Skip to main content

Privacy Policy

Last updated: 2026-05-02

1. Introduction

Bel Consulting OÜ (trading as ApexMail) (“we”, “us”) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard personal data when you use our services, in compliance with Regulation (EU) 2016/679 (General Data Protection Regulation) and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

Data Controller: Bel Consulting OÜ, Sakala 7-2, 10141 Tallinn, Estonia. Registry code: 16588745 VAT number: EE102951727

2. Data We Collect

  • Website visitors (marketing site): IP address, browser type and user agent, device information, pages visited, referring URL, and timestamps — collected automatically from server access logs. The marketing site runs no analytics scripts and embeds no tracking pixels or advertising cookies.
  • Prospects: name, email address, company name, phone number (if provided), and communication history, provided via contact forms or email.
  • Account data: name, email, company, billing address, VAT number, payment method tokens (card details are processed by Stripe and never reach our servers), API key metadata, login timestamps, IP addresses, and audit log entries.
  • Usage data: API calls, email sending volumes, delivery events, and engagement events (opens and clicks) for messages you send.
  • Recipient data (as processor for our customers): recipient email addresses and names, email content (subject, body, headers, attachments), and delivery and engagement metadata. When tracking is enabled by the sending customer, open and click events also record the recipient’s IP address and user agent.
  • Technical data: IP addresses (used for authentication, rate limiting, and fraud and abuse prevention), browser type, device information.
  • AI processing: when you use optional AI-assisted features, the subject lines and message content you submit are processed to generate the requested analysis (for example, subject-line insights).

We process data under GDPR Article 6(1)(b) (contract performance), Article 6(1)(f) (legitimate interest), and Article 6(1)(a) (consent) where applicable.

4. Data Storage

The supplied configuration targets EEA regions for core email-service data and telemetry storage. Active locations, enabled subprocessors, and transfer safeguards depend on the deployed environment and applicable agreement. For a complete breakdown and confirmation process, see our Data Locations page.

Summary Location Matrix

Data CategoryPrimary LocationBackup / ReplicaProcessing
Core email infrastructure (messages, delivery metadata, account data)EU data centre — GermanyEU data centre — FinlandEEA — no third-country transfer
OAuth authentication tokensGoogle LLC / GitHub, Inc. (US entities, SCCs)Provider-managedUS (SCCs)
Payment and billing recordsStripe, Inc. (US, SCCs)Provider-managed (India for support)US/India (SCCs)
Support ticketsEU data centre — GermanyEU data centre — FinlandEEA — no third-country transfer

We do not transfer personal data outside the EEA without adequate safeguards (Standard Contractual Clauses or an adequacy decision under Article 45).

5. Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected:

Data CategoryRetention Period
Account dataDuration of contract + 30 days
Billing records7 years (Estonian accounting law)
Email content (body, subject, headers, attachments)7 days by default; plan-dependent, up to 730 days on Enterprise
Event logs (delivery, open, and click events)30 days by default (7 days on the Free plan); plan-dependent, up to 730 days on Enterprise
Support tickets2 years after resolution

See our Data Retention Policy for full details.

6. Your Rights

Under GDPR, you have the following rights:

  • Right of access (Art. 15) — obtain confirmation of whether we process your data and access that data.
  • Right to rectification (Art. 16) — request correction of inaccurate data.
  • Right to erasure (Art. 17) — request deletion of your data (“right to be forgotten”).
  • Right to restriction of processing (Art. 18) — restrict processing under certain conditions.
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@apexmail.ee. We will respond within 30 days.

7. Complaints

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

  • Website: https://www.aki.ee
  • Address: Väike-Ameerika 19, 10129 Tallinn, Estonia
  • Email: info@aki.ee

8. Cookies

See our Cookie Policy for details on cookies and tracking.

9. Contact

For privacy inquiries: privacy@apexmail.ee Data Protection Lead: Bel Consulting OÜ, Sakala 7-2, 10141 Tallinn, Estonia