Legal
Privacy policy
This English version is a translation for your convenience. In case of doubt, the German version applies.
This privacy policy describes which personal data Safkom GmbH processes when operating the Mailcockpit website and app, for what purposes, how long the data is kept and what rights you have.
It is based on the Swiss Federal Act on Data Protection (FADP, SR 235.1) as in force since 1 September 2023 and the Data Protection Ordinance (DPO, SR 235.11). For people in the European Union (EU) and the European Economic Area (EEA, including Liechtenstein) it also contains the information required by the EU General Data Protection Regulation (GDPR); these passages are marked “GDPR”.
The essentials
- The website and the app run on our own server in Switzerland (Infomaniak, data centre in the Canton of Geneva).
- The website sets no cookies, uses no tracking and loads no content from third-party servers.
- We read the emails of connected mailboxes only to make the dashboard work – on behalf of the customer who connects the mailboxes.
- No tracking, no analytics tools, no advertising, no selling of data, no profiling, no training of AI models with your data.
- The app sets only one strictly necessary cookie for signing in.
- We store mailbox passwords encrypted; you can set up a second factor for your account.
- You can delete your account yourself and export your team’s data. Backup copies expire after 14 days at most.
1. Controller and contact
The controller for the processing described in this policy as Safkom’s own processing (see section 3) is:
Safkom GmbH
Oberdorfstrasse 11
5722 Gränichen
Switzerland
UID: CHE-283.267.062
Email, including for data protection matters: contact@mailcockpit.app
Hereinafter “Safkom”, “we” or “us”.
We have not appointed a data protection advisor under Art. 10 FADP or a data protection officer under Art. 37 GDPR. Please send all requests to the address above.
2. Scope
This privacy policy applies to:
- our website mailcockpit.app (the address mailcockpit.ch redirects there), including the waitlist;
- the “Mailcockpit” web application at my.mailcockpit.app, also when you install it as an app on your computer or phone (a so-called progressive web app, PWA);
- the emails that Mailcockpit itself sends (system emails);
- your contact with us, for example by email.
It does not apply to other providers’ websites we link to, nor to your email provider (for example Hostpoint, GMX, Microsoft), which processes your emails under its own rules.
3. Two roles: controller and processor
With Mailcockpit we have two different roles:
3.1 Safkom as controller. For the data we need to operate the website and the service itself, we decide how and why it is processed. This mainly covers website and waitlist data, account and sign-in data, team and role management, security logs, system emails, device notifications, support and (later) billing.
3.2 Safkom as processor. For the content of connected mailboxes and everything a team creates from it (projects, tasks, notes, drafts, daily overviews, the who-did-what log), we process the data on behalf of our customer (Art. 9 FADP; processor under Art. 28 GDPR). The customer is the person or company that opens a team and connects mailboxes. The customer is the controller of this data and decides which mailboxes are connected and who in the team has access. The details are set out in our data processing agreement. We still describe this processing here so that it is transparent what happens with the data.
3.3 Do you correspond with one of our customers? Then your data (for example your name, email address and the content of your emails) may be contained in a mailbox connected to Mailcockpit. For questions and requests (for example access or erasure), please contact that customer. If we receive such a request, we forward it as far as we can identify the customer responsible.
3.4 Private use. If you use Mailcockpit as an individual exclusively for personal purposes, the FADP does not apply to your own processing (Art. 2 para. 2 let. a FADP; similarly Art. 2 para. 2 let. c GDPR). We still treat the content of your mailboxes in exactly the same way: only to provide the service and only on your instructions.
4. Which data we process and why
4.1 Account
- Data: name, email address, password (only as a non-reversible hash using scrypt, never in plain text), time the email address was confirmed, settings, time of last sign-in, failed-attempt counter and any lockout, version and time of your acceptance of the terms. Optionally a second factor (TOTP secret, stored encrypted) and recovery codes (stored only as hashes). While you change your email address, also the new, not yet confirmed address.
- Purpose: setting up and managing the account, signing in, protecting the account, communicating with you about the service.
