Privacy Policy

Last updated: 2026-04-30

How Splitsoft handles personal data. Where you (the Customer) use the Service to send email to your own contacts, we act as a processor on your behalf and our Data Processing Addendum applies. Where we hold data about you (billing, login), we act as a controller and this Policy applies directly.

1. Who we are

Splitsoft, Inc. (Delaware, USA) operates email.splitsoft.com and the underlying email-sending platform. Contact: privacy@splitsoft.com.

2. Data we hold as a controller (about you, the Customer)

3. Data we process as a processor (on your behalf)

When you use the Service to send Messages, we process the following on your behalf, governed by our DPA:

We are not the controller of this data. You are. You are responsible for having a lawful basis to send to each Recipient and for honoring Recipient rights under applicable law. We will support you with the data export and deletion endpoints described in Section 8.

4. Legal bases (where GDPR / UK GDPR applies)

5. Retention

DataRetentionWhy
Message bodies (HTML, text, attachments)30 daysBounce diagnosis, support, deliverability investigation.
Message metadata (envelope, timestamps, SMTP codes, opens/clicks)13 monthsYear-over-year deliverability trends, fraud and abuse review.
Suppression-list entries (bounces, complaints, unsubscribes)Lifetime of accountTo prevent re-sending to addresses that have bounced or complained.
Account and billing records (invoices, payment history)Indefinite, as required by tax law (typically 7–10 years)Statutory record-keeping under US/EU/UK rules.
Admin audit log2 yearsSecurity investigation.
Encrypted backups (Postgres, MariaDB)35 days, then purgedDisaster recovery; deletion in production propagates within this window.

6. Sub-processors

We use the following sub-processors. We notify Customers of changes at least 30 days in advance via email and via the published list at this URL.

7. Data residency

By default, all production data sits on Vultr infrastructure in the United States. EU residency (Frankfurt) becomes available with milestone M9 of our roadmap. We do not transfer Customer Data outside the elected region except for encrypted, off-region backups, which are encrypted with keys held in the production region.

8. Your rights and how to exercise them

Where you are a natural person whose personal data we hold as a controller (e.g. you are the Splitsoft account holder), you may exercise the following rights subject to applicable law:

Authenticated Customers can self-serve via the data endpoints in the admin panel: /api/data-export (download), /api/data-erasure (delete), /api/data-portability (machine-readable handoff). Anyone may also email privacy@splitsoft.com; we respond within 30 days.

Where you are a Recipient (you received an email sent through us by one of our Customers), Splitsoft is not the controller of your data. We will route your request to the relevant Customer; you may identify the Customer from the unsubscribe footer of the email you received.

9. Cookies

The marketing site (email.splitsoft.com) sets no analytics or advertising cookies. The admin panel sets a single first-party session cookie issued by NextAuth (next-auth.session-token), strictly necessary to keep you logged in. We do not embed third-party trackers.

10. Security

Our technical and organizational measures are described on our security page. We will notify affected Customers of a confirmed personal-data breach without undue delay and in any event within 72 hours of becoming aware, as required by Art. 33 GDPR and our DPA.

11. Children

The Service is not directed at children under 16 and we do not knowingly process their personal data.

12. Changes

We will post material changes to this Policy at least 30 days before they take effect, and notify the account email of record. Historic versions are archived on request.

13. Contact and complaints

Questions: privacy@splitsoft.com. EU/UK users have the right to lodge a complaint with their local supervisory authority. Our EU representative under Art. 27 GDPR will be appointed before EU launch (M9). [REVIEW: appoint Art. 27 rep before EU GA.]