Skip to content

Your data and the GDPR

At Sooma, email is treated as what it is: private correspondence. Your data stays in the European Union, subject only to the GDPR and European law, and is never read or used for advertising.

Who is responsible for your data

It depends on the relationship:

  • If your mailbox belongs to the company you work for, the company is the data controller and Sooma is the processor (Art. 28 GDPR). Sooma stores and transmits messages, attachments, contacts and calendars on the company's behalf, following its instructions.
  • For customer account, billing and contact data, Sooma is the data controller.

Business customers can get a Data Processing Agreement (DPA), annexed to the service contract. Request it from dpo@sooma.com.

Where your data is kept

  • The servers are in NOS's data centre in Portugal.
  • Backups are kept in Berlin, Germany.
  • No personal data is transferred outside the European Union.

Sooma is a Portuguese company and is not covered by third-country extraterritorial access laws such as the US CLOUD Act. Any access to data is only possible under Portuguese law, with judicial oversight.

How it is protected

  • In transit: all communication (webmail, IMAP, SMTP) is encrypted with TLS, with no exceptions.
  • At rest: messages are stored encrypted (AES-256) on the servers.
  • Redundancy: the infrastructure is redundant and backed up regularly, so a failure does not mean data loss.
  • Staff access: limited to the minimum necessary, with dedicated authentication and a log of who accesses what. The team is in Europe.

Sooma is implementing ISO/IEC 27001 and aligning with the NIS2 Directive. Current certifications are listed in Certifications.

You can also protect your account: see Change and recover your password and Recognise phishing and fraud.

What we don't do

Messages are not read, indexed or used to build advertising profiles. Mailbox content is not analysed for commercial, advertising or profiling purposes.

How long we keep data

Data Period
Mailbox content deleted 60 days after the service ends
Technical logs 14 days
Account, billing and contact data for the duration of the contract and up to 10 years after it ends (legal and tax obligations)
Registered Email certificates 10 years

Before ending the service, keep what you need: see Take your data with you.

Requests from authorities

Data is only provided when a request is legally valid and formally correct: Sooma checks the requesting entity's competence, the legal basis, judicial authorisation and proportionality. No data is handed to third-country authorities on the basis of direct requests, and there is no mechanism for permanent or automated access by authorities.

Sooma publishes an annual Transparency Report. Between 1 January and 31 August 2026 it received zero requests from authorities.

Your rights

The GDPR gives you the right of access, rectification, erasure, restriction, portability and objection regarding your data.

  • Data in your company mailbox: since the company is the controller, send your request first to your company's administrator or data protection officer. Sooma helps the company respond.
  • Account and billing data, or questions about Sooma's processing: write to dpo@sooma.com. We reply within 30 days at most.

If you believe your rights have not been respected, you can lodge a complaint with the supervisory authority. In Portugal this is the Comissão Nacional de Proteção de Dados (cnpd.pt).

Take your data with you

Your data is yours and uses open formats, so you can take it wherever you want:

  • Contacts: export as vCard (.vcf). See Import and export.
  • Calendars: export as iCalendar (.ics), from the same article.
  • Messages: any IMAP application (Outlook, Thunderbird, Apple Mail) downloads the full mailbox. In Outlook you can save everything to a file: see Back up with Outlook. In webmail you can also save a message as an .eml file. To export whole mailboxes or many accounts, contact support.

Learn more