privacy policy
last updated 2026-08-24 · mittera.eu
This Privacy Policy explains what personal data the mittera Service (mittera.eu and any subdomain) collects, why, and what you can do about it. mittera is an flndrn brand, not a company of its own. The Service is operated by flndrn Limited (the “Operator”, also the data controller for the purposes of the EU General Data Protection Regulation), registered at Arch. Makariou III 171, Vanezis Business Center 4th floor, 3027 Limassol, Cyprus. Day-to-day development takes place in Flanders, Belgium. For brand and legal context see the Terms of Service.
1. What we collect
We process the following categories of personal data:
- Account data — email address (required) and display name (optional). Sign-in is email and password, plus one-time codes sent to that address. There are no social sign-in providers.
- Organisation and workspace metadata — the names you give organisations, audiences, templates and broadcasts, which plan your account runs on, and an audit log of actions taken in your organisation.
- API keys — never stored at all: we keep only a SHA-256 hash and a short display suffix, so a key you lose cannot be read back out of our database by anyone, including us.
- The email you send — from, to, subject, and the HTML and text bodies, kept in the email log so you can see delivery status. We do not read or mine this content.
- Delivery events — whether an email was delivered, opened, clicked or bounced, reported back by the delivery provider for the log and analytics.
- Operational telemetry — request paths, response codes and latency on the API and dashboard, and the metering samples that usage is billed from.
- IP-derived identifiers — your IP address is hashed with a server-side pepper at the moment a request is logged. The plaintext IP is never written to disk.
- Billing data (on a paid plan) — your billing email address. No payment processor is engaged yet, so no card token exists today.
2. What we do not collect
- The content of your emails beyond what is needed to transmit and log them. We do not read, mine, profile, sell or train models on it.
- Third-party advertising cookies, marketing trackers or session-replay tools. mittera.eu ships zero analytics scripts to your browser.
- Plaintext IP addresses, browser fingerprints or device identifiers for advertising purposes.
3. Why we process it
The legal bases for processing under GDPR Article 6 are:
- Contract (Art. 6(1)(b)) — to send the email you asked us to send and run your dashboard.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention and operational debugging. The audit log and IP hashing fall under this basis.
- Legal obligation (Art. 6(1)(c)) — when a court order, regulatory subpoena, or DSA/DMA disclosure requirement compels us.
- Consent (Art. 6(1)(a)) — used only for optional product announcements; you can decline at sign-up and withdraw any time.
4. Who we share with
We share data only with the third-party processors listed at mittera.eu/subprocessors — most importantly the delivery provider that transmits your email. Each is bound by a data-processing agreement that limits them to the purpose for which we engage them. We do not sell personal data, and we disclose to law enforcement only when required by binding legal process.
5. Retention
- Account data — kept while your account is active, then a 30-day soft-delete window, then permanent erasure.
- Email log and delivery events — 13 months, then rotated, so an invoice can be reconstructed and disputed.
- Audit logs — 13 months, then rotated, so security incidents that surface late can be investigated.
The Operator does not currently operate customer-facing backups of email content. Export what you need over the API or your own records.
6. Security
TLS on every public endpoint; AES-256-GCM for stored credentials at rest; passwords hashed with a memory-hard key-derivation function; SHA-256 for API key hashes, compared in constant time. SSH access to the host is key-only. Dependency updates roll weekly. No system is ever fully secure; if you discover a vulnerability, please email security@mittera.eu rather than disclosing publicly.
7. International transfers
Your data is hosted on a single EU-hosted server. Some subprocessors are located outside the EU; transfers to them rely on Standard Contractual Clauses approved by the European Commission. The subprocessors page notes each processor’s location.
8. Your rights
Under GDPR you have the right to access, rectify, erase and port your data, to restrict or object to processing, to withdraw consent, and to complain to your local data protection authority. The Operator’s lead supervisory authority is the Belgian Data Protection Authority.
To exercise any of these rights, email privacy@mittera.eu. We answer within 72 hours and resolve within 30 days.
9. Cookies
mittera.eu sets first-party cookies only, and only to keep you signed in. Full detail is in the Cookie Policy.
10. Children
mittera is not directed to children under 16 and we do not knowingly collect their data.
11. Updates
Material changes to this policy will be announced on this page and emailed to the address on your account at least 30 days before they take effect.
12. Contact
Privacy questions and rights requests: privacy@mittera.eu.