Privacy Policy, Data Processing and Protection

We are committed to protecting the personal data and privacy of the users of the migadu.com web site and the services offered, including, by way of example - the email and other communications sent through those services.

Migadu minimises the requirement of personal data disclosure to the bare essentials neccessary for uninterupted service delivery. Even with such minimal data, we have technical and organizational measures in place which protect your data best possible.

All our data is 100% encrypted at rest and in motion. Data center providers hold international security certifications which naturally vary by the data center location.

We do not process personal data, but we are obliged to say that the processing of personal data takes place in compliance with the EU General Data Protection Regulation (GDPR) as well as with the local, Swiss Federal Data Protection Act (DPA) data protection laws applicable to the Migadu-Mail GmbH.

We are always at your disposal for any questions, including those about privacy. If you have any questions or concerns regarding this policy, please get in touch.


Name and Address of The Controller

Migadu-Mail GmbH
Rohnen 587
CH-9414 Schachen
Switzerland

Email address: contact@migadu.com


Name and Address of The Data Protection Officer

Michael Bruderer
Migadu-Mail GmbH
Rohnen 587
CH-9414 Schachen
Switzerland

Email address: contact@migadu.com

Any data subject may, at any time, contact our Data Protection Officer directly with all questions and suggestions concerning data protection.


Personal Data

All personal data is kept securely by us and thus protected from unauthorized access.

To use our services and enter into a contractual relationship, we collect:

  • pre-existing, confirmed email address as inventory data

Once an account has been provisioned by our system, entry of additional personal information becomes possible but is not required by any means:

  • full name
  • postal address
  • additional email address(es)
  • organization / company name
  • VAT number

The scope of such voluntarily provided data is to facilitate billing and administration on the side of our users and will only be used for receipt generation. We have no internal use of such data, nor do we ever disclose it with third parties. The voluntarily provided data is also subject to our strict privacy protection.

For the execution of credit card payments, your credit card data will be directly sent to our payment service provider Stripe. This includes the transfer of personal data into a third country (USA). An agreement entered into with Stripe defines appropriate safeguards and demands that the data is only processed in compliance with the GDPR and only for the purpose of execution of payments. This agreement can be examined here: https://stripe.com/privacy-shield-policy.

For the transaction of payments we also adhere to our data minimisation policy. From the submitted payment information through Stripe, we collect only the essential information required to conclude the transaction.

Migadu provides services for saving, editing, presentation and electronic transmission of data, such as email service, contact management and data storage. This content data is voluntarily entered into Migadu by the customer. When signing up for a Migadu account, you give consent to the processing of this data according to Art. 6 DSGVO 1. a). All textual content is securiely stored for the user and its communication partners. Due to the nature of the open communication systems, this information is accessable by Migadu-Mail GmbH. This data can be deleted by the user at any time in its entirety.

In order to maintain email server operations, for error diagnosis and for prevention of abuse, mail server logs are stored max. 30 days. These logs contain sender and recipient email addresses and time of connection but no customer IP addresses. Storage takes place for the purposes of the legitimate interests pursued by the controller according to Art. 6 DSGVO 1. f).

In order to maintain operations, for prevention of abuse and and for visitors analysis, IP addresses of users are processed. Storage only takes place for IP addresses made anonymous which are therefore not personal data any more. This processing takes place for the purposes of the legitimate interests pursued by the controller according to Art. 6 DSGVO 1. f).

With the exception of payment data, we will not disclose your personal data including your email address to third parties. However, we can be legally bound to provide content data (in case of a valid Swiss Federal court order) and inventory data to prosecution services. There will be no sale or leasing of data.


Data Security

We use reasonable and appropriate physical, electronic, and administrative safeguards to protect Personal Data from loss, misuse and unauthorized access, disclosure, alteration and destruction, taking into account the nature of the Personal Data and the risks involved in processing that information.


Data Storage Period

The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case. In case a customer objected to the amount of the charged fees, the accounting data may be stored until the objections are terminally clarified. Furthermore, inventory data can be stored for up to two years if the handling of a complaint and other reasons require this for an orderly settlement of the contract. Moreover the deletion of inventory and billing data may be omitted provided that legal regulations or the prosecution of claims require this. Order-related data and the addresses associated with the order are stored in respect to tax, contract and commercial law retention periods and erased at the end of those periods.


Data Processing

By signing up for and using our services, you give us your consent to process your personal data. We emphasize that you can withdraw your consent for the future at any time by terminating your account. Upon such authorized request we will inform you about the data we have stored about you free of charge. Please use your provided Migadu account to access and manage all personal data. In addition we are obliged to delete, to correct or to restrict processing of the data stored about you upon termination request. Please note that requests for termination via email cannot be processed as email message cannot be taken as a proof of account ownership, unless you send also your password in plain text.

You may object to the processing of your personal data as well as to lodge a complaint with a supervisory authority and the federal commissioner for data privacy of Switzerland (Feldeggweg 1, Berne).


Data Portability

We work only with open standards meaning your data is always portable. You can make use of your right to data portability by exporting your personal data stored with Migadu, anytime and without explicit approval of Migadu.


Cookies

Beyond technical requirements for establishing a working session on our website and webmail, we do not use cookies or any form of tracking.


Contact From Our Web Page

On our web pages we offer the opportunity to get in contact with us via email or contact form. In doing so personal data is voluntarily transferred to us, stored automatically and only used for the purpose of dealing with the request and getting in contact with the affected person. We do not disclose this personal data to third parties.