Privacy
Privacy Policy for the Email Service
Last updated: 28 September 2026
This policy describes how personal data is processed when we operate the email service at mail.vipmail.app and when you visit this website. Where we process mailbox contents on behalf of business customers, we conclude a data processing agreement (DPA) with them under Art. 28 GDPR before processing begins. As a rule, we cannot inform people directly if they send us a message but are not our customers. For them, we make this policy publicly available under Art. 14(5)(b) GDPR.
Controller
intelligent piXel GmbH, Enzianstraße 4a, 82319 Starnberg, Germany
Managing Director: George A. Rauscher. Authorised officer (Prokuristin): Dr. Maria-Louise Morgott. Commercial register: HRB 207679, Amtsgericht München (Munich Local Court). VAT identification number: DE291416044.
Email: my@intelligent-pixel.com. Data protection, whitelisting and abuse reports: postmaster@vipmail.app
Two Roles That Must Be Kept Apart
We act as a processor under Art. 28 GDPR for our business customers with regard to the contents of their mailboxes. Each business customer determines the purposes and means of this processing. We conclude a data processing agreement (DPA) with business customers before processing begins.
We act as an independent controller for everything that serves the protection and secure operation of the service: defending against attacks, filtering unwanted and harmful messages, and the logging this requires. The legal basis is Art. 6(1)(f) GDPR. This processing also serves to fulfil our obligations under Art. 32 GDPR. As a provider of a telecommunications service, we are also subject to the provisions of the Telecommunications Digital Services Data Protection Act (TDDDG).
This policy also applies to people who are not our customers and merely send us a message.
Source and Categories of Data
We collect our customers' data directly from the data subject, both in the course of the contractual relationship and when the service is used.
For people who send us a message but are not our customers, we receive the data not from them but from the message and the technical delivery process. We therefore provide the following information on the source and categories of the data under Art. 14 GDPR:
| Category | Source |
|---|---|
| IP address of the delivering system | technical set-up of the connection |
| country and type of network derived from the IP address | matching on our servers against publicly accessible address allocation registries |
| sender and recipient address | SMTP transmission |
| subject, message ID, timestamp | message headers |
| forwarding chain, technical headers | message headers |
| domain names and links contained in the message | the message itself |
| results of authentication checks | our own check based on public DNS records |
| reputation data on IP addresses and domain names | queries to public directories |
| information on previous events involving the same sender, the same domain or the same delivering address, and on existing correspondence with the recipient | our own checking procedures |
| check results and decision | our own checking procedures |
| message content | the message itself |
Message contents are processed automatically and exclusively for the purposes of delivery, storage in the mailbox and defence against malware, fraud and unsolicited advertising. A person views them only in the cases set out in section 6.
In addition, with every sign-in to a mailbox we receive the IP address, the time, the protocol used and the account being accessed. We derive the country from the IP address.
For our customers, we also process contract and contact data (such as name, company, address, email address, telephone number and, where applicable, VAT identification number), billing and payment data, and the mailbox access credentials.
Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Delivery, storage and provision of messages | Art. 6(1)(b) GDPR |
| Contract administration and billing | Art. 6(1)(b) GDPR; retention under Art. 6(1)(c) GDPR in conjunction with Section 257 HGB and Section 147 AO |
| Filtering of spam, malware and phishing | in relation to our customers, Art. 6(1)(b) GDPR as part of the service; otherwise Art. 6(1)(f) GDPR |
| Defence against attacks on the infrastructure | Art. 6(1)(f) GDPR; for traffic data, Section 12 TDDDG |
| Restricting sign-in via mail programs by country of origin to protect the mailboxes | Art. 6(1)(b) and (f) GDPR |
| Provision and securing of the vipmail.app website | Art. 6(1)(f) GDPR |
| Logging for troubleshooting and preservation of evidence | Art. 6(1)(f) GDPR; for traffic data, Section 12 TDDDG |
| Testing new protection methods using log and header data, without viewing message contents | Art. 6(1)(f) GDPR, within the scope of Section 3(3) TDDDG |
| Handling enquiries, quotes, whitelisting requests and abuse reports | Art. 6(1)(b) and (f) GDPR |
| Handling requests from data subjects, including the review of automated decisions | Art. 6(1)(c) GDPR in conjunction with Art. 12 to 22 GDPR |
The measures for the security of the service also serve to fulfil our obligations under Art. 32 GDPR. Where we process traffic data as a provider of a telecommunications service, this is additionally governed by Sections 9 and 12 TDDDG.
