Privacy Policy
Last updated: September 2026
This policy explains how Better Email ApS (“Better Email”, “we”) handles personal data when you visit better.email, contact us, or use the Better Email platform. It applies together with our Cookie Policy, Sub-Processor list and Data Processing Agreement.
1. Who we are
Better Email ApS
CVR 42361194
Italiensvej 2, 5th, 2300 København S, Denmark
Phone: +45 42 48 38 28
General: hello@better.email
Data protection: privacy@better.email
Security: security@better.email
We also have an office c/o Regus, Bei den Mühren 1, 20457 Hamburg, Germany. Better Email ApS is legally represented by Nicki Pabst.
2. Our roles: controller and processor
For visitors to our website, people who contact us, leads, and the account and billing contacts of our customers, Better Email is the data controller. This policy covers that processing.
For content our customers put into the platform (campaign content, design systems, uploaded assets, test sends, and any personal data that appears in them), Better Email is a data processoracting on the customer's instructions. That processing is governed by our Data Processing Agreement and the customer's own privacy policy. If you are a recipient of a campaign built in Better Email, please contact the sender.
3. What we collect
- •Website visitors: IP address, browser and device type, pages viewed, referrer, and, with your consent, analytics and advertising identifiers.
- •Leads and forms: name, work email, company, role, the message or request you send, uploaded files you attach to a demo or migration request, and the page you submitted from.
- •Account users: name, work email, role, organisation, sign-in events, and settings. If your organisation uses SSO, your identity provider sends us your name and email.
- •Platform content: the campaigns, design systems, assets and comments you and your team create. We process this as a processor (section 2).
- •Support: the content of support conversations and the account context needed to help.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Operate the website and keep it secure | IP address, browser and device data, server logs | Legitimate interest (Art. 6(1)(f)): running and protecting our services |
| Respond to demo requests, contact forms and document requests | Name, work email, company, role, message | Pre-contractual steps at your request (Art. 6(1)(b)) and legitimate interest in following up |
| Send marketing about Better Email | Name, work email, company, interaction history | Consent (Art. 6(1)(a)) or, for existing customers, legitimate interest with an opt-out in every message |
| Create and administer customer accounts and billing | Name, work email, role, organisation, invoicing details | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for bookkeeping |
| Measure website usage and improve the product | Pages viewed, clicks, referrer, aggregated usage data | Consent (Art. 6(1)(a)) for cookies and similar identifiers; legitimate interest for cookieless, aggregated statistics |
| Advertising measurement and remarketing | Advertising identifiers, conversion events | Consent (Art. 6(1)(a)), given through the cookie settings |
| Provide support and manage the customer relationship | Name, work email, support messages, account context | Contract (Art. 6(1)(b)) |
| Comply with law and defend legal claims | Records required by the Danish Bookkeeping Act, correspondence | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
5. Cookies and tracking
Analytics and advertising technologies on better.email run only after you accept them in the cookie banner. You can change your choice at any time through the “Cookie settings” link in the footer. The full list of vendors, cookies and lifetimes is in our Cookie Policy.
6. Recipients and sub-processors
We share personal data with the service providers that host and support our services, each bound by a data processing agreement. The current list, with purpose, data categories, location and transfer mechanism for each provider, is published on our Sub-Processor page.
We also disclose personal data where the law requires it, to professional advisers under confidentiality, and, if the business is sold or merged, to the acquiring party under the same protections. We do not sell personal data.
7. International transfers
Customer data is stored and processed in the EU (Cloudflare Workers, Convex, AWS S3 in eu-west-1, Cloudflare R2 with EU jurisdiction, PostHog EU, Sentry EU). A limited set of providers process specific data in the United States:
| Provider | Data | Purpose |
|---|---|---|
| WorkOS, Inc. | Account data | Authentication and enterprise SSO |
| Stripe, Inc. | Account and payment data | Payments and subscriptions |
| Anthropic, PBC | Customer content | AI campaign building and coding assistant |
| OpenAI, L.L.C. | Customer content | AI analysis and translation |
| Firecrawl | Public URLs | Web content retrieval for the AI assistant |
| Easy Tech Solution LLC (EmailPreviewServices) | Customer content | Email client previews |
| Cloudflare, Inc. | Usage data, customer content at the edge | CDN, DNS and DDoS protection (EU storage, global edge) |
These transfers rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum, supported by transfer impact assessments. AI providers are used through their API offerings only and are contractually prohibited from training models on customer content. Customers can disable AI features per workspace, or run inference under their own AI provider account in an EU region. See the AI section of our security page.
8. Retention
| Data | Retention period |
|---|---|
| Website lead data (demo, contact and document request forms) | 24 months from last contact |
| Account and billing records | 5 years after the end of the financial year, per the Danish Bookkeeping Act |
| Activity and access logs | 30 days |
| Uploaded assets (images, fonts, files) | Up to 2 years after last access or contract end |
| Campaign and design system statistics | For the term of the agreement |
| Backups | Daily; not archived beyond one day |
| Customer content after termination | Deleted 3 months after termination unless the customer instructs otherwise |
| Personal data export on request | Delivered within 7 working days |
Where the law requires a longer period, or we need the data to defend a legal claim, we keep only what that purpose requires.
9. Security
Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Access to production systems is limited to named engineers on a least-privilege basis. Customers control access with SSO, multi-factor authentication through their identity provider, SCIM provisioning, roles, and an organisation-wide audit log. We take daily backups, use DDoS protection, monitor errors and uptime, and publish service status at status.better.email. If a personal data breach affects you, we notify affected customers without undue delay and within 24 hours of becoming aware of it. The full list of measures is on our Security page.
10. Your rights
- •Access: Get a copy of the personal data we hold about you.
- •Rectification: Have inaccurate data corrected.
- •Erasure: Have your data deleted where we have no overriding reason to keep it.
- •Restriction: Ask us to pause processing while a question is resolved.
- •Portability: Receive data you gave us in a machine-readable format.
- •Objection: Object to processing based on legitimate interest, including direct marketing.
- •Withdraw consent: Withdraw consent at any time, for example through the cookie settings. This does not affect processing before the withdrawal.
To exercise a right, email privacy@better.email. We answer within one month. We may ask you to confirm your identity first.
You can complain to the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, datatilsynet.dk. If you live in another EU or EEA country, you can also contact your local supervisory authority.
11. California residents
If you live in California, you have the right to know what personal information we collect and how we use it, to delete it, to correct it, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising these rights.
We do not sell personal information for money. Advertising pixels on our website can count as “sharing” under California law. They only run after you accept marketing cookies, and you can turn them off at any time through the “Cookie settings” link in the footer, which is also our “Do Not Sell or Share My Personal Information” control. We honour Global Privacy Control signals. For other requests, email privacy@better.email.
12. Children
Our website and platform are for businesses and are not directed at anyone under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We update this policy when our processing changes and revise the date at the top. For material changes affecting customers, we give notice through the platform or by email.
14. Contact
Questions about this policy or your data: privacy@better.email. Better Email ApS, Italiensvej 2, 5th, 2300 København S, Denmark.