- Retention: until you delete the account (see section 9).
4.2 Teams, roles and invitations
- Data: team name, type (personal space or team), plan and, where applicable, end of a trial, memberships with role (owner, admin, member), permissions per mailbox, settings per membership (for example daily overview by email, device notifications), invitations (email address of the invited person, intended role, who invited them, times).
- Visibility: team members see the names, email addresses and roles of the other members. Which team mailboxes and which data derived from them a member can see is decided by the owner and the admins (permissions per mailbox); the owner always sees all team mailboxes. Mailboxes in a person’s personal space are visible only to that person.
- Purpose: collaboration in the team, managing permissions, enforcing plan limits.
- Retention: until the team is deleted or you leave the team. Invitations expire after 7 days; we delete the invitation details 90 days after acceptance, revocation or expiry.
4.3 Sign-in, sessions and security log
- Sessions: when you sign in, we store a session: a hash of the random sign-in token (the token itself exists only in your browser’s cookie), times, the active team, the IP address and your browser identifier (user agent). A session ends when you sign out, at the latest after 30 days, and is then deleted.
- Security log: we log security-relevant events with time, account or team concerned and IP address: registration, sign-in, failed sign-in, lockout after failed attempts, sign-out, enabling and disabling the second factor, use of a recovery code, changing and resetting the password, changing the email address and profile, creating, renaming, exporting and deleting teams, plan changes, invitations, changes to memberships and permissions, signing out all sessions and deleting the account. Passwords, codes, tokens and email content are never logged.
- Purpose: protecting accounts and the service, detecting and preventing abuse (for example limiting sign-in attempts), investigating security incidents, evidence.
- Retention: security log 12 months from the event – for security and evidence reasons also if the account has since been deleted.
4.4 Mailbox credentials (on behalf of the customer)
- Data: name and address of the mail servers (IMAP and SMTP), ports, connection type, user name, password or – when signing in with Microsoft – access tokens, your own sender addresses and your signature.
- Protection: we store passwords and tokens encrypted (AES-256-GCM) with a separate key per team. The master key from which these keys are derived exists only on the server and is not part of the backups.
- Purpose: connecting to your mailboxes to fetch, send and move emails.
- Retention: until the mailbox is removed from the team or the team is deleted.
4.5 Mailbox content and team work data (on behalf of the customer)
- Data: we fetch the emails from connected mailboxes and store a copy on our server, separated per team in its own database: headers (sender, recipients, subject, date, technical identifiers), content (text and HTML), attachments, folders and status (for example read). In addition, the data you create in the dashboard: areas, projects, tasks, deadlines, reminders, notes, assignments, drafts, your own uploads, daily overviews and notifications.
- Sensitive data: emails may contain data about third parties and also sensitive personal data (for example health, proceedings, religion, social assistance measures). The customer decides which emails end up in the dashboard by choosing the mailboxes.
- Actions in the mailbox: on your instruction we send emails via your mailbox’s SMTP server, move emails to your mailbox’s trash folder and set the “read” flag. We make no other changes to your mailbox. If a mailbox is removed from the dashboard, the emails in the mailbox itself remain unchanged.
- Purpose: solely providing the dashboard’s features for the team concerned (displaying, searching, organising, reminding, replying). Automatic sorting (for example assigning an email to a project based on sender or subject) only serves to organise your emails and is not profiling.
- Retention: as long as the mailbox is connected and the team exists. If you remove a mailbox, we immediately delete the copies stored for it. If you delete a team, we immediately delete all its data. After a subscription ends, the period set out in the terms and conditions applies. Backup copies expire after 14 days at most.
4.6 Who-did-what log (on behalf of the customer)
- Data: for changes in the team we record who (identifier and name of the member) did what and when (for example “replied”, “assigned to a project”, “completed a task”), with a reference to the conversation, task or project concerned – without email content. We also record for each draft who created, edited, took over, discarded or sent it and when. In addition, the dashboard briefly shows who currently has an email open or is writing a reply; this indicator is not stored and expires after about one minute.