Our legitimate interests within the meaning of Art. 6(1)(f) GDPR are: the availability and integrity of the service, the protection of our customers against fraud, malware and identity theft, the protection of the mailboxes against unauthorised access, and the fulfilment of our obligation under Art. 32 GDPR to ensure an appropriate level of security. We have weighed these interests against the interests of the data subjects. Processing is limited to what is necessary for defence, and the data is not analysed for any other purpose. We do not create profiles for advertising or other unrelated purposes. For the information on previous events, which we use solely for the delivery decision, see section 8.1.
Requirement to Provide Data
Processing the data mentioned above is a technical prerequisite without which an email cannot be delivered at all. It does not arise from a statutory obligation on the sender or from a contract with the sender, but from the procedure itself. Without this data, a message cannot be accepted, checked or delivered.
There is no statutory obligation to provide us with data. Anyone who wishes to become our customer must provide the information required to conclude and perform the contract. Without it, we cannot conclude a contract or operate a mailbox.
Mandatory fields are marked in our forms. Without this information, we cannot handle your request via the form. Instead, you can contact us informally at postmaster@vipmail.app.
Secrecy of Telecommunications
As a provider of an email service, we are subject to the secrecy of telecommunications under Section 3 TDDDG. We uphold it. We only acquire knowledge of the content and detailed circumstances of communications to the extent necessary to provide the service, including protecting our technical systems (Section 3(3) TDDDG).
Incoming messages are automatically checked for malware, fraud and unsolicited advertising. No person views the message text or attachments. The only exception is where the mailbox holder expressly asks us to do so in order to clarify a case in their own mailbox, and only to that extent. To handle faults, abuse reports and requests for review (section 9), authorised persons view the log entries available for the case concerned. These contain the detailed circumstances of the case, including the subject line where applicable, but no message text or attachments.
Everyone at our company who has access to this data is bound to the secrecy of telecommunications and to confidentiality.
Hosting of the Mail Service and the Website
7.1 Mail Service
The service is operated on virtual servers that we rent from Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, and administer ourselves. The servers are located in data centres in Germany and Finland. All mailbox contents, logs and backups are processed and stored exclusively in data centres within the European Union. Hetzner acts as our processor under Art. 28 GDPR, provides only the infrastructure and processes the data solely on our instructions. Access to mailbox contents is not part of the commissioned services.
For queries to public reputation directories, see section 8.2.
7.2 The vipmail.app Website
This website is also operated on a web server administered by us within the infrastructure provided by Hetzner. When a page is requested, the web server processes technically necessary connection data so that the website can be delivered, the encrypted connection established and secure operation ensured.
| Logged data | Purpose |
|---|---|
| IP address | delivery, security and abuse detection |
| host accessed, requested address and path | provision of the requested page and troubleshooting |
| date and time of access | operation, error analysis and preservation of evidence |
| request method and protocol, HTTP status and amount of data transferred | technical delivery and stability monitoring |
| referring page, if transmitted by the browser | error analysis and protection against abuse |
| browser and operating system information from the user agent | compatibility, error analysis and defence against attacks |
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure, stable and error-free provision of the website and in detecting, fending off and investigating attacks and abuse.
