Pro Emails Logo

Pro Emails

Privacy Policy

This Privacy Policy explains how ProEmails collects, uses, stores, and protects your personal information when you use our email hosting services.

Effective date: March 28, 2026 Version 1.0

Privacy at a Glance

  • shieldAll data stored exclusively on servers within the European Union.
  • visibility_offNo employee or agent can access or read your emails.
  • smart_toyAI spam filtering runs entirely on our EU servers — no data sent to third parties.
  • blockWe do not sell, rent, or trade your personal data.
  • delete_foreverAll data permanently deleted immediately upon account deletion.

1. Who We Are

ProEmails ("ProEmails", "we", "us", "our") is the data controller responsible for the processing of your personal data as described in this Privacy Policy.

ProEmails

9 Orchard Road

Stevenage

Hertfordshire, SG1 3HD

United Kingdom

Data Protection Officer:

Email: dpo@proemails.uk

We are registered with the Information Commissioner's Office (ICO) in the United Kingdom and comply with the UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU) 2016/679 ("GDPR") as it applies to EU-based users.

2. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our website at proemails.uk
  • Individuals who create a ProEmails account or subscribe to any of our plans
  • Individuals whose personal data is processed in connection with email services provided by ProEmails (including senders and recipients of emails handled by our infrastructure)
  • Individuals who contact us for support, enquiries, or complaints

By using our services, accessing our website, or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.

3. Information We Collect

3.1 Information You Provide Directly

Account Registration

Full name, email address, chosen username, password (stored using irreversible cryptographic hashing), and billing information. We do not store complete payment card details; these are handled by our payment processor.

Communications

Any information you provide when contacting our support team, including the content of your messages and any attachments.

Account Preferences

Settings, display preferences, notification preferences, and other configuration data.

3.2 Email Data

As an email hosting provider, we process email data on your behalf, including:

  • Email messages (including body text and headers)
  • File attachments
  • Email metadata (sender, recipient, timestamps, subject lines, routing information)
  • Address book and contact lists
  • Calendar entries and scheduling data (where applicable to your plan)
  • Spam filtering logs (automated)

3.3 Information Collected Automatically

Connection Data

IP address, browser type and version, operating system, referring URLs, access times, and pages viewed on our website.

Security & System Logs

Login timestamps, authentication events, connection protocols (IMAP/SMTP/Webmail), and error logs. These are collected for security monitoring, abuse prevention, and service reliability.

3.4 Information We Do NOT Collect

  • We do not read or manually review the content of your emails.
  • We do not collect data from third-party sources about you.
  • We do not use tracking pixels, web beacons, or fingerprinting technologies on your email communications.
  • We do not collect biometric data, government-issued identification, or sensitive personal data as defined under Article 9 GDPR (unless you voluntarily include such information in your emails).

4. How We Collect Your Information

  • check_circle Directly from you — when you register, configure your account, contact support, or use our services.
  • check_circle Automatically — through server logs, security systems, and connection data when you access our services or website.
  • check_circle From email transmissions — email data is received and stored as part of the normal operation of providing email hosting services. This includes emails sent to your ProEmails addresses by third parties.

5. Purposes of Processing

We process your personal data for the following specific purposes:

Providing Email Services

Sending, receiving, routing, storing, and displaying emails on your behalf; managing your mailbox, contacts, and calendar; providing webmail, IMAP, and SMTP access.

Account Management

Creating and managing your account, processing payments, managing subscriptions, and providing billing support.

Security & Abuse Prevention

Detecting and preventing spam, phishing, malware, and other abusive activity; protecting our infrastructure and users from security threats; enforcing our terms of service.

AI-Powered Spam Filtering

Automatically classifying incoming emails as legitimate or spam using AI models that run exclusively on our EU-based servers. See Section 8 for full details.

Customer Support

Responding to your enquiries, troubleshooting technical issues, and providing assistance with your account.

Legal Compliance

Complying with applicable laws, regulations, and lawful requests from competent authorities, including tax and financial regulations.

Service Improvement

Analysing anonymised, aggregated usage data to improve service reliability, performance, and features. We do not use email content for this purpose.

7. Email Content & Confidentiality

Our Guarantee

  • lockNo human reads your emails. No ProEmails employee, contractor, or agent has access to the content of your email communications.
  • visibility_offNo manual review. We do not manually inspect, read, or review email content for any purpose.
  • blockNo advertising use. We do not use email content to build profiles, target advertising, or for any marketing purpose.
  • money_offNo selling. We do not sell, rent, lease, or otherwise monetise your email content or personal data.

Access to infrastructure systems (servers, storage) is restricted by technical controls to automated processes required for service delivery. During maintenance operations, technical safeguards prevent personnel from accessing plaintext email content. Any unauthorised access to customer email content by personnel would constitute a violation of our internal policies and applicable law.

8. AI & Automated Processing

ProEmails employs AI-based technology for automated spam and malware filtering. This section explains how this processing works and the safeguards in place.

How It Works

  • Incoming emails are analysed in real-time by our AI classification models.
  • The models assess patterns, headers, content signals, and sender reputation to identify spam, phishing, and malware.
  • Classified emails are moved to the appropriate folder (inbox or spam) automatically.

Data Processing Safeguards

  • EU-only processing: All AI models run exclusively on ProEmails-owned servers located within the European Union.
  • No third-party AI services: No email data is transmitted to any external AI provider, cloud AI service, or third-party API.
  • No human review: The AI process is fully automated. No human reviews the classification decisions or the content processed.
  • No data retention by AI systems: The AI filtering system processes data in real-time and does not retain copies of email content after classification.
  • No profiling: AI classification results are not used to build user profiles or for any purpose other than email delivery.

