OP Mail Privacy Notice
This notice explains how Azrak Group Ltd handles your personal data when you use OP Mail. A mail provider holds some of the most private information a person has, and we think you are entitled to a plain explanation of what we do with it.
The short version. Your mail is yours. We do not read it for advertising, we do not build profiles from it, we do not sell it, and we do not use it to train machine learning models. We hold it so we can deliver it to you, and we access its contents only where it is strictly necessary and lawful, such as investigating a fault you have reported to us or responding to a serious abuse or security incident.
Contents
- Who is responsible for your data
- What we collect
- Why we process it, and our lawful basis
- How we treat the contents of your mailbox
- Sensitive information in your mail
- Who we share data with
- Where your data is held
- How long we keep it
- How we protect it
- Your rights
- Cookies and our website
- Children
- Changes to this notice
- How to complain
- Contact us
1. Who is responsible for your data
The data controller for OP Mail is Azrak Group Ltd, a company registered in England and Wales with company number 16788982, whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
We are registered with the Information Commissioner's Office under registration number ZC115618.
For any question about this notice or about your data, contact hello@opmail.io.
Where you use OP Mail as an organisation and create mailboxes for your own people, you are the controller for those people's data and we act as your processor for it. In that case this notice describes what we do, and the contract between us governs our obligations to you.
2. What we collect
Account data
The details needed to create and run your account: your name, your email address, your chosen mailbox address, any custom domain you use, your plan, and your billing records.
Mailbox content
The mail you send and receive, including message bodies, subjects, attachments, and your folder structure. Also your calendars, contacts, and any filtering rules you set up.
Traffic and delivery data
Information needed to deliver mail and keep the service working: sender and recipient addresses, timestamps, message sizes, delivery status and the results of spam and malware checks.
Technical and security data
Connection logs including IP addresses, the client or app you connected with, authentication events including failed sign-in attempts, and diagnostic logs used to find faults and detect abuse.
Support correspondence
Messages you send us, and our replies.
3. Why we process it, and our lawful basis
Under UK GDPR we must have a lawful basis for each purpose. Ours are:
| What we do | Lawful basis |
|---|---|
| Provide the mailbox: receive, store, index, search and deliver your mail, calendars and contacts | Performance of our contract with you |
| Create and administer your account, and provide support | Performance of our contract with you |
| Take payment and keep billing records | Performance of our contract, and legal obligation for accounting records |
| Filter spam, malware and abuse, protect accounts from unauthorised access, and keep the service secure and available | Our legitimate interests in securing the service and protecting our users, and those of the people who correspond with you |
| Investigate faults, and maintain and improve reliability | Our legitimate interests in operating a working service |
| Respond to lawful requests from authorities, and comply with our legal duties | Legal obligation |
| Send you service messages about security, availability or billing | Performance of our contract with you |
| Send you optional product news, if you have asked for it | Your consent, which you can withdraw at any time |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and freedoms, and we limit the processing to what is necessary for the purpose. You can object to processing based on legitimate interests, and we explain how in the rights section below.
4. How we treat the contents of your mailbox
This is the part that matters most, so we will be specific.
We do not read your mail to sell advertising, to build a profile of you, to score you, or to train machine learning models. We do not sell, rent or trade your mail or any information derived from it.
Automated processing. Inbound and outbound mail passes through automated spam, malware and abuse checks, and your mail is indexed so that your own search works. These are machine processes that serve you and protect the service. No person reads your mail as part of them, and their output is not used for marketing.
Access by a person is limited to these situations:
- You ask us to help with a specific problem and access is needed to resolve it. We will limit ourselves to what is necessary for that request.
- We are investigating a credible report of abuse originating from an account, or a security incident affecting the service.
- We are required to by law, for example a valid court order or statutory notice. Where we are legally permitted to tell you about such a request, we will.
Access of this kind is restricted to staff who need it for the task in hand.
5. Sensitive information in your mail
Mailboxes sometimes contain special category data, such as information about health, beliefs or political opinions, simply because that is what people write to each other about. We do not seek out this information, we do not attempt to detect or categorise it, and we do not process it for any purpose of our own.
