Data Protection and Privacy

Privacy Policy

This Privacy Policy ("Policy") describes how MaileniumAI ("we", "us", "our", or "Company") collects, uses, discloses, and protects your personal information when you use our email marketing platform and services (collectively, the "Service"). By using our Service, you agree to the collection and use of information in accordance with this Policy.

Last Updated: March 2, 2026

1. Information We Collect

01.

1.1 Information You Provide to Us. We collect information that you provide directly to us when you:

  • Account Information: When you create an account, we collect your name, email address, phone number, company name, billing address, and payment information. We also collect your password, which is encrypted and stored securely.
  • Profile Information: We collect information you choose to provide in your profile, such as your avatar, timezone preferences, notification settings, and communication preferences.
  • Contact Data: When you import or add contacts to your account, we collect and store contact information including names, email addresses, phone numbers, custom fields, tags, and any other information you provide about your contacts.
  • Content and Communications: We collect the content you create, including email campaigns, templates, automation workflows, forms, and any messages or communications you send through our Service.
  • Support Communications: When you contact our support team, we collect your contact information and the content of your communications, including any attachments or files you provide.
  • Survey and Feedback: We may collect information you provide when participating in surveys, feedback forms, or other voluntary submissions.
03.

1.2 Information We Collect Automatically. When you use our Service, we automatically collect certain information about your device and usage patterns:

  • Device Information: We collect information about your device, including IP address, browser type and version, operating system, device identifiers, and mobile network information.
  • Usage Data: We collect information about how you interact with our Service, including pages visited, features used, time spent on pages, click patterns, search queries, and navigation paths.
  • Log Data: Our servers automatically record information when you access our Service, including access times, dates, error logs, and system performance data.
  • Email Tracking: We collect information about email delivery, opens, clicks, bounces, unsubscribes, and other engagement metrics for emails sent through our Service.
  • Location Data: We may collect approximate location information based on your IP address, though we do not collect precise GPS location data without your explicit consent.
05.

1.3 Information from Third Parties. We may receive information about you from third-party services:

  • Authentication Providers: If you sign in using OAuth providers (such as Google), we receive your name, email address, and profile picture from the provider.
  • Payment Processors: Our payment processors (such as Stripe) provide us with transaction information, payment method details, and billing information necessary to process your payments.
  • Integration Partners: When you connect third-party services (such as Shopify, WordPress, or Salesforce), we may receive data from those services in accordance with your authorization and their privacy policies.
  • Email Service Providers: We receive delivery and engagement data from email service providers (such as Amazon SES) regarding emails sent through our Service.
07.

1.4 Cookies and Similar Technologies. We use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your browsing activities. For detailed information about our use of cookies, please see our Cookies Policy.

2. How We Use Your Information

01.

We use the information we collect for the following purposes:

02.

2.1 Service Provision and Operation. We use your information to provide, maintain, and improve our Service, including: (a) creating and managing your account; (b) processing your subscriptions and payments; (c) sending, delivering, and tracking emails on your behalf; (d) providing customer support and responding to your inquiries; (e) managing your contacts, campaigns, and automation workflows; (f) generating analytics and reports; and (g) ensuring the security and integrity of our Service.

03.

2.2 Communication. We use your contact information to: (a) send you service-related notifications, including account updates, security alerts, and system maintenance notices; (b) respond to your support requests and inquiries; (c) send you marketing communications (with your consent, where required by law); (d) provide you with product updates, feature announcements, and educational content; and (e) send you transactional emails related to your use of the Service.

04.

2.3 Personalization and Improvement. We use your information to: (a) personalize your experience and customize content, features, and recommendations; (b) analyze usage patterns to improve our Service, develop new features, and enhance user experience; (c) conduct research and analytics to understand user behavior and preferences; and (d) train and improve our AI-powered features and recommendations.

05.

2.4 Legal Compliance and Protection. We use your information to: (a) comply with applicable laws, regulations, and legal processes; (b) enforce our Terms of Service and other agreements; (c) protect our rights, property, and safety, as well as those of our users and third parties; (d) detect, prevent, and address fraud, security threats, and other illegal activities; and (e) respond to government requests and legal proceedings.

06.

2.5 Business Operations. We use your information for business purposes, including: (a) processing payments and managing billing; (b) conducting audits and compliance reviews; (c) managing our business relationships and partnerships; (d) analyzing business trends and performance; and (e) planning and executing business transactions, such as mergers or acquisitions.

3. Information Sharing and Disclosure

01.

We do not sell your personal information. We may share your information in the following circumstances:

02.

