Privacy Policy
This Privacy Policy explains how ProEmails collects, uses, stores, and protects your personal information when you use our email hosting services.
Privacy at a Glance
- shieldAll data stored exclusively on servers within the European Union.
- visibility_offNo employee or agent can access or read your emails.
- smart_toyAI spam filtering runs entirely on our EU servers — no data sent to third parties.
- blockWe do not sell, rent, or trade your personal data.
- delete_foreverAll data permanently deleted immediately upon account deletion.
1. Who We Are
ProEmails ("ProEmails", "we", "us", "our") is the data controller responsible for the processing of your personal data as described in this Privacy Policy.
ProEmails
9 Orchard Road
Stevenage
Hertfordshire, SG1 3HD
United Kingdom
Data Protection Officer:
Email: dpo@proemails.uk
We are registered with the Information Commissioner's Office (ICO) in the United Kingdom and comply with the UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU) 2016/679 ("GDPR") as it applies to EU-based users.
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to our website at proemails.uk
- Individuals who create a ProEmails account or subscribe to any of our plans
- Individuals whose personal data is processed in connection with email services provided by ProEmails (including senders and recipients of emails handled by our infrastructure)
- Individuals who contact us for support, enquiries, or complaints
By using our services, accessing our website, or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.
3. Information We Collect
3.1 Information You Provide Directly
Account Registration
Full name, email address, chosen username, password (stored using irreversible cryptographic hashing), and billing information. We do not store complete payment card details; these are handled by our payment processor.
Communications
Any information you provide when contacting our support team, including the content of your messages and any attachments.
Account Preferences
Settings, display preferences, notification preferences, and other configuration data.
3.2 Email Data
As an email hosting provider, we process email data on your behalf, including:
- Email messages (including body text and headers)
- File attachments
- Email metadata (sender, recipient, timestamps, subject lines, routing information)
- Address book and contact lists
- Calendar entries and scheduling data (where applicable to your plan)
- Spam filtering logs (automated)
3.3 Information Collected Automatically
Connection Data
IP address, browser type and version, operating system, referring URLs, access times, and pages viewed on our website.
Security & System Logs
Login timestamps, authentication events, connection protocols (IMAP/SMTP/Webmail), and error logs. These are collected for security monitoring, abuse prevention, and service reliability.
3.4 Information We Do NOT Collect
- We do not read or manually review the content of your emails.
- We do not collect data from third-party sources about you.
- We do not use tracking pixels, web beacons, or fingerprinting technologies on your email communications.
- We do not collect biometric data, government-issued identification, or sensitive personal data as defined under Article 9 GDPR (unless you voluntarily include such information in your emails).
4. How We Collect Your Information
- check_circle Directly from you — when you register, configure your account, contact support, or use our services.
- check_circle Automatically — through server logs, security systems, and connection data when you access our services or website.
- check_circle From email transmissions — email data is received and stored as part of the normal operation of providing email hosting services. This includes emails sent to your ProEmails addresses by third parties.
5. Purposes of Processing
We process your personal data for the following specific purposes:
Providing Email Services
Sending, receiving, routing, storing, and displaying emails on your behalf; managing your mailbox, contacts, and calendar; providing webmail, IMAP, and SMTP access.
Account Management
Creating and managing your account, processing payments, managing subscriptions, and providing billing support.
Security & Abuse Prevention
Detecting and preventing spam, phishing, malware, and other abusive activity; protecting our infrastructure and users from security threats; enforcing our terms of service.
AI-Powered Spam Filtering
Automatically classifying incoming emails as legitimate or spam using AI models that run exclusively on our EU-based servers. See Section 8 for full details.
Customer Support
Responding to your enquiries, troubleshooting technical issues, and providing assistance with your account.
Legal Compliance
Complying with applicable laws, regulations, and lawful requests from competent authorities, including tax and financial regulations.
Service Improvement
Analysing anonymised, aggregated usage data to improve service reliability, performance, and features. We do not use email content for this purpose.
6. Legal Bases for Processing
Under Article 6(1) of the UK GDPR and EU GDPR, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Email hosting, sending, receiving, and storage | Contract performance (Art. 6(1)(b)) |
| Account management and billing | Contract performance (Art. 6(1)(b)) |
| AI spam filtering | Contract performance (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Service improvement (aggregated data only) | Legitimate interests (Art. 6(1)(f)) |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, you may object at any time (see Section 14).
7. Email Content & Confidentiality
Our Guarantee
- lockNo human reads your emails. No ProEmails employee, contractor, or agent has access to the content of your email communications.
- visibility_offNo manual review. We do not manually inspect, read, or review email content for any purpose.
- blockNo advertising use. We do not use email content to build profiles, target advertising, or for any marketing purpose.
- money_offNo selling. We do not sell, rent, lease, or otherwise monetise your email content or personal data.
Access to infrastructure systems (servers, storage) is restricted by technical controls to automated processes required for service delivery. During maintenance operations, technical safeguards prevent personnel from accessing plaintext email content. Any unauthorised access to customer email content by personnel would constitute a violation of our internal policies and applicable law.
8. AI & Automated Processing
ProEmails employs AI-based technology for automated spam and malware filtering. This section explains how this processing works and the safeguards in place.
How It Works
- Incoming emails are analysed in real-time by our AI classification models.
- The models assess patterns, headers, content signals, and sender reputation to identify spam, phishing, and malware.
- Classified emails are moved to the appropriate folder (inbox or spam) automatically.
