Lumail Privacy Policy
Last updated: 2026-09-03
Overview
This Privacy Policy explains how Codelynx, LLC ("Codelynx", "we", "us", or "our") handles personal data through Lumail (the "Service") at lumail.io.
Codelynx is the controller of account, billing, support, and website data that it collects for its own purposes. When a Lumail customer uploads subscriber data or sends email through the Service, that customer decides why and how the data is used and is normally the data controller. Codelynx processes that subscriber data to provide Lumail on the customer's instructions.
Lumail is an early-stage service. We do not currently offer an Article 28 Data Processing Agreement (DPA), our customer terms do not currently incorporate the European Commission's Standard Contractual Clauses (SCCs), and Codelynx does not currently rely on an EU-U.S. Data Privacy Framework certification. See DPA and GDPR Contract Status.
If your use requires an executed DPA or a transfer mechanism for EEA, UK, or Swiss personal data, do not place that data in Lumail until the required agreement is available and signed.
1. Personal Data We Process
Account and organization data
- Name, email address, organization details, authentication and security records
- Plan, invoices, and payment-related identifiers; card details are handled by Stripe and are not stored directly by Lumail
- Support messages and administrative activity
Subscriber and email data provided by customers
- Email address, name, phone number, IP address, country, tags, and custom fields
- Subscription status and, when Lumail's native double opt-in is used, confirmation time and IP address
- Consent evidence and list-provenance records, such as the collection source, method, date, and consent language
- Campaign, workflow, transactional email, and message-content data
- Delivery and engagement events, including sends, deliveries, opens, clicks, bounces, complaints, and unsubscribes
Technical data
- IP address, browser user agent, device and request metadata, timestamps, logs, and security events
- Domain and DNS verification data
- Cookies and similar identifiers used for authentication, preferences, product analytics, and reliability
2. Why We Process Data
We process personal data to:
- Provide accounts, subscriptions, email delivery, analytics, workflows, and support
- Authenticate users, secure the Service, prevent abuse, and enforce sending limits
- Handle unsubscribes, bounces, complaints, and suppression records
- Review compliance with our Anti-Spam, Consent, and List Quality policy, including requesting consent evidence and list provenance and suspending sending when that evidence is not provided
- Diagnose incidents and improve product reliability and usability
- Meet legal, accounting, and contractual obligations
For account data, our legal bases may include performance of a contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations. For subscriber data, the Lumail customer is responsible for selecting and documenting the appropriate legal basis and for providing required notices.
3. Service Providers, Subprocessors, and Locations
The following providers are currently relevant to account, subscriber, or email data. Locations describe the configured service or typical processing location; edge networks and support access may involve additional countries.
- netcup: application hosting and self-hosted Redis in Nuremberg, Germany
- Neon / Databricks: PostgreSQL database for accounts, subscribers, and email events in AWS eu-central-1, Frankfurt, Germany
- Amazon Web Services (SES): email delivery and delivery feedback in ap-southeast-2, Sydney, Australia
- Cloudflare: DNS, CDN, and security through a global edge network, plus R2 email-content archives configured for APAC without an EU-only jurisdiction guarantee
- Hatchet: background jobs and email workflow orchestration, self-hosted in Nuremberg, Germany
- Upstash QStash: queued message orchestration through the EU service endpoint
- PostHog Cloud EU: product analytics and application diagnostics in Frankfurt, Germany
- Stripe: billing and payment processing through global infrastructure, including the United States and EEA
- Telegram: limited operational alerts, which may include a subscriber address when a delivery operation fails; Telegram is a global service without a Lumail-specific data residency commitment
Subscriber records and core email events are primarily stored together in the Frankfurt PostgreSQL database. Email content may also be archived in the APAC R2 bucket, and transactional message content is processed by the self-hosted Hatchet worker. Email addresses and message metadata are necessarily shared with SES for delivery.
