Privacy Policy
Privacy and security are fundamental principles at Mxsec. This Privacy Policy details how we handle user data and ensure privacy by design across our services.
This privacy notice is in strict compliance with the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 of the European Parliament and of the Council.
Legal Entity & Infrastructure Jurisdiction
Mxsec is operated by Anders Yuran, located at Havouza 15, 4706 Pissouri, Cyprus. Company operations are subject to the laws of Cyprus and the European Union.
Our primary email server infrastructure is physically located in secure data centers in Germany. Consequently, all stored email data benefits from the strict digital privacy protections of both German law and EU-wide regulations.
Data Minimization & Registration
In accordance with Article 5(1)(c) of the GDPR (Data Minimization), we collect no personal identity information during account setup. We do not require, ask for, or store your name, physical address, phone number, or national ID.
No-IP-Logging Policy
By default, Mxsec operates a strict Zero-IP-Logging policy:
- We do not record, store, or monitor source IP addresses when you access your mailbox or send emails via SMTP, IMAP, or Webmail.
- Connection logs, authentication logs, and web server access logs do not write user IP addresses to disk.
- Outgoing email headers are stripped of originating IP addresses to protect sender privacy.
Cookies & Session Management
Mxsec.org uses only strictly technical, essential cookies required for basic web functionality and session state:
- Mxsec Session Cookie (JSESSIONID): A temporary, randomly generated identifier stored solely to maintain your webmail session during registration, login, and billing interaction. It contains no personal identifiers and expires when you close your browser.
Mail Processing, Spam Filter & Security
To protect our network integrity and keep inbox storage free from abusive content, incoming and outgoing unencrypted mail is scanned in-memory for viruses and malicious spam (using automated engines such as SpamAssassin/Rspamd). Content is processed transiently in memory and is never recorded to persistent logs.
If messages are PGP-encrypted prior to transmission, our systems cannot inspect message contents; automated processing in those cases is limited strictly to unencrypted RFC transport headers (such as message size, message ID, and date/time stamps).
Legal Process & Law Enforcement Assistance
Mxsec does not track or log user activity under normal operating conditions. However, as an EU-based service provider, Mxsec must comply with legally binding, valid court orders issued by competent judicial authorities in our legal jurisdiction.
In the event of a valid court order requiring targeted surveillance or real-time monitoring of a specific account, targeted logging may be enabled strictly for the designated account moving forward, as dictated by applicable legal procedures.
Privacy by Design
We protect your digital sovereignty. By stripping connection logs and removing personal identifier requirements, Mxsec provides an email environment where privacy is guaranteed by default.
