
EU/UK Privacy Notice
Your privacy rights under GDPR and how we safeguard your data
Last Updated: 2 August 2026
1. Introduction
This Privacy Notice applies to users in the European Economic Area (EEA), United Kingdom, and other regions where GDPR or similar regulations apply. It supplements the main Mailopoly Privacy Policy and provides specific information required under the General Data Protection Regulation (GDPR) and UK GDPR.
2. Our Role: Controller and Processor
Mailopoly Pty Limited is the data controller for the personal data we collect in order to operate our business and provide accounts — registration and contact details, billing data, support correspondence, and technical and usage data.
In respect of the contents of accounts you connect to the Service — your messages, their metadata and attachments, and the personal data of the people you correspond with — Mailopoly acts as a data processor on your behalf. You are the controller of that data. We process it only on your instructions and to provide the Service to you, in accordance with our Terms of Use, and we do not determine the purposes for which you collect or hold it.
Where you connect an account in the course of employment or on behalf of an organisation, that organisation is ordinarily the controller and you are responsible for ensuring you are authorised to connect it.
Our EU representative is [Name/Company] and can be contacted at [contact details]. Our UK representative is [Name/Company] and can be contacted at [contact details].
3. Legal Bases for Processing
We process your personal data under the following legal bases:
- Contract Performance: Processing necessary for the performance of our contract with you — email management services, including the AI processing that sorts, summarises and organises your mail and powers Poly. This processing is inseparable from the Service and is provided under our contract with you, not under consent
- Legitimate Interests: Processing necessary for our legitimate interests, including:
- Improving our services
- Ensuring network security
- Preventing fraud
- Direct marketing to business customers
- Legal Obligation: Processing necessary to comply with legal requirements
- Consent: Processing based on your specific consent, such as:
- Marketing communications
- Analytics cookies
4. Data Processing Details
| Category of Data | Purpose | Legal Basis | Retention Period |
|---|---|---|---|
| Account Data | Service provision | Contract | Duration of account plus 30 days |
| Email Content | Email management | Contract | As long as necessary for service |
| Third-party data within connected accounts | Providing the Service to the account holder | Processed on the account holder's instructions (they are controller) | As long as necessary for service |
| Usage Data | Service improvement | Legitimate Interest | 12 months |
| Marketing Data | Promotional communications | Consent | Until consent withdrawal |
Special category and criminal offence data. The Service is not designed or intended for the processing of data falling within Article 9 (special categories) or Article 10 (criminal convictions and offences) of the GDPR. We do not seek such data and do not process it for any purpose of our own. Because mailboxes may contain it incidentally, account holders are responsible for ensuring they have a lawful basis and, where required, a condition under Article 9 or Article 10, before connecting an account containing such material.
No monitoring. We do not monitor, review or moderate the contents of connected accounts. Automated security and abuse checks may be performed voluntarily to protect the platform, and are not a review of content.
5. International Transfers
We transfer personal data to countries outside the EEA/UK. We ensure adequate protection through:
- EU Standard Contractual Clauses
- UK International Data Transfer Agreement
- Adequacy decisions where applicable
- Additional technical and organizational measures
5a. Our Commitments as Your Processor
Where we act as your processor — for the contents of the accounts you connect — we commit to the following, as required by Article 28(3) of the GDPR. These commitments are set out in full in our Data Processing Agreement, which applies to business customers, is incorporated into our Terms of Use, and is available on request from privacy@mailopoly.com.
- Documented instructions: we process the contents of your connected accounts only to provide the Service to you and on your instructions, including for transfers to third countries, unless required otherwise by law.
- Confidentiality: our personnel are bound by confidentiality obligations and access customer content only where necessary to operate or support the Service.
- Security: we maintain the technical and organisational measures described in section 8, appropriate to the risk, as required by Article 32.
- Subprocessors: we engage subprocessors under written terms imposing equivalent obligations, maintain a current list of subprocessors (available on request from privacy@mailopoly.com), and give at least 30 days notice before adding a new one. If you object to an addition, your remedy is to terminate the affected part of the Service before the change takes effect. We cannot route an individual customer's data around a subprocessor.
- Data subject requests: we assist you, by appropriate technical and organisational measures, in responding to requests from data subjects to exercise their rights, and we forward to you any such request we receive directly.
- Breach notification: we notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own obligations under Articles 33 and 34. This is notification to you as controller; notifying affected individuals, where required, remains your decision.
- Assistance: we assist you, taking into account the nature of the processing and the information available to us, with data protection impact assessments and prior consultation under Articles 35 and 36.
- Deletion or return: on termination we delete your data as described in the retention table above, unless retention is required by law. Export of your data before deletion is available on request.
- Audit information: we make available the information reasonably necessary to demonstrate compliance with these obligations, including our security assessment reports, and will respond to reasonable written security questionnaires.
6. Your Rights
Under the GDPR and UK GDPR, you have the following rights:
- Access: Obtain confirmation about your data processing and access your data
- Rectification: Correct inaccurate data and complete incomplete data
- Erasure: Request deletion of your data in certain circumstances
- Restriction: Limit processing of your data in certain circumstances
- Portability: Receive your data in a structured format and transmit it to another controller
- Objection: Object to processing based on legitimate interests or direct marketing
- Withdraw Consent: Withdraw previously given consent
- Lodge Complaints: File complaints with supervisory authorities
7. Automated Decision-Making
Our service uses automated processing to:
- Filter and organize emails
- Extract events and tasks
- Generate response suggestions
This processing is how the Service works and cannot be switched off separately; if you do not want it, do not connect an account. Significant decisions affecting your legal rights are not made solely through automated means, and this processing does not produce legal or similarly significant effects within the meaning of Article 22.
8. Data Protection
We implement appropriate technical and organizational measures including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Staff training and confidentiality agreements
- Incident response procedures
9. Contact Information
To exercise your rights or ask questions about this notice, contact:
Data Protection Officer
Mailopoly Pty Limited
Email: dpo@mailopoly.com
EU Representative:
[Name/Company]
[Address]
Email: [email]
UK Representative:
[Name/Company]
[Address]
Email: [email]
10. Updates to This Notice
We may update this notice periodically. Significant changes will be notified to you through our service or by email. Continued use of our services after such notifications constitutes acceptance of the updated notice.