Skip to content

Privacy Policy

Last updated 15 September 2026

This policy explains what personal data Gundhus AS collects when you visit waymail.app, use the Waymail console or API, or write to us — and how Waymail handles the personal data of the people our customers send email to.

Who we are

Waymail is owned and operated by Gundhus AS, Hellvikskogsvei 93, 1459 Nesodden, Norway, organisation number 922 852 014 (“Gundhus AS”, “we”, “us”).

Our role depends on whose data it is.

If you received an email sent through Waymail, the organisation that sent it is the one to ask about your data. If you ask us instead, we will pass your request on to them and help them answer it.

The short version

Visiting waymail.app

The website and the documentation are static pages served by Amazon CloudFront. They set no cookies, run no analytics, and load no scripts, fonts or other content from third parties. CloudFront's access logging is not enabled, so we keep no record of your visit.

To deliver the pages and protect its network, Amazon processes your IP address and the details of each request transiently, as any web host must. The legal basis is our legitimate interest in running a website that works and is secure (GDPR Article 6(1)(f)).

Using the console

Signing in. Clerk provides the console's accounts and sign-in. It processes your name, email address and authentication details — a password, or the identity from a sign-in provider such as Google — along with information about your sessions and devices, including IP addresses, to keep your account secure. Clerk's bot protection uses Cloudflare Turnstile, which examines your browser to tell people from automated sign-ups.

Workspaces. For each workspace you belong to, we store your user ID, email address and role. An invitation to a workspace holds the invitee's email address until 30 days after the invitation expires.

Audit log. Administrative actions — creating or revoking an API key, adding a domain, changing members or settings, removing an address from the suppression list, and similar — are recorded with who took the action, when, and the IP address it came from. The log is kept for 400 days and is available to the workspace in the console, so a workspace can always establish what was done to it, and by whom.

Browser storage. The console keeps your region and selected workspace in your browser's session storage — and, if you sign in with an API key rather than an account, that key — all of which is cleared when you close the tab. Clerk sets cookies that keep you signed in. Both are strictly necessary for the console to work, and neither is used to track you.

The legal bases are providing the service you signed up for (Article 6(1)(b)) and our legitimate interest in keeping accounts and workspaces secure (Article 6(1)(f)).

Billing. For a workspace on a paid plan, we keep the billing contact's name and email address, the organisation's name, address and VAT or organisation number, and our invoices and payment records. Payments will be taken by a payment provider, which we add to the subprocessors below before anyone is charged. We count each workspace's emails per month to apply its plan; the count is a number, not a list of recipients. The legal bases are our contract (Article 6(1)(b)) and our obligations under bookkeeping law (Article 6(1)(c)).

Writing to us

Email sent to hello@waymail.app passes through Cloudflare Email Routing, which forwards it to our mailbox at Zoho Mail, in Zoho's EU data centres. We use your name, address and message to reply to you and to keep a record of the conversation, and keep it for 24 months after the last message — longer only if it becomes part of a customer relationship that needs it. The legal basis is our legitimate interest in answering you (Article 6(1)(f)), or steps you asked us to take before entering into a contract (Article 6(1)(b)).

Email sent through Waymail

When a customer sends email through Waymail, we process the following on their behalf.

Open and click tracking. To show a sender whether a message was opened, Waymail can add a tiny invisible image to it. Click tracking passes a click through Waymail on its way to the link so it can be counted. Both are off unless the customer switches them on for a sending domain, and a customer who does is responsible for any consent the law requires for them. For an open we record when it happened and the user-agent string of the mail client that fetched the image; for a click, the same and which link was followed. We do not record IP addresses for either. Mail apps that fetch images automatically — Apple Mail Privacy Protection, for one — register opens nobody made, so an open is a hint, not proof.

Unsubscribing. Marketing email sent through Waymail carries an unsubscribe link and the standard List-Unsubscribe header, which lets your mail app offer a one-click unsubscribe button. If the message was sent for a particular topic and you are one of the sender's contacts, unsubscribing opts you out of that topic only. Otherwise it adds your address to the sender's suppression list for marketing email — their receipts and account notices can still reach you.

Bounces and complaints. When a message to you hard-bounces, or you report it as spam, Waymail adds your address to that sender's suppression list so they do not email it again.

