Advanced Email Technologies
How it works About Pricing Security FAQ Contact
ENESFRITDE
Log in Start free
How it works About Pricing Security FAQ Contact
ENESFRITDE
Log in Start free
Legal

Privacy Policy

How Advanced Email Technologies collects, uses, and protects personal data in connection with the Certified Email and Certified Notification services.

Effective date: 11 August 2026  ·  Last updated: 11 August 2026
Document
Privacy Policy
Data controllerAdvanced Email Technologies
Registered addressVia Stoppani 13, 24121 Bergamo, Italy
Contactprivacy@certifiedemail.pro
Governing frameworkRegulation (EU) 2016/679; Legislative Decree 196/2003, as amended
1. Who we are 2. Scope 3. Data we collect 4. How we use it 5. Certified message content 6. Who we share data with 7. International transfers 8. Retention 9. Security 10. Cookies 11. Your rights 12. Automated decisions 13. Children's privacy 14. Changes to this policy 15. Contact & complaints

1. Who we are

Advanced Email Technologies ("Advanced Email Technologies", "we", "us", "our") is the data controller for personal data processed through the Certified Email and Certified Notification services (together, the "Service"), available at certifiedemail.pro. Our registered address is Via Stoppani 13, 24121 Bergamo, Italy. For any question about this policy or your personal data, contact us at privacy@certifiedemail.pro.

We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and Italian Legislative Decree No. 196/2003 (the Personal Data Protection Code), as amended by Legislative Decree No. 101/2018. Our processing activities do not meet the thresholds in Article 37 GDPR that require the appointment of a statutory Data Protection Officer. All data protection enquiries are handled directly by our privacy team at the address above.

2. Scope of this policy

This policy applies to personal data we process about:

  • Visitors to our marketing website;
  • Registered users of the Service (account holders);
  • Individuals named as recipients on a certified email or certified notification sent through the Service; and
  • Individuals who contact our support or sales team.

It does not cover the practices of third-party sites we may link to, or of senders who use the Service to contact you — a sender remains separately responsible, as an independent controller, for their own communications and their own lawful basis for contacting you.

3. Personal data we collect

3.1 Account data

Name, email address, password (stored as a salted hash), billing address, and, where applicable, VAT or tax identification number.

3.2 Certified communication data

The content and attachments of messages you certify, the recipient's email address, delivery and acceptance responses from the recipient's mail server, and — for Certified Notification — the identity details you specify for the recipient (name and identifying number) and the identity details the recipient enters to unlock the document.

3.3 Technical and usage data

IP address, browser and device type, pages visited, timestamps, and log-in activity. See Section 10 for cookie-based collection.

3.4 Payment data

Payment card and billing details are collected and processed by our third-party payment processor. We do not store full card numbers on our own systems.

3.5 Correspondence

Records of support tickets, emails, and other communications you send us.

4. How we use your data, and our legal basis

  • —To provide the Service (create your account, relay and certify messages, generate certificates) — necessary for performance of our contract with you (Art. 6(1)(b) GDPR).
  • —To generate and preserve evidentiary certificates (content hash, delivery record, independent timestamp) — necessary for performance of our contract and our legitimate interest in providing a reliable evidentiary record (Art. 6(1)(b) and (f)).
  • —To process payment and comply with accounting and tax law — necessary to perform our contract and to comply with legal obligations (Art. 6(1)(b) and (c)).
  • —To secure the Service (fraud prevention, abuse monitoring, access logging) — legitimate interest in protecting our systems and users (Art. 6(1)(f)).
  • —To respond to support requests — necessary for performance of our contract and our legitimate interest in resolving your query (Art. 6(1)(b) and (f)).
  • —To send service and account communications (certificates, receipts, security notices) — necessary for performance of our contract (Art. 6(1)(b)).
  • —To send optional marketing communications — only with your consent, which you may withdraw at any time (Art. 6(1)(a)).
  • —To comply with legal obligations, including responding to lawful requests from courts or regulators (Art. 6(1)(c)).

5. Certified message content and evidentiary retention

The core function of the Service is to create an independent, tamper-evident record of a message's delivery and content. This means that, unlike an ordinary email provider, we intentionally retain a cryptographic fingerprint (SHA-256 hash) of the message and its attachments, the delivery response from the recipient's mail server, and a third-party RFC 3161 timestamp — for as long as your account remains active, so that the certificate remains verifiable.

Because this record can contain personal data about you and about the message recipient, we limit its use strictly to generating, storing, and — at your request — reproducing your certificate. We do not read, scan, or use certified message content for advertising, profiling, or any purpose beyond providing and securing the Service. Access to stored messages and certificates requires authenticated login; we do not expose them via public or guessable links.