3.1 Service Providers and Vendors. We share information with third-party service providers who perform services on our behalf, including: (a) cloud hosting and infrastructure providers (such as AWS, MongoDB); (b) payment processors (such as Stripe); (c) email delivery services (such as Amazon SES); (d) analytics and monitoring services; (e) customer support platforms; (f) marketing and advertising services; and (g) other vendors necessary to operate our Service. These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

03.

3.2 Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity or successor organization, subject to the same privacy protections outlined in this Policy.

04.

3.3 Legal Requirements. We may disclose your information if required by law, regulation, legal process, or government request, including: (a) responding to subpoenas, court orders, or other legal processes; (b) complying with law enforcement requests; (c) protecting our legal rights and interests; and (d) preventing harm to users or the public.

05.

3.4 Consent. We may share your information with third parties when you have provided explicit consent for such sharing, such as when you authorize integrations with third-party services or participate in partner programs.

06.

3.5 Aggregated and Anonymized Data. We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for research, analytics, marketing, or other business purposes.

07.

3.6 Contact Data. When you send emails through our Service, recipient email addresses and engagement data may be processed by email service providers and delivery networks. We do not share your contact lists with third parties for their own marketing purposes.

4. Data Security

01.

4.1 Security Measures. We implement industry-standard technical and organizational security measures to protect your information from unauthorized access, disclosure, alteration, or destruction, including:

  • Encryption: We use TLS 1.3 encryption for data in transit and AES-256 encryption for data at rest. Sensitive information, including passwords and payment data, is encrypted using industry-standard algorithms.
  • Access Controls: We implement role-based access controls, multi-factor authentication, and principle of least privilege to ensure that only authorized personnel can access your information.
  • Network Security: We use firewalls, intrusion detection systems, DDoS protection, and other network security measures to protect our infrastructure.
  • Regular Security Audits: We conduct regular security assessments, vulnerability scans, and penetration testing to identify and address security vulnerabilities.
  • Employee Training: We provide regular security training to our employees and contractors and require them to sign confidentiality agreements.
  • Incident Response: We maintain an incident response plan to promptly address and mitigate security incidents.
03.

4.2 Data Breach Notification. In the event of a data breach that poses a risk to your personal information, we will notify affected users and relevant authorities in accordance with applicable data protection laws, typically within 72 hours of becoming aware of the breach.

04.

4.3 Your Responsibilities. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. Please use strong, unique passwords and enable multi-factor authentication when available.

05.

4.4 No Absolute Security. While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your information to the best of our ability.

5. Data Retention

01.

5.1 Retention Periods. We retain your personal information for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Account Information: We retain your account information for the duration of your account's existence and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
  • Contact Data: We retain contact data you upload to our Service for as long as your account is active or until you delete it. Deleted contacts are permanently removed from our systems within 30 days, except where retention is required by law.
  • Campaign and Email Data: We retain campaign data, email content, and analytics for the duration of your account and for up to 90 days after account termination, unless you request earlier deletion.
  • Payment Information: We retain payment and billing records as required by law, typically for 7 years for tax and accounting purposes.
  • Log Data: We retain server logs and system logs for up to 12 months for security and debugging purposes.
03.

5.2 Deletion Requests. You may request deletion of your personal information at any time by contacting us or using the deletion tools in your account settings. We will honor deletion requests in accordance with applicable law, subject to our legal obligations to retain certain information.

04.

5.3 Backup Data. Information may persist in backup systems for a limited period after deletion. We securely delete backup data in accordance with our retention policies.

6. Your Privacy Rights

01.

Depending on your location, you may have certain rights regarding your personal information:

02.

6.1 Access and Portability. You have the right to access your personal information and receive a copy of your data in a structured, commonly used, and machine-readable format. You can access much of your information through your account settings or by contacting us.

03.

6.2 Correction and Update. You have the right to correct inaccurate or incomplete personal information. You can update most information through your account settings or by contacting our support team.

04.

6.3 Deletion. You have the right to request deletion of your personal information, subject to certain exceptions, such as when we need to retain information for legal compliance or legitimate business purposes.

05.

6.4 Objection and Restriction. You have the right to object to certain processing of your personal information and to request restriction of processing in certain circumstances.

06.

6.5 Opt-Out of Marketing. You can opt out of marketing communications at any time by clicking the unsubscribe link in our emails or updating your communication preferences in your account settings. You may still receive service-related communications.

07.

6.6 Data Portability. You have the right to receive your personal information in a portable format and to transfer it to another service provider where technically feasible.

08.

6.7 Withdrawal of Consent. Where we process your information based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.

09.

6.8 Non-Discrimination. We will not discriminate against you for exercising your privacy rights.

10.

