Privacy Policy
Last updated: 25 July 2026
We take the protection of personal data seriously and process as little data as possible. This policy describes which data we process when providing the BgLetter Channel, for what purpose and for how long.
1. Controller
The controller responsible for the processing of your personal data is:
Email:
2. Two roles: your data and your recipients’ data
For the data you store with us as a customer — account, contract and usage data — we are the controller within the meaning of the GDPR. For the data of the recipients you provide for a send, you are the controller and we are exclusively the processor pursuant to Art. 28 GDPR. We process this recipient data only on your instructions, solely in order to carry out the send, and never use it for our own purposes.
3. Which data we collect
Account data: company name, name of the contact person, email address, password (exclusively as a hash value), language setting, role and team membership. Contract and billing data: plan, booking and payment status, invoice numbers and amounts, PayPal transaction identifiers. Configuration data: the credentials of your email account (stored encrypted), sender details, templates and drafts. Usage and log data: the time and type of security-relevant actions, IP address and technical metadata in server logs to prevent misuse. Recipient data: the addresses and personalisation fields you provide for each send.
4. Purposes and legal bases
We process your data in order to establish and perform the contract, including provision of the Channel, send control, billing and support (Art. 6(1)(b) GDPR), to comply with legal obligations such as retention under tax and commercial law (Art. 6(1)(c) GDPR), on the basis of our legitimate interests in security, prevention of misuse, error analysis and further development of the service (Art. 6(1)(f) GDPR), and on the basis of your consent where you have given it (Art. 6(1)(a) GDPR). No automated decision-making or profiling takes place.
5. Recipient data: no address management
BgLetter deliberately maintains no contact database. You provide the recipient data yourself for each send; it is processed solely to carry out that send and is deleted automatically and irretrievably no later than thirty days after the send — together with the content of the message sent and the associated open and click events. The only thing stored permanently is the unsubscribe list: we retain addresses that have objected to further receipt so that your next send reliably excludes those individuals. This processing is necessary to fulfil the obligations under Art. 21 GDPR.
6. Retention period
Recipient addresses, personalisation data, message content and open and click events: no more than 30 days after the send. Anonymous key figures and the subject lines of a campaign: for the duration of your account. Account, contract and configuration data: for the duration of your account and 30 days thereafter until final deletion. Unsubscribes: permanently, as required by law. Invoices and accounting records: ten years in accordance with retention obligations under tax and commercial law. Security-relevant logs: as a rule 90 days. You can delete your account at any time in the settings and export your data beforehand.
7. Storage location and security
Data is processed on the servers of a hosting provider in Germany (EU). Transmission is exclusively encrypted (TLS). Credentials for your email account are stored encrypted with AES-256, passwords exclusively as a non-reversible hash value. Access is limited to the necessary minimum, logged, and secured by role and tenant separation as well as two-factor authentication. Absolute protection against unauthorised access is technically impossible for transmission over the internet.
8. Recipients and processors
We pass data only to carefully selected service providers with whom data processing agreements are in place: a hosting provider with servers located in Germany (operation of the infrastructure), PayPal (payment processing; PayPal processes the payment data as a controller in its own right under its own terms), and Anthropic (provision of the AI functions for translation and the assistant). The actual email sending takes place via the email provider you configure, which you select yourself and which is your responsibility. There is no disclosure for advertising purposes, no sale and no other use for third-party purposes.
9. AI-assisted functions
When you use AI translation or the assistant, the relevant content — the text of your message in the case of translation, your question in the case of the assistant — is transmitted to Anthropic for processing. Personalisation placeholders such as {{NAME}} remain unchanged; recipient addresses are not transmitted. Use is voluntary: you trigger every translation yourself, and without your action no transmission takes place. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). For the transfer to the USA we rely on the European Commission’s standard contractual clauses together with supplementary measures.
10. International data transfers
Your data is stored on servers in Germany (EU/EEA). The controller is domiciled in Switzerland, which the European Commission recognises as providing an adequate level of data protection (Art. 45 GDPR); processing may therefore take place within the EEA and Switzerland. A transfer to the USA takes place exclusively in the context of the AI functions and is safeguarded by standard contractual clauses. We do not carry out any further transfers to third countries.
12. Open and click measurement for your sends
For the emails you send, we record on your behalf whether a message was opened and whether a link was clicked. You are the controller for this measurement; you must inform recipients about it and, where required, obtain their consent. These events are deleted together with the recipient data after thirty days at the latest; after that only anonymous totals remain.
13. Your rights
You have the right to obtain information about the data stored about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You may withdraw consent you have given at any time with effect for the future. You can export account and campaign data yourself at any time and delete your account completely in the settings.
You also have the right to lodge a complaint with a supervisory authority — in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), in the European Union with the data protection authority responsible for you — if you believe that the processing of your data infringes applicable law.
14. Changes to this Privacy Policy
We adapt this Privacy Policy when the service or the legal situation changes. The version published on this page at the relevant time applies; we additionally notify customers of material changes in text form.
15. Contact
If you have questions about data protection or wish to exercise your rights, you can reach us at the address and email address stated in the Impressum. We have not appointed a data protection officer, as the statutory requirements for doing so are not met.
Email:
This page is provided for information purposes and does not constitute legal advice.
See also: Terms of Service · Data Processing Agreement (DPA) · Impressum / Legal notice