Privacy notice
Effective [not yet set]
This notice explains how [not yet set] (“we”) handles the personal data we are responsible for — as the controller, in the words of the General Data Protection Regulation (GDPR). It covers people who have a Corresso account, anyone who visits our sign-in and other public pages, and anyone who writes to us.
It does not cover the email that businesses read and answer with Corresso. That mail is the business’s, and we handle it only on the business’s behalf. If you wrote to a business that uses Corresso, the last section is for you.
Who is responsible
- Controller: [not yet set], [not yet set], CVR [not yet set]
- Address: [not yet set]
- Privacy questions and requests: [not yet set]
- Data protection officer: [not yet set]
What we process, why, and on what legal basis
Your account
- What: your name, email address and time zone; which organisations you belong to and your role in each (owner, admin or agent); and your password, which we store only as a one-way bcrypt hash that cannot be turned back into the password.
- Where it comes from: your organisation, which decides who gets an account and gives us your name and email address for it.
- Why: so you can sign in and use Corresso for your organisation.
- Legal basis: our and your organisation’s legitimate interest in providing the service your organisation has agreed with us (GDPR art. 6(1)(f)). If you accepted that agreement yourself, it is also necessary for the contract (art. 6(1)(b)).
- How long: for as long as your account exists. When your organisation’s agreement with us ends, we delete it within 30 days, and from backups within one further backup cycle.
The conversations, notes, draft replies and assignments you work on in Corresso are your organisation’s data, not ours. We process them on your organisation’s behalf under our data processing agreement, and your organisation decides what happens to them.
Signing in
- What: each time you sign in, we record a session: your user id, the IP address and browser (user agent) you signed in from, when you signed in, and when the sign-in ends. Your browser keeps a cookie that points to it.
- Why: to keep you signed in, and to be able to trace misuse of your account.
- Legal basis: our legitimate interest in keeping accounts and the service secure (art. 6(1)(f)).
- How long: a sign-in ends 30 days after you signed in, and a daily clean-up then deletes its record. Signing out deletes it at once, and resetting your password deletes all your sign-ins.
Resetting your password
- What: your email address, and the email we send to it with a link to set a new password.
- Why: to let you back into your account when you have forgotten your password.
- Legal basis: our legitimate interest in giving account holders a secure way back in (art. 6(1)(f)).
- How long: the link works for 15 minutes. We send the email through Postmark (see who receives the data), which keeps a copy of each sent message for up to 45 days.
Security logs
- What: every request to Corresso is logged with the IP address it came from, the time and the address of the page. In the lines the application itself writes, a request’s parameters — what is typed into a form, and what follows the “?” in an address — are filtered first: passwords, email addresses, message text and search terms are replaced with “[FILTERED]”. The rest of a page’s address is written as it is. So the address of a password-reset page appears in full, with the one-off token from its link; that token stops working after 15 minutes, or as soon as the password is changed. Two web servers pass each request on to the application, and neither filters anything: each writes a line of its own that records your browser (user agent) and the full address of each page — including a search typed into the inbox, or a customer’s email address carried in a link. The inner one writes into Corresso’s own log, next to the application’s lines; the outer one, in front of Corresso, keeps a log of its own. To slow down password guessing, we also count sign-in and password-reset attempts per IP address, and to stop a mistake or a misused account from sending mail in bulk, we count how often each person sends.
- Why: to keep Corresso running and secure, and to find and fix faults and attacks.
- Legal basis: our legitimate interest in the security and operation of the service (art. 6(1)(f)).
- How long: a counter counts for at most 3 minutes. It stays in our cache database, under the IP address or account it counts, until the cache’s routine clean-up deletes it; that clean-up runs as new entries are written and removes those more than two weeks old. Corresso’s own log is written to the server’s standard output, where Docker keeps it in files rotated by size: three files of at most 50 MB each, the oldest deleted first. When we release a new version, the old version’s log stays on the server with it until our deployment tool removes that version, which it does once it is no longer among the five most recently retired versions. The outer web server’s log is a single file of at most 10 MB, started afresh whenever it fills up. So how long a line survives depends on how busy the service is and how often we release, not on a date. Records of background tasks that failed, which can contain error messages, are deleted after 30 days.
Product pictures from Shopify
- What: in an organisation that has connected its Shopify store, opening a conversation with a customer who has orders there shows pictures of the products ordered. Your browser fetches those pictures directly from Shopify’s servers (cdn.shopify.com), not from ours, so Shopify receives what any website receives when a browser asks it for a file: your IP address, your browser’s details (user agent), the address of the picture, and the address of Corresso’s site — but not of the page you are on. We store none of this.
- Why: so the person answering can see at a glance what the customer bought.
- Legal basis: our legitimate interest, and your organisation’s, in showing the order next to the conversation, as your organisation asked when it connected its store (art. 6(1)(f)).
- Who receives it: Shopify, which decides for itself what it does with it, under its own privacy policy. For people in the EEA, that policy names its Irish company, Shopify International Ltd., as the recipient, and says Shopify sends the data on to other Shopify companies — including in Canada, where it is headquartered, and the USA — under its binding corporate rules, and to its own service providers under standard contractual clauses.