Where such information passes through or rests in your mailbox, we handle it only as part of storing and delivering your mail at your direction, and we apply the same protections as to everything else in your account.
6. Who we share data with
We do not sell your data. We share it only where it is necessary, and with these categories of recipient:
- The people you correspond with. This is inherent in email: when you send a message, its content and headers go to the recipient and pass across the mail servers involved in delivering it.
- Infrastructure and hosting providers that supply the servers, networking and storage on which the service runs.
- Payment providers that process subscription payments. We do not store your full card details.
- Backup and disaster recovery providers that hold encrypted backup copies.
- Professional advisers such as accountants or lawyers, where needed and under a duty of confidentiality.
- Authorities, where we are required to disclose by law.
Each provider acting on our behalf does so as our processor, under a written contract requiring them to protect your data and to act only on our instructions. We will tell you the specific providers we currently use if you ask us at hello@opmail.io.
7. Where your data is held
Your mail is stored on infrastructure located in the United Kingdom and the European Economic Area.
Email is a global protocol, so when you exchange mail with someone whose provider is elsewhere, that message will necessarily travel to that provider's country. That is a function of email itself rather than a transfer we choose to make, and we cannot control the practices of another person's mail provider.
If we ever need to transfer your data outside the UK or EEA for our own operational purposes, we will do so only where the destination is covered by UK adequacy regulations, or under appropriate safeguards such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
8. How long we keep it
| Data | Retention |
|---|---|
| Mailbox content, calendars and contacts | For as long as your account is open. You control it and can delete it at any time. |
| Mailbox content after your account closes | Deleted within 30 days of closure. |
| Encrypted backup copies | Overwritten in the normal backup rotation within 90 days. |
| Connection, authentication and delivery logs | Kept only as long as needed for security and troubleshooting, and no longer than 12 months. |
| Billing and accounting records | 6 years, as required by UK company and tax law. |
| Support correspondence | Up to 24 months after the matter is closed. |
Where a period is expressed as "within", it is the outer limit. We routinely delete sooner where we no longer need the data.
9. How we protect it
- Connections to the service are encrypted in transit using TLS, and we use TLS for mail delivery to other providers wherever they support it.
- Access to production systems is restricted to the few people who need it, and is individually authenticated.
- Backups are encrypted, and we hold an off-site copy so that your mail survives the loss of a single location.
- We keep the mail platform patched and monitored, and we log authentication events so that unauthorised access attempts can be detected.
No service can promise perfect security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.
10. Your rights
Under UK data protection law you have the right to:
- Be informed about how we use your data, which is the purpose of this notice.
- Access a copy of the personal data we hold about you.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data in certain circumstances, sometimes called the right to be forgotten.
- Restrict processing in certain circumstances.
- Data portability, meaning a copy of the data you provided to us in a commonly used, machine-readable format. For mail, you can export at any time, and we will help if you ask.
- Object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent where we rely on it, without affecting processing carried out before you withdrew it.
To exercise any of these, email hello@opmail.io. We will respond within one month. We do not charge for this, and we will not ask you to justify your request. We may need to confirm your identity first, so that we do not disclose your data to someone else.
11. Cookies and our website
The opmail.io marketing site does not use advertising or tracking cookies, and does not run third-party analytics that profile you.
The webmail and account portal use strictly necessary cookies or equivalent local storage to keep you signed in and to keep your session secure. These are exempt from the consent requirement under the Privacy and Electronic Communications Regulations because without them the service you asked for cannot be provided.
12. Children
OP Mail is not directed at children, and we do not knowingly create accounts for children under 16. If you believe a child has an account with us, contact us and we will look into it.
13. Changes to this notice
We may update this notice, for example if the service changes or the law does. The current version is always at this address and the date at the top shows when it last changed. Where a change materially affects how we handle your data, we will tell you by email before it takes effect.
14. How to complain
If you are unhappy with how we have handled your data, please tell us first at hello@opmail.io so we have the chance to put it right.
You also have the right to complain to the Information Commissioner's Office at any time:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
15. Contact us
Email hello@opmail.io, or write to Azrak Group Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.