Privacy Policy

Last updated: 2026-05-02

This Policy explains how Splitsoft, Inc. ("Splitsoft", "we") handles personal data. Where you (the customer) use the Service to send email to your own contacts, we act as a processor on your behalf and our Data Processing Addendum applies. Where we hold data about you directly (billing, login), we act as a controller and this Policy applies.

1. Who we are

Splitsoft, Inc. operates email.splitsoft.com and the underlying email-sending platform. Contact: privacy@splitsoft.com.

2. Data we collect as a controller (about you)

3. Data we process as a processor (on your behalf)

When you use the Service to send messages we process the following on your behalf, governed by our DPA:

You are the controller of this data. You are responsible for having a lawful basis to send to each recipient and for honoring recipient rights under applicable law.

4. Retention

DataRetention
Message bodies (HTML, text, attachments)30 days
Message metadata (envelope, opens, clicks, SMTP codes)13 months
Suppression-list entries (bounces, complaints, unsubscribes)Lifetime of the account
Account and billing recordsAs required by tax law (typically 7–10 years)
Admin audit log2 years
Encrypted backups35 days, then purged

5. Sub-processors

We use a small set of sub-processors to operate the Service. The current list is published in Annex III of our DPA. We notify customers at least 30 days in advance of additions or replacements.

6. Your rights

Where you are a natural person whose personal data we hold as a controller, you may, subject to applicable law: request access, rectification, erasure, portability, or restriction of your personal data, and object to processing based on legitimate interest.

Authenticated customers can self-serve via the data endpoints we ship in the admin panel:

Anyone may also email privacy@splitsoft.com; we respond within 30 days.

Where you are a recipient of email sent through us by one of our customers, Splitsoft is not the controller of your data. We will route your request to the relevant customer; you can identify them from the unsubscribe footer of the email you received.

7. EU representative

EU/UK users have the right to lodge a complaint with their local supervisory authority. Our representative under Art. 27 GDPR is TBD and will be appointed before EU general availability.

8. Cookies

The marketing site sets no analytics or advertising cookies. The admin panel sets a single first-party session cookie issued by NextAuth (next-auth.session-token), strictly necessary to keep you logged in. We do not embed third-party trackers.

9. Security and breach notification

Encryption at rest, TLS in transit, role-based access, audit logging, and tested backups. We will notify affected customers of a confirmed personal-data breach without undue delay and in any event within 72 hours of becoming aware, as required by Art. 33 GDPR.

10. Children

The Service is not directed at children under 16 and we do not knowingly process their personal data.

11. Changes

Material changes to this Policy will be posted at least 30 days before they take effect, with notice to the account email of record.

12. Contact

privacy@splitsoft.com