Personvernerklæring

Sist oppdatert 16 August 2026

A plain-language summary of what we do, and do not do, with your data. We are the controller for your account, and your processor for the email you send and receive through the API.

Dette dokumentet er kun tilgjengelig på engelsk. Den engelske teksten er den rettslig bindende versjonen.

Who we are

Mailhuset is a transactional email service operated by Dalysie AS, a company registered in Norway. You can reach us about privacy at support@mailhuset.com.

The short version

We keep the account, billing and usage data needed to run your Mailhuset account, and we process the email you send and receive through the API only to deliver it. We do not read the contents of your transactional messages, we do not sell your data, and we host in the European Union. For the email data we handle on your behalf, you are in charge and we act on your instructions.

Two roles: your account, and your email

For your own account data (your login, billing and how you use the dashboard), Mailhuset is the data controller and this policy explains what we do with it.

For the email you send and receivethrough the API, which contains your recipients’ data, you are the controller and Mailhuset is your processor: we handle that data only to provide the service, on your documented instructions. Those terms live in our Data Processing Agreement.

Your account information

When an account is created we store your email address and a securely hashed password. If you turn on two-factor authentication we store the secret needed to check your codes. API keys are stored only as secure hashes, never in a form we can read back. We use this to sign you in, authenticate your API calls, and manage your plan.

The email you send

For each message you send, we keep a log of the delivery details: the sender and recipient addresses, the subject, the status (delivered, bounced, complained), and timestamps. We use this to show your activity, handle bounces and complaints, meter your usage and protect the service. We do not store the body of your transactional messages: it passes through our system to the delivery backend and is not retained.

If you use templates, contact lists or broadcasts, we do store that content, because you save it with us on purpose: your template bodies, your contacts’ email addresses and any fields you add, and the content of a broadcast.

The email you receive

If you use inbound routes to receive email, we store those messages so we can deliver them to you: the sender, subject, body and any attachments, along with the spam and authentication checks. Message bodies and attachments are held in Amazon S3 in the European Union (Ireland), encrypted at rest, and large attachments are served to you through short-lived download links.

Suppression list

To protect deliverability, we keep a suppression list of recipient addresses that have hard bounced or complained, so we stop sending to them. It holds the address and the reason. This is a core part of running an email service responsibly.

Payments

Payments are handled by our providers: Polar acts as our merchant of record for card payments, and Paystack processes payments in Ghana. We never see or store your full card number. We keep a record of your plan, invoices and usage so your account works and for our own accounting.

Usage and security logs

To keep the service reliable and to prevent abuse, we record basic events such as API usage, rate limiting and a standard security trail of account actions like sign-ins and password changes. We never log the contents of your transactional messages.

Cookies

When you sign in, we set a single secure, httpOnly cookie so you stay signed in. Your browser also remembers small preferences locally, such as your light or dark theme. We do not use advertising or cross-site tracking cookies.

Sub-processors we use

We share only what is needed to run the service, with providers that act on our behalf: Amazon Web Services to deliver and receive email and to store inbound content (in the EU), Microsoft Azure to host and run the service (in the EU), and Polar and Paystack to process payments. The current list, with regions and roles, is on our sub-processors page. We do not sell or rent your data, and we do not use it for advertising.

Where your data is processed

Mailhuset runs on Microsoft Azure in the European Union (Sweden). Email is sent through Amazon SES in the EU (Stockholm) and inbound content is stored in Amazon S3 in the EU (Ireland). Amazon Web Services is a US company, so where personal data is transferred to it we rely on the safeguards required by law, such as the European Commission’s standard contractual clauses. Polar and Paystack process payment data under their own safeguards.

How long we keep your data

We keep your account data, message logs, stored email content and suppression list for as long as your account is open, so your history and deliverability protections stay intact. You can ask us to delete your account and its data at any time (see below), and payment records are kept as long as needed for accounting and legal reasons.

Legal basis for processing

Where data-protection law such as the GDPR applies, we rely on: performing our contract with you to provide the service and process payments; complying with legal obligations such as keeping accounting records; and our legitimate interest in keeping the service secure and preventing abuse.

Security

We take reasonable measures to protect your data: connections use HTTPS, passwords and API keys are stored only as secure hashes, two-factor authentication is available, access to our cloud backends uses short-lived federated credentials rather than stored keys, and access to systems is limited. No service can promise perfect security, but we work to keep your information safe and to fix issues quickly.

Your rights and choices

You can ask us to access, correct or delete your account and the data tied to it by emailing support@mailhuset.com, and we will action it. Depending on where you live you may have further rights over your personal data. If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority; in Norway this is Datatilsynet.

Your recipients’ data

The people you send to, and receive from, are your contacts, not ours. If one of them asks us about their data, we will refer them to you as the controller rather than act on it ourselves, unless the law requires otherwise. How we handle that data on your behalf is set out in the Data Processing Agreement.

Children

Mailhuset is a service for businesses and developers and is not directed at children. We do not knowingly collect personal information from anyone under 16.

Changes to this policy

We may update this policy as Mailhuset grows. When we make a meaningful change we will update the date above and, where appropriate, let you know.

Contact

Questions about your privacy or this policy? Email us at support@mailhuset.com.