iOS and Android (io.zomail.mail), the webmail and admin console, and this website. It is written to meet the EU/UK General Data Protection Regulation (GDPR), Vietnam's Decree 13/2023/NĐ-CP on personal data protection, and similar laws.
In short: we process data to run the service your organisation uses. We do not sell personal data, we do not use it for advertising, and our apps and websites contain no analytics, advertising or tracking SDKs.
1. Who is responsible for your data
Zomail is used by organisations (our customers) that give accounts to their staff and others. There are two roles:
- Your organisation is the controller
- for the content of its workspace — mail, calendars, contacts, Drive files and meetings — and for the user accounts it creates. Zomail processes that content on the organisation's behalf, as its processor, following its instructions and our Terms of Service. If your account comes from your employer or another organisation, its administrator decides how your workspace data is used: contact them first, and we will help them answer you.
- Zomail is the controller
- for the data we need to run our own business: customer signup and billing details, the account and security data we use to protect the service, data about visitors to zomail.io, and messages you send us.
With a Private Mail licence the software runs on the customer's own server: the customer operates that server and controls all data on it. Zomail receives only the limited service data described under "Private Mail servers".
2. The data we process
- Account data
- Name, e-mail address, password, a recovery e-mail address if you add one, language and time-zone preferences, and 2-step verification settings. Passwords are stored as bcrypt hashes; while you are signed in, an encrypted copy is kept with your session so our servers can open your mailbox for you.
- Signup and billing data
- Company name, contact name, e-mail address and phone number, the chosen domain, buyer type, tax code (for an individual buyer this can be a national ID number, as Vietnamese invoicing requires), billing address, the IP address used to sign up or pay, orders, invoices, receipts and payment status. Card and wallet details are entered on the payment provider's page (PayPal or OnePay) and are never received or stored by Zomail; we receive the payment result, a reference, the card type, and for PayPal the payer's e-mail address.
- Workspace content
- The mail and attachments, calendars, contacts, tasks, Drive files and documents, filters and settings you and your colleagues store, and meeting details. We store it to provide the service.
- Security and service logs
- IP address, time, browser or app, and device name of sign-ins and sessions; server logs (which include IP addresses and, for mail, sender and recipient addresses, but not message content); message-trace records (sender, recipients, subject, time, size, spam and delivery results of each message passing through the platform) so administrators can see what happened to a message; and audit logs of administrative and security actions.
- Mobile app data
- A device push token, device name, model, operating-system and app version, your notification choices, and a random installation ID, so the apps stay signed in and can receive notifications. See "Mobile apps".
- Support and contact
- What you write to us and our replies.
- Website visitors
- zomail.io sets no cookies and has no analytics or advertising tags. It loads its typeface from Google Fonts (which receives your IP address) and fetches prices from our own API.
We do not collect precise location, the contacts stored on your phone, or data for advertising. We do not ask for special categories of data; anything of that kind in your mail or files is workspace content controlled by your organisation.
3. How we use data, and our legal bases
We use personal data only for the purposes below. Under the GDPR and Decree 13/2023 our legal bases are: performance of a contract (providing the service you or your organisation signed up for), legal obligation (for example accounting records or lawful requests from authorities), legitimate interests that do not override your rights (security and abuse prevention), and consent where we ask for it — you can withdraw consent at any time, without affecting processing that already took place.
- Provide the service
- Deliver, store, sync and display your mail, calendars and files; send the notifications you turn on; run the features you use. — Contract (for workspace content: on your organisation's instructions).
- Accounts and billing
- Create the workspace, verify signups, allow one free trial per organisation, invoice, take payments and send renewal notices. — Contract; legal obligation for invoices.
- Security and abuse prevention
- Automated spam and malware filtering of mail (including checking sending servers against public DNS blocklists such as Spamhaus), detection of compromised accounts, sending limits, sign-in protection and audit logs. — Legitimate interests; contract.