Data Processing Safeguards
- EU-only processing: All AI models run exclusively on ProEmails-owned servers located within the European Union.
- No third-party AI services: No email data is transmitted to any external AI provider, cloud AI service, or third-party API.
- No human review: The AI process is fully automated. No human reviews the classification decisions or the content processed.
- No data retention by AI systems: The AI filtering system processes data in real-time and does not retain copies of email content after classification.
- No profiling: AI classification results are not used to build user profiles or for any purpose other than email delivery.
Under Article 22 GDPR, this automated processing does not produce legal effects or similarly significant effects on you. If you believe a legitimate email has been incorrectly filtered, you can review your spam folder at any time or contact our support team.
9. Data Storage & Security
All personal data and email data is stored on servers physically located within the European Union. We implement technical and organisational security measures in accordance with Article 32 GDPR.
Security Measures
Encryption in Transit
All connections encrypted via TLS 1.2+ (IMAP, SMTP, Webmail).
Encryption at Rest
Email data and databases encrypted using AES-256.
Password Security
Passwords stored using irreversible cryptographic hashing algorithms.
End-to-End Encryption
OpenPGP / GnuPG encryption available on all plans.
Access Controls
Role-based access, multi-factor authentication for staff, principle of least privilege.
Infrastructure Security
Firewalls, intrusion detection and prevention, DDoS mitigation, continuous monitoring.
Physical Security
EU data centres with biometric access control, 24/7 CCTV, and on-site security.
Incident Response
Documented incident response plan with defined escalation procedures.
10. Data Retention & Deletion
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
Active Subscriptions
All data is retained for the duration of your active subscription.
Account Deletion (Voluntary or Non-Payment)
Upon account deletion, all personal data, email content, attachments, metadata, contacts, calendar entries, and associated account data are immediately and permanently deleted from our active systems and backup infrastructure. No residual copies are retained.
Legal Retention
Where required by law (e.g., financial records for tax compliance), we retain only the minimum data necessary for the legally mandated retention period. Email content is never subject to legal retention obligations.
Support Enquiries
Support ticket data is retained for 12 months after resolution for quality assurance, then permanently deleted.
11. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:
Payment Processors
We use third-party payment processors to handle subscription billing. These processors receive only the information necessary to process payments (name, billing address, payment method details) and are contractually prohibited from using your data for any other purpose. They do not have access to your email data.
Infrastructure Providers
EU-based data centre operators who host our physical servers. These providers act as data processors under a Data Processing Agreement (DPA) in accordance with Article 28 GDPR and do not have logical access to your data.
Legal Requirements
We may disclose your data if required to do so by law, court order, or lawful request from a competent authority. Where legally permitted, we will notify you of such requests before disclosure. We carefully review all requests to ensure they are lawful and proportionate.
We do not share email content with any third party under any circumstances, except where required by a binding legal order.
All data processors are bound by Data Processing Agreements and are required to implement appropriate technical and organisational measures. A full list of our sub-processors is available upon request from our Data Protection Officer.
12. International Data Transfers
No international transfers. All personal data, email content, and associated data is stored and processed exclusively on servers located within the European Union. We do not transfer your data to any country outside the EU/EEA.
Should our infrastructure requirements change in the future, any transfer of personal data outside the EU/EEA will only take place in compliance with Chapter V of the GDPR, using appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or Binding Corporate Rules. You will be notified of any such change, and this Privacy Policy will be updated accordingly.
14. Your Rights
Under the UK GDPR and EU GDPR, you have the following rights. To exercise any right, contact us at dpo@proemails.uk. We will respond within one month, extendable by two months for complex requests.
Right of Access (Art. 15)
Request a copy of all personal data we hold about you, including the purposes of processing, categories of data, and recipients.
Right to Rectification (Art. 16)
Request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure (Art. 17)
Request deletion of your personal data where there is no compelling reason to continue processing. Note: requesting erasure of your account will result in immediate, permanent deletion of all data.
Right to Restrict Processing (Art. 18)
Request that we limit how we use your data while a dispute is resolved or an objection is considered.
Right to Data Portability (Art. 20)
Receive your personal data in a structured, commonly used, machine-readable format (e.g., for email migration to another provider).
Right to Object (Art. 21)
Object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Rights Related to Automated Decision-Making (Art. 22)
The right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
We will not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive (in which case a reasonable fee may be charged, or we may refuse to act). We may request proof of identity before fulfilling requests.
15. Children's Privacy
ProEmails services are not directed at children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children.
If you become aware that a child has provided us with personal data without parental consent, please contact us immediately at dpo@proemails.uk. We will take steps to promptly delete such data.
16. Data Breach Procedures
In the event of a personal data breach affecting your data:
- check_circle We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR).
- check_circle If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (Article 34 GDPR).
- check_circle We maintain a breach register documenting all incidents, including the nature of the breach, data affected, consequences, and remedial actions taken.
17. Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party websites you visit.
18. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or business operations.
- Material changes will be communicated via email to registered users and/or a prominent notice on our website.
- The "Effective date" at the top of this page will always reflect the date of the latest revision.
- We encourage you to review this page regularly.
- Continued use of our services after changes take effect constitutes acceptance of the updated policy.
19. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data:
Data Protection Officer
Email: dpo@proemails.uk
Postal Address
ProEmails, 9 Orchard Road, Stevenage, Hertfordshire, SG1 3HD, United Kingdom
We will respond to all legitimate requests within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority (see our GDPR page for details).
Questions about your privacy?
Our Data Protection Officer is available to address any privacy-related concerns.
Contact Our DPO