Skip to content
mailbackup.io
How it worksPricingContact
DeutschStart free

Privacy Policy

This is a convenience translation. Only the German
Datenschutzerklärung is legally binding. In case of any
discrepancy, the German version prevails.

Last updated: August 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

dedimax solutions GmbH
Wieseneck 32
17192 Waren (Müritz)
Germany

Telephone: +49 3991 404040
Email: info@mailbackup.io

2. Overview

mailbackup.io is a service for backing up email mailboxes and contacts for business customers. This privacy policy distinguishes three processing contexts:

  1. Visiting the website — we are the controller.
  2. Customer account and contract performance — we are the controller.
  3. Contents of the backed-up mailboxes — here we process data exclusively on behalf of our customers as a processor pursuant to Art. 28 GDPR. The controller for this data is the respective customer; the basis is the data processing agreement (DPA) concluded with that customer.

All storage and processing takes place on servers within the European Union.

3. Visiting the website

3.1 Server log files

When you access our website, our server automatically processes: IP address, date and time of access, URL requested, referrer URL, browser and operating system used, and the HTTP status code. This data serves to ensure operation, analyse faults and defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation). Log data is deleted after 30 days at the latest, unless it is needed to investigate a specific security incident.

3.2 Cookies and storage on your device

We set no cookies on the mailbackup.io website. It also contains no tracking pixels and no analytics or marketing tools, and it loads no third-party resources whatsoever; even the fonts are served from our own servers. A consent prompt (cookie banner) is therefore not required.

A single value is placed in your browser’s local storage: the language you selected using the language switch (key mailbackup.lang, value de or en). It is stored only if you switch the language yourself. It serves solely to show you the start page in your chosen language on a later visit, and it is at no point transmitted to us or to any third party. Because this is a function you explicitly requested, storing it requires no consent under § 25(2) no. 2 TDDDG. You can delete the value at any time through your browser’s storage settings; the site works without any restriction without it.

Only in the application at app.mailbackup.io do we set two strictly necessary cookies: a session cookie for signing in to the customer account, and a cookie protecting against cross-site request forgery (CSRF). The legal basis is § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b) GDPR. We set no tracking, analytics or marketing cookies there either.

3.3 Contact form and enquiries

Through the contact form on mailbackup.io we process the details you enter there: name, email address, your message, and the language of the page the message was sent from. These details are not stored in a database but delivered directly as an email to our support address, where they are handled like any other incoming enquiry.

We additionally process the IP address on submission in order to limit the number of submissions per sender (abuse protection). For this purpose the form uses a hidden field (a “honeypot”) instead of a captcha; no third-party service is embedded.

The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry serves the initiation or performance of a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and in protecting the form against abuse). We retain your enquiry and our reply for as long as this is necessary to handle the matter and as statutory retention obligations require; otherwise we delete the correspondence once the matter is closed and no further questions are to be expected.

4. Customer account and contract performance

4.1 Customer account and registration

When a customer account is set up, we process: company name, name and email address of the designated users, password (stored as a hash) or passkey data, the chosen language, the time of acceptance of the Terms and Conditions and the privacy policy, and log data on security-relevant events (e.g. sign-ins). The legal basis is Art. 6(1)(b) GDPR (performance of a contract); for the time of acceptance additionally Art. 6(1)(c) GDPR (obligation to demonstrate compliance).

If the account is set up by registering on the website, we initially process the data provided only provisionally, until you confirm the activation link sent to your email address. A customer account only comes into existence upon that confirmation. Unconfirmed registrations are deleted in full after a few days.

4.2 Payment processing

Payment is processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (“Stripe”). The data required for payment processing is transmitted to Stripe (company name, email address, payment data, invoice amounts). Stripe may transfer data to Stripe, Inc. in the USA; the transfer is safeguarded by Stripe’s certification under the EU-US Data Privacy Framework and by standard contractual clauses. The legal basis is Art. 6(1)(b) GDPR. Details: https://stripe.com/privacy.

4.3 Transactional emails

We send system emails (invitations, password resets, disruption and expiry notifications) via our own mail servers, operated by us within the European Union; no external dispatch service provider is used. The legal basis is Art. 6(1)(b) GDPR.

4.4 Invoice and contract data

We retain invoice and accounting data in accordance with commercial and tax retention obligations (§ 147 AO, § 257 HGB) for up to ten years. The legal basis is Art. 6(1)(c) GDPR.

5. Processing of the backed-up mailbox data (processing on behalf)

The core of the service is backing up our customers’ email mailboxes and contacts. In doing so we process all contents of the connected mailboxes: email messages including attachments, metadata (sender, recipients, subject, timestamps, folder structure) and contact data.

For this data we are a processor pursuant to Art. 28 GDPR; the controller is the respective customer. The nature, scope and purpose of the processing, the parties’ obligations and the sub-processors engaged are governed by the data processing agreement we conclude with every customer.

To make scanned documents searchable we use text recognition (OCR); individual file attachments are transmitted for this purpose to neuraforce GmbH, Dora-Koch-Stetter-Weg 22, 18055 Rostock, Germany, as a sub-processor, with processing in the EU.

Data subjects whose data is contained in backed-up mailboxes should address the respective customer as controller in order to exercise their rights. We support our customers in answering such requests within the framework of the DPA.

6. Recipients and processors

We engage the following service providers:

Service providerPurposePlace of processing
OVH GmbH, Christophstraße 19, 50670 Köln (or the OVHcloud group)Server hostingEU
Stripe Payments Europe, Ltd., Dublin, IrelandPayment processingEU / USA (DPF, SCC)
neuraforce GmbH, Dora-Koch-Stetter-Weg 22, 18055 RostockText recognition (OCR) of file attachmentsEU

No transfer of personal data to third parties takes place beyond this, unless we are legally obliged to do so.

7. Data security

We take technical and organisational measures pursuant to Art. 32 GDPR, in particular: transport encryption (TLS) for all connections, encryption of all storage media holding customer data (encrypted file systems), encrypted storage of credentials and certificates, role-based access control, logging of administrative access, and encrypted, geo-redundant backups within the EU.

8. Retention periods

We store backed-up mailbox data for as long as the customer account exists. What matters is the end of the customer relationship, not the end of a paid subscription: if a customer ends their subscription, the account and all data already backed up remain in place — only further backups of the affected mailboxes stop. Nothing is deleted along that path.

Only when the customer closes their account, or the contract otherwise ends, do we make the data available for export in accordance with the DPA and subsequently delete it, including backup copies. Account data is deleted at the same time, unless statutory retention obligations preclude this. Section 3.1 applies to server log data, section 3.3 to contact enquiries, and section 4.4 to invoice data.

9. Your rights

As a data subject you have the following rights, insofar as we are the controller for the processing in question:

  • Access to the personal data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)

An informal message to info@mailbackup.io is sufficient to exercise these rights. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the authority responsible for us is the Landesbeauftragter für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern, Werderstraße 74a, 19055 Schwerin, Germany.

10. Changes to this privacy policy

We adapt this privacy policy when the service or the legal situation changes. The version published on this page at the time applies.

mailbackup.io

A service of dedimax solutions GmbH, Waren (Müritz), Germany.

This site sets no cookies and loads no third-party resources.

German is the governing language; these are convenience translations:ImprintPrivacy PolicyTerms and Conditions
Sign in to app.mailbackup.ioContactDeutsch

© 2026 dedimax solutions GmbH