Privacy Policy
This Privacy Policy explains what personal data Adlerwacht collects, why, and how it is protected, for both the organizations that send attachments through our service and the recipients who register an account to view them.
Who is responsible for your data
QkSkima K.K. (QkSkima株式会社), headquartered in Fukuoka, Kitakyushu, Yahatanishi, Rikimarumachi 11-6-312, Japan, is the controller responsible for the personal data described in this policy.
EU representative (Art. 27 GDPR)
As a company established outside the European Union that processes personal data of individuals in the EU, we are required to designate a representative established in the EU. Colin Atkins serves as our EU representative for this purpose and can be reached at privacy@adlerwacht.com.
Data Protection Officer
Colin Atkins is our Data Protection Officer. You can reach him directly at privacy@adlerwacht.com with any question about this policy or your personal data.
What we collect
We collect only what is necessary to operate the service:
- Account identity: your email address and a device-bound passkey credential (WebAuthn) — we never collect or store a password.
- Attachment data: the recipient's email address, the sending organization's member email (where provided), the filename, file type, and the file content itself, for attachments routed to you through the service. We do not open, scan, or inspect the content of any attachment — see "How we store and protect attachment content" below.
- Relay routing data (organizations only): the destination SMTP host and port for your domain, used to route your outbound mail through our gateway. See "Your email credentials" below for how your email password is handled during that process — we never collect or store it.
- Billing data (organizations only): company name, billing address, VAT ID, and billing email, used to issue invoices.
- Technical data limited to what is strictly required to run the service (e.g. a session cookie to keep you signed in). We do not use analytics, advertising, or tracking cookies, and we do not log or store IP addresses except transiently, in memory, to check access to our administrative panel.
Your email credentials
To route your organization's outbound mail through our gateway, your email program authenticates using your own email address and your existing email account password — the same one you already use with your email provider. We store the destination SMTP host and port for your domain, since we need them to know where to route your mail, but we never collect or store your email password. Your gateway receives it only to authenticate and relay each individual send, forwards it straight through to your own mail server for that server to verify, and never logs or persists it. In GDPR terms, we act as one processor within that sending chain — never the custodian of your email password.
Why we process this data
We process this data to provide the service you or your organization requested: creating and securing your account, delivering attachments to their intended recipient, and invoicing the organization that contracted with us. Where you are a recipient, our legal basis is the performance of the contract between us and the sending organization, which necessarily involves you as the intended recipient. Where you are a sender, organization admin, or member, our legal basis is performance of our contract with you or your organization, and, for billing records, our legal obligation to maintain accounting records.
How long we keep it
We retain attachment files for as long as your organization's plan's retention period allows, then delete them automatically — the exact number of days depends on your plan and is shown on your billing page. We retain account and billing records for as long as your organization's account remains active, plus any period required by applicable bookkeeping or tax law. If your organization's account is cancelled, closed, or suspended for non-payment, see our Cancellation Policy for exactly when attachment files are deleted — deletion removes the file content itself; your organization record, member accounts, and audit history are retained even after that.
Where your data is stored
Each geographic deployment of our service (for example, our Germany-based deployment and, separately, a Japan-based deployment) runs on its own independent server with its own database and file storage. Data collected through one deployment is not copied, replicated, or shared with any other deployment. This means that, in practice, data submitted via a given deployment stays in that deployment's hosting region.
Sub-processors
We use three third-party service providers to operate the infrastructure the service runs on: netcup, for server hosting, SMTP2GO, for sending transactional emails (such as invitation links), and Sinch, for placing phone verification calls. We do not share your data with any advertising, analytics, or data-broker service, because we do not use any.
International data transfers
Because our company is based in Japan and our customers include both EU and Japan-based organizations, personal data may in some circumstances be accessed from Japan even where it is stored on an EU-based server (for example, by authorized personnel operating the service). Japan and the European Union are each recognized by the other as providing an adequate level of data protection under a mutual adequacy arrangement in place since 2019, which is the mechanism we rely on for such access, subject to Japan's supplementary rules for handling data originating in the EU. We will update this section once counsel has confirmed our specific arrangements meet those supplementary rules.
Your rights
Depending on where you are located, you may have some or all of the following rights over your personal data:
- Access — to obtain a copy of the personal data we hold about you.
- Rectification — to have inaccurate data corrected.
- Erasure — to have your data deleted, subject to any legal retention obligations.
- Restriction or objection — to limit or object to certain processing.
- Portability — to receive your data in a portable format, where applicable.
- Withdrawal of consent — where processing is based on consent, at any time, without affecting processing carried out before withdrawal.
- Complaint — to lodge a complaint with your local data protection authority (in the EU) or the Personal Information Protection Commission (in Japan).
How we protect your data
Our service is passwordless by design — there is no password database that can be stolen or guessed. Every account, whether a recipient, a sending organization's member, or a platform operator, authenticates using a device-bound WebAuthn passkey. Administrative access to the service is further restricted by network-level access controls. A full technical description of our security measures is maintained internally and available to customers or auditors on request.
In the event of a data breach
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, within the timeframes required by applicable law (72 hours under GDPR, without undue delay under Japan's APPI).
Children's privacy
Our service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as our service or legal obligations change. Material changes will be reflected in the version number shown at the top of this page; where a change materially affects how we use data you have already provided, we will take reasonable steps to notify you.
Contact us
For any question about this policy or to exercise your rights, contact us at privacy@adlerwacht.com.