Lumail Privacy Policy
Last updated: 2026-09-15
Overview
This Privacy Policy explains how Codelynx, LLC ("Codelynx", "we", "us", or "our") handles personal data through Lumail (the "Service") at lumail.io.
Codelynx is the controller of account, billing, support, and website data that it collects for its own purposes. When a Lumail customer uploads subscriber data or sends email through the Service, that customer decides why and how the data is used and is normally the data controller. Codelynx processes that subscriber data to provide Lumail on the customer's instructions.
Organization owners and administrators can review and electronically accept a Data Processing Agreement (DPA) in Settings → Configuration → Data Processing Agreement, then download the accepted contract. See Data Processing Agreement. Version 2026-09-15.1 incorporates EU SCC Modules Two and Three, the UK ICO Addendum and Swiss adaptations. It does not establish a Data Privacy Framework certification.
Accepting the DPA establishes the applicable Customer-to-Codelynx transfer terms. It does not complete the required transfer assessment, supply every supplementary measure, or verify the safeguards for each onward transfer.
1. Personal Data We Process
Account and organization data
- Name, email address, organization details, authentication and security records
- Plan, invoices, and payment-related identifiers; card details are handled by Stripe and are not stored directly by Lumail
- Support messages and administrative activity
- DPA acceptance records: organization legal name and address, signer identity and legal name, accepted document version and text, and acceptance time
Subscriber and email data provided by customers
- Email address, name, phone number, IP address, country, tags, and custom fields
- Subscription status and, when Lumail's native double opt-in is used, confirmation time and IP address
- Consent evidence and list-provenance records, such as the collection source, method, date, and consent language
- Campaign, workflow, transactional email, and message-content data
- Delivery and engagement events, including sends, deliveries, opens, clicks, bounces, complaints, and unsubscribes
Technical data
- IP address, browser user agent, device and request metadata, timestamps, logs, and security events
- Domain and DNS verification data
- Cookies and similar identifiers used for authentication, preferences, product analytics, and reliability
2. Why We Process Data
We process personal data to:
- Provide accounts, subscriptions, email delivery, analytics, workflows, and support
- Authenticate users, secure the Service, prevent abuse, and enforce sending limits
- Handle unsubscribes, bounces, complaints, and suppression records
- Review compliance with our Anti-Spam, Consent, and List Quality policy, including requesting consent evidence and list provenance and suspending sending when that evidence is not provided
- Diagnose incidents and improve product reliability and usability
- Meet legal, accounting, and contractual obligations
For account data, our legal bases may include performance of a contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations. For subscriber data, the Lumail customer is responsible for selecting and documenting the appropriate legal basis and for providing required notices.
3. Service Providers, Subprocessors, and Locations
The following providers are currently relevant to account, subscriber, or email data. Locations describe the configured service or typical processing location; edge networks and support access may involve additional countries.
- netcup: application hosting and self-hosted Redis in Nuremberg, Germany
- Neon / Databricks: PostgreSQL database for accounts, subscribers, and email events in AWS eu-central-1, Frankfurt, Germany
- Amazon Web Services (SES): email delivery and delivery feedback in ap-southeast-2, Sydney, Australia
- Cloudflare: DNS, CDN, and security through a global edge network, plus R2 email-content archives configured for APAC without an EU-only jurisdiction guarantee
- Hatchet: background jobs and email workflow orchestration, self-hosted in Nuremberg, Germany
- Upstash QStash: queued message orchestration through the EU service endpoint
- PostHog Cloud EU: product analytics and application diagnostics in Frankfurt, Germany
- Stripe: billing and payment processing through global infrastructure, including the United States and EEA
- Google: managed AI features when used; prompts, content and tool results may contain customer-provided personal data, without an EU-only location commitment
- OpenAI / ChatGPT: optional customer-connected AI features under the applicable account terms; a fallback to managed AI may apply, so the selected connection does not establish an EU-only boundary
- Tchao: support conversations and related workspace identity
- Telegram: limited operational alerts, which may include a subscriber address when a delivery operation fails; Telegram is a global service without a Lumail-specific data residency commitment
- Google Gemini / managed Google AI: optional capture-page and in-app assistant generation when those features are used; residency and prompt retention follow the configured Google AI tier and are not independently certified here
- Customer-connected ChatGPT: optional, only when an organization connects its own OpenAI account; prompts may fall back to managed Google AI if that connection fails
- Tchao: optional live-support widget when enabled; Tchao is a separately controlled processor for support conversations
- Umami (self-proxied /stats): first-party website analytics on public marketing pages
See the subprocessor register for the maintained list. Provider marketing pages are not evidence that a particular contractual tier is in force.
Subscriber records and core email events are primarily stored together in the Frankfurt PostgreSQL database. Email content may also be archived in the APAC R2 bucket, and transactional message content is processed by the self-hosted Hatchet worker. Email addresses and message metadata are necessarily shared with SES for delivery.
