Effective 10 May 2026
AtPigeon hosts email on your domain. We see what we have to in order to deliver and store mail — and nothing else. This page explains what personal data we collect, why, who processes it on our behalf, and the rights you have under the GDPR.
The data controller is AtPigeon BV, Keizersgracht 421-A, 1016 GC Amsterdam, the Netherlands. You can contact us at [email protected] for any privacy question or to exercise the rights below.
When we host mailboxes for an organisation, that organisation is the controller of the message content; AtPigeon acts as a processor for them. When you sign up directly as an individual, we are the controller. The DPA we offer to organisation customers is available on request.
.eml files plus PostgreSQL metadata. We do not read this content; we store it so you can.We do not sell your data. We do not run advertising. We do not profile you for marketing.
We rely on a small number of vendors to run the service. They process data on our behalf, under contract:
An up-to-date sub-processor list is available on request. We notify customers of new sub-processors at least 30 days before they go live.
Mail bodies, metadata and account data are stored in the European Union. Some operational tooling (logs, error reports, payment processing) may transfer personal data outside the EU; in those cases we rely on the EU Standard Contractual Clauses or an equivalent safeguard.
Under the GDPR, you can ask us to:
Email [email protected] and we’ll respond within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your EU country of residence.
We encrypt data in transit (TLS 1.2+, MTA-STS, DANE where the recipient supports it) and at rest (AES-256 on storage volumes, with per-mailbox keys for server-side encryption). Passwords are hashed with bcrypt. We run least-privilege access for staff and audit privileged actions. See the Security page for more.
On the public marketing site we set no third-party tracking cookies. Inside the apps we set strictly necessary cookies for authentication and CSRF protection only. We don’t use Google Analytics or similar trackers.
AtPigeon is not directed at children under 16. If you believe a child has signed up, contact us and we will delete the account.
We will post any update with a new effective date. For material changes we’ll email account owners at least 30 days before the change takes effect.
Privacy questions: [email protected]. Postal: AtPigeon BV, Keizersgracht 421-A, 1016 GC Amsterdam, the Netherlands.