1. General Provisions
1.1. This Privacy Policy defines the procedure for processing, storing, using, and protecting the information of users of the SmakMail service.
1.2. The Policy applies to all information that the service receives about the user when using the service, placing orders, using email addresses, interacting with support, and otherwise using the service functionality.
1.3. By using the service, the user confirms that they have read this Privacy Policy and agree to its terms.
1.4. If the user does not agree with the terms of this Privacy Policy, they must stop using the service.
2. Administration Contact Information
2.1. For questions regarding data processing, confidentiality, data deletion, claims, and requests, the user may contact the service administration:
Email: smakprojectsup@gmail.com
Telegram: @cmak_lolz
3. What Data Is Processed
3.1. The service may process the following user data:
- Telegram ID, username, name, and other data transmitted by Telegram
- email addresses issued to the user
- data required for access to mailboxes
- information about orders, payments, refunds, and support requests
- technical data about the user's actions in the service
- IP addresses, connection information, operation times, service journals, and logs
- the content of incoming messages
- message metadata, including sender, recipient, subject, date, time of receipt, technical headers, and other related information
3.2. The service does not process data that is not needed for the operation of the service, except where such processing is necessary for security, review of requests, compliance with legal obligations, or resolution of disputes.
4. Purposes of Data Processing
4.1. User data is processed for the following purposes:
- registration and identification of the user
- provision of email addresses and related functionality
- receipt, transmission, storage, and display of incoming messages
- processing of orders, payments, refunds, and support requests
- protection of the service against abuse, attacks, bypass of restrictions, and other violations
- maintaining technical logs and internal records
- compliance with applicable legal requirements
- dispute resolution and review of user claims
5. Where Data Is Located and How It Is Processed
5.1. The primary storage of user data is carried out on a server located in the Russian Federation.
5.2. The server that stores the service data is located in the Russian Federation.
5.3. A technical server located in the Netherlands is used to receive incoming messages.
5.4. The server in the Netherlands performs the following functions:
- the public IP of the service
- MX
- SMTP edge
- TCP/TLS proxy for IMAP
- WireGuard/IPsec tunnel to the server in Moscow
- Postfix technical queue only for the duration of delivery
5.5. The server in the Netherlands is used as a technical node for receiving and transit delivery of messages into infrastructure in the Russian Federation.
5.6. The primary storage of user data and messages is carried out in the Russian Federation.
5.7. Data backups are stored on a separate server located in the Russian Federation.
6. Cross-Border Data Transfer
6.1. The user is informed and agrees that, during the receipt and delivery of messages, part of the data may be temporarily transmitted through a server located in the Netherlands.
6.2. Such transfer is technical and transit in nature and is used for message reception, stable delivery, and increased trust from external services.
6.3. The primary storage of user data and messages is carried out in the Russian Federation.
6.4. Cross-border transfer of personal data is regulated by Article 12 of Federal Law No. 152-FZ. Before such transfer begins, the operator must take into account the legal requirements for cross-border transfer of personal data.
7. Data Retention Periods
7.1. Message content is stored for at least 185 days from the moment of receipt.
7.2. Message metadata and other related technical information are stored for up to 3 years.
7.3. By decision of the administration, certain data may be stored longer if necessary for service security, dispute resolution, investigation of violations, or compliance with legal requirements.
7.4. After the retention periods expire, data may be deleted, anonymized, or archived to the extent permitted by the internal rules of the service and applicable law.
8. Grounds for Data Processing
8.1. User data is processed on the following grounds:
- user consent expressed through the start of service use
- necessity to perform the User Agreement and provide the functionality of the service
- necessity to fulfill obligations established by law
- the legitimate interest of the service administration in protecting infrastructure, preventing abuse, resolving disputes, and ensuring the stable operation of the service
9. Transfer of Data to Third Parties
9.1. The service does not sell users' personal data to third parties.
9.2. Access to data may be provided only to the extent necessary for:
- the technical operation of the service
- payment and refund processing
- review of user requests
- ensuring security
- compliance with legal requirements
9.3. Data may be transferred to third parties only in the following cases:
- if required by law or by a mandatory request of an authorized authority
- if necessary for payments, refunds, or technical support of the service
- if the user has personally given consent
- if the transfer is necessary to protect the rights, security, and legitimate interests of the service
10. Data Protection
10.1. The service takes reasonable technical and organizational measures to protect user data from unauthorized access, destruction, modification, blocking, copying, distribution, and other unlawful actions.