- Visibility: team members, each for the mailboxes they are allowed to see.
- Purpose: collaboration in the team (“last edited by”), avoiding duplicate replies.
- Retention: as long as the team exists. If a member leaves the team, their previous entries remain in the team’s log with their name.
4.7 System emails
- Data: your email address, your name and the content of the system email.
- What for: confirming your email address (link valid for 48 hours), resetting your password (link valid for 60 minutes), confirming a new email address, invitations to a team (link valid for 7 days), notices about your plan and your seats in a team and – only if you switch it on – the daily overview by email. The daily overview contains titles of tasks, projects and deadlines and thus information originating from your emails.
- Sending: via the mail server of our email provider Hostpoint AG, Switzerland, from a sender address at mailcockpit.app.
- Invitations to third parties: if a team invites someone, that person receives an email from us with the name of the team and of the person who invited them.
4.8 Device notifications (push, optional)
- Optional and per device: you only receive notifications on your phone or computer if you switch them on for that device. You can switch them off again at any time.
- Data we store: the delivery address (endpoint) your browser receives from its vendor’s push service, your device’s public keys, the browser identifier, times and an error counter.
- Content: a notification may contain, for example, the sender, subject or project of a new email or a due reminder. The content is end-to-end encrypted (standard RFC 8291): only your device can read it.
- Browser vendors’ push services: the encrypted notification is technically delivered via the push service of your browser’s vendor – depending on the browser Google (Firebase Cloud Messaging), Apple, Mozilla or Microsoft (Windows Push Notification Service). These services cannot read the content but see metadata such as delivery address, time and size of the notification. Your browser, not we, determines which service is used. These services may use servers outside Switzerland, in particular in the USA (see section 8).
- Retention: until you switch notifications off on the device, delete your account or the push service reports the delivery address as invalid.
4.9 Setup assistant when connecting a mailbox
When you enter an email address while adding a mailbox, the dashboard suggests the matching server settings. For this, our server uses:
- a built-in list of known providers;
- a DNS lookup of the mail servers (MX record) for the domain part of the address (for example “mycompany.ch”);
- a query to the public Mozilla/Thunderbird directory (autoconfig.thunderbird.net) – likewise only with the domain part, never with the full email address.
The queries are made from our server, so Mozilla sees our server’s address, not yours. We store nothing except the settings you then adopt. If the domain belongs to an individual (for example “firstname-lastname.ch”), even the domain part can be personal data.
4.10 Signing in with Microsoft (optional, once available)
For mailboxes at Microsoft (Outlook, Hotmail, Microsoft 365) you can sign in directly with Microsoft and allow Mailcockpit to access your mailbox. Signing in takes place on Microsoft’s pages; Microsoft processes data under its own privacy policy. We receive access tokens for IMAP and SMTP and the email address and store the tokens encrypted like a password (section 4.4). You can revoke the permission at any time in your Microsoft account or remove the mailbox in the dashboard.
4.11 Remote images in emails
Images that an email would load from the internet are blocked by default. If you explicitly load them for an email or a sender, your browser fetches the images directly from the sender’s server. That server can then see, for example, your IP address, the time and the fact that the email was opened. If you add a signature logo via a web address, our server fetches the image once from that address.
4.12 Contact and support
- Data: your contact details and the content of your message; for support cases, any further information you give us.
- Email to us: we receive and store emails to contact@mailcockpit.app in our mailbox at our email provider, Hostpoint AG, Switzerland.
- Access to team data: we look at your team’s content (for example a specific email) only if you ask us to and only as far as necessary to solve the problem (see section 5).
- Retention: 2 years after the request has been closed; longer if the correspondence forms part of our business records (up to 10 years).
- Setup by video call (for plans with setup): the appointment takes place via Zoom (USA) or Microsoft Teams (Microsoft, USA); we agree on the tool with you when scheduling. Video, audio and – if you share your screen – its content are transmitted; emails may become visible. We do not record and do not store any content; you enter passwords yourself. The video call provider’s privacy terms apply; for transfers abroad see section 8.