6.9 Exercising Your Rights. To exercise your privacy rights, please contact us at privacy@mailenium.ai or use the privacy controls in your account settings. We will respond to your request within 30 days, or as required by applicable law.

7. Cookies and Tracking Technologies

01.

7.1 Types of Cookies. We use the following types of cookies and similar technologies:

  • Essential Cookies: Required for the Service to function properly, including authentication, security, and load balancing.
  • Functional Cookies: Enable enhanced functionality and personalization, such as remembering your preferences and settings.
  • Analytics Cookies: Help us understand how users interact with our Service, including page views, click patterns, and user flows.
  • Advertising Cookies: Used to deliver relevant advertisements and measure advertising effectiveness (used only with your consent).
03.

7.2 Cookie Management. You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our Service. For more information, please see our Cookies Policy.

04.

7.3 Do Not Track. Our Service does not currently respond to "Do Not Track" signals from browsers. We continue to monitor developments in this area and may implement support in the future.

8. Third-Party Services and Integrations

01.

8.1 Third-Party Services. Our Service integrates with various third-party services, including payment processors, email delivery services, analytics providers, and business tools. When you use these integrations, your information may be shared with the third-party service in accordance with their privacy policies.

02.

8.2 Your Responsibility. When you authorize integrations or connect third-party services to your account, you are responsible for reviewing and understanding the privacy practices of those third parties. We are not responsible for the privacy practices of third-party services.

03.

8.3 Links to Third-Party Websites. Our Service may contain links to third-party websites. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

9. International Data Transfers

01.

9.1 Data Transfers. Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our servers and service providers are located. These countries may have different data protection laws than your country.

02.

9.2 Transfer Safeguards. When we transfer your information internationally, we implement appropriate safeguards to protect your information, including: (a) Standard Contractual Clauses approved by the European Commission; (b) adequacy decisions by relevant data protection authorities; and (c) other legally recognized transfer mechanisms.

03.

9.3 Your Consent. By using our Service, you consent to the transfer of your information to countries outside your country of residence, including the United States, for the purposes described in this Policy.

10. Children's Privacy

01.

Our Service is not intended for children under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete such information promptly.

11. California Privacy Rights (CCPA)

01.

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

02.

11.1 Right to Know. You have the right to know what personal information we collect, use, disclose, and sell (if applicable). You can request a copy of your personal information and information about our data practices.

03.

11.2 Right to Delete. You have the right to request deletion of your personal information, subject to certain exceptions.

04.

11.3 Right to Opt-Out. You have the right to opt out of the sale of your personal information. We do not sell personal information, but you can still exercise this right for any future changes to our practices.

05.

11.4 Right to Non-Discrimination. We will not discriminate against you for exercising your CCPA rights.

06.

11.5 Authorized Agents. You may designate an authorized agent to exercise your CCPA rights on your behalf. We may require verification of the agent's authorization.

07.

11.6 Shine the Light. California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes.

12. European Privacy Rights (GDPR)

01.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

02.

12.1 Legal Basis for Processing. We process your personal information based on: (a) your consent; (b) performance of a contract; (c) compliance with legal obligations; (d) protection of vital interests; (e) performance of a task in the public interest; and (f) legitimate interests, where such interests are not overridden by your rights and freedoms.

03.

12.2 Data Protection Officer. You can contact our Data Protection Officer at dpo@mailenium.ai for questions about our data processing practices or to exercise your GDPR rights.

04.

12.3 Supervisory Authority. You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your privacy rights.

05.

12.4 Automated Decision-Making. We do not use automated decision-making, including profiling, that produces legal effects or significantly affects you, except with your explicit consent or as otherwise permitted by law.

13. Changes to This Privacy Policy

01.

13.1 Policy Updates. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. We will notify you of material changes by: (a) posting the updated Policy on our website with a new "Last Updated" date; (b) sending you an email notification to the email address associated with your account; and (c) displaying a prominent notice on our Service.

02.

13.2 Continued Use. Your continued use of our Service after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree to the changes, you should discontinue use of our Service and contact us to delete your account.

03.

13.3 Review Period. We encourage you to review this Policy periodically to stay informed about how we collect, use, and protect your information.

14. Contact Information

01.

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

02.

MaileniumAI Privacy Team
Email: privacy@mailenium.ai

03.

For general inquiries or support, please contact us at support@mailenium.ai or visit our Help Portal.

Acceptance of Privacy Policy

By using MaileniumAI's Service, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree with any part of this Policy, you must not use our Service.

This Privacy Policy is effective as of the date listed above and will remain in effect except with respect to any changes in its provisions in the future, which will take effect immediately upon posting to our website.