We do not sell or rent personal data. We disclose it only as needed to operate the Service, comply with law, protect users and the Service, or complete a business transaction subject to appropriate safeguards.
4. International Transfers
Using Lumail can transfer personal data from the EEA, UK, or Switzerland to countries that may not provide an equivalent level of protection, including the United States and Australia.
Codelynx is not currently presenting itself as certified under the EU-U.S. Data Privacy Framework. DPA version 2026-09-15.1 incorporates the European Commission's 2021 Standard Contractual Clauses, the UK ICO Addendum and Swiss adaptations for applicable Customer-to-Codelynx restricted transfers. Those terms do not replace the required transfer assessment, supplementary measures where needed, or the safeguards required for each onward transfer to a service provider.
5. Customer Responsibilities and Subscriber Privacy
Customers must:
- Collect and document explicit, verifiable consent before adding a subscriber or sending marketing or bulk email
- Provide their own privacy notice and honor access, correction, objection, deletion, and portability requests
- Include required sender identity and unsubscribe controls
- Configure open and click tracking only when legally permitted and disclosed
- Maintain records showing each list's source, collection method, date, consent language, and the recipient's affirmative request or agreement
- Provide those records to Lumail on request
Lumail does not permit purchased, rented, borrowed, scraped, harvested, appended, lookup-derived, enriched, or otherwise non-consensual recipient lists. It also does not permit contest or giveaway lists without explicit marketing consent for the customer's organization and the intended emails, or cold outreach to establish a relationship. Lumail may immediately suspend an organization's sending access when the organization cannot provide requested consent or provenance evidence, or when we reasonably suspect spam or email abuse. These platform rules are stricter than any less restrictive rule that may otherwise apply to a particular type of recipient or jurisdiction.
Lumail's native double opt-in can keep new subscribers pending until they confirm. The transactional send API is not a supported custom double-opt-in state machine: sending to an unknown address creates a TRANSACTIONAL contact unless Add transactional recipients to the marketing list is on, and adding a tag does not itself record GDPR consent or change a pending subscriber to confirmed. See GDPR in Lumail.
6. Cookies and Email Tracking
Lumail uses cookies and similar technology for authentication, preferences, security, product analytics, and diagnostics. We do not operate third-party advertising networks through the Service. Public marketing pages may set a first-party analytics cookie through the /stats script, a sidebar_state preference cookie in the application, and a lumail_ref affiliate referral cookie.
Open tracking uses a remote image and click tracking rewrites links. These features may collect an IP address, user agent, timestamp, and requested link. Customers are responsible for deciding whether consent or another legal basis is required. Marketing campaign sends still use open and click tracking. Transactional API, SDK, MCP, and native double-opt-in confirmation emails default tracking to disabled unless the customer explicitly enables tracking.open and tracking.links. Account OTP and magic-link emails are sent without tracking.
7. Retention and Deletion
Lumail does not currently offer a contractually guaranteed retention schedule for every data category.
- Account and organization data is generally kept while the account is active and afterward when needed for security, disputes, accounting, or legal obligations.
- Subscriber records and event history remain until an authorized organization administrator runs lawful erasure, the organization account is closed, or we remove them under an operational or legal process.
- Ordinary
DELETE /api/v1/subscribers/{id}is disabled and returns 405. Unsubscribe stops marketing mail and keeps history. Lawful erasure is a separate owner/admin action that scrubs identifiable subscriber fields, email bodies, snapshots, and related events, then writes a hashed tombstone so the address cannot be re-imported. - Suppression hashes and delivery-guard identities may be retained to prevent an address that unsubscribed, bounced, complained, or was erased from being emailed again.
- Sent-email content archives are deleted when erasure runs; provider logs (SES, PostHog, backups, historical import files) may remain until their provider-controlled expiry. Lumail does not promise complete third-party deletion without a documented downstream request.
- DPA acceptance evidence is retained as a contractual record; the signed version is not changed by subsequent profile edits.
Customers needing a specific deletion deadline should contact us before using the Service. See GDPR in Lumail and the customer compliance guide.
8. Rights and Requests
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data, and to complain to a supervisory authority.
Subscribers should normally contact the Lumail customer that sent the email because that customer controls the subscriber data. Customers and Lumail account holders can contact [email protected]. We may need to verify identity and authority before acting. Statutory response periods apply; we do not promise that every request will be completed within 30 days where an extension or exemption is legally available.
9. Security
We use measures such as TLS in transit, access controls, environment separation, and provider security controls. No service is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.
10. Children's Privacy
Lumail is not intended for children under 13, and we do not knowingly collect personal data directly from children. Customers must not use Lumail to process children's data unless they have all legally required permissions and have first agreed appropriate terms with us.
11. Changes
We may update this policy as the Service, providers, or legal requirements change. We will update the date above and provide additional notice when required by law.
12. Contact
For privacy questions or complaints:
Codelynx, LLC
8 The Green STE B, Dover, Delaware 19901, United States
Privacy and incidents: [email protected]
Product support: [email protected]
See the security and incident page.