The website does not use web analytics, advertising trackers or content from external providers. When pages are requested and when our forms are used, we do not set cookies and do not store any data in the browser's local storage or session storage. No usage profiles are created.
After sign-in, the webmail at mail.vipmail.app sets technically necessary cookies to maintain your session and secure the sign-in. No consent is required for this (Section 25(2) no. 2 TDDDG). Further processing is based on Art. 6(1)(b) GDPR.
Individual verification URLs under /verify/, which our customers can use to check the authenticity of our notices, are not recorded in the web server's access log. The randomly generated verification key they contain is therefore not logged together with the page request. We describe the processing of information from the contact, quote, whitelisting and abuse report forms in section 11.
Protection Against Spam, Malware and Phishing
Every incoming message passes through several independent checks. These checks serve defensive purposes. Contents are not analysed for any other purpose. We do not create profiles for advertising or other unrelated purposes.
8.1 Checks on the Servers We Operate
- verification of sender authentication under SPF (RFC 7208), DKIM (RFC 6376), DMARC (RFC 7489) and ARC (RFC 8617)
- check of the reverse DNS record of the delivering address in line with the recommendation in RFC 1912 section 2.1
- check for empty sender information under RFC 5321
- scanning of attachments for malware and blocking of dangerous file types
- content-based analysis by locally operated filtering software, including learning methods
- comparison with findings from previous events: whether a delivering address, a sender domain or a sender has previously attracted attention or been unremarkable, and whether correspondence already exists between sender and recipient
- temporary deferral of suspicious deliveries with a request to retry delivery
- detection of automated address queries and of messages sent to addresses that exist solely to track down address harvesters
These checks take place on the servers we operate. Message contents do not leave our servers in the process. Learning methods store only derived statistical features from which messages cannot be reconstructed. These features are continuously aged out. We use the information on previous events and on existing correspondence solely for the delivery decision, in particular to protect genuine business mail from being misjudged. Where this involves an evaluation within the meaning of Art. 4(4) GDPR, it is limited to this protective purpose. The retention period is set out in section 13.
8.2 Queries to Public Reputation Directories
To assess the delivering IP address and the links contained in messages, we query public reputation directories. The query is made via the internet's Domain Name System (DNS) using our own name server on our system and contains only the IP address or domain name to be checked. Sender and recipient addresses, subject, time of the message and message contents are not transmitted. The operator of the directory learns only that our server is requesting information about this IP address or domain name.
The operators of these directories are independent bodies and not processors. We have no influence over whether they log incoming queries. The legal basis for the query is Art. 6(1)(f) GDPR. Our legitimate interest is defence against spam, malware and fraud.
The operators receive only the IP address or domain name, without any further information that would make it easier to link it to a person. On request, we will tell you which directories we query.
8.3 Outcome of the Checks
Depending on the outcome, a message is delivered, moved to the junk folder or not delivered. As a rule, we do not deliver messages with dangerous file types, such as executable programs, scripts or disk images. This also applies to outgoing messages from our customers.
Automated Decisions and Your Right to Review
Our system decides automatically whether a message is delivered, moved to the junk folder or not delivered. The blocking of attacking addresses and network ranges and the restriction of sign-in via mail programs by country of origin (section 10) are also automated. It has not been conclusively settled in law whether these constitute decisions within the meaning of Art. 22(1) GDPR. As a precaution, we therefore inform you under Art. 13(2)(f) and Art. 14(2)(g) GDPR and grant you the rights described below. In relation to our customers, the filtering is part of the service (Art. 22(2)(a) GDPR).
The logic behind it. Every message passes through several independent checks. Each check that is triggered increases a numerical score. Depending on how high this score is, the message is moved to the junk folder or not delivered. As a rule, several checks must be triggered at the same time for this. However, certain unambiguous findings are enough on their own to prevent a message from being delivered. These include, in particular:
- an unrelated sender presenting itself as a bank, payment service or public authority, including in the message text
- a message in the name of a sender that is particularly often forged, without a valid cryptographic signature
- certain types of file attachment typically used for fraud
- unauthenticated messages in writing systems that do not occur in our customers' business correspondence
- dangerous file types
Conversely, dedicated checks of our own protect authenticated business mail from being filtered out merely because several minor grounds for suspicion add up. We do not publish specific thresholds and weightings, because spammers and fraudsters could otherwise tailor their mailings to them.
