Data Processing Agreement
How the small amount of data we process is protected
1. Scope
Our applications are local-first: in normal app use, no personal data reaches us at all, so no data processing agreement is needed for using the apps themselves. The only personal data we process server-side relates to direct MoltenMail Pro purchases (license issuance and validation), as described in the Privacy Policy (“MoltenMail Pro Licensing & Payments”). This page summarises the processing terms that apply to that data.
2. Roles and Data
- •Controller: Goldcote Ltd (see the Imprint for company details).
- •Data processed: purchaser email address, payment confirmation reference, license key (stored only as a one-way hash), a random per-device identifier, and — only with opt-in consent — an email address for product updates.
- •Purpose and legal basis: performance of the license contract (GDPR art. 6(1)(b)); consent for optional marketing email (art. 6(1)(a)).
3. Subprocessors
We use the following subprocessors, each bound by a data processing agreement. Transfers outside Switzerland or the EU/EEA are covered by Standard Contractual Clauses or an equivalent adequacy safeguard.
- •Stripe — payment processing.
- •Cloudflare — hosting of the licensing service and its database (license records are held in a database hosted in the European Union); Cloudflare also provides this website's security layer (essential security cookies only).
- •Resend — delivery of the license-key email and any marketing email you opt into.
We will update this list before adding or replacing a subprocessor for license data.
4. Security and Retention
- •License keys are never stored in readable form — only as one-way hashes.
- •Email content, credentials, and app usage are never transmitted to us or to any subprocessor.
- •License records are retained while the license is active and for 24 months after it ends, then purged. Opt-in marketing addresses are kept until you unsubscribe, then suppressed.
- •Personal-data breaches are notified as described in the Privacy Policy (Swiss FADP art. 24; GDPR art. 33 — within 72 hours to the competent supervisory authority). Breach contact: moltenrock@moltenmail.com.
5. Your Instructions and Rights
We process license data only as needed to provide the service you purchased. You can request access, correction, deletion, or export of your data at any time — email moltenrock@moltenmail.com and we will respond within 30 days.
6. Countersigned Copy
Business customers who require a countersigned Data Processing Agreement for their records can request one at moltenrock@moltenmail.com.
Goldcote Ltd Software
Last Updated: July 2026