1. Who we are
Humblesend is a business email platform operated by Illumetric Technologies AB, a Swedish limited company. For the personal data described below where we decide why and how it is processed, Illumetric Technologies AB is the data controller.
Illumetric Technologies ABPontus Ols Väg 8
263 61 Viken, Sweden
Organisation number: 559497-2886
VAT number: SE559497288601
Email: [email protected]
Our Data Protection Officer is Mats-Ola Ström. You can contact the DPO at [email protected] and mark the message “Data protection”.
2. When we are controller and when we are processor
Illumetric as controller
We act as controller for data about website visitors, prospective customers, account holders, customer administrators, billing contacts, and people who communicate directly with us. This includes deciding how we operate accounts, secure the service, invoice customers, analyse the website, and meet legal obligations.
Illumetric as processor
A Humblesend customer normally decides why and how to process the subscriber, recipient, campaign, and transactional-message data uploaded to or generated through its workspace. For that Customer Data, the customer is controller and Illumetric acts as processor on the customer’s documented instructions. Our data-processing terms are included in the Terms of Service.
If you received an email from a Humblesend customer: that customer is usually the controller and is the best first contact for access, deletion, consent, or unsubscribe questions. We assist our customer in responding to valid requests. The unsubscribe link in a marketing email can be used without creating a Humblesend account.
3. Personal data we process
The data depends on how you interact with Humblesend and may include:
- Account and identity data: name, business email address, company, role, workspace membership, authentication-provider identifier, password hash, session data, two-factor authentication status, and encrypted authentication secrets or recovery codes.
- Billing and commercial data: billing contact, company details, VAT number, billing address, subscription, invoices, payment status, and limited payment-method details provided by Stripe. Humblesend does not store complete card numbers.
- Customer Data: subscriber and recipient details, contact properties, list and segment membership, consent and subscription records, suppressions, campaign content, transactional-message content, Layouts, Brand Guides, uploaded media and fonts, translation source text and proposals, sender information, and customer-configured fields.
- Delivery and engagement data: message identifiers, timestamps, delivery, bounce, complaint, delay, unsubscribe, and—where lawfully enabled—open or link-interaction events.
- Device, log, and security data: IP address, browser and device information, request and event timestamps, session identifiers, audit events, authentication attempts, and information used to identify abuse, fraud, or service faults.
- Website and preference data: pages viewed, referral information, approximate location derived from IP address, cookie choices, and analytics identifiers where you have consented.
- Communications: support requests, feedback, survey responses, and other correspondence with us.
We obtain data from you, your organisation, workspace administrators, email recipients’ interactions, identity and payment providers, delivery providers, and automatically from the service and your device. Customers must not use Humblesend for special-category data unless they have a valid legal basis, have assessed the risks, and our written agreement expressly permits the processing.
4. Why we process personal data
| Purpose | Typical data | GDPR legal basis |
|---|---|---|
| Provide accounts, authentication, workspaces, email functionality, support, and requested services | Account, identity, Customer Data, delivery data, communications | Performance of a contract or steps requested before entering one |
| Manage subscriptions, payments, invoices, and customer relationships | Account, company, billing, payment status, communications | Contract; legal obligations for accounting and tax |
| Secure Humblesend, prevent fraud and abuse, enforce sending rules, and protect deliverability | Identity, device, log, audit, delivery, complaint, and suppression data | Legitimate interests in security, service integrity, and protecting customers and recipients; legal obligations where applicable |
| Maintain, troubleshoot, and improve the service | Usage, log, performance, support, and aggregated service data | Legitimate interests in operating and improving a reliable business service |
| Measure website use with Google Analytics | Cookie identifiers, device, usage, and approximate location data | Consent |
| Send product information or business communications | Contact details, role, preferences, and communication history | Consent where required; otherwise legitimate interests for proportionate B2B communications, subject to your right to object |
| Establish, exercise, or defend legal claims and comply with lawful requests | Relevant account, billing, communication, security, and service records | Legal obligation or legitimate interests in protecting our legal rights |
When we rely on legitimate interests, we consider the necessity of the processing and balance our interests against the rights and reasonable expectations of the people affected. When we act as processor, the customer—not Illumetric—determines the legal basis for Customer Data.
