Privacy Policy
Last updated 15 September 2026
This policy explains what personal data Gundhus AS collects when you visit waymail.app, use the Waymail console or API, or write to us — and how Waymail handles the personal data of the people our customers send email to.
Who we are
Waymail is owned and operated by Gundhus AS, Hellvikskogsvei 93, 1459 Nesodden, Norway, organisation number 922 852 014 (“Gundhus AS”, “we”, “us”).
Our role depends on whose data it is.
- For the people who visit our website, sign in to the console or write to us, we are the controller: we decide what is collected and why, and this policy is our account of it.
- For the data our customers send through Waymail — their recipients' addresses, the messages, their contacts, and what happened to each message — the customer is the controller and we are their processor. We process that data only on their instructions, under the data processing terms in our Terms of Service.
If you received an email sent through Waymail, the organisation that sent it is the one to ask about your data. If you ask us instead, we will pass your request on to them and help them answer it.
The short version
- The website sets no cookies, runs no analytics, loads nothing from third parties and keeps no access logs.
- The console signs you in through Clerk, and keeps a log of administrative actions — including the IP address each came from — for 400 days.
- Our customers' email data is stored and processed in the EU, in Frankfurt. Message bodies are kept for 7 to 90 days, as each customer chooses, or not at all. Delivery history is kept for 30 days, 90 days or 13 months, depending on the customer's plan.
- The only company that processes our customers' email data on our behalf is Amazon Web Services, which runs the infrastructure.
- We do not sell personal data or use it for advertising.
Visiting waymail.app
The website and the documentation are static pages served by Amazon CloudFront. They set no cookies, run no analytics, and load no scripts, fonts or other content from third parties. CloudFront's access logging is not enabled, so we keep no record of your visit.
To deliver the pages and protect its network, Amazon processes your IP address and the details of each request transiently, as any web host must. The legal basis is our legitimate interest in running a website that works and is secure (GDPR Article 6(1)(f)).
Using the console
Signing in. Clerk provides the console's accounts and sign-in. It processes your name, email address and authentication details — a password, or the identity from a sign-in provider such as Google — along with information about your sessions and devices, including IP addresses, to keep your account secure. Clerk's bot protection uses Cloudflare Turnstile, which examines your browser to tell people from automated sign-ups.
Workspaces. For each workspace you belong to, we store your user ID, email address and role. An invitation to a workspace holds the invitee's email address until 30 days after the invitation expires.
Audit log. Administrative actions — creating or revoking an API key, adding a domain, changing members or settings, removing an address from the suppression list, and similar — are recorded with who took the action, when, and the IP address it came from. The log is kept for 400 days and is available to the workspace in the console, so a workspace can always establish what was done to it, and by whom.
Browser storage. The console keeps your region and selected workspace in your browser's session storage — and, if you sign in with an API key rather than an account, that key — all of which is cleared when you close the tab. Clerk sets cookies that keep you signed in. Both are strictly necessary for the console to work, and neither is used to track you.
The legal bases are providing the service you signed up for (Article 6(1)(b)) and our legitimate interest in keeping accounts and workspaces secure (Article 6(1)(f)).
Billing. For a workspace on a paid plan, we keep the billing contact's name and email address, the organisation's name, address and VAT or organisation number, and our invoices and payment records. Payments will be taken by a payment provider, which we add to the subprocessors below before anyone is charged. We count each workspace's emails per month to apply its plan; the count is a number, not a list of recipients. The legal bases are our contract (Article 6(1)(b)) and our obligations under bookkeeping law (Article 6(1)(c)).
Writing to us
Email sent to hello@waymail.app passes through Cloudflare Email Routing, which forwards it to our mailbox at Zoho Mail, in Zoho's EU data centres. We use your name, address and message to reply to you and to keep a record of the conversation, and keep it for 24 months after the last message — longer only if it becomes part of a customer relationship that needs it. The legal basis is our legitimate interest in answering you (Article 6(1)(f)), or steps you asked us to take before entering into a contract (Article 6(1)(b)).
Email sent through Waymail
When a customer sends email through Waymail, we process the following on their behalf.
- Addresses — the recipients' email addresses and names, and any other addresses on the message: cc, bcc and reply-to.
- The message — its subject, HTML and text bodies, attachments, headers and tags.
- Contacts — the customer's audience: email addresses, names, custom properties and topic subscriptions.
- Delivery history — a record of each message, who it went to and when, and what followed: sent, delivered, delayed, bounced, complained, opened, clicked.
- Suppressions — addresses that must not be emailed again, with the reason: a hard bounce, a spam complaint, an unsubscribe, or the customer's own decision.
Open and click tracking. To show a sender whether a message was opened, Waymail can add a tiny invisible image to it. Click tracking passes a click through Waymail on its way to the link so it can be counted. Both are off unless the customer switches them on for a sending domain, and a customer who does is responsible for any consent the law requires for them. For an open we record when it happened and the user-agent string of the mail client that fetched the image; for a click, the same and which link was followed. We do not record IP addresses for either. Mail apps that fetch images automatically — Apple Mail Privacy Protection, for one — register opens nobody made, so an open is a hint, not proof.
