Legal
Privacy Policy
How we collect, use, store, and share your information when you use Ṣọ Email Security.
Policy update in review
This policy was updated on 25 July 2026 to describe how our Services actually work today, and to cover all three of our products: the consumer apps and browser extension, the Ṣọ Shield developer API, and our enterprise and managed service provider platform.
Where a practice is still being changed, we say so plainly and mark it In progress. Those notes describe work we are doing now, not work that is already finished.
SO Labs (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share user data and personal information when you use our services. This policy applies to our website, browser extension, mobile applications (iOS and Android), desktop applications, and any related services (collectively referred to as the “Services”).
The Services cover three products:
- ▸Our consumer products: the website, the browser extension, and the mobile and desktop apps.
- ▸The Ṣọ Shield developer API: analysis endpoints that other businesses call from their own products. See Section 11.
- ▸Our enterprise and managed service provider platform: currently in early access with design partners. See Section 12.
01Information We Collect
1.1 Email Account Data
When you connect your email account (including Gmail, Outlook, Hotmail, Office 365, Yahoo, or other supported email providers) to our Services, we access the following information:
- ▸Email Messages: Metadata (e.g., sender, recipient, subject) and email content when you open an email as required for the functionality of the app
- ▸OAuth Tokens and Authentication Credentials: We use OAuth tokens for authentication wherever supported by your email provider. We do not request or store your email account password unless a specific connection method (such as IMAP) requires credentials, in which case this will be disclosed at connection time and any stored credentials are protected using encryption.
- ▸Email Processing: Our Services analyze email content to provide threat detection and categorization. This analysis happens on our servers, not on your device. To be precise about what that means:
- Email content is transmitted to our servers over an encrypted connection (TLS).
- It is analyzed in memory and discarded as soon as the verdict is returned to your app.
- It is not written to our database. The only exception is when you choose to report an incorrect result, described in Section 4.3.
- We do not intentionally disclose email content to third parties except as described in this Policy.
In progress: operational diagnostic logs may transiently capture parts of a request, including email content, while it is being processed. We are actively removing email content from our application logs. Until that work is finished, we cannot state that no email content ever appears in a log line. See Section 4.4.
- ▸Email Headers: For Premium, Team, and Enterprise subscribers, we analyze SPF, DKIM, and DMARC records for authentication validation
- ▸Links and URLs: For Premium, Team, and Enterprise subscribers, we extract and analyze links within emails for security scanning
- ▸Attachments: For Premium, Team, and Enterprise subscribers, we access attachment metadata and content for security analysis
1.2 Dark Web Breach Monitoring Data
When you use our dark web breach monitoring feature:
- ▸Email Address: Your registered email address is submitted to the Have I Been Pwned (HIBP) API to check against known data breaches. Only the email address is sent. No passwords, email content, or other personal data is shared with HIBP.
- ▸Breach Results: Information returned by HIBP (breach name, breach date, types of data exposed) is stored on our servers to provide you with alerts and dashboard access.
- ▸Scan History: Timestamps and metadata of when breach scans were performed are logged for service reliability.
We never have access to, store, or transmit your actual passwords for breach monitoring purposes. HIBP tells us if your email appeared in a breach, not the credentials themselves.
1.3 Meeting Security and Deepfake Detection Data
Notice on Meeting Participant Consent. Audio analysis, transcription, and deepfake detection may trigger recording, wiretap, and privacy laws that vary by jurisdiction. You are responsible for obtaining all required consents from meeting participants before using these features. See Section 2.6 of our Terms of Service for details.
When you use our meeting security features (via the Chrome extension):
- ▸Audio and Video: Meeting audio and video are processed entirely on your device using locally-run AI models (ONNX Runtime via WebAssembly). No audio or video data is ever transmitted to our servers.
- ▸Transcriptions: Meeting transcriptions are generated on your device using a local Whisper model. Transcripts are stored locally in your browser (Chrome Storage API and IndexedDB) and are never sent to our servers.
- ▸Deepfake Scores: Audio and video deepfake analysis scores are computed locally. Only anonymized, aggregate detection statistics (not individual scores or meeting content) may be used for service improvement.
- ▸IP and Geolocation: WebRTC ICE candidate data is analyzed locally to detect VPN/datacenter routing and timezone mismatches. This data is not transmitted to our servers.
- ▸AI Models: Deepfake detection and transcription models are downloaded from a CDN on first use and cached locally in IndexedDB. Model integrity is verified via SHA-256 checksums.
