This translation is provided for convenience. The Polish version of this document is binding and prevails in case of any discrepancy. Wersja polska
Privacy policy
We explain what data we process, why, for how long and who we share it with — and how to exercise your rights.
1. Who the controller is
The controller of the personal data of Ezra Mail Users is Operator usługi Ezra Mail (“we”, the “Service Provider”). For personal data matters write to privacy@saauf.xyz. We have not appointed a data protection officer — we are not required to; we handle all matters at this address.
2. Two roles: controller and processor
- As a controller we process the data of people who have an Account, are invited to an Organization or contact us — for the purposes described in section 3.
- As a processor we process data contained in an Organization’s mail and settings (e.g. data of the correspondents of a company using Ezra Mail). The Organization (our Customer) is the controller of that data, and we act on its instructions under the data processing agreement.
If you corresponded with a company that uses Ezra Mail and want to exercise your rights, contact that company directly — it decides about your data. If you write to us, we will forward your request to the relevant Organization.
3. Data, purposes, legal bases and periods
| Purpose | Data | Legal basis | How long |
|---|---|---|---|
| Running the Account and providing the Service | Full name, email, password hash (bcrypt), profile photo, chosen language, roles and permissions, assigned mailbox, last sign-in date, version and date of acceptance of the Terms; if you turn them on — the encrypted two-step verification secret, hashes of backup codes, and public keys and names of passkeys | Contract — Art. 6(1)(b) GDPR; for people acting on behalf of the Customer — the legitimate interest of the Customer and the Service Provider in performing the contract (Art. 6(1)(f)) | Until the Account is deleted |
| Invitations to an Organization | Email address of the invitee, role, who sent the invitation | Legitimate interest of the Customer in inviting a co-worker (Art. 6(1)(f)) | Until the invitation is accepted; unused — 30 days after expiry |
| System messages | Email, first name, message content (invitations, password resets, notices about changes to the Service) | Contract (Art. 6(1)(b)) | One-time links — until used or expired (reset: 1 hour, invitation: 7 days); the link record — up to 30 days |
| Security and abuse prevention | Hashes of the IP address and email address in attempt counters, the Organization activity log (who, what, when), hosting technical logs | Legitimate interest — protecting the Service and Accounts (Art. 6(1)(f)) | Attempt counters — 48 hours; activity log — 24 months; hosting logs — according to the provider’s policy, usually up to 30 days |
| Billing and Plan changes | Billing details provided by the Owner, Plan history | Legal obligation — tax and accounting law (Art. 6(1)(c)), contract (Art. 6(1)(b)) | Invoices and accounting records — 5 years from the end of the year in which the tax obligation arose; Plan change request — until the Organization is deleted |
| Contact, complaints and reports | Data from correspondence sent to @saauf.xyz addresses | Legitimate interest — handling requests and defending against claims (Art. 6(1)(f)) | Until the matter is closed, then until claims become time-barred (generally 3 years) |
| Feedback about the Service | Feedback text and category, the page it was sent from (if you allow it), language, browser, Account and Organization | Legitimate interest — developing and fixing the Service (Art. 6(1)(f)) | 24 months |
| AI usage statistics | Provider and model, number of tokens, call result, User — without message content | Legitimate interest — accounting for Plan limits (Art. 6(1)(f)) | 13 months |
When the retention period ends, we delete data automatically. Deleting an Account deletes the Account data and the Organizations in which you were the only person. Data in backups disappears as they are overwritten, within no more than 30 days.
4. Where we get data from
You provide most data yourself when creating an Account or using the Service. If someone from an Organization invited you, the inviting person provided your email address and role. Technical data (e.g. a hash of your IP address) is generated automatically when you use the Website.
5. Recipients of data
- Infrastructure providers we entrust data to: hosting, database and mail delivery — the full list with locations is on the Sub-processors page.
- The AI provider chosen by the Organization — only the content needed to prepare a reply. When the Organization uses its own key, the provider acts under its agreement with the Organization.
- The Organization you belong to — its Owners and Administrators see your name, email, role and actions recorded in the activity log.
- Public authorities — only when required by law.
We do not sell data, do not use it for advertising and do not use message content to train AI models.
6. Transfers outside the European Economic Area
Some of our providers are based in the USA. We transfer data to them on the basis of the European Commission’s adequacy decision (EU-US Data Privacy Framework) for certified providers, or on the basis of standard contractual clauses approved by the Commission (Art. 46(2)(c) GDPR). You can obtain a copy of the safeguards by writing to privacy@saauf.xyz.
7. Your rights
You have the right to:
- access your data and receive a copy — download it yourself under Account settings → Download my data;
- rectify your data — change your name and photo in account settings, other data on request;
- erasure — delete your Account yourself in account settings;
- restriction of processing and data portability (the export is in JSON format);
- object to processing based on legitimate interest — on grounds relating to your particular situation;
- lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or with the supervisory authority in your country of residence.
We respond to requests without undue delay and no later than within one month. We may ask you to confirm your identity, e.g. with a message sent from the address linked to the Account.
8. Do you have to provide data
Providing your name, email address and password is voluntary, but you cannot create an Account without them. Billing details are required to switch to a paid Plan.
9. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you (Art. 22 GDPR). Automatic tagging and AI replies in an Organization’s mailboxes are enabled by the Organization as the controller of that data.
10. Security
We use, among other things, encrypted connections (TLS, HSTS), bcrypt password hashes, encryption of stored keys and secrets (AES-256-GCM), isolation of Organization data, optional two-step verification and passkeys, sign-in rate limits and an activity log. Details are in Security measures. Cookies are described in the Cookie policy.
11. Changes to this policy
We update this policy when the Service, the list of providers or the law changes. We announce significant changes in advance by email and on the Website. The effective date of the current version is shown at the top of the page.