Under Article 22 GDPR, this automated processing does not produce legal effects or similarly significant effects on you. If you believe a legitimate email has been incorrectly filtered, you can review your spam folder at any time or contact our support team.

9. Data Storage & Security

All personal data and email data is stored on servers physically located within the European Union. We implement technical and organisational security measures in accordance with Article 32 GDPR.

Security Measures

Encryption in Transit

All connections encrypted via TLS 1.2+ (IMAP, SMTP, Webmail).

Encryption at Rest

Email data and databases encrypted using AES-256.

Password Security

Passwords stored using irreversible cryptographic hashing algorithms.

End-to-End Encryption

OpenPGP / GnuPG encryption available on all plans.

Access Controls

Role-based access, multi-factor authentication for staff, principle of least privilege.

Infrastructure Security

Firewalls, intrusion detection and prevention, DDoS mitigation, continuous monitoring.

Physical Security

EU data centres with biometric access control, 24/7 CCTV, and on-site security.

Incident Response

Documented incident response plan with defined escalation procedures.

10. Data Retention & Deletion

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Active Subscriptions

All data is retained for the duration of your active subscription.

Account Deletion (Voluntary or Non-Payment)

Upon account deletion, all personal data, email content, attachments, metadata, contacts, calendar entries, and associated account data are immediately and permanently deleted from our active systems and backup infrastructure. No residual copies are retained.

Legal Retention

Where required by law (e.g., financial records for tax compliance), we retain only the minimum data necessary for the legally mandated retention period. Email content is never subject to legal retention obligations.

Support Enquiries

Support ticket data is retained for 12 months after resolution for quality assurance, then permanently deleted.

11. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

Payment Processors

We use third-party payment processors to handle subscription billing. These processors receive only the information necessary to process payments (name, billing address, payment method details) and are contractually prohibited from using your data for any other purpose. They do not have access to your email data.

Infrastructure Providers

EU-based data centre operators who host our physical servers. These providers act as data processors under a Data Processing Agreement (DPA) in accordance with Article 28 GDPR and do not have logical access to your data.

Legal Requirements

We may disclose your data if required to do so by law, court order, or lawful request from a competent authority. Where legally permitted, we will notify you of such requests before disclosure. We carefully review all requests to ensure they are lawful and proportionate.

We do not share email content with any third party under any circumstances, except where required by a binding legal order.

All data processors are bound by Data Processing Agreements and are required to implement appropriate technical and organisational measures. A full list of our sub-processors is available upon request from our Data Protection Officer.

12. International Data Transfers

No international transfers. All personal data, email content, and associated data is stored and processed exclusively on servers located within the European Union. We do not transfer your data to any country outside the EU/EEA.

Should our infrastructure requirements change in the future, any transfer of personal data outside the EU/EEA will only take place in compliance with Chapter V of the GDPR, using appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or Binding Corporate Rules. You will be notified of any such change, and this Privacy Policy will be updated accordingly.

13. Cookies & Similar Technologies

Our website and webmail interface use cookies and similar technologies as described below:

Strictly Necessary Cookies

Essential for authentication, session management, security tokens, and CSRF protection. These cookies cannot be disabled without preventing the service from functioning.

Functional Cookies

Used to remember user interface preferences such as language settings, theme selection, and display options.

What We Do NOT Use

  • Third-party advertising cookies
  • Third-party analytics or tracking services
  • Social media tracking pixels
  • Behavioural advertising or retargeting technologies
  • Cross-site tracking technologies

We comply with the EU ePrivacy Directive (Directive 2002/58/EC as amended) and applicable national implementations. Our strictly necessary cookies are exempt from consent requirements under Article 5(3) of the ePrivacy Directive.

14. Your Rights

Under the UK GDPR and EU GDPR, you have the following rights. To exercise any right, contact us at dpo@proemails.uk. We will respond within one month, extendable by two months for complex requests.

Right of Access (Art. 15)

Request a copy of all personal data we hold about you, including the purposes of processing, categories of data, and recipients.

Right to Rectification (Art. 16)

Request correction of inaccurate personal data or completion of incomplete data.

Right to Erasure (Art. 17)

Request deletion of your personal data where there is no compelling reason to continue processing. Note: requesting erasure of your account will result in immediate, permanent deletion of all data.

Right to Restrict Processing (Art. 18)

Request that we limit how we use your data while a dispute is resolved or an objection is considered.

Right to Data Portability (Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format (e.g., for email migration to another provider).

Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

Rights Related to Automated Decision-Making (Art. 22)

The right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

We will not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive (in which case a reasonable fee may be charged, or we may refuse to act). We may request proof of identity before fulfilling requests.

15. Children's Privacy

ProEmails services are not directed at children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children.

If you become aware that a child has provided us with personal data without parental consent, please contact us immediately at dpo@proemails.uk. We will take steps to promptly delete such data.

16. Data Breach Procedures

In the event of a personal data breach affecting your data:

  • check_circle We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR).
  • check_circle If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (Article 34 GDPR).
  • check_circle We maintain a breach register documenting all incidents, including the nature of the breach, data affected, consequences, and remedial actions taken.

18. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or business operations.

  • Material changes will be communicated via email to registered users and/or a prominent notice on our website.
  • The "Effective date" at the top of this page will always reflect the date of the latest revision.
  • We encourage you to review this page regularly.
  • Continued use of our services after changes take effect constitutes acceptance of the updated policy.

19. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data:

Data Protection Officer

Email: dpo@proemails.uk

Postal Address

ProEmails, 9 Orchard Road, Stevenage, Hertfordshire, SG1 3HD, United Kingdom

We will respond to all legitimate requests within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority (see our GDPR page for details).

Questions about your privacy?

Our Data Protection Officer is available to address any privacy-related concerns.

Contact Our DPO
menu