Privacy Notice
Last updated: 2026-07-27
1. Who is responsible for your data
The data controller for TrueVIP Access Mailbox is Martynas Sklizmantas, a self-employed sole trader (trabajador autónomo) established in Spain, VAT number ESY9832835G, Carrer pla de L'Era 17, Salou, Spain ("we", "us"). As an EU-established controller we process personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
For payment processing, Paddle.com Market Limited ("Paddle") acts as an independent data controller in its own right — see Section 6.
2. What we collect
- Billing email — the address you give when claiming a mailbox, used to send your payment link and mailbox notifications, and passed to Paddle to process your order.
- Mailbox address and key fingerprint — your assigned mailbox address and the fingerprint of the Ed25519 key that identifies it. We never see or store your private key.
- Inbound email content — the body and headers of mail delivered to your mailbox, so you can read it over IMAP or the HTTP API.
- IMAP/API access logs — login timestamps and source IPs, kept for authentication and abuse/security monitoring.
We do not read or use your inbound mail content for advertising or profiling, and the Service has no capability to send mail on your behalf.
3. Why we process it (lawful basis)
- Performance of a contract (GDPR Art. 6(1)(b)) — provisioning and operating your mailbox, billing you for it.
- Legitimate interests (Art. 6(1)(f)) — access logging for account security and abuse prevention.
- Legal obligation (Art. 6(1)(c)) — accounting and tax records Paddle keeps for your payments.
4. Retention
Mailbox content and access credentials are retained for as long as your mailbox stays active, plus a limited grace period after expiry to allow reactivation before deletion. Access logs are retained only as long as needed for security and abuse investigation, then deleted or aggregated. Billing records are retained by Paddle for as long as applicable tax law requires.
5. Your rights
Under the GDPR you have the right to access the personal data we hold about you, correct inaccurate data, request erasure, restrict or object to processing, and receive a copy of your data in a portable format. To exercise any of these, use our Contact page. Requests relating specifically to payment/billing data held by Paddle should also be directed to Paddle, since Paddle acts as an independent controller for that data.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Spanish Agencia Española de Protección de Datos (AEPD). If you live elsewhere in the EU or EEA, you may instead complain to the data protection authority in your own country of residence.
6. Paddle as an independent controller
Paddle processes your billing details (name, billing address, payment instrument, transaction history) as an independent data controller for payment processing, fraud prevention, and tax compliance. Paddle's own Privacy Policy governs that processing.
7. International transfers
Paddle may process billing data outside the EEA under its own documented safeguards (such as Standard Contractual Clauses) — see Paddle's Privacy Policy for details. We do not otherwise transfer inbound mail content outside the EEA.
8. Security
Mailbox access requires possession of the private key matching your registered Ed25519 public key; the Service does not use passwords for this. We apply reasonable technical and organisational measures to protect stored mail and access credentials, but no service can guarantee absolute security.
9. Changes
We may update this notice from time to time; the "Last updated" date above reflects the current version.