The significance. If a message is not delivered, it does not reach the recipient. If an IP address is blocked, then, depending on the type of block, it can no longer reach either our sign-in interfaces or any of our services.
Your rights. You have the right to obtain a review by a person, to express your own point of view and to contest the decision. To do so, use the whitelisting form or contact postmaster@vipmail.app informally. Please describe the circumstances. Every challenge is reviewed by a person, not automatically. The review is based on the log entries available for the case and on the information you provide. Log entries for undelivered messages are available for 60 days, and log entries for blocks for up to twelve weeks. Please therefore submit your request within these periods where possible. If the review shows that the decision was wrong, we will correct it, for example by adjusting the check or whitelisting the sender.
If your IP address is completely blocked, you can also reach us at my@intelligent-pixel.com.
Protection Against Attacks on the Infrastructure
The service is continuously exposed to automated attacks, from scans for open entry points and vulnerabilities to targeted sign-in attempts on mailboxes. We defend against the following:
- aggressive probing of our systems for open entry points and vulnerabilities
- repeated sign-in attempts on mailboxes
- attempts to discover valid addresses
- the distribution of malware and fraudulent messages
- the misuse of our systems to relay other people's mail
This involves processing the IP address, the time, the protocol used, the account being accessed and the country derived from the IP address. Suspicious addresses are blocked automatically. The duration depends on the severity and repetition of the attacks and ranges from short blocks to 24 months for repeated serious attacks. Blocks can cover entire network ranges if attacks repeatedly originate from them. To avoid locking our customers out in the process, we store the IP addresses of successful sign-ins and, before imposing such a block, automatically check whether legitimate sign-ins have come from the range concerned. We also use publicly available lists of known attacker networks. We download these lists. No information about you is transmitted in the process.
There are two types of block. A block on the sign-in interfaces only prevents signing in to mailboxes. Emails can still be delivered from such a network. We completely block addresses and network ranges from which serious or repeated attacks demonstrably originate. Emails from these sources can then no longer be delivered to our customers, and the webmail cannot be accessed from them either.
We only permit sign-ins via mail programs from selected countries from which our customers usually work. For this purpose, at sign-in the IP address is matched on our server against publicly available address allocation registries. It is not transmitted to anyone in the process. Anyone who temporarily needs to sign in from another country can request whitelisting from us.
We do this to keep the service available and to protect our customers. The legal basis is Art. 6(1)(f) GDPR and, in relation to our customers, additionally Art. 6(1)(b) GDPR. For traffic data, Section 12 TDDDG also applies. The measures also serve to fulfil our obligations under Art. 32 GDPR. You can request a review of a block by a person in accordance with section 9.
Forms on vipmail.app
Forms for contact enquiries, quote requests, whitelisting requests and abuse reports are available on vipmail.app. In each case, an informal message to postmaster@vipmail.app is equally sufficient.
11.1 Information Processed
- Contact: name, email address and your message
- Quote: name, email address, telephone number, company, where applicable VAT identification number, address, domain name and website, as well as your information on company size, number of mailboxes, previous provider, migration of existing mailboxes and the website
- Whitelisting: name, where applicable company, telephone number, email address, the IP address or sender address concerned and the type of messages involved
- Abuse report: name, email address, the address, IP address or URL concerned, the type of abuse and your description
In addition, when you submit a form, we process the following technically necessary information: your IP address, the browser identifier (user agent), the time, and the country and type of network derived from the IP address. We use this information to detect and fend off misuse of the forms. We transmit it together with your form entries to the receiving mailbox (section 11.3) and log it on our web server. Mandatory fields are marked in the form. All other information is voluntary.