4.13 Payment and billing data
Applies only once payment is introduced. Until then we process no payment data. We will name the payment provider in this policy before we introduce payment.
- Data: name or company, billing address, VAT number where applicable, chosen plan, invoices, payment status and the identifier at the payment provider.
- Payment provider: payments are handled by a specialised payment provider. We do not see or store full card or account details.
- Purpose: billing, accounting, dunning, compliance with legal obligations.
- Retention: invoices and accounting records 10 years (Art. 958f of the Swiss Code of Obligations); other data until the end of the contractual relationship.
4.14 Website, hosting and server logs
- Hosting: the website and the app run on our own virtual server at Infomaniak Network SA, Geneva, in a data centre in Switzerland (Plan-les-Ouates, Geneva).
- No cookies, no tracking: the website sets no cookies, stores nothing in your browser and uses no analytics, advertising or social media services.
- No third-party content: the website and the app load no fonts, scripts, images or other content from third-party servers; everything comes from our server. (Exception in the app: images in emails that you explicitly load, section 4.11.)
- Access log: for every request to the website or the app, the web server stores the IP address, time, requested address, status code, amount of data transferred and browser identifier (user agent) – no content. Purpose: operation, security and troubleshooting. Retention: 30 days at most, after which it is deleted automatically.
- Domains and DNS: the domain mailcockpit.app is registered with Cloudflare, Inc. (USA), which also hosts its DNS records. We use Cloudflare for DNS only, without proxy: Cloudflare merely answers the question at which IP address our server can be reached. This query is usually made by your internet provider’s DNS resolver. The pages themselves and everything you enter do not pass through Cloudflare but travel directly between your device and our server in Switzerland. The domain mailcockpit.ch is registered with Hostpoint AG (Switzerland), which also hosts its DNS records; our server redirects requests to mailcockpit.ch to mailcockpit.app.
- Encryption: all connections are encrypted with HTTPS. The certificates are issued by Let’s Encrypt (Internet Security Research Group, USA); Let’s Encrypt only receives our domain names, no visitor data.
4.15 Waitlist and early access
- How it works: the waitlist form sends nothing to our server. It opens a prepared message to contact@mailcockpit.app in your email app. We only receive your details once you send that message.
- Data: name, email address and – optionally – company, number of mailboxes, number of people and plan of interest, as well as your consent; plus the usual information contained in an email (for example the time).
- Purpose: we use the details only to inform you about early access and the launch of Mailcockpit and to take your wishes into account in development. We do not sell them or pass them on to third parties.
- Where: the message arrives in our mailbox at Hostpoint AG, Switzerland (section 4.12).
- Retention: we delete your details when you ask us to – a short email to contact@mailcockpit.app is enough – or as soon as we no longer need them for this purpose.
- Consent: you can withdraw your consent at any time with effect for the future.
4.16 Only one free trial per person
- Purpose: where we offer a free trial, each person should use it only once. This protects the offer against abuse.
- Data: when an account is deleted or its sign-in address is changed, we store a check value of the previous email address; when a mailbox is connected, a check value of that mailbox (mail server and user name as well as the mailbox’s own address). We also store the reason or a random identifier of the account, whether a trial was running, and the date. A check value is a hash (HMAC-SHA256) of the normalised address, calculated with a secret key of our server. We do not store the address itself; without the secret key it cannot be recovered from the check value, not even by trial and error.
- Retention: 24 months from the last use, after which the check values are deleted automatically.
- Your rights: if you are wrongly refused a trial, contact us and we will reset the block.
5. What we don’t do
- We show no advertising and sell no data.
- We use no tracking, no analytics tools (for example Google Analytics) and no social media plug-ins – neither on the website nor in the app.
- We create no profiles of you or your correspondents.
- We do not use your data to train AI models and do not pass it on to AI providers.