1.4 Mobile Application Data
When you use our iOS or Android mobile applications:
- ▸Email Access: Email content is accessed via Gmail API, Microsoft Graph API, or IMAP protocols. Content is sent to our analysis API over TLS, analyzed in memory, and discarded when the verdict is returned. It is not written to our database, except as described in Section 4.3, and we do not intentionally disclose email content to third parties except as described in this Policy. See Section 4.4 for how diagnostic logs are handled.
- ▸Local Storage: Email metadata, categorization results, and user preferences are stored locally on your device using SQLite.
- ▸Push Notifications: If enabled, we use platform notification services (Apple Push Notification Service, Firebase Cloud Messaging) to deliver security alerts. Only notification metadata is sent, never email content.
1.5 Other Personal Information
We also collect:
- ▸Account Information: Your name, email address, profile information, and subscription tier when you register with us
- ▸Subscription Data: Payment information, billing history, subscription status, and free trial usage (processed securely through Stripe)
- ▸Usage Data: Information about how you interact with our Service, including:
- Device type, operating system, and browser type
- Feature usage patterns and frequency
- Error logs and performance data
- Threat detection statistics and categorization results
Information collected is used for the purposes of fulfilling contractual service requirements, service improvements, and troubleshooting.
1.6 Mailbox Search Queries
When you search your mailbox inside the Services, the search itself runs against your mailbox through your provider's API or against the copy of your metadata held on your device.
- ▸What is recorded today: our backend currently writes the text of your search query into a service event log, together with a timestamp and your account identifier. This log exists for reliability and troubleshooting.
- ▸What we never do with it: search terms are not used for advertising, profiling, or model training, and they are not shared with third parties.
- ▸In progress: we are changing this so that only the fact that a search happened is recorded, and not the query text.
You can ask us to delete search event records associated with your account at any time using the contact details in Section 14.
02How We Use Your Information
We use the information we collect to:
- ▸Core Services: Process, analyze, categorize, and manage emails as specified by the app's functionality across Free, Premium, Team, and Enterprise tiers
- ▸Security Analysis: Perform AI-powered threat analysis, link scanning, attachment scanning, and email authentication validation
- ▸Breach Monitoring: Submit your email address to the HIBP API to check for exposure in known data breaches, store results, and send you alert notifications
- ▸Meeting Security: Facilitate on-device audio and video deepfake detection, live transcription, and VPN detection during your video calls. All processing occurs locally.
- ▸Account Management: Authenticate your identity, manage your account, and process subscription services
- ▸Communication: Communicate with you about updates, issues, support requests, and subscription changes
- ▸Legal Compliance: Comply with legal obligations and enforce our Terms of Service
- ▸Service Improvement: Use de-identified content from user-reported false positives to improve the accuracy of our predictive models and security features
| Purpose | Legal Basis (GDPR/UK GDPR) |
|---|---|
| Provide core Services | Contractual necessity |
| Secure authentication and threat analysis | Legitimate interests |
| Subscription management & billing | Contractual necessity / Legal obligation |
| Breach monitoring (email lookup via HIBP) | Contractual necessity / Legitimate interests |
| Meeting security (on-device deepfake detection) | Contractual necessity |
| Improve services (false positive reports) | Consent |
| Communications (support, updates) | Contractual necessity / Legitimate interests |
| Developer API usage accounting and billing | Contractual necessity |
| Service reliability, diagnostic, and security logs | Legitimate interests |
| Legal compliance | Legal obligation |
We do not use your data for advertising purposes or any purpose unrelated to providing the Services.
If you use the Ṣọ Shield developer API, or our enterprise and partner platform, Sections 11 and 12 explain how those work and who controls the data in each case.
03Service Tiers and Features
3.1 Free Tier
Free users receive (no time limit, no credit card required):
- ▸Email Categorization: Automatic sorting and organization of emails
- ▸AI Email Threat Analysis: Phishing and spoofing detection
- ▸Dark Web Breach Monitoring: Automated nightly scans and email alerts when new breaches are found
- ▸Audio Deepfake Detection: Real-time on-device voice clone detection during meetings
- ▸Live Meeting Transcription: On-device speech-to-text via local Whisper model
- ▸VPN/Datacenter Detection: Identifies when meeting participants route through VPNs or cloud infrastructure
- ▸Post-Meeting Recap: Automatic summary of key points, action items, and decisions
3.2 Premium Tier
Premium subscribers receive all Free features plus:
- ▸Advanced Link Scanner: Real-time analysis of URLs and links within emails for malicious content
- ▸Attachment Scanner: Security analysis of email attachments for threats and malware
- ▸SPF/DKIM/DMARC Validation: Email authentication protocol verification
- ▸Sender Verification and Email Tracker Blocking
- ▸Video Deepfake Detection: On-device face analysis during video calls
- ▸Timezone Mismatch Alerts: Flags when participant IP geolocation does not match claimed timezone
- ▸Meeting PDF Export and Unlimited History
- ▸Custom Business Email: Domain, mailbox, and auto-configured SPF/DKIM/DMARC (yearly plans only)
Note: New users can access all Premium features through our 7-day free trial before subscription begins.