- Support and troubleshooting
- Answer your requests and fix problems. Staff look at workspace content only when you or your administrator ask us to, or when it is necessary to investigate abuse or a security incident. — Contract; legitimate interests.
- Service e-mails
- Messages about your account, security, billing and changes to the service. We do not send marketing e-mail without consent. — Contract; consent for marketing.
- Legal requirements
- Keep accounting records and respond to valid legal requests. — Legal obligation.
Zomail does not use your content to train AI models, does not sell personal data, and does not make decisions with legal or similarly significant effects about you by automated means alone.
5. International transfers
Zomail is offered worldwide and our sub-processors operate in several countries, so personal data may be processed outside your country — for example backups in Singapore and notifications through Apple and Google. Where the law requires it we use appropriate safeguards (such as standard contractual clauses) and carry out the transfer impact assessment that Decree 13/2023 requires for transfers out of Vietnam. Details are in our data processing agreement, available on request.
6. How long we keep data
- Workspace content
- As long as the account exists. Trash and Junk are emptied automatically after 30 days (your organisation can choose 7, 30, 90 days or never). A mailbox deleted by an administrator can be restored for 30 days, then it is removed.
- Server logs
- 7 days, then deleted automatically.
- Message-trace records
- 30 days. Records of messages sent through our servers (sender, recipients, subject, delivery status — not the body) are kept for 90 days for delivery troubleshooting and abuse handling.
- Audit logs and DMARC reports
- 400 days. When an account is erased, its e-mail address in the audit log is replaced by an anonymous code.
- Unpaid workspaces
- Suspended 7 days after the renewal date, cancelled after 60 more days, and scheduled for deletion 90 days after that, with notice to the owners 14 days before.
- Deletion requests
- An organisation deletion runs 14 days after we approve it, so a mistake can still be undone. An erasure request under data-protection law (Decree 13/2023, GDPR) is completed within 72 hours, without a grace period, and we send the customer a certificate of erasure.
- Backups
- Encrypted backups cannot be edited piece by piece; they age out under our retention schedule, at the latest about 379 days (12 monthly copies plus pruning) after the data was deleted. Until then, erased accounts are listed (as one-way hashes) so that any restore deletes them again before use.
- Billing records
- Orders, invoices, receipts and credit notes are kept for as long as accounting and tax law requires (in Vietnam, at least 10 years), also after the workspace is deleted. They contain no mail content.
- Signup records
- Passwords and verification codes of unfinished signups are wiped when the signup expires. The signup record itself (contact details, IP address) is kept as part of our customer records, and the contact e-mail, phone number and company name used for a free trial are kept so that each organisation gets one trial. [RETENTION PERIOD FOR SIGNUP RECORDS — TO BE SET]
- Compliance archive
- Only if your organisation turns it on: messages are kept for the retention period it sets (7 years by default), under its control.
7. Security
- Encryption in transit: TLS for the web, the apps, IMAP, SMTP submission, CalDAV and CardDAV; mail exchanged with other servers uses TLS whenever they support it, enforced with MTA-STS and DANE where the receiving domain publishes them.
- Backups are encrypted before they are stored off-site; Drive files are encrypted at rest.
- 2-step verification with an authenticator app (with recovery codes) is available to every user and required for administrators.
- Passwords are stored as bcrypt hashes; sessions and devices can be reviewed and signed out; sign-in attempts are rate-limited.
- Access to production systems is limited to staff who need it, and administrative actions are recorded in audit logs.
- Incoming mail is scanned for malware and spam.
Zomail does not offer end-to-end encryption: our servers process message content in order to deliver, filter, index and display it. No system is perfectly secure. If a personal data breach affects you, we will inform your organisation and the competent authorities as the law requires (under Decree 13/2023, within 72 hours).