Unsubscribing. Marketing email sent through Waymail carries an
unsubscribe link and the standard List-Unsubscribe header, which lets
your mail app offer a one-click unsubscribe button. If the message was sent for a particular topic and you are one
of the sender's contacts, unsubscribing opts you out of that topic only. Otherwise it adds your address to the
sender's suppression list for marketing email — their receipts and account notices can still reach you.
Bounces and complaints. When a message to you hard-bounces, or you report it as spam, Waymail adds your address to that sender's suppression list so they do not email it again.
How long we keep it
| Data | Kept for |
|---|---|
| Message bodies and attachments | 7, 30, 60 or 90 days from when we received the message, as the workspace chooses (60 by default) — or only until it is sent, if the workspace keeps metadata only. A message scheduled to be sent later than that keeps its body until it has been sent or cancelled. A change applies to messages already stored as well as to new ones, though a message still waiting to be sent keeps its body at least until it has gone. Anything stored without a period is deleted after 120 days. |
| Delivery history — message records and their events | 30 days, 90 days or 13 months, depending on the workspace's plan, from when we received the message — or, for a message scheduled to be sent later, from the time it is scheduled for, so that it can be sent then. |
| Contacts and topic subscriptions | Until the customer deletes them. |
| Suppressions | For as long as the workspace exists, so that an unsubscribe or a complaint is never forgotten. The customer can remove an entry; removals are recorded in the audit log. |
| Webhook delivery attempts | 30 days. |
| Audit log | 400 days. |
| Operational logs | 90 days. They record each API request's endpoint, result, duration and workspace. They are built to leave out message content, recipient addresses and credentials, and error messages are scrubbed of email addresses before they are written. |
| Your console account | Until you delete it, subject to Clerk's own retention of security records. |
| Billing records | As long as Norwegian bookkeeping law requires — generally five years. |
| Correspondence with us | 24 months after the last message. |
Expiry is carried out by the storage itself, not by a job that could stop running: message bodies by Amazon S3 lifecycle rules, and records by DynamoDB's time-to-live. Both act within days of the date rather than to the minute, and a deleted message body is gone for good a further 7 days later. When a workspace changes its period, we move the bodies it has already stored onto the new one, usually within the hour, and the storage then deletes those already past it within days; when it chooses metadata only, we delete them outright, old versions and all. Our database keeps continuous backups for 35 days, used only to recover from a failure, so a deleted record remains in them until it ages out.
When a workspace is closed, we delete its data within 30 days, except where the law requires us to keep something.
Where the data is
For a workspace in the EU region, everything described under Email sent through Waymail — and the workspace's audit log — is stored and processed in Amazon Web Services' Frankfurt region (eu-central-1), and its email is sent through Amazon SES in the same region. A workspace's region is chosen when it is created and cannot change.
The website and the console's own files are served from CloudFront's global network. They are static files and contain no personal data.
Clerk and Cloudflare, which handle console sign-in and our own domain, are based in the United States. Both are certified under the EU–US Data Privacy Framework, which the European Commission recognises as giving adequate protection, and a transfer outside it relies on the Commission's Standard Contractual Clauses.
Subprocessors
| Company | What it does for us | Where |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, databases and email delivery (Amazon SES) | Frankfurt, Germany; website and console files worldwide through CloudFront |
| Clerk, Inc. | Console accounts and sign-in | United States |
| Cloudflare, Inc. | DNS for waymail.app; forwarding email sent to waymail.app addresses; Turnstile bot protection at sign-in | Global network |
| Zoho Corporation B.V. | Our own mailbox, for email sent to hello@waymail.app | EU |
Only Amazon Web Services processes our customers' email data. The others handle the console's sign-in, our own domain and our mailbox; none of them receives the messages our customers send, or the addresses they send them to. We announce changes to this list at least 30 days before they take effect.
Security
- Data is encrypted in transit with TLS, and at rest with encryption keys we manage in AWS Key Management Service.
- Message bodies are kept in private storage with all public access blocked, readable only by the services that need them.
- API keys are stored only as hashes. A key is shown once, when it is created, and cannot be retrieved afterwards.
- Webhook payloads are signed, so a receiver can verify that they came from Waymail and were not altered.
- Access to production systems is restricted to the people who operate them, and administrative actions are audited.
If a personal data breach affects data we process for a customer, we tell that customer without undue delay and within 48 hours of becoming aware of it, as the Data Processing Agreement sets out, so they can meet their own obligations. If one affecting data we control is likely to put your rights at high risk, we tell you directly.
Your rights
Under the GDPR you can ask for a copy of your personal data, and ask us to correct it, delete it, restrict how we use it, or give it to you in a portable form. You can object to processing based on our legitimate interests. Write to hello@waymail.app; we answer within a month. For data we process for one of our customers, we pass your request to them and help them answer it.
You can also complain to a data protection authority — Datatilsynet, the Norwegian Data Protection Authority, or the authority where you live or work.
Waymail is a service for businesses, and is not directed at children.
Changes and contact
When this policy changes, we update the date at the top. If a change is material, we tell customers by email at least 30 days before it takes effect.
Questions about this policy or your data: hello@waymail.app, or Gundhus AS, Hellvikskogsvei 93, 1459 Nesodden, Norway.