- Safkom staff do not look at the content of your mailboxes – unless (a) you explicitly ask us to in support, (b) it is unavoidable to fix a fault or a security incident, and then only as far as necessary, or (c) we are legally obliged to.
6. Legal bases
Switzerland (FADP): we process personal data according to the principles of Art. 6 FADP (lawfully, in good faith, proportionately, for specific purposes, transparently, accurately). Where a justification is required, we rely on the performance of the contract with you (Art. 31 para. 2 let. a FADP), on your consent (waitlist), on our overriding interest (in particular in the security of the service and in preventing abuse) or on a legal obligation.
EU/EEA (GDPR):
| Processing | Legal basis |
|---|---|
| Account, teams, providing the service, system emails about your account, daily overview, device notifications, setup assistant | contract (Art. 6(1)(b) GDPR) |
| Sessions, security log, server logs of the website and the app, preventing abuse | legitimate interest in the security of the service and the protection of accounts (Art. 6(1)(f) GDPR) |
| Check values against repeated use of the trial | legitimate interest in protecting the offer against abuse (Art. 6(1)(f) GDPR) |
| Waitlist and information about early access | consent (Art. 6(1)(a) GDPR) |
| Invitation email to an invited person | legitimate interest of the inviting team in collaboration (Art. 6(1)(f) GDPR) |
| Contact and support | contract or legitimate interest in answering requests (Art. 6(1)(b) or (f) GDPR) |
| Invoices and accounting (once payment is introduced) | contract and legal obligation (Art. 6(1)(b) and (c) GDPR) |
| Establishing or defending legal claims | legitimate interest (Art. 6(1)(f) GDPR) |
| Mailbox content and team work data | processing on behalf of the customer (Art. 28 GDPR); the legal basis lies with the customer |
Where we rely on a legitimate interest, you can object (section 13).
7. Recipients and processors
We only disclose personal data where this is necessary for the service, where you initiate it or where we are legally obliged to. Our processors may only process the data on our instructions and not for their own purposes.
| Recipient | Purpose | Data | Location |
|---|---|---|---|
| Infomaniak Network SA, Geneva | operation of our own virtual server (hosting of the website and the app) | all data of the service and the website, access logs | Switzerland (data centre in Plan-les-Ouates, Geneva) |
| Hostpoint AG | our email provider: mailbox contact@mailcockpit.app (including waitlist and support), sending system emails; registration and DNS of the domain mailcockpit.ch | content and details of emails to and from us, email address, name, content of system emails (including the daily overview) | Switzerland |
| Cloudflare, Inc. | registration of the domain mailcockpit.app and DNS – DNS only, no proxy | DNS queries (name queried, IP address of the querying DNS resolver); no content of the website or the app | USA and worldwide (section 8) |
| Browser vendors’ push services: Google, Apple, Mozilla, Microsoft | delivering device notifications (only if you switch them on) | end-to-end encrypted content, metadata (delivery address, time, size) | USA and other countries (section 8) |
| Mozilla Corporation (Thunderbird directory autoconfig.thunderbird.net) | suggesting server settings (section 4.9) | domain part of an email address only | USA and other countries (section 8) |
| Microsoft (only if you use signing in with Microsoft) | signing in and access to your Microsoft mailbox | Microsoft sign-in data, tokens | as stated by Microsoft |
| Zoom or Microsoft (only for setup by video call) | setup video call (section 4.12) | video, audio, shared screen, appointment details | USA and other countries (section 8) |
| Payment provider – only once payment is introduced; we will name it here beforehand | payment processing | billing and payment data | will be stated beforehand |
In addition:
- Members of your team see the team’s data within their permissions (section 4.2).
- Recipients of your emails receive the emails you send via the dashboard – via your own mailbox’s SMTP server.
- Your email provider receives the requests with which we access your mailbox.
- Authorities and courts only receive data where we are legally obliged to provide it.
- Advisors (for example fiduciaries, auditors, lawyers) only receive data as far as necessary; they are bound by confidentiality.