11.2 Protection of the Forms
The forms run on our web server. Apart from the transmission to the receiving mailbox (section 11.3), they do not integrate any third-party services. They use no external scripts, no tracking and no cookies. To protect against misuse, when a form is loaded and when it is submitted we use your IP address to check which country and which type of network the request comes from. Requests from certain countries and from data centre, VPN and comparable anonymising networks may be rejected automatically. This check runs exclusively on our server, using publicly accessible country and network registries held there. Your IP address is not transmitted to anyone in the process. If your request is rejected, you can reach us informally at any time at postmaster@vipmail.app.
11.3 Transmission and Recipients
Your information is transmitted directly and in encrypted form to a mailbox of Proton AG, Switzerland, and stored there. Proton AG acts as our processor under Art. 28 GDPR. The European Commission has issued an adequacy decision for Switzerland (Decision 2000/518/EC), which remains in force under Art. 45(9) GDPR. A transfer to Switzerland is therefore permitted without further safeguards.
11.4 Legal Bases, Handling and Retention Period
We handle contact and quote requests on the basis of Art. 6(1)(b) GDPR where they are aimed at concluding a contract, and otherwise on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in responding to your request. We process whitelisting requests and abuse reports, together with the log entries available for the case, on the basis of Art. 6(1)(f) GDPR. If you use them to exercise your rights under Art. 21 or Art. 22(3) GDPR, the legal basis is additionally Art. 6(1)(c) GDPR in conjunction with Art. 12, 21 and 22 GDPR. The country and network check under section 11.2 is based on Art. 6(1)(f) GDPR. Our legitimate interest is protecting the forms against automated misuse.
We do not obtain consent for this processing, because it is based on the legal bases mentioned. The checkbox in the forms merely confirms that you have taken note of this information.
Every enquiry, request and report is reviewed by a person. We will inform you of the outcome of a whitelisting request. We delete the information as soon as it is no longer needed for handling your request and no retention obligation applies. If an enquiry leads to a contract, we retain the relevant documents for as long as commercial and tax law require (Section 257 HGB, Section 147 AO).
We lift a block if the review shows that the reason for it no longer applies or that the block goes further than necessary. Your rights under the GDPR, in particular under Art. 17, Art. 21 and Art. 22(3), remain unaffected.
Availability and Backups
Incoming mail has an additional safeguard. If the primary server fails, a backup mail server at another location accepts mail for existing recipients, holds it and delivers it as soon as the primary server is reachable again. The backup mail server does not host any mailboxes. Messages held there are removed after successful delivery. If a message cannot be delivered within seven days, it is removed, and the backup mail server sends a non-delivery report to the sender in accordance with the standard rules of email.
Mailbox contents are continuously backed up to a storage system separate from the mail server and additionally to a separate storage medium. The backups are stored exclusively within the European Union. For security reasons, we do not provide any further information on exactly where they are located or how they are structured.
Backups are automatically overwritten after a few days, and after one week at the latest. If you delete a message in your mailbox, it may still be contained in a backup until then. Backups are used to restore data. We do not otherwise access individual messages in backups.
