Legal

Privacy Policy

Effective date: October 5, 2026 · Last updated: October 5, 2026

In short:we collect what we need to run your business email, we don’t sell personal data or use your email content for advertising, and the business that owns each HavitoMail account is responsible for the personal data in its mailboxes.

1. Who We Are and Our Role

HavitoMail is operated by Fastlegal Technologies Private Limited, Jaipur, Rajasthan, India (“we”, “us”). This Policy explains how we process personal data when you visit havitomail.com or use the HavitoMail service (the “Service”). Capitalised terms not defined here have the meaning given in our Terms of Service.

  • Account, billing and website data — we decide why and how it is processed, so we are the data fiduciary (under India’s Digital Personal Data Protection Act, 2023, the “DPDP Act”) and controller (under the EU/UK GDPR, where it applies).
  • Email content and the data of Mailbox Users and correspondents — the Account Owner decides what is sent, received and stored, so the Account Owner is the data fiduciary/controller and we process that data only on their behalf, to provide the Service. The Account Owner is responsible for having a lawful basis, giving any required notices (including to employees whose mailboxes they control), and handling requests from those individuals.

2. Data We Collect

2.1 Data you give us

  • Account details: name, email address, password (stored as a one-way bcrypt hash), and account settings.
  • Domains and mailboxes: domain names, DNS configuration, mailbox addresses and display names, aliases, catch-all and auto-reply settings, signatures.
  • Mailbox credentials: mailbox passwords are stored on our access-restricted servers in a form our mail servers can use to authenticate IMAP and SMTP sign-ins.
  • Billing: plan, amount, currency, dates and payment-provider transaction IDs. Card and UPI details are collected by our payment processors — we never receive or store full card numbers.
  • Support: messages you send to us and our replies.

2.2 Email content

Messages, attachments and folders in mailboxes hosted on the Service, which may contain personal data of Mailbox Users and anyone they correspond with.

2.3 Data collected automatically

  • Server and access logs: IP address, browser/user agent, requested pages, timestamps, sign-in events.
  • Mail logs: sender and recipient addresses, message IDs, sending/receiving IP addresses, sizes, timestamps and delivery status — needed to deliver mail and fight spam and abuse.
  • Approximate country derived from your IP address, to show prices in the right currency.
  • Cookies and local storage — see Section 8.

3. How and Why We Use Data

  • To provide the Service — create accounts and mailboxes, send, receive, store and display email, verify DNS (performance of our contract with you).
  • To bill you — process payments, issue receipts, and send trial, renewal and expiry reminders (contract; legal obligation).
  • To keep the Service secure — detect and prevent spam, phishing, fraud, malware and abuse; enforce our Terms; protect our IP reputation (legitimate interests; legal obligation).
  • To support you and to send essential service announcements (contract; legitimate interests).
  • To comply with law — tax and accounting records, lawful requests from authorities (legal obligation).
  • To improve the Service using aggregated, non-content usage information (legitimate interests).

We do not sell personal data, and we do not read, scan or profile email content for advertising. Content is processed automatically to deliver mail and filter spam and malware. Our staff access Content only where needed to investigate abuse or a security incident, when you ask us to for support, or when required by law.

4. Where Data Is Stored

The Service and its mailboxes are hosted on servers operated by OVH SAS in a data centre in Strasbourg, France (European Union). We are based in India and may access data from India to operate and support the Service. Our payment processors may process billing data in India, the United States or other countries. By using the Service you understand that your data will be transferred to and processed in these locations, and we take reasonable steps to protect it in line with this Policy and applicable law.

5. Who We Share Data With

  • Hosting: OVH SAS (servers and network infrastructure).
  • Payments: Razorpay (INR payments) and Dodo Payments (USD payments; acts as merchant of record) — they receive the data needed to process your payment under their own privacy policies.
  • Email delivery: recipients’ mail servers necessarily receive the messages you send and the associated technical data.
  • DNS: domain names are queried against public DNS resolvers to verify your configuration.
  • Authorities: law-enforcement agencies, courts and regulators, where required by law or to prevent fraud, abuse or harm (see our Terms).
  • Business transfers: a buyer or successor in a merger, acquisition or sale of assets, subject to this Policy.

We do not share personal data with advertisers or data brokers.

6. How Long We Keep Data

  • Account and mailbox data: while the account exists. If an account remains paused for non-payment for more than 90 days, it may be permanently deleted after a final notice. Account Owners can delete mailboxes and domains at any time.
  • Email content: until it is deleted by the user, the Account Owner, or with the account.
  • Server and mail logs: generally up to 90 days, longer if needed to investigate abuse or as required by law.
  • Billing records: up to 8 years, as required by Indian tax and company law.
  • Backups: deleted data may persist in backups for a limited period until those backups are overwritten.

7. Security

We use reasonable security safeguards, including TLS encryption for web, IMAP and SMTP connections, bcrypt hashing of account passwords, HTTP-only session cookies, DKIM/SPF/DMARC, access restrictions on servers and databases, and regular software updates.

However, no system is completely secure. You are responsible for using strong, unique passwords, protecting your devices and credentials, and keeping your own backups. To the maximum extent permitted by law, we are not responsible for unauthorised access, loss or disclosure resulting from causes beyond our reasonable control, including compromise of your own credentials or devices. If a personal data breach occurs that affects you, we will notify you and the authorities as required by law.

8. Cookies and Local Storage

  • Session cookie (strictly necessary): keeps you signed in. It is HTTP-only and expires after 7 days or when you sign out.
  • Browser local storage on your device: theme and display preferences, unsent drafts, email signatures, and recently used contacts for address autocomplete. This stays on your device; you can clear it in your browser at any time.

We do not use advertising or cross-site tracking cookies.

9. Emails We Send You

We send service emails that are necessary for your account — for example, verification, password reset, receipts, security notices, and trial or plan reminders (which start 5 days before your trial or plan ends and continue daily during the grace period). These are part of the Service and cannot be switched off while you have an account. If we send optional product news, every such email will include a way to opt out.

10. Your Rights

Subject to applicable law (including the DPDP Act and, where it applies, the GDPR), you may:

  • access a summary of the personal data we process about you;
  • correct, complete or update inaccurate data;
  • request erasure of your data (subject to legal retention requirements);
  • withdraw consent, where processing is based on consent;
  • nominate another person to exercise your rights in the event of death or incapacity (DPDP Act);
  • where the GDPR applies, request portability or restriction, object to processing, and lodge a complaint with a data protection supervisory authority;
  • seek grievance redressal from our Grievance Officer (Section 13).

Email privacy@havitomail.com from your registered address. We may need to verify your identity, and will respond within 30 days or the time required by law. If your data is in a mailbox belonging to a business (for example, your employer or someone you emailed), please contact that business — it controls that data — and we will assist them as required.

11. Children

The Service is for businesses and is not intended for anyone under 18. We do not knowingly collect personal data of children. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to This Policy

We may update this Policy from time to time. We will post the new version here with an updated date and, for material changes, notify Account Owners by email or in the Service.

13. Grievance Officer and Contact

Questions, requests and complaints about this Policy or your personal data:

Grievance Officer, HavitoMail

Fastlegal Technologies Private Limited, Jaipur, Rajasthan, India

Privacy requests: privacy@havitomail.com

Grievances: grievance@havitomail.com

Support: support@havitomail.com