- In the event of a transfer of the business (for example a sale), data may pass to the successor; we will inform you beforehand.
The list of sub-processors for mailbox content is set out in Annex 2 of the data processing agreement, which we will publish when sales start.
8. Transfers abroad
We store and process your data in Switzerland. Data may be transferred abroad in the following cases:
- Device notifications: the push services of Google, Apple, Mozilla and Microsoft may use servers in the USA and other countries. The content is end-to-end encrypted; the services only see metadata. Your browser determines which service is used, and the transfer only takes place if you switch notifications on.
- Setup assistant: query to the directory of Mozilla Corporation (USA) with the domain part of an email address; the servers may also be located in other countries.
- Signing in with Microsoft (only if you use it): as stated by Microsoft.
- Setup by video call (only if you book it): Zoom or Microsoft, USA and other countries.
- DNS of the domain mailcockpit.app: Cloudflare, USA and worldwide – DNS queries only, no content.
- Payment provider (only once payment is introduced): we will name the provider and its location here before we introduce payment.
Safeguards: the EU and EEA states ensure adequate data protection under Annex 1 DPO. For the USA, this applies under Annex 1 DPO (since 15 September 2024) to companies certified under the Swiss-U.S. Data Privacy Framework; for people in the EU/EEA, the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework of 10 July 2023 applies. Where a provider is not certified or data is transferred to another state without adequate data protection, we rely on the European Commission’s standard contractual clauses recognised by the FDPIC (Art. 16 para. 2 let. d FADP; Art. 46 GDPR) or – for device notifications and video calls, which you choose yourself – on the exception for the performance of a contract with you (Art. 17 para. 1 let. b FADP; Art. 49(1)(b) GDPR). You can obtain a copy of the safeguards on request.
9. Retention and deletion
We keep personal data only as long as necessary for the purpose or as required by law. Overview:
| Data | Retention |
|---|---|
| Server access log (website and app) | 30 days at most |
| Waitlist details | until you ask for deletion or we no longer need them |
| Account (section 4.1) | until the account is deleted |
| Sessions including IP address and browser identifier | until sign-out, 30 days at most |
| Security log | 12 months from the event, also after the account has been deleted |
| Check values against repeated use of the trial | 24 months from the last use |
| One-time links (confirmation, password, invitation) | until used or expired (48 hours, 60 minutes, 7 days) |
| Invitation details | 90 days after acceptance, revocation or expiry |
| Mailbox credentials | until the mailbox is removed or the team is deleted |
| Mailbox content and team work data | until the mailbox is removed or the team is deleted; after the end of the contract as set out in the terms and conditions |
| Who-did-what log | as long as the team exists |
| Device notifications (device registration) | until switched off, the account is deleted or the push service reports it as invalid |
| Contact and support correspondence | 2 years after closure, up to 10 years as business records |
| Invoices and accounting records (once payment is introduced) | 10 years (Art. 958f Swiss Code of Obligations) |
| Backups | 14 days at most |
Deleting your account: you can delete your account yourself under “Account & security”. We then immediately delete your account, your personal space and all teams in which you are the only member – with all their data. If you are the only owner of a team with other members, you first have to transfer ownership or delete the team. In teams with other members, the team’s data remains (it belongs to the team); your entries in the who-did-what log remain there with your name.
Backups: we back up all data every night on our server. Deleted data therefore disappears from the backups only after 14 days at most. If we restore a backup after an incident, we delete again any data whose deletion you requested in the meantime. An additional encrypted off-site copy is planned; it will be stored in Switzerland, and we will name the provider here before setting it up.
10. Data security
We protect your data with appropriate technical and organisational measures (Art. 8 FADP, Art. 1–6 DPO, Art. 32 GDPR), including:
- encrypted transmission (HTTPS with certificates from Let’s Encrypt) between your device and our server; connections to mail servers encrypted only (TLS);
- mailbox passwords and tokens encrypted (AES-256-GCM), a separate key per team, master key not in the backups;
- a separate database per team;
- passwords only as hashes (scrypt), optional second factor (TOTP), lockout after repeated failed attempts, limited sign-in attempts;
- protection against attacks via other websites, strict security rules for displaying emails, remote images blocked by default;
- a hardened server (key-only access, firewall, automatic security updates), service running with restricted rights;
- nightly backup, kept for 14 days at most.
