Privacy Policy

Last updated: September 2026

This policy explains how Better Email ApS (“Better Email”, “we”) handles personal data when you visit better.email, contact us, or use the Better Email platform. It applies together with our Cookie Policy, Sub-Processor list and Data Processing Agreement.

1. Who we are

Better Email ApS

CVR 42361194

Italiensvej 2, 5th, 2300 København S, Denmark

Phone: +45 42 48 38 28

General: hello@better.email

Data protection: privacy@better.email

Security: security@better.email

We also have an office c/o Regus, Bei den Mühren 1, 20457 Hamburg, Germany. Better Email ApS is legally represented by Nicki Pabst.

2. Our roles: controller and processor

For visitors to our website, people who contact us, leads, and the account and billing contacts of our customers, Better Email is the data controller. This policy covers that processing.

For content our customers put into the platform (campaign content, design systems, uploaded assets, test sends, and any personal data that appears in them), Better Email is a data processoracting on the customer's instructions. That processing is governed by our Data Processing Agreement and the customer's own privacy policy. If you are a recipient of a campaign built in Better Email, please contact the sender.

3. What we collect

  • •Website visitors: IP address, browser and device type, pages viewed, referrer, and, with your consent, analytics and advertising identifiers.
  • •Leads and forms: name, work email, company, role, the message or request you send, uploaded files you attach to a demo or migration request, and the page you submitted from.
  • •Account users: name, work email, role, organisation, sign-in events, and settings. If your organisation uses SSO, your identity provider sends us your name and email.
  • •Platform content: the campaigns, design systems, assets and comments you and your team create. We process this as a processor (section 2).
  • •Support: the content of support conversations and the account context needed to help.

4. Purposes and legal bases

PurposeDataLegal basis
Operate the website and keep it secureIP address, browser and device data, server logsLegitimate interest (Art. 6(1)(f)): running and protecting our services
Respond to demo requests, contact forms and document requestsName, work email, company, role, messagePre-contractual steps at your request (Art. 6(1)(b)) and legitimate interest in following up
Send marketing about Better EmailName, work email, company, interaction historyConsent (Art. 6(1)(a)) or, for existing customers, legitimate interest with an opt-out in every message
Create and administer customer accounts and billingName, work email, role, organisation, invoicing detailsContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for bookkeeping
Measure website usage and improve the productPages viewed, clicks, referrer, aggregated usage dataConsent (Art. 6(1)(a)) for cookies and similar identifiers; legitimate interest for cookieless, aggregated statistics
Advertising measurement and remarketingAdvertising identifiers, conversion eventsConsent (Art. 6(1)(a)), given through the cookie settings
Provide support and manage the customer relationshipName, work email, support messages, account contextContract (Art. 6(1)(b))
Comply with law and defend legal claimsRecords required by the Danish Bookkeeping Act, correspondenceLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f))

5. Cookies and tracking

Analytics and advertising technologies on better.email run only after you accept them in the cookie banner. You can change your choice at any time through the “Cookie settings” link in the footer. The full list of vendors, cookies and lifetimes is in our Cookie Policy.

6. Recipients and sub-processors

We share personal data with the service providers that host and support our services, each bound by a data processing agreement. The current list, with purpose, data categories, location and transfer mechanism for each provider, is published on our Sub-Processor page.

We also disclose personal data where the law requires it, to professional advisers under confidentiality, and, if the business is sold or merged, to the acquiring party under the same protections. We do not sell personal data.

7. International transfers

Customer data is stored and processed in the EU (Cloudflare Workers, Convex, AWS S3 in eu-west-1, Cloudflare R2 with EU jurisdiction, PostHog EU, Sentry EU). A limited set of providers process specific data in the United States:

ProviderDataPurpose
WorkOS, Inc.Account dataAuthentication and enterprise SSO
Stripe, Inc.Account and payment dataPayments and subscriptions
Anthropic, PBCCustomer contentAI campaign building and coding assistant
OpenAI, L.L.C.Customer contentAI analysis and translation
FirecrawlPublic URLsWeb content retrieval for the AI assistant
Easy Tech Solution LLC (EmailPreviewServices)Customer contentEmail client previews
Cloudflare, Inc.Usage data, customer content at the edgeCDN, DNS and DDoS protection (EU storage, global edge)

These transfers rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum, supported by transfer impact assessments. AI providers are used through their API offerings only and are contractually prohibited from training models on customer content. Customers can disable AI features per workspace, or run inference under their own AI provider account in an EU region. See the AI section of our security page.

8. Retention

DataRetention period
Website lead data (demo, contact and document request forms)24 months from last contact
Account and billing records5 years after the end of the financial year, per the Danish Bookkeeping Act
Activity and access logs30 days
Uploaded assets (images, fonts, files)Up to 2 years after last access or contract end
Campaign and design system statisticsFor the term of the agreement
BackupsDaily; not archived beyond one day
Customer content after terminationDeleted 3 months after termination unless the customer instructs otherwise
Personal data export on requestDelivered within 7 working days

Where the law requires a longer period, or we need the data to defend a legal claim, we keep only what that purpose requires.

9. Security

Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Access to production systems is limited to named engineers on a least-privilege basis. Customers control access with SSO, multi-factor authentication through their identity provider, SCIM provisioning, roles, and an organisation-wide audit log. We take daily backups, use DDoS protection, monitor errors and uptime, and publish service status at status.better.email. If a personal data breach affects you, we notify affected customers without undue delay and within 24 hours of becoming aware of it. The full list of measures is on our Security page.

10. Your rights

  • •Access: Get a copy of the personal data we hold about you.
  • •Rectification: Have inaccurate data corrected.
  • •Erasure: Have your data deleted where we have no overriding reason to keep it.
  • •Restriction: Ask us to pause processing while a question is resolved.
  • •Portability: Receive data you gave us in a machine-readable format.
  • •Objection: Object to processing based on legitimate interest, including direct marketing.
  • •Withdraw consent: Withdraw consent at any time, for example through the cookie settings. This does not affect processing before the withdrawal.

To exercise a right, email privacy@better.email. We answer within one month. We may ask you to confirm your identity first.

You can complain to the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, datatilsynet.dk. If you live in another EU or EEA country, you can also contact your local supervisory authority.

11. California residents

If you live in California, you have the right to know what personal information we collect and how we use it, to delete it, to correct it, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising these rights.

We do not sell personal information for money. Advertising pixels on our website can count as “sharing” under California law. They only run after you accept marketing cookies, and you can turn them off at any time through the “Cookie settings” link in the footer, which is also our “Do Not Sell or Share My Personal Information” control. We honour Global Privacy Control signals. For other requests, email privacy@better.email.

12. Children

Our website and platform are for businesses and are not directed at anyone under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

We update this policy when our processing changes and revise the date at the top. For material changes affecting customers, we give notice through the platform or by email.

14. Contact

Questions about this policy or your data: privacy@better.email. Better Email ApS, Italiensvej 2, 5th, 2300 København S, Denmark.