Retention Periods
| Type of data | Duration |
|---|---|
| Message contents in the mailbox | until deleted by the mailbox holder |
| Messages on the backup mail server | until delivery, at most seven days |
| Mailbox backups | automatically overwritten after a few days, and after one week at the latest |
| Delivery and connection logs | 14 days |
| Content check logs | 14 days |
| Logs of undelivered messages | 60 days |
| Attack defence logs | up to twelve weeks |
| IP addresses of our customers' successful sign-ins (protection against wrongful blocks) | up to one year |
| Information on the temporary deferral of suspicious deliveries | up to five weeks |
| Information on previous events and existing correspondence, and statistical features derived by learning methods | for as long as they are necessary for the delivery decision. They are continuously aged out and overwritten |
| Web server access and error logs | 14 days |
| Form logs on the web server | up to twelve weeks |
| Block lists for IP addresses and network ranges | staggered by severity, at most 24 months |
| Information from forms (contact, quote, whitelisting, abuse) | until it is no longer needed for handling, subject to statutory retention obligations |
| Contract and billing documents | until the expiry of the retention periods under commercial and tax law (Section 257 HGB, Section 147 AO) |
The 60-day period for logs of undelivered messages enables the review under section 9. The longer period for attack defence logs is necessary in order to detect repeated attacks from the same source and to determine the duration of a block accordingly. The longer period for block lists is necessary because the same network ranges are used for attacks repeatedly and a short period would undermine the protection. We store the IP address or network range together with the reason for and time of the block, but no further personal details.
Recipients of Data
We do not sell or rent out personal data, do not analyse it for advertising purposes, do not use it to create profiles for advertising or other unrelated purposes, and do not pass it on to third parties for their own purposes.
The following categories of recipients receive data within the scope of the purposes described:
| Category | Purpose | Based in |
|---|---|---|
| Data centre operator (processor) | provision of the infrastructure, including backup storage | Germany, processing in the EU |
| Provider of the receiving mailbox for form submissions | transmission and receipt of contact and quote requests, whitelisting requests and abuse reports | Switzerland (adequacy decision) |
| Operators of public reputation directories (independent bodies) | answering DNS queries on IP addresses and domain names; no transmission of sender or recipient addresses or message contents | see section 8.2 |
| Payment service provider (independent body) | processing of our customers' payments | depending on the payment method chosen |
On request, we will tell you the specific recipients.
Authorities receive data only where we are legally obliged to provide it. We examine every request for its lawfulness and limit disclosure to what is legally required.
Technical and Organisational Measures
- encrypted transmission in line with the state of the art; sign-ins via mail programs are only possible in encrypted form
- signing of outgoing messages with DKIM
- two-factor sign-in (2FA) available for mailboxes; separate app passwords for mail programs
- network firewall at the data centre and our own firewall on the server, with automatic blocking of attacking addresses, graduated by severity
- backup to a separate storage system, with every backup checked for completeness
- backup mail server for receiving mail at a second location
- continuous automated monitoring with alerting
- all staff bound to the secrecy of telecommunications and to confidentiality
- documentation of configuration changes
Right to Object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out on the basis of Art. 6(1)(f) GDPR (Art. 21(1) GDPR).
If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
You can send your objection informally to postmaster@vipmail.app.
Your Other Rights
You have the right of access to the data stored about you (Art. 15 GDPR), to rectification of inaccurate data (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to data portability (Art. 20 GDPR). For your right to have automated decisions reviewed by a person, see section 9.
Please send your request to postmaster@vipmail.app or to my@intelligent-pixel.com.
A note on access: logs are deleted automatically after the periods stated in section 13; delivery and connection logs, for example, are deleted after 14 days. Our response to an access request can therefore only cover data that still exists at the time of your request.
If your request concerns the contents of a mailbox operated by one of our business customers, for example because you have corresponded with the mailbox holder or are employed there, please contact that mailbox holder. For these contents, we act as a processor and may not provide information without the mailbox holder's instructions.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
Under Section 29 TDDDG, the competent authority for the processing of personal data in the provision of our email service as a telecommunications service is: Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI, Federal Commissioner for Data Protection and Freedom of Information), Graurheindorfer Straße 153, 53117 Bonn, Germany.
For all other processing, for example when you visit this website or use our forms, the competent authority is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA, Bavarian Data Protection Authority), Promenade 18, 91522 Ansbach, Germany.
Changes
We update this policy whenever the technical procedures or the legal requirements change. The version published on vipmail.app at any given time is authoritative. We will inform our customers separately of any material changes.