We do not sell or rent personal data. We disclose it only as needed to operate the Service, comply with law, protect users and the Service, or complete a business transaction subject to appropriate safeguards.
4. International Transfers
Using Lumail can transfer personal data from the EEA, UK, or Switzerland to countries that may not provide an equivalent level of protection, including the United States and Australia.
Codelynx is not currently presenting itself as certified under the EU-U.S. Data Privacy Framework, and Lumail does not currently offer customer SCCs or another Lumail-level transfer addendum. Individual providers may rely on their own transfer safeguards for the services they supply to Codelynx, but those provider arrangements do not replace a DPA and valid transfer mechanism between an EU customer and Codelynx.
5. Customer Responsibilities and Subscriber Privacy
Customers must:
- Collect and document explicit, verifiable consent before adding a subscriber or sending marketing or bulk email
- Provide their own privacy notice and honor access, correction, objection, deletion, and portability requests
- Include required sender identity and unsubscribe controls
- Configure open and click tracking only when legally permitted and disclosed
- Maintain records showing each list's source, collection method, date, consent language, and the recipient's affirmative request or agreement
- Provide those records to Lumail on request
Lumail does not permit purchased, rented, borrowed, scraped, harvested, appended, lookup-derived, enriched, or otherwise non-consensual recipient lists. It also does not permit contest or giveaway lists without explicit marketing consent for the customer's organization and the intended emails, or cold outreach to establish a relationship. Lumail may immediately suspend an organization's sending access when the organization cannot provide requested consent or provenance evidence, or when we reasonably suspect spam or email abuse. These platform rules are stricter than any less restrictive rule that may otherwise apply to a particular type of recipient or jurisdiction.
Lumail's native double opt-in can keep new subscribers pending until they confirm. The transactional send API is not a supported custom double-opt-in state machine: sending to an unknown address creates a TRANSACTIONAL contact unless Add transactional recipients to the marketing list is on, and adding a tag does not itself record GDPR consent or change a pending subscriber to confirmed. See GDPR in Lumail.
6. Cookies and Email Tracking
Lumail uses cookies and similar technology for authentication, preferences, security, product analytics, and diagnostics. We do not operate third-party advertising networks through the Service.
Open tracking uses a remote image and click tracking rewrites links. These features may collect an IP address, user agent, timestamp, and requested link. Customers are responsible for deciding whether consent or another legal basis is required. Transactional API tracking defaults to enabled unless the customer explicitly disables it.
7. Retention and Deletion
Lumail does not currently offer a contractually guaranteed retention schedule for every data category.
- Account and organization data is generally kept while the account is active and afterward when needed for security, disputes, accounting, or legal obligations.
- Subscriber records and event history remain until the customer deletes them, closes the account, or we remove them under an operational or legal process.
- Suppression information may be retained to prevent an address that unsubscribed, bounced, or complained from being emailed again.
- Sent-email content archives and provider logs may remain after a subscriber row is deleted. Lumail does not currently guarantee that the subscriber delete API erases every archive object or third-party log.
Customers needing a specific deletion deadline should contact us before using the Service. We are developing clearer retention controls and downstream deletion procedures.
8. Rights and Requests
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data, and to complain to a supervisory authority.
Subscribers should normally contact the Lumail customer that sent the email because that customer controls the subscriber data. Customers and Lumail account holders can contact [email protected]. We may need to verify identity and authority before acting. Statutory response periods apply; we do not promise that every request will be completed within 30 days where an extension or exemption is legally available.
9. Security
We use measures such as TLS in transit, access controls, environment separation, and provider security controls. No service is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.
10. Children's Privacy
Lumail is not intended for children under 13, and we do not knowingly collect personal data directly from children. Customers must not use Lumail to process children's data unless they have all legally required permissions and have first agreed appropriate terms with us.
11. Changes
We may update this policy as the Service, providers, or legal requirements change. We will update the date above and provide additional notice when required by law.
12. Contact
For privacy questions or complaints:
Codelynx, LLC
State of Delaware, United States