This website today
The public website is already online. It is static and contains no JavaScript, cookies, tracking or advertising. Fonts, images and styles come from our own server; the browser does not load embedded third-party resources.
When a page is requested, the server processes the IP address and HTTP request to deliver it. Access logging is not enabled in Caddy. There are no website statistics, including aggregated visitor analytics. The website currently offers no registration or customer accounts.
System and security logs are kept for server operations. These may include IP addresses from failed administrator sign-ins. The system journal is limited to seven days. Provider-side logging and its retention periods have not yet been confirmed.
Responsible entity and contact
The entity responsible for this website is patchletter UG (haftungsbeschränkt), Meisterweg 16, 45896 Gelsenkirchen, Germany, represented by managing director Kolja Sagorski. For questions about data processing: legal@patchletter.com. General contact: hello@patchletter.com, telephone +49 209 73085753. Further operator details are in the imprint.
Contractual details of the hosting provider and DNS operator and their data locations still need to be completed. Legal review of the privacy policy is pending. Complete evidence of exclusively European data processing is therefore not yet available.
Concept for the planned mail service
The mail service has not launched. The following information is a draft of its data processing, not a description of accounts or features available today.
Our goal is to store only data necessary to provide the service, without advertising, tracking or profiling. Locations, providers and legal bases need to be confirmed and documented before launch.
| Data | Planned purpose | Planned retention |
|---|---|---|
| Mail, attachments, contacts, calendars | providing the service | until you delete; 30 days after cancellation |
| Account data | sign-in and contract | contract term plus 30 days |
| Login logs with IP address | security and abuse prevention | 7 days at most |
| SMTP logs without content | delivery and troubleshooting | 14 days at most |
| Abuse cases | spam and fraud prevention | 90 days at most |
| Invoices | statutory retention | applicable period still to be reviewed |
| Backups | recovery | 30 days rolling and encrypted; not yet set up |
Planned deletion and data rights
Access, export, correction and deletion through account settings are planned. These features are not yet publicly available.
The deletion concept is intended to remove access to encrypted data by removing the associated keys, then delete stored copies within the specified periods. The implementation, including backups, must be checked before launch. This does not promise an already working irreversible deletion process.