If you close your account, we retain certificates and the underlying evidentiary record for the period described in Section 8, to preserve their evidentiary value and to meet our own record-keeping obligations, after which they are deleted.

6. Who we share data with

We do not sell personal data. We share it only with the following categories of recipients, each bound by a data processing agreement where they act on our behalf:

  • Infrastructure and hosting providers, to operate the Service;
  • Payment processors, to process subscription and pay-as-you-go charges;
  • The independent timestamping authority, to issue RFC 3161 timestamps on certificates;
  • Email delivery infrastructure providers, to relay certified messages via SPF/DKIM/DMARC-authenticated channels;
  • Professional advisers (legal, accounting, insurance), where necessary for their services; and
  • Courts, regulators, or law enforcement, where we are legally required to disclose data, or to establish, exercise, or defend legal claims.

7. International data transfers

Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision of the European Commission or on appropriate safeguards under Article 46 GDPR, such as the European Commission's Standard Contractual Clauses, together with supplementary technical and organisational measures where required. You may request a copy of the relevant safeguard by writing to privacy@certifiedemail.pro.

8. Data retention

  • Account data: for as long as your account is active, and up to 10 years afterwards to meet Italian accounting, tax, and civil-law limitation-period obligations.
  • Certificates and evidentiary records: for as long as your account is active, so certificates remain independently verifiable; deleted within 90 days of account closure unless a longer period is required by law or to defend a legal claim.
  • Payment records: retained by our payment processor and by us as required by applicable Italian tax and accounting law, typically up to 10 years.
  • Support correspondence: up to 3 years after the matter is resolved.
  • Marketing consent records: until you withdraw consent, plus a limited period to evidence that withdrawal.

9. Security

  • —TLS encryption for data in transit, including every relayed message
  • —SHA-256 hashing to detect any alteration of certified content
  • —Access to stored messages and certificates restricted to authenticated account holders
  • —Role-based access controls and access logging for our own personnel
  • —Regular review of technical and organisational measures under Article 32 GDPR

No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Garante per la Protezione dei Dati Personali within 72 hours, and affected individuals, as required by Articles 33 and 34 GDPR.

10. Cookies and similar technologies

Our website uses cookies that are strictly necessary to operate it, together with optional analytics cookies deployed only with your consent. Full details of the cookies we use and how to manage your preferences are set out in our Cookie Policy.

11. Your rights under the GDPR

If you are in the European Economic Area, the United Kingdom, or another jurisdiction granting equivalent rights, you may:

  • —Access the personal data we hold about you (Art. 15)
  • —Rectify inaccurate or incomplete data (Art. 16)
  • —Erase your data in certain circumstances (Art. 17)
  • —Restrict processing in certain circumstances (Art. 18)
  • —Receive a copy of your data in a portable format (Art. 20)
  • —Object to processing based on our legitimate interest, including direct marketing (Art. 21)
  • —Withdraw consent at any time, without affecting processing carried out before withdrawal (Art. 7(3))

To exercise any of these rights, write to privacy@certifiedemail.pro. We will respond within one month, as required by Article 12(3) GDPR. We may need to verify your identity before acting on a request, and some requests concerning certified evidentiary records may be limited where erasure or restriction would compromise a certificate already relied upon by a third party — in which case we will explain the specific limitation that applies.

12. Automated decision-making

We do not use your personal data for automated decision-making, including profiling, that produces legal or similarly significant effects on you.

13. Children's privacy

The Service is intended for business and professional use by adults. In accordance with Article 2-quinquies of the Italian Personal Data Protection Code, as introduced by Legislative Decree No. 101/2018, we do not knowingly collect personal data from individuals under 14 without the consent of a parent or legal guardian. If you believe a child has provided us with personal data without such consent, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal obligations. We will post the revised version on this page with an updated "Last updated" date, and, where changes are material, notify registered users by email.

15. How to contact us, and complaints

Questions, requests, or concerns about this policy or our handling of your personal data can be sent to:

Advanced Email Technologies
Via Stoppani 13, 24121 Bergamo, Italy
privacy@certifiedemail.pro

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority. As our registered address is in Italy, our lead supervisory authority is the Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma, Italy — garanteprivacy.it. If you reside in another EEA member state, you may instead lodge a complaint with the supervisory authority in your own country of residence.

Advanced Email Technologies

Registered electronic delivery and content-proof certification.

Product

About How it works Pricing Security

Company

Contact FAQ

Legal

Privacy Policy Cookie Policy Terms of Service
© 2026 Certified Email — a service of Advanced Email Technologies. All rights reserved.
ENESFRITDE