- How long: we keep nothing. Shopify keeps it for as long as its privacy policy says.
This happens only in organisations that have connected a Shopify store. Everywhere else, no page of Corresso loads anything from another company’s servers.
When you write to us
- What: your name and email address, what you write, and our replies.
- Why: to answer you.
- Legal basis: our legitimate interest in answering the people who contact us (art. 6(1)(f)); when you write about an agreement between us and your organisation, also art. 6(1)(b).
- How long: while the matter is open, and afterwards only for as long as we need it to show what was agreed with your organisation.
Cookies
Corresso sets two cookies of its own, and no others: one keeps you signed in for 30 days, the other protects forms and ends when you close your browser. Both are strictly necessary for the service you have asked for, so under Danish law they need no consent (Cookiebekendtgørelsen, BEK nr. 1148 af 9. december 2011, § 4, stk. 1, nr. 2). We use no analytics, advertising or tracking, and apart from the Shopify product pictures described above, no page loads anything from another company’s servers — not even fonts. Each cookie is described in our cookie declaration.
Who receives the data
Personal data about you reaches these companies:
- Hetzner Online GmbH, Germany, hosts our servers and database.
- AC PM, LLC (Postmark), USA, delivers the email we send you, such as password resets. It keeps sent messages for up to 45 days, and addresses that bounced or complained on a suppression list until they are removed.
- Our email provider stores the email you send us: [not yet set].
- Shopify receives your IP address and browser details directly from your browser when Corresso shows product pictures, in organisations that have connected a Shopify store (see above).
Hetzner and Postmark process the data on our instructions, under data processing agreements with us. Shopify does not work for us: it handles what it receives under its own privacy policy. Beyond those listed here, we disclose personal data only where the law requires it. We never sell it, and never use it for advertising.
Transfers outside the EU and EEA
Our servers are in Germany. Postmark processes data in the USA. That transfer rests on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795): AC PM LLC is covered by ActiveCampaign, LLC’s certification under it. Should that decision fall away, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) in Postmark’s data processing agreement apply instead. You can ask us for a copy of these safeguards at [not yet set].
Where our email provider stores mail outside the EU or EEA, the safeguard it relies on is named above.
What Shopify receives when your browser loads a product picture, Shopify sends on outside the EU and EEA itself, under the safeguards its own privacy policy names (see above).
How long we keep it
| Data | Kept |
|---|---|
| Your account | While your account exists; deleted within 30 days after your organisation’s agreement with us ends, and from backups within one further backup cycle |
| A sign-in | 30 days from when you signed in, then deleted by a daily clean-up; at once when you sign out |
| A password-reset email | The link works for 15 minutes; Postmark keeps the sent email for up to 45 days |
| Sign-in, reset and sending counters | Count for at most 3 minutes; then deleted by the cache’s routine clean-up of entries more than two weeks old |
| What Shopify receives when a product picture loads | Nothing kept by us; Shopify keeps it as its own privacy policy says |
| Corresso’s request log | Rotated by size: three files of at most 50 MB each; an old version’s log until that version is removed from the server |
| The outer web server’s request log | One file of at most 10 MB, started afresh when full |
| Records of failed background tasks | 30 days |
| Database backups | At most 30 days |
| Email you send us | While the matter is open, then only as long as needed to show what was agreed |
Your rights
Under the GDPR you have the right to:
- get a copy of the personal data we hold about you (art. 15);
- have it corrected if it is wrong (art. 16);
- have it erased (art. 17);
- have its processing restricted (art. 18);
- receive the data you gave us in a machine-readable form, or have it sent to someone else, where we process it to perform a contract with you (art. 20);
- object (art. 21). Because we rely on legitimate interests, you may object at any time on grounds relating to your particular situation, and we then stop unless we have compelling legitimate grounds that override your interests, rights and freedoms, or need the data for legal claims.
To use these rights, write to [not yet set]. We answer without undue delay and within one month. If a request is complex, or we receive many, we may take up to two further months, and then tell you so within the first month (art. 12(3)). Your organisation can also ask us to correct or remove your account. We do not rely on consent for any of this, so there is no consent to withdraw.
Complaints
You can complain to the Danish Data Protection Agency (Datatilsynet):
- Carl Jacobsens Vej 35, 2500 Valby, Denmark
- +45 33 19 32 00 · dt@datatilsynet.dk · www.datatilsynet.dk
Do you have to give us this data?
No law requires you to. Without an email address and a password there is no account, however, and without the sign-in and security records we cannot let anyone sign in safely.
Automated decisions
We make no decisions about you based solely on automated processing, and we do not profile you (GDPR art. 22).
If you emailed a business that uses Corresso
Businesses use Corresso to read and answer the email their customers send them. If you wrote to one, that business decides what happens to your message: it is the controller, and we process your message only on its behalf and on its instructions, under a data processing agreement. Its own privacy notice explains how it handles your data, and it is the one to ask to see, correct or delete it.
If you write to us instead, we pass your request on to that business, as our agreement with it requires.
Changes to this notice
When what we do with personal data changes, we update this notice and the date at the top. We tell account holders by email before a change that affects them takes effect.