3.3 Team and Enterprise Tiers
Team and Enterprise tiers include all Premium features plus team management, analytics dashboards, centralized monitoring, and admin controls. Enterprise additionally includes SSO/SAML, custom API integrations, and dedicated support. These tiers may involve processing of aggregated team-level analytics data on our servers. This may include aggregate counts of threats detected, user seats, feature usage, policy status, and security trends, but does not include email content.
Where an organisation or a managed service provider connects mailboxes on behalf of other people, Section 12 sets out who controls the data and what quarantine stores.
3.4 Security Assessment Process
Our service uses predictive models and security tools to analyze and categorize your emails for potential security threats. Specifically, we analyze:
- ▸Sender reputation and email headers
- ▸Link destinations and attachment characteristics (Premium, Team, and Enterprise)
- ▸Email content patterns associated with common scams and phishing attempts
- ▸Behavioral patterns that may indicate suspicious activity
- ▸Email authentication records and validation (Premium, Team, and Enterprise)
3.5 False Positives and User Feedback
These models may occasionally produce false positives or inaccurate predictions. To continuously improve our service, we provide a mechanism for users to report these inaccuracies. User feedback is crucial for enhancing the accuracy and effectiveness of our service for all users.
3.6 Automated Decision Making
Our service includes automated analysis that may flag emails as potentially suspicious. While this automated process helps protect your security:
- ▸No emails are automatically deleted or moved without your confirmation
- ▸You maintain full control over all actions taken on your emails
- ▸You can provide feedback on any automated decision
04How We Store and Protect Your Information
4.1 Data Storage and Retention
Data that we store is protected using technical and organizational safeguards in compliance with relevant industry standards.
- ▸Email data: Email content is transmitted to our servers over TLS, analyzed in memory, and discarded when the verdict is returned. It is not written to our database, except as described in Section 4.3 (reported false positives). We do not intentionally disclose email content to third parties except as described in this Policy. Only analysis results (threat scores, categorization labels) and minimal metadata necessary to operate the Services are retained. See Section 4.4 for diagnostic logs.
- ▸Link and Attachment Analysis: For Premium, Team, and Enterprise users, link destinations and attachment metadata may be temporarily cached for security analysis (maximum 24 hours)
- ▸Authentication tokens and two-factor secrets: OAuth access tokens, OAuth refresh tokens, and two-factor authentication secrets are held in our access-controlled database systems for as long as the account stays connected, and are removed when you disconnect the account or delete your account.
- These values are transmitted only over TLS.
- They are never returned in API responses and are never shown in the dashboard or the apps.
- Access is limited to the small number of staff and systems that need it, and access is logged.
In progress: these fields are not yet protected by application-level encryption at rest. We are adding application-level encryption at rest for them. Until that work ships, protection relies on database access controls, restricted staff access, and encryption in transit. We are not claiming encryption at rest for these fields today.
- ▸Breach monitoring results: Stored on our servers for the duration of your account to provide breach alerts and dashboard access. Deleted upon account deletion.
- ▸Meeting data (audio, video, transcripts): Processed and stored entirely on your local device. Never transmitted to or stored on our servers.
- ▸Account information: Retained until you request deletion or close your account
- ▸Subscription data: Retained as required for billing, tax, and legal compliance purposes (minimum 7 years for tax records, or as required by applicable law)
4.2 Data Security
We implement technical and organizational measures to protect your information, including:
- ▸Encrypted transmission of data in transit (HTTPS, TLS). How stored data is protected varies by field. Section 4.1 sets out exactly how authentication tokens and two-factor secrets are held today, and what we are changing.
- ▸Regular security audits and vulnerability assessments
- ▸Access controls limiting employee access to personal data
- ▸Secure development practices and regular security training for our team
- ▸Enhanced security measures for Premium, Team, and Enterprise features including isolated processing environments
In the event of a data breach that may affect your personal data, we will notify you without undue delay, consistent with our legal obligations.