To be frank: email content is stored in the team’s database on the server. It is protected by the server’s access restrictions but – unlike mailbox passwords – not additionally encrypted individually. No system is completely secure. Please protect your account with a strong password and the second factor.
A detailed description of the measures is set out in Annex 1 of the data processing agreement.
11. Cookies and browser storage
Website: the website sets no cookies and stores nothing in your browser.
App: the app uses a single cookie:
| Name | Purpose | Duration | Type |
|---|---|---|---|
__Host-edsid | keeps you signed in (random session token) | until sign-out, 30 days at most | strictly necessary, for our domain only, HttpOnly, Secure, SameSite=Lax |
Signing in is not possible without this cookie. It is strictly necessary and therefore requires no consent. We set no cookies for analytics, advertising or by third parties.
In addition, the app stores in your browser: the program files of the interface (so that it starts quickly and can be installed) and small interface settings (for example whether you have dismissed a notice). Email content is not cached there. You can delete this data at any time in your browser settings.
12. No automated individual decisions
We make no decisions based solely on automated processing that have legal effects for you or significantly affect you (Art. 21 FADP, Art. 22 GDPR). Automatic sorting of emails in the dashboard is not such a decision.
13. Your rights
Within the applicable law, you have in particular the following rights:
- access to whether and which personal data we process about you (Art. 25 FADP; Art. 15 GDPR);
- rectification of inaccurate data (Art. 32 para. 1 FADP; Art. 16 GDPR);
- erasure (Art. 32 para. 2 let. c FADP; Art. 17 GDPR);
- restriction or prohibition of processing or disclosure (Art. 32 para. 2 FADP; Art. 18 GDPR);
- delivery or transfer of your data in a common electronic format (Art. 28 FADP; Art. 20 GDPR);
- objection to processing based on a legitimate interest (Art. 30 para. 2 let. b FADP; Art. 21 GDPR);
- withdrawal of consent with effect for the future (Art. 7(3) GDPR), for example for the waitlist.
Much of this works directly in the app: change your name and email address and delete your account under “Account & security”; switch device notifications on and off; owners and admins can export all of a team’s data as a file (.tar.gz) and delete teams.
How to reach us: by email to contact@mailcockpit.app or by post to the address in section 1. To prevent unauthorised persons from obtaining information, we may ask for proof of your identity (for example a request from your account or from the registered address). We usually reply within 30 days. Access is free of charge; if the effort is disproportionate, a contribution to costs of at most CHF 300 may be charged (Art. 19 DPO) – we will inform you beforehand. The law may restrict these rights in individual cases (for example Art. 26 FADP); we will then give reasons.
Mailbox content: if your request concerns emails in a mailbox of one of our customers, please contact that customer (section 3.3). We support them in responding.
14. Complaints to a supervisory authority
We would appreciate it if you contacted us first. However, you can contact the competent supervisory authority at any time:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
- EU/EEA (GDPR): the data protection supervisory authority in the state where you live or work or where the alleged infringement took place (Art. 77 GDPR); the European Data Protection Board keeps a list at edpb.europa.eu. In Liechtenstein: Datenschutzstelle Liechtenstein, www.datenschutzstelle.li.
15. Minors
Mailcockpit is intended for companies, organisations and adult individuals. Minors may only use it with the consent of their legal representative.
16. Changes to this privacy policy
We update this privacy policy when the website, the service, our providers or the law change. The version published at https://mailcockpit.app/en/privacy/ applies. We inform registered users of material changes in advance by email or in the app.
17. Contact
Safkom GmbH, Oberdorfstrasse 11, 5722 Gränichen, Switzerland
Email: contact@mailcockpit.app