10.2. The following may be used to protect data:
- secure communication channels
- access rights separation
- system logs and action auditing
- backups
- server-side and network protection measures
- other information security measures
10.3. The law requires the operator to take measures, including those provided for by Articles 18.1 and 19 of Federal Law No. 152-FZ.
10.4. Despite the measures taken, no data transmission and storage system can guarantee absolute protection against all possible threats.
11. Violation Review and Administrative Access to Data
11.1. In case of suspicion of a violation of the service rules, abuse, fraud, malicious activity, hacking attempts, bypass of restrictions, or other actions that create a threat to the service, users, or third parties, the administration has the right to conduct an internal review.
11.2. As part of such a review, the administration has the right to analyze:
- technical logs
- message metadata
- information about mailboxes
- data about orders, payments, and connections
- other information necessary to establish the circumstances of the violation
11.3. If necessary for investigating violations, protecting the service, users, or the legitimate interests of the administration, the administration has the right to access message content.
12. User Rights
12.1. The user has the right to contact support regarding the processing of their data.
12.2. The user has the right to request information about the processing of their personal data, as well as its clarification, updating, blocking, or deletion, if this does not contradict the requirements of the law, mandatory retention periods, the security interests of the service, or the need to resolve disputes. The data subject's right to obtain information about the processing of their data is provided by Article 14 of Federal Law No. 152-FZ.
12.3. The user has the right to stop using the service at any time.
12.4. The user understands and accepts that deletion of certain data may be impossible until mandatory retention periods expire.
13. Use of the Mail Service
13.1. The service provides email addresses only for receiving incoming messages.
13.2. The user is informed that messages received through the service are stored and processed within the service infrastructure in accordance with this Privacy Policy.
13.3. The user understands that, in order to ensure delivery and increase trust from external services, message receipt is carried out through a technical node in the Netherlands, followed by transfer of data to the Russian Federation.
14. Cookies and similar technologies
14.1. SmakMail uses cookies, localStorage, and sessionStorage for the operation of the website, cabinet, webmail, security, saving the interface language, user sessions, partner attribution, and storing selected cookie settings.
14.2. Necessary cookies include technical cookies, without which certain functions of the service cannot work correctly: language selection, login to the cabinet, login to the webmail, administrative session, request security and saving the user session. Such cookies are used only to provide the functions requested by the user.
14.3. SmakMail may also use affiliate cookies, for example, to save clicks on an affiliate link and correctly account for affiliate remuneration.
14.4. Analytical cookies and similar technologies are used only after the user's consent. SmakMail can use Yandex Metrica for analytics. Analytics helps you evaluate traffic, traffic sources, page performance, and improve your service. The user can opt out of analytics and use only the necessary cookies.
14.5. Consent to the analysis is stored in the user's browser. The user can change the selection on the Cookie Policy page or clear the site data in the browser settings.
15. Policy Change
15.1. The Service has the right to change this Privacy Policy without notifying users individually.
15.2. The new edition of the Privacy Policy comes into force from the moment of its publication, unless otherwise specified in the edition itself.
16. Final provisions
16.1. When starting to use the service, the User confirms that he has read this Privacy Policy and agrees with it.
16.2. In everything that is not regulated by this Privacy Policy, the service is guided by the applicable legal norms and internal rules of the service.
16.3. The operator collecting personal data via the Internet is obliged to provide access to the personal data processing policy. This directly follows from Article 18.1 of Federal Law No. 152-FZ.