4.3 Processing of Reported Content
When you report inaccurate predictions by clicking the designated button:
- ▸We copy only the specific email content necessary for improving our service
- ▸Any personally identifiable information (PII) is automatically removed
- ▸The de-identified content is used solely for service improvement purposes
- ▸Original email content is never stored on our servers in its complete form
- ▸Retention of reported content: reported content is retained until you ask us to delete it, or until we delete it during a review. We do not currently run an automated purge for this content, so we do not claim a fixed maximum retention period for it.
In progress: we are building automated deletion so that reported content is removed within 90 days of submission. Until that is live, you can have anything you reported deleted on request by emailing privacy@soemailsecurity.com.
4.4 Diagnostic and Service Logs
Running a security service requires logs. We want to be straight with you about what they can contain today.
- ▸Request and error logs: our servers record request paths, timestamps, response codes, account identifiers, and error traces so we can keep the Services reliable and investigate abuse.
- ▸Transient capture of request data: because analysis requests carry email content, diagnostic logs may transiently capture parts of that content while a request is being handled. This is a side effect of logging, not a store of your mail, and it is not used for any purpose other than diagnosing faults.
- ▸Event logs: service event records, including the mailbox search query text described in Section 1.6, are written for reliability and troubleshooting.
- ▸In progress: we are removing email content from application logs and removing search query text from event logs. This work is under way and is not finished. We will update this section when it is.
Logs are kept only as long as needed for reliability, billing accuracy, and security investigation, then rotated out. Access to logs is restricted to staff who need it.
05Sharing Your Information
We do not sell, rent, or share your personal information for cross-context behavioral advertising. We only share your information in the following circumstances:
5.1 Sub-Processors and Service Providers
These are the third parties that receive data from the Services, what they do, and what they get.
| Provider | Purpose | Data shared |
|---|---|---|
| Amazon Web Services | Hosting and infrastructure | All Service data, at rest and in transit |
| Stripe | Payments and subscription billing | Billing identifiers and payment data |
| Have I Been Pwned | Dark web breach lookup | Your email address only |
| Gmail API and OAuth sign-in | The mailbox access you authorise, and basic profile information | |
| Microsoft | Outlook Graph API and OAuth sign-in | The mailbox access you authorise, and basic profile information |
| Apple | Sign in with Apple | Authentication identifiers |
| Email delivery provider (via SMTP) | Transactional and alert emails | Your email address and the content of the messages we send you |
| Wise | Referral programme payouts | Your payout email address, only if you join the referral programme |
| Our own machine learning classification service | Email threat analysis | Email subject and body, held in memory only |
Our machine learning classification service runs on our own infrastructure. It is listed here for transparency, not because it is an outside company.
Only your email address goes to Have I Been Pwned. No passwords, no email content, and no other personal data is sent there.
If you use Custom Business Email, third-party email hosting, routing, domain registration, DNS, or deliverability providers may also process domain, mailbox, DNS, and message-routing data as necessary to provide that specific feature.
We do not use advertising networks or data brokers, and we do not sell your data to anyone.
All of these providers are bound by confidentiality obligations and may use your data only to provide their service to us. This list may change as our infrastructure changes, and we will give notice of material changes as described in Section 13. If you have questions about a provider on this list, email privacy@soemailsecurity.com.
5.2 Other Circumstances
- ▸With Your Consent: If you explicitly authorize us to share specific information
- ▸For Legal Compliance: To comply with applicable laws, regulations, or legal requests
- ▸Business Transfers: In connection with any merger, sale of company assets, or acquisition of all or a portion of our business by another company, or in the unlikely event of bankruptcy
06Browser Extension Permissions
Our Browser extension requires the following permissions:
- ▸Read and change your data on websites you visit: This allows us to analyze email content on supported email provider websites to identify security threats and provide categorization. This permission is technically broad because of how browsers describe extension access, but Ṣọ only activates on supported email and meeting websites needed to provide the Services. We do not read or modify content on any other websites.
- ▸Display notifications: To alert you about potential security issues and categorization results
- ▸Access supported email provider websites: Limited to the specific email provider domains you connect to the Services. We do not access, log, or track your activity on any other websites.
- ▸Access to downloads (Premium, Team, and Enterprise): For attachment scanning functionality
- ▸Network requests (Premium, Team, and Enterprise): For link scanning and real-time threat intelligence
- ▸Tab capture: Used to capture meeting audio for on-device deepfake detection and transcription. Audio is processed locally via WebAssembly and is never sent to any server.