8. Your rights and how to use them
Depending on where you live, you have the right to be informed; to access, correct and delete your data; to restrict or object to processing; to withdraw consent; to data portability; and to complain to an authority. In Vietnam these are the rights of data subjects under Article 9 of Decree 13/2023.
- Access and correction: see and change your name, recovery address and security settings in Settings at any time; ask your administrator or us for anything else.
- Deletion: in webmail or the mobile app, open Settings → Account → Delete account. For a mailbox that belongs to an organisation, the organisation's owners or administrators review the request, because that mailbox and its mail are the organisation's records. If you are the sole owner of a workspace you created yourself, the request deletes that workspace. An owner can also ask us to delete the whole organisation.
- Export: copy your mail, calendars and contacts out at any time over IMAP, CalDAV and CardDAV, download single messages (.eml) and Drive files. A full export of an account or workspace is available on request through your organisation's administrator or Zomail support.
- Objection and restriction: write to us and we will stop the processing unless we have compelling legitimate grounds or need it for legal claims.
- Complaints: you may complain to your data-protection authority — in Vietnam, the Department of Cybersecurity and High-Tech Crime Prevention (A05), Ministry of Public Security; in the EU or UK, your local supervisory authority.
If your account is provided by an organisation, send requests about workspace content to its administrator. You can also write to privacy@zomail.io; we will forward the request and help the organisation answer. We reply within the time limits the law sets (for erasure under Decree 13/2023: 72 hours) and may need to verify your identity first.
9. Mobile apps
The Zomail apps for iOS and Android (io.zomail.mail) connect to your organisation's Zomail server, to Apple or Google for notifications and, while you sign in, to Zomail Cloud (api.zomail.io) to find which server holds your address. They contain no advertising, analytics, crash-reporting or tracking SDKs and do not track you across other companies' apps or websites. Images in a message are loaded from the sender's servers only after you tap to show them.
- Camera
- Only to scan the QR code shown when you sign in to Zomail on a computer. Camera images are not stored or sent.
- Notifications
- New mail, calendar reminders, meeting invitations and new-device sign-in alerts, if you allow them. You choose the categories and whether previews show the sender and subject.
- Photos and files
- Only when you pick a photo or file to attach to a message; nothing else on the device is read.
- Face ID, Touch ID, fingerprint
- To lock the app and to approve QR sign-ins. The check is done by your device; biometric data never leaves it and is never available to Zomail.
The apps keep recent mail on your device for speed and offline reading, protected by your device's own storage protection; signing out removes it. Sign-in tokens are kept in the iOS Keychain or protected by the Android Keystore. On Android, the Google components that deliver notifications and read QR codes (Firebase Cloud Messaging, ML Kit) may send Google limited diagnostic data under Google's terms. You can request deletion of your account inside the app (Settings → Account → Delete account), as described above.
10. Private Mail servers
With a Private Mail licence, mail and files stay on the customer's server. For licensing, updates and monitoring, the server regularly sends Zomail its software version, health checks, usage totals (number of mailboxes and storage used), its domain names, backup status and public DKIM keys — not mailbox content or user details. So that Zomail can help restore the server, its backup key is held by Zomail in encrypted form. If the customer uses Zomail's notification relay, its users' push notifications pass through Zomail Cloud to Apple and Google; if it uses backup storage provided by Zomail, backups are encrypted on the customer's server before upload. Cloud AI is enabled on a Private server only by Zomail, after a data processing agreement.
11. Children
Zomail is a service for organisations and professionals. It is not directed at children: users must be at least 16 years old, and the mobile apps are listed for adults (18+). If you believe a child's data has been given to us, contact us and we will delete it.
12. Changes to this policy
When we change this policy, we update the effective date and version at the top of this page. For material changes we e-mail workspace owners before the changes take effect.
13. Contact
[COMPANY LEGAL NAME], [ADDRESS]. Privacy questions and requests: privacy@zomail.io. [DATA PROTECTION OFFICER / EU-UK REPRESENTATIVE — IF REQUIRED]