Posteo
Posteo is an email service provider based in Berlin, Germany, offering paid email accounts for individuals and businesses.
Score
Citation
At no point in time do we voluntarily give personal data to third party companies or service contractors. All data is exclusively stored on our servers in Germany. Posteo is financed by our customers: There are no advertising partners or investors.
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
When you delete content data, it's deleted immediately. If the data has been backed up in one of our daily security backups, it will remain there for an additional 7 days until it is completely deleted.
In general, Posteo does not delete content data from an account as long as the contractual relationship is standing and has not been terminated by you or through Posteo in accordance with our terms and conditions.
[...]
Payment data cannot be deleted upon your request as it would conflict with legal requirement of retaining this information for 10 years for tax authorities.
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
At no point in time do we voluntarily give personal data to third party companies or service contractors. All data is exclusively stored on our servers in Germany. Posteo is financed by our customers: There are no advertising partners or investors.
Score
Notes
Posteo does not collect data that can be shared to law enforcement or connected to an individual.
Score
Citation
We always technically protect your content data with the latest security technologies (see our information page about encryption). In addition, content data is consistently saved on encrypted hard drives to protect them from physical access. We operate and maintain our own server infrastructure. All of our servers and stored data are located in Germany. We save all content data daily in a security backup and keep this data for a duration of 7 days. As a security precaution, please create an additional copy of your content data on a regular basis just in case you accidentally delete this data. Additionally, we offer the possibility to encrypt all emails, notes, contacts and calendar entries that are saved at Posteo individually with the password of the account (AES-encryption). You can do this in the settings of your mailbox at the touch of a button. Users of end-to-end encryption can add an additional level of encryption by applying inbound encryption to all incoming emails.
Notes
Additional information on how Posteo protects data at https://posteo.de/en/site/encryption. They were independently audited by Cure53 and other companies as noted on the aforementioned page.
Score
Citation
This privacy policy is currently valid and is applicable as of July 2019.
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
There is no way to easily provide a user with notice of a data breach except via the service
Score
Notes
There is no easy way to reach out to users' informing them of such an update (apart from through the service)
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Notes
No information proving such
Score
Citation
As a matter of principle, we do not collect and save any inventory data (such as names, addresses, etc.) from you. When registering, you do not enter any inventory data and we do not collect any other personally related data.
We effectively prevent data theft with this concept of data economy. The only data sets that cannot be stolen with 100 percent certainty are those that do not exist within a company. Futhermore, payment data is not connected to your account at Posteo. Because of this, in total, no inventory data exists for your account at Posteo. In other words, Posteo does not keep records with customer data or personally related data to your account.
In 2017, this was confirmed independently within an audit report by the German Federal Commissioner for Data Protection after an on-site inspection.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Citation
You can subscribe to Posteo's newsletter if you'd like by opting in within your account settings. You have the option to unsubscribe from the newsletter at any time.
Score
Citation
As a matter of principle, we do not collect and save any inventory data (such as names, addresses, etc.) from you. When registering, you do not enter any inventory data and we do not collect any other personally related data.
We effectively prevent data theft with this concept of data economy. The only data sets that cannot be stolen with 100 percent certainty are those that do not exist within a company. Futhermore, payment data is not connected to your account at Posteo. Because of this, in total, no inventory data exists for your account at Posteo. In other words, Posteo does not keep records with customer data or personally related data to your account.
Last Updated
June 24, 2020
Sources
Contributors