- ▸Offscreen documents: Used to run AI models (ONNX Runtime) in a background context for meeting security analysis. All inference occurs on your device.
These permissions are used only for the purposes of providing our email security and meeting security services and are not used to track general browsing activity.
07Service Provider Requirements and API Usage
7.1 Service Provider Compliance
Ṣọ Email Security adheres to the applicable requirements for each email service provider, including:
- ▸Google's Limited Use Requirements (for Gmail)
- ▸Microsoft's API Terms of Use (for Outlook, Hotmail, and Office 365)
- ▸Similar requirements for other supported email providers
In all cases, your email data is:
- ▸Used only for providing or improving the Services
- ▸Not used for advertising purposes or shared with third parties
- ▸Handled securely and kept confidential at all times
7.2 Google Workspace API Usage
Notwithstanding any other provision in this Privacy Policy, our use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When using Google Workspace APIs (including Gmail):
- ▸We use data obtained through Google Workspace APIs only to provide and improve user-facing features within Ṣọ Email Security
- ▸We do not transfer Google Workspace APIs data to others except: (i) as necessary to provide or improve user-facing features that are prominent in the user interface, (ii) to comply with applicable law or valid legal process, or (iii) as part of a merger, acquisition, or sale of assets with notice to users
- ▸We do not use Google Workspace APIs data to develop, improve, or train generalized or non-personalized artificial intelligence (AI) or machine learning (ML) models. Any AI/ML processing of Google Workspace APIs data is used only for the user-facing email security functions of Ṣọ Email Security and not for generalized model training
- ▸We do not use Google Workspace APIs data to serve advertisements
- ▸We do not allow humans to read Google Workspace APIs data unless: (a) we have obtained your affirmative consent for specific messages, (b) it is necessary to investigate abuse, security incidents, service errors, or specific support requests, in each case under access controls and audit logging, (c) to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations
08Your Rights and Choices
8.1 Access and Control
You have the right to:
- ▸Access your information: You can request a copy of the personal information we hold about you by emailing privacy@soemailsecurity.com or soemailfeedback@soemailsecurity.com
- ▸Correct your information: You can update your account information through your account settings or by contacting us
- ▸Delete your information: You can request deletion of your account and all associated data, including breach results, reported content, and service event records, by emailing privacy@soemailsecurity.com or soemailfeedback@soemailsecurity.com. Put “Data deletion request” in the subject line. Deletion timing is described below.
- ▸Downgrade subscription: Premium, Team, and Enterprise subscribers can downgrade to Free tier while retaining basic functionality
- ▸Revoke access: You can revoke our access to your email account by visiting your email provider's account permissions or security page:
Deletion Timeline and Exceptions
When you submit a deletion request, we will delete your personal data from active production systems within 30 days. Backup copies may persist for up to 90 days due to standard backup rotation, after which they are permanently overwritten. Certain records are retained beyond this period where required by law or legitimate business purpose:
- ▸Billing, payment, and tax records: retained for the period required by applicable tax and accounting law (typically 7 years)
- ▸Records related to legal claims, regulatory investigations, or fraud prevention: retained until resolution and any applicable limitation period has expired
- ▸Anonymized or aggregated data that no longer identifies you: may be retained indefinitely
8.2 Opt-Out
You may:
- ▸Opt out of email communications: Follow the unsubscribe instructions in any email we send
- ▸Opt out of reporting: False positive reporting only occurs when you explicitly click on the reporting link. You can choose not to click this link and still use the core service without any limitations
- ▸Disable specific features: Premium, Team, and Enterprise subscribers can selectively disable link scanning, attachment scanning, or authentication validation while maintaining other premium features
- ▸Limit permissions: You can choose not to provide certain permissions to our extension, but this may limit the functionality of the Services
8.3 Consent for Reporting
When you click on the reporting link for a false positive, you are providing explicit consent to copy and process the relevant email content as described in Section 4.3. This consent is provided on a case-by-case basis, as reporting only occurs when you actively choose to click the reporting link.
8.4 California (CCPA/CPRA) Rights
If you are a California resident, you also have the right to:
- ▸Know what personal information we collect and how it is used
- ▸Request deletion of personal information
- ▸Request correction of inaccurate personal information
- ▸Opt out of the sale or sharing of personal information (we do not sell or share)
- ▸Limit the use of Sensitive Personal Information (SPI), where applicable
09Children's Privacy
Our Services are not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 13 (COPPA compliance). In the European Union, the minimum age for consent varies between 13 and 16 depending on local law.
