This Data Privacy Statement is provided in English for your convenience. Please note that in case of a dispute or discrepancy between the German Data Privacy Statement and the English translation, the German version shall prevail.
Status: September 26, 2022
We are responsible for the protection of your personal data, and we take this responsibility very seriously. Therefore
Processing of personal data takes place in compliance with the General Data Protection Regulation (GDPR) as well as with the country-specific data protection laws applicable to Tutao GmbH.
We are always at your disposal for any questions about privacy. Please contact us via email: firstname.lastname@example.org.
Email address: email@example.com
All personal data is kept secure by us and thus protected from unauthorized access.
For the initiation of a contractual relationship and for service provision we collect
as inventory data.
For invoicing and determining the VAT we collect for paid product variants
as inventory data.
For the transaction of payments we collect depending on the chosen payment method the following payment data (inventory data):
This inventory data is processed for the performance of the contract with the customer according to Art. 6 para. 1 p. 1 lit. b) GDPR. For the execution of direct debiting we will share your banking details with the authorized credit institution. For the execution of PayPal payments we will share your PayPal data with PayPal (Europe).
For the execution of credit card payments your credit card data will be shared with our payment service provider Braintree. This includes the transfer of personal data into a third country (USA). An agreement entered into with Braintree defines appropriate safeguards and demands that the data is only processed in compliance with the GDPR and only for the purpose of execution of payments.
Tutanota provides services for saving, editing, presentation and electronic transmission of data, such as email service, contact management and data storage. This content data is voluntarily entered into Tutanota by the customer. When signing up for a Tutanota account, you give consent to the processing of this data according to Art. 6 para. 1 p. 1 lit. a) GDPR. All textual content is encrypted for the user and its communication partners in a way that even Tutao GmbH has no access to the data. This data can be deleted by the user.
In order to maintain email server operations, for error diagnosis and for prevention of abuse, mail server logs are stored max. 7 days. These logs contain sender and recipient email addresses and time of connection but no customer IP addresses. Storage takes place for the purposes of the legitimate interests pursued by the controller according to Art. 6 para. 1 p. 1 lit. f) GDPR.
In order to maintain operations, for prevention of abuse and and for visitors analysis, IP addresses of users are processed. Storage only takes place for IP addresses made anonymous which are therefore not personal data any more. This processing takes place for the purposes of the legitimate interests pursued by the controller according to Art. 6 para. 1 p. 1 lit. f) GDPR.
With the exception of payment data, we will not disclose your personal data including your email address to third parties. However, we can be legally bound to provide content data (in case of a valid court order) and inventory data to prosecution services. There will be no sale of data.
The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case. In case a customer objected to the amount of the charged fees, the accounting data may be stored until the objections are terminally clarified. Furthermore, inventory data can be stored for up to two years if the handling of a complaint and other reasons require this for an orderly settlement of the contract. Moreover the deletion of inventory and billing data may be omitted provided that legal regulations or the prosecution of claims require this. Order-related data and the addresses associated with the order are stored in respect to tax, contract and commercial law retention periods and erased at the end of those periods.
We use technical analysis options very sparingly and only if you have consented in advance and to the extent that this is necessary for the further development and improvement of Tutanota. In particular, we do not use analysis tools such as Google Analytics or other third-party tools.
Our goal is to improve the user interface and the handling of Tutanota. For this it is necessary to identify the places in Tutanota that do not yet work perfectly.
If you have given consent in advance, your anonymized usage data will be sent to our servers. For this purpose, we generate and store a random ID on your device, which is shared by all accounts logged in on this device. This ID is sent along wih the usage test data to the server in case usage statistics are performed for the function used in the client. The anonymized usage data is stored by us in such a way that no conclusion can be drawn about the user. The usage statistics can refer to the following data, for example:
For individual usage statistics, we may subsequently ask you for an evaluation of the functionality, which can optionally be sent to us. Participation in such a survey is voluntary and also anonymous. It is not possible to draw conclusions about the participating person.
Third parties have no access to the random ID stored on your device.
You can revoke your consent to participate in the anonymized usage statistics at any time by deactivating this function in the settings of your account. The random ID stored on your device is used only as long as users of the device participate in the collection of usage statistics.
You can delete the random ID stored locally on your device yourself at any time, for instance, like this:
The anonymized usage data may be used for research purposes. Otherwise, the usage data is not passed on to third parties.
In order to be able to evaluate campaigns with partners and advertising campaigns (e.g. advertising via Google or other search engines), we store an ID of the campaign with your Tutanota account when you reach Tutanota via a campaign link and register a Tutanota account. To be able to assign returning users to a campaign, we store a cryptographic hash of the IP address and the user agent (including information about the user's browser and operating system) together with the campaign ID when you visit our website via a campaign link. If you visit our website via a search query and an advertising campaign, we also store the keywords and the search query together with the hash and the campaign ID. By using the hash, it is no longer possible to infer the IP address or the user agent. The keywords and the search query are not stored with the Tutanota account.
The hash and the campaign ID, keywords and search query stored together with the hash are deleted after 72 hours. Beyond this period of 72 hours, for the purpose of evaluating the campaign and until the completion of the evaluation, only completely anonymized campaign data (keywords and search query) are stored and processed without any link to the hash.
Insofar as we process personal data during the campaign analysis, this is done on the basis of Art 6 para. 1 p. lit. f) GDPR. Our interest in being able to evaluate advertising campaigns and to improve our marketing activities constitute a legitimate interest within the meaning of Art. 6 para. 1 p. lit. f) GDPR.
According to European data protection law, you have the right
Insofar as your personal data is processed on the basis of legitimate interests pursuant to Art. 6 para. 1 p. 1 lit. f GDPR you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, insofar as there are grounds for doing so that arise from your particular situation.
If you would like to exercise your right to object, it is sufficient to send an email to: firstname.lastname@example.org.
On our web pages we offer the opportunity to get in contact with us via email or contact form. In doing so personal data is voluntarily transferred to us, stored automatically and only used for the purpose of dealing with the request and getting in contact with the affected person. We will not disclose this personal data to third parties.