Privacy Policy for Mailsound
Last updated: 2026-09-04
Virtunet B.V. (Dullofsakker 44, 5688VD Oirschot, the Netherlands, KvK 95773444) is the controller for the personal data described in sections 1 to 4 and the processor for the data described in section 5. Contact: support@mailsound.virtunet.io.
1. What we collect and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Your email address | sign-in links, service emails, invoices | contract | until account deletion |
| Plan, payment status, Stripe customer and invoice ids | billing | contract, legal obligation (tax records) | account life; invoices 7 years (Dutch tax law) |
| VAT id and billing address you enter at checkout | invoicing | legal obligation | 7 years |
| Terms acceptance (timestamp, terms version) | proof of contract | contract, legal obligation | until account deletion plus 7 years |
| Support emails you send us | answering you | legitimate interest | 12 months, then deleted from the support mailbox |
| Rate-limit counters (salted hash of IP address or email) | abuse prevention | legitimate interest | 24 hours |
| Server request logs (IP address, user agent, URL, timestamp) at our hosting provider | security, abuse prevention | legitimate interest | Cloudflare's short standard retention |
| Free tools on this site (no account): the input you give the tool and the result | providing the tool | legitimate interest | Same as a signed-in check: the submitted HTML, the excerpts in the findings and the checked URLs are deleted after 24 hours; findings without content are kept 90 days. |
| We do not use analytics or advertising trackers. The only cookie is the | |||
| session cookie that keeps you signed in. Preferences for visitors without | |||
| an account stay in your browser's local storage. Section 1 also applies to | |||
| visitors who use the free tools without an account; Virtunet B.V. is the | |||
| controller for that data. |
2. Where data is stored and processed
Account data and everything you submit to the Service are stored in the European Union (Cloudflare Durable Objects with the EU jurisdiction setting). Requests are processed at the Cloudflare data centre nearest to you, which may be outside the EU while you are outside the EU; data is not stored there. Transactional email is sent through Resend from its EU region (AWS eu-west-1, Ireland), which keeps message logs for 30 days. Payments are processed by Stripe. Support email is handled in a Fastmail mailbox hosted in the United States; only support conversations go there, never product data. Transfers outside the EU rely on the EU standard contractual clauses of the sub-processor concerned. The full list is at https://mailsound.virtunet.io/subprocessors.
3. Who we share data with
Only the sub-processors listed above, to provide the Service. We do not sell data and we do not share it for advertising. We disclose data if the law requires it.
4. Your rights
You can access, correct, export, restrict and delete your data, and object to processing based on legitimate interest. The account page (or the project page for products without accounts) offers export and deletion; deletion removes all your data from the Service within 24 hours, except invoice records we must keep for tax law. We make no decisions about you by automated means that have legal or similarly significant effects. Write to support@mailsound.virtunet.io for anything you cannot do from the page; we answer within one month. You can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). If your request concerns data that one of our customers put into the Service about you, we forward it to that customer, who is the controller, and tell you we did so.
5. Data you submit to the Service
The content you give the Service (for example HTML, URL lists, contract rows, domain names, client names, recipient addresses) may contain personal data of your customers, contacts or staff. For that data you are the controller and we are your processor under the Data Processing Agreement at https://mailsound.virtunet.io/dpa. Retention for each data class in Mailsound:
| Data | Where | Retention |
|---|---|---|
| Email address, plan, Stripe customer id, terms acceptance timestamp | DO (EU) | until deletion |
| Submitted HTML or .eml HTML part | DO (EU) | 24 hours, then deleted |
| Findings with excerpts of the submitted HTML (snippets up to 120 characters) and the link and image URLs checked | DO (EU) | 24 hours, then the excerpts and URLs are deleted |
| Findings without content (feature ids, severities, client families, line and column numbers, counts, and the link and image check statuses: result, HTTP status code, redirect hop count, size) | DO (EU) | 90 days |
| API key hash | DO (EU) | until rotated or deleted |
| Rate-limit and fetch-budget counters and the submitter identity on a check (salted hash of IP, or account id) | DO (EU) | 24 hours |
| Transactional mail logs | Resend (EU) | 30 days |
6. Security
Data in transit is encrypted (TLS). Stored data is encrypted at rest by our hosting provider. Access is limited to the operator of the Service. Sign-in uses single-use, time-limited email links; we store no passwords.
7. Business transfers
If the Service or Virtunet B.V. is sold or transferred, your data may be transferred to the buyer under the same terms; we will email account holders at least 14 days before, with the option to delete the account.
8. Changes
We will update the date above when this policy changes and email account holders about material changes.