If you become aware that a child has provided us with personal information without appropriate parental consent, please contact us at soemailfeedback@soemailsecurity.com. If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that information from our servers.
10Compliance with Privacy Regulations
We are committed to complying with applicable privacy regulations, including:
- ▸General Data Protection Regulation (GDPR): For users in the European Economic Area, we respect your rights to access, correct, delete, and port your personal data, and to object to certain processing activities
- ▸California Consumer Privacy Act & California Privacy Rights Act (CCPA/CPRA): For California residents, we respect your rights as outlined in Section 8.4
- ▸For EEA/UK residents, transfers rely on Standard Contractual Clauses (SCCs) or other recognized safeguards.
11Developer API (Ṣọ Shield API)
The Ṣọ Shield API lets other businesses send content to our analysis endpoints from inside their own products. This section applies to API customers and to the content they submit.
- ▸Who controls the data: content an API customer submits may belong to that customer's own end users. For that content, the customer is the data controller and Ṣọ acts as a processor, acting only on the customer's instructions.
- ▸Submitted content: content sent to the analysis endpoints is analysed in memory and discarded when the verdict is returned. It is not written to our database.
- ▸What we do keep: the analysis service persists request metadata for usage accounting and billing. That means the endpoint called, the timestamp, the credits consumed, and the response status. It does not include the content that was submitted.
- ▸No external calls: the API analysis service makes no calls to external third parties, so content submitted to it does not leave our infrastructure.
- ▸Logs: the diagnostic logging described in Section 4.4 applies to API requests as well.
- ▸Data Processing Agreement: API customers should contact us for a Data Processing Agreement. See our Data Processing Agreement and the API Terms.
API customers are responsible for having a lawful basis for the content they send us, and for giving their own end users any notice or obtaining any consent that applies.
12Enterprise, MSP, and Partner Use
Early access. The enterprise and managed service provider platform is at an early-access, design-partner stage. The data flows described here reflect the current design. They may change as the platform develops, and we will update this section when they do.
This section applies where an organisation, a managed service provider (MSP), or a partner connects mailboxes rather than an individual connecting their own.
- ▸Who controls the data: where an organisation connects its own mailboxes, that organisation is the controller and Ṣọ acts as a processor. Where an MSP or partner connects mailboxes belonging to its own clients, the partner acts as processor for those clients and Ṣọ acts as a sub-processor.
- ▸Quarantine: quarantine is designed to store only metadata and the verdict. That means sender, subject, timestamp, message id, and the reason the message was held. Message bodies and attachments are not stored in quarantine.
- ▸Admin visibility: administrators can see verdicts, quarantine metadata, and aggregate reporting for the mailboxes in their tenant. The organisation is responsible for telling its own people that the Services are in use.
- ▸Instructions only: we process tenant data on the controller's instructions, and we delete or return it at the end of the engagement as set out in the Data Processing Agreement.
- ▸Agreement and contact: enterprise, MSP, and partner customers should use our Data Processing Agreement. For questions or to request one, email sales@soemailsecurity.com.
Where the Data Processing Agreement and this Privacy Policy differ for tenant data, the Data Processing Agreement governs.
13Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- ▸Post the updated policy on our website with an updated effective date
- ▸Notify you via email and/or a prominent notice on our website
- ▸Update the “Effective Date” at the top of this page
- ▸In some cases, seek your explicit consent to continue using our Services with the new terms
We encourage you to review this Privacy Policy periodically to stay informed about our data practices. The date at the top of this page always shows when it was last changed.
14Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- ▸Privacy questions, data access, and data deletion: privacy@soemailsecurity.com
- ▸General support and feedback: soemailfeedback@soemailsecurity.com
- ▸Enterprise, MSP, and API agreements: sales@soemailsecurity.com
- ▸Mailing Address: SO Labs, 7909 Flint Rd SE #202 Calgary AB T2H 1G3 Canada
To ask us to delete your data, email privacy@soemailsecurity.com with “Data deletion request” in the subject line. The timing and the limited exceptions are set out in Section 8.1.
EEA/UK Users:
Our Services are primarily directed to users in North America. We do not intentionally target or market our Services to individuals in the European Economic Area (EEA) or the United Kingdom. As such, we have not appointed a representative under GDPR or UK GDPR.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. Your continued use of the Services constitutes your agreement to its terms.