Account, company, billing, and authentication fields identified as required are necessary to enter into or perform the contract and, where applicable, meet invoicing obligations. Without them, we may be unable to create an account, provide the Service, or process a subscription. Analytics consent and optional profile or marketing information are voluntary; refusing them does not prevent use of the core Service.
7. EU data location and international transfers
Humblesend’s primary application databases, stored Customer Data, and backups are hosted in an AWS region located in the European Union. Customer-uploaded email media is stored in a Cloudflare R2 bucket configured for EU jurisdiction. Some providers or their support, security, payment, or analytics operations may nevertheless process limited personal data outside the European Economic Area.
Where personal data is transferred outside the EEA, we use a lawful transfer mechanism as required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, and supplementary technical or organisational measures appropriate to the risk. You may contact our DPO for information about the relevant safeguard and, where available, a copy of it.
8. How long we keep data
We keep personal data only for as long as necessary for its purpose, customer instructions, and applicable legal obligations. Our standard launch retention periods are:
| Data | Standard retention |
|---|---|
| Account, workspace, and profile data | For the active account, then normally deleted or anonymised within 30 days after account closure |
| Customer Data and stored email content | For the subscription term and up to 30 days afterward for export or recovery, unless the customer deletes it sooner or instructs otherwise |
| Translation proposals | Up to 30 days unless accepted or deleted sooner |
| Backup copies | Removed through the backup cycle within 90 additional days and isolated from ordinary use |
| Authentication, audit, delivery, and security logs | Normally up to 12 months; longer only for an active security incident, abuse investigation, legal claim, or customer instruction |
| Consent, complaint, unsubscribe, and suppression records | As instructed by the customer and as reasonably necessary to demonstrate compliance and continue honouring an objection or suppression |
| Support communications | Normally 24 months after the request is closed |
| Google Analytics data | No more than 14 months |
| Invoices and accounting records | At least seven years, as required by Swedish accounting law |
A court order, legal hold, unresolved dispute, security incident, or statutory obligation may require longer retention. When deletion is not immediately possible, we restrict the data from ordinary use until deletion is completed.
9. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may request access to your personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects and the GDPR provides that right.
To exercise a right concerning data for which Illumetric is controller, email [email protected]. We may need to verify your identity and will normally respond within one month. If we process the data solely for a Humblesend customer, please contact that customer first; we will assist them as required.
Direct marketing: you can object at any time to processing for direct marketing, including related profiling. Use the unsubscribe link in the message or contact us. We may retain a minimal suppression record so we can continue to respect the objection.
You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or the supervisory authority where you live or work. We encourage you to contact our DPO first so we have an opportunity to address the concern.
10. Security and data incidents
We use technical and organisational measures appropriate to the risk, including access controls, least-privilege administration, encryption in transit, protected authentication credentials, two-factor authentication support, tenant-aware access controls, logging, backups, vulnerability management, and incident-response procedures. No online system can be guaranteed completely secure, so customers must also protect their accounts, devices, credentials, and API keys.
We investigate suspected personal-data breaches and notify affected customers and supervisory authorities when required. When acting as processor, we notify the relevant customer without undue delay after becoming aware of a breach involving Customer Data.
11. Automated processing, business users, and children
Humblesend may automatically detect suspicious authentication, sending patterns, complaints, bounces, or other abuse indicators and may temporarily limit sending to protect recipients and the service. Material enforcement decisions can be reviewed by a person. We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Humblesend is a business service, is not directed to consumers or children, and may be used only by people aged 18 or older acting for a business or professional organisation.
12. Changes and contact
We may update this policy when Humblesend, our providers, or legal requirements change. We will publish the revised policy here, update the date above, and provide reasonable advance notice of material changes when appropriate.
Questions, rights requests, and data-protection concerns can be sent to [email protected] or by post to Illumetric Technologies AB, Pontus Ols Väg 8, 263 61 Viken, Sweden.