PineKeep
Join the beta

Data processing agreement

Article 28 DPA

Version 2026-09-26.2. The agreement becomes binding when you create an account or otherwise accept it. It supplements the terms.

Last updated 2026-09-26.

Parties

Controller: the organisation that creates the account and uses PineMail to send or receive email. Processor: PineCore Systems, a trading name of Bröderna Saxin AB, company registration number 559379-4364.

Subject and duration

The processor processes personal data in email messages and attachments, files, calendars and contacts, file shares and transfers (including recipients' addresses and access codes), metadata, domains, API keys, and delivery events to provide the service. Processing lasts while the account is active and then until the data is deleted.

Nature of processing

Collection, storage, forwarding via the email provider, display in the web app, in mail and calendar apps (IMAP, SMTP, CalDAV) and through the API, sharing files with the people the controller chooses, and deletion. Shares stop giving access at the end date the controller sets. Deletion happens on instruction, when a transfer's time runs out, and by the automatic rules in the terms: mail in the trash after 30 days, and unstarred, unpinned mail attachments older than 30 days when storage is full. Categories: identifiers, contact details, and the content the controller puts in. Data subjects: the controller's staff, customers, and other senders and recipients.

Instructions

The processor processes data only on the controller's documented instructions, given through use of the service, and by law. The processor informs the controller if an instruction conflicts with the GDPR.

No use for the processor's own purposes

The processor does not process the data for its own purposes. In particular, it does not use the data to train, test or improve AI or machine-learning models, does not use it for advertising or profiling, and does not sell it or make it available to anyone who would. Sub-processors may only process the data to provide their part of the service, under their own data processing agreements.

Security

The service and its database run on a dedicated server in Helsinki, Finland, which also holds the keys. Attachments, original messages and files, of PineMail and of PineKeep, are stored encrypted on a server the processor runs itself in Sweden, on mirrored disks with hourly and daily snapshots kept up to two weeks. Every six hours an encrypted backup (restic, AES-256) of the database is copied over an encrypted connection to that server, which can add backups but not change or delete them. Connections to the service use TLS, which ends on that server. Message text, original messages, attachments, files, transfers, the state of documents edited together and thumbnails are encrypted at rest with AES-256-GCM by the application. The search index holds keyed hashes of words, not the words. Subjects, addresses, dates, file names, calendars, contacts and other metadata are not encrypted at rest, so the service can sort, show and search them. The key is held by the application on the same server, apart from the database and the stored files; the server's disks are not encrypted as a whole. Mail is not end-to-end encrypted. Incoming mail is checked for spam and malware on the server; for this, the sending IP address and domain names in the message are looked up in public DNS blocklists, and nothing else leaves the server. Sign-in can be protected with an authenticator app. Administration requires a fresh security code and is logged. The security page describes this in full.

Sub-processors

The controller approves the sub-processors in the list. New sub-processors are announced there. Object to contact@pinemail.app.

International transfers

Stored data stays on the servers in Finland and Sweden, both in the EU. Outbound mail is relayed via Amazon SES in Stockholm, which processes message content in transit. Inbound mail is received directly by the Helsinki server. Cloudflare also answers DNS. Cloudflare, Inc. and Amazon Web Services are US-owned and can be subject to US law on access to data they process. Standard contractual clauses and the EU-US Data Privacy Framework apply.

Assistance, deletion, and audit

The processor assists with data-subject rights, impact assessments, and incident notification. Personal-data breaches are reported without undue delay, at the latest within 48 hours of awareness. After termination, data is deleted or returned on request except where law requires retention. Backups are at present kept without an end date, so data deleted in the service remains in the encrypted backups. The controller may request written information about the safeguards.

Liability

Swedish law. Ordinary courts. Contact: contact@pinemail.app.

TermsPrivacyPromisesSecurityDPASub-processorsCookiesAccessibilityPricingStatusAboutContact