How long we keep it

Data Kept for
Message bodies and attachments 7, 30, 60 or 90 days from when we received the message, as the workspace chooses (60 by default) — or only until it is sent, if the workspace keeps metadata only. A message scheduled to be sent later than that keeps its body until it has been sent or cancelled. A change applies to messages already stored as well as to new ones, though a message still waiting to be sent keeps its body at least until it has gone. Anything stored without a period is deleted after 120 days.
Delivery history — message records and their events 30 days, 90 days or 13 months, depending on the workspace's plan, from when we received the message — or, for a message scheduled to be sent later, from the time it is scheduled for, so that it can be sent then.
Contacts and topic subscriptions Until the customer deletes them.
Suppressions For as long as the workspace exists, so that an unsubscribe or a complaint is never forgotten. The customer can remove an entry; removals are recorded in the audit log.
Webhook delivery attempts 30 days.
Audit log 400 days.
Operational logs 90 days. They record each API request's endpoint, result, duration and workspace. They are built to leave out message content, recipient addresses and credentials, and error messages are scrubbed of email addresses before they are written.
Your console account Until you delete it, subject to Clerk's own retention of security records.
Billing records As long as Norwegian bookkeeping law requires — generally five years.
Correspondence with us 24 months after the last message.

Expiry is carried out by the storage itself, not by a job that could stop running: message bodies by Amazon S3 lifecycle rules, and records by DynamoDB's time-to-live. Both act within days of the date rather than to the minute, and a deleted message body is gone for good a further 7 days later. When a workspace changes its period, we move the bodies it has already stored onto the new one, usually within the hour, and the storage then deletes those already past it within days; when it chooses metadata only, we delete them outright, old versions and all. Our database keeps continuous backups for 35 days, used only to recover from a failure, so a deleted record remains in them until it ages out.

When a workspace is closed, we delete its data within 30 days, except where the law requires us to keep something.

Where the data is

For a workspace in the EU region, everything described under Email sent through Waymail — and the workspace's audit log — is stored and processed in Amazon Web Services' Frankfurt region (eu-central-1), and its email is sent through Amazon SES in the same region. A workspace's region is chosen when it is created and cannot change.

The website and the console's own files are served from CloudFront's global network. They are static files and contain no personal data.

Clerk and Cloudflare, which handle console sign-in and our own domain, are based in the United States. Both are certified under the EU–US Data Privacy Framework, which the European Commission recognises as giving adequate protection, and a transfer outside it relies on the Commission's Standard Contractual Clauses.

Subprocessors

Company What it does for us Where
Amazon Web Services EMEA SARL Hosting, storage, databases and email delivery (Amazon SES) Frankfurt, Germany; website and console files worldwide through CloudFront
Clerk, Inc. Console accounts and sign-in United States
Cloudflare, Inc. DNS for waymail.app; forwarding email sent to waymail.app addresses; Turnstile bot protection at sign-in Global network
Zoho Corporation B.V. Our own mailbox, for email sent to hello@waymail.app EU

Only Amazon Web Services processes our customers' email data. The others handle the console's sign-in, our own domain and our mailbox; none of them receives the messages our customers send, or the addresses they send them to. We announce changes to this list at least 30 days before they take effect.

Security

If a personal data breach affects data we process for a customer, we tell that customer without undue delay and within 48 hours of becoming aware of it, as the Data Processing Agreement sets out, so they can meet their own obligations. If one affecting data we control is likely to put your rights at high risk, we tell you directly.

Your rights

Under the GDPR you can ask for a copy of your personal data, and ask us to correct it, delete it, restrict how we use it, or give it to you in a portable form. You can object to processing based on our legitimate interests. Write to hello@waymail.app; we answer within a month. For data we process for one of our customers, we pass your request to them and help them answer it.

You can also complain to a data protection authority — Datatilsynet, the Norwegian Data Protection Authority, or the authority where you live or work.

Waymail is a service for businesses, and is not directed at children.

Changes and contact

When this policy changes, we update the date at the top. If a change is material, we tell customers by email at least 30 days before it takes effect.

Questions about this policy or your data: hello@waymail.app, or Gundhus AS, Hellvikskogsvei 93, 1459 Nesodden, Norway.