Corresso All legal documents

Privacy notice

Effective [not yet set]

This notice explains how [not yet set] (“we”) handles the personal data we are responsible for — as the controller, in the words of the General Data Protection Regulation (GDPR). It covers people who have a Corresso account, anyone who visits our sign-in and other public pages, and anyone who writes to us.

It does not cover the email that businesses read and answer with Corresso. That mail is the business’s, and we handle it only on the business’s behalf. If you wrote to a business that uses Corresso, the last section is for you.

Who is responsible

What we process, why, and on what legal basis

Your account

The conversations, notes, draft replies and assignments you work on in Corresso are your organisation’s data, not ours. We process them on your organisation’s behalf under our data processing agreement, and your organisation decides what happens to them.

Signing in

Resetting your password

Security logs

Product pictures from Shopify

This happens only in organisations that have connected a Shopify store. Everywhere else, no page of Corresso loads anything from another company’s servers.

When you write to us

Cookies

Corresso sets two cookies of its own, and no others: one keeps you signed in for 30 days, the other protects forms and ends when you close your browser. Both are strictly necessary for the service you have asked for, so under Danish law they need no consent (Cookiebekendtgørelsen, BEK nr. 1148 af 9. december 2011, § 4, stk. 1, nr. 2). We use no analytics, advertising or tracking, and apart from the Shopify product pictures described above, no page loads anything from another company’s servers — not even fonts. Each cookie is described in our cookie declaration.

Who receives the data

Personal data about you reaches these companies:

Hetzner and Postmark process the data on our instructions, under data processing agreements with us. Shopify does not work for us: it handles what it receives under its own privacy policy. Beyond those listed here, we disclose personal data only where the law requires it. We never sell it, and never use it for advertising.

Transfers outside the EU and EEA

Our servers are in Germany. Postmark processes data in the USA. That transfer rests on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795): AC PM LLC is covered by ActiveCampaign, LLC’s certification under it. Should that decision fall away, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) in Postmark’s data processing agreement apply instead. You can ask us for a copy of these safeguards at [not yet set].

Where our email provider stores mail outside the EU or EEA, the safeguard it relies on is named above.

What Shopify receives when your browser loads a product picture, Shopify sends on outside the EU and EEA itself, under the safeguards its own privacy policy names (see above).

How long we keep it

Data Kept
Your account While your account exists; deleted within 30 days after your organisation’s agreement with us ends, and from backups within one further backup cycle
A sign-in 30 days from when you signed in, then deleted by a daily clean-up; at once when you sign out
A password-reset email The link works for 15 minutes; Postmark keeps the sent email for up to 45 days
Sign-in, reset and sending counters Count for at most 3 minutes; then deleted by the cache’s routine clean-up of entries more than two weeks old
What Shopify receives when a product picture loads Nothing kept by us; Shopify keeps it as its own privacy policy says
Corresso’s request log Rotated by size: three files of at most 50 MB each; an old version’s log until that version is removed from the server
The outer web server’s request log One file of at most 10 MB, started afresh when full
Records of failed background tasks 30 days
Database backups At most 30 days
Email you send us While the matter is open, then only as long as needed to show what was agreed

Your rights

Under the GDPR you have the right to:

To use these rights, write to [not yet set]. We answer without undue delay and within one month. If a request is complex, or we receive many, we may take up to two further months, and then tell you so within the first month (art. 12(3)). Your organisation can also ask us to correct or remove your account. We do not rely on consent for any of this, so there is no consent to withdraw.

Complaints

You can complain to the Danish Data Protection Agency (Datatilsynet):

Do you have to give us this data?

No law requires you to. Without an email address and a password there is no account, however, and without the sign-in and security records we cannot let anyone sign in safely.

Automated decisions

We make no decisions about you based solely on automated processing, and we do not profile you (GDPR art. 22).

If you emailed a business that uses Corresso

Businesses use Corresso to read and answer the email their customers send them. If you wrote to one, that business decides what happens to your message: it is the controller, and we process your message only on its behalf and on its instructions, under a data processing agreement. Its own privacy notice explains how it handles your data, and it is the one to ask to see, correct or delete it.

If you write to us instead, we pass your request on to that business, as our agreement with it requires.

Changes to this notice

When what we do with personal data changes, we update this notice and the date at the top. We tell account holders by email before a change that affects them takes effect.