Legal
Privacy Policy
This Privacy Policy explains how xmailCloud collects, uses, stores, secures, and shares personal data when you use our website, webmail application, admin console, and related support or billing workflows.
Information we collect
We collect information you provide directly, such as account details, billing contacts, support requests, domain configuration details, mailbox identities, and other service setup information.
We also process service-generated data such as authentication logs, mailbox metadata, usage activity, device and browser information, operational telemetry, and support diagnostics needed to run and secure the platform.
- Account and identity information
- Billing and subscription information
- Domain and mailbox configuration data
- Usage, diagnostic, and security event data
- Support communications and attachments you submit
How we use information
We use personal data to provide the service, authenticate users, provision mailboxes, process payments, respond to support requests, detect abuse, improve product reliability, and comply with legal obligations.
Where AI-assisted features are enabled, relevant message content or user prompts may be processed solely to generate requested outputs such as summaries, rewrites, or signature drafts.
Legal bases for processing
Depending on your location and relationship to the service, we process personal data based on contractual necessity, legitimate interests, consent where required, and compliance with legal obligations.
Our legitimate interests include fraud prevention, platform security, service improvement, administrative management, and customer support operations.
How information is shared
We do not sell personal data. We may share information with infrastructure providers, mailbox and storage providers, payment processors, authentication providers, customer support tools, and monitoring providers that help us operate the service.
We may also disclose information where necessary to comply with law, enforce agreements, respond to lawful requests, protect users, or prevent abuse, fraud, or security threats.
Data retention
We retain personal data only for as long as needed to provide the service, maintain security records, resolve disputes, comply with contractual obligations, and satisfy legal or regulatory requirements.
Mailbox content, drafts, and attachments remain available until you or your organization delete them, the mailbox is deprovisioned, or storage is otherwise cleared under your account lifecycle. Billing events, audit records, support requests, and verification snapshots may be retained for longer where required for accounting, fraud prevention, or operational security.
Security measures
We use administrative, technical, and organizational safeguards designed to protect customer information against unauthorized access, misuse, disclosure, alteration, and loss.
These safeguards may include encryption in transit, access controls, role-based permissions, audit logging, secure infrastructure practices, service isolation, and operational monitoring.
International transfers
If personal data is transferred across borders, we take steps intended to ensure an appropriate level of protection consistent with applicable privacy laws and contractual commitments.
Where required, such transfers may rely on contractual safeguards, service-provider commitments, or other valid transfer mechanisms.
Your rights
Depending on applicable law, you may have rights to access, correct, update, delete, restrict, object to, or export certain personal data.
Where we process data on behalf of an organization, requests should generally be directed first to that organization as the primary controller of mailbox content and account usage.
- Request access to personal data we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion where retention is no longer required
- Object to certain processing or request restriction
- Request a portable copy where legally applicable
Children's privacy
The service is not directed to children and is not intended for use by individuals who are not legally permitted to enter into binding service agreements under applicable law.
Changes to this policy
We may update this Privacy Policy to reflect operational, legal, or technical changes. When we do, we will revise the date above and provide additional notice where required.