Test mode — no real letters are sent and no real money is charged.
Skip to content
Print and Mail Company

Privacy Policy

Last updated: 6 October 2026

In short: LeFaLux vGmbH in Luxembourg runs Print and Mail Company and is responsible for the personal data described in this policy.

  • We use your data to run your account, print and post your letters, take payments and meet our legal obligations. We don't sell data, build advertising profiles or train AI on your documents.
  • We process the content of your letters only to print them. Uploaded PDFs and print files are deleted automatically 30 days after the letter is posted.
  • Our data is stored in the EU. Where a provider is based outside the EU, legal safeguards apply.
  • For business customers, we handle recipient data and letter content as a processor under our Data Processing Agreement.
  • You can access, correct or delete your data and use your other rights by writing to privacy@printandmailcompany.com. You can also complain to the Luxembourg data protection authority (CNPD).

1. Who is responsible and how to contact us

Print and Mail Company (printandmailcompany.com) is operated by LeFaLux vGmbH, 40 rue du Travail, L-2625 Beggen, Luxembourg, registered with the Luxembourg Trade and Companies Register (RCS) under number B298899, VAT number LU36784104 ("we", "us", "our").

We are the controller of the personal data described in this policy, except where section 5 explains that we act on behalf of a business customer.

For privacy questions and to exercise your rights, write to privacy@printandmailcompany.com or send a letter to the address above. For all other questions, contact support@printandmailcompany.com.

This policy is based on the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Luxembourg Act of 1 August 2018 on the organisation of the National Data Protection Commission and the general data protection framework, and the Luxembourg rules on privacy in electronic communications. It covers our website, customer accounts, our REST API and our MCP server for AI assistants. Our Terms of Service and Cookie Policy complement it. Our company details are also listed in the Imprint.

2. Overview

The table summarises what we process, why, on which legal basis and for how long. Sections 3 to 10 explain the details.

Data Purpose Legal basis Retention
Account data (name, email address, password hash, language, currency, settings) Running your account, sign-in, service emails, support Contract (Art. 6(1)(b)) Until you delete your account
Recipient and return addresses, letter details (options, status, dates, tracking number) Printing the envelope, posting the letter, status updates, support and claims Contract (Art. 6(1)(b)); legitimate interests for recipients (Art. 6(1)(f)); as processor for business customers 12 months after posting, then deleted or anonymised
Letter content (uploaded PDFs, composed letters, print files) Checking, printing and posting your letter Contract (Art. 6(1)(b)); as processor for business customers Deleted automatically 30 days after posting, or 30 days after upload if never sent
Payment data (amount, card brand, issuing country, card type, last four digits) Payments, card surcharge, receipts, refunds Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) 10 years
Invoices and credit records Invoicing, VAT and accounting Legal obligation (Art. 6(1)(c)) 10 years
Communications with us Answering requests, complaints and reports Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) Up to 3 years after the matter is closed
Technical logs and session data (IP address, browser information) Security, operation, troubleshooting, abuse prevention Legitimate interests (Art. 6(1)(f)) Logs: 30 days. Sessions: until you sign out or the session expires
Cookies Necessary website functions; optional cookies only with your consent Legitimate interests (Art. 6(1)(f)); consent (Art. 6(1)(a)) See our Cookie Policy
AI assistant, OAuth and API connections Letting assistants and software you authorise act for you Contract (Art. 6(1)(b)) Until you revoke access or delete your account
Newsletter (optional) News about our service Consent (Art. 6(1)(a)) Until you unsubscribe
Records of consent Proving your choices Legal obligation (Art. 6(1)(c) with Art. 7(1)) As long as the consent applies, plus 3 years
Fraud and abuse records Preventing misuse, protecting recipients, legal claims Legitimate interests (Art. 6(1)(f)) As long as needed, normally up to 3 years after the case is closed

3. The data we process

3.1 Account data

When you create an account, we process your name, email address, password, preferred language, account currency and your choice about our newsletter. We store your password only as a salted hash, so we cannot read it. We also record when you created your account, whether your email address is verified and the status of your account.

If you sign in with Google, Google sends us your name, email address, Google account identifier and profile picture (if you have one), together with the sign-in tokens Google issues. We never receive your Google password. If you sign in with a magic link, we email you a one-time link that expires after a short time.

3.2 Sender and recipient addresses

For each letter we process the recipient's name, company name (if given) and postal address exactly as you enter them, and the return address. If you don't provide your own return address, we print our company address instead. Addresses you save in your address book stay there until you delete them.

We print the recipient's address directly on the envelope. You provide these details; we don't obtain addresses from other sources.

3.3 Letter content

Letter content means the PDF you upload or the text an AI assistant sends us through our compose tool, and the print-ready files we generate from it (the letter pages and the envelope print file). We also store the file name, file size, page count, the results of our automatic format check and the options you choose, such as colour, double-sided printing, envelope size and registered mail.

Our automatic check looks only at technical properties: page size, margins, page count and colour. It does not analyse the meaning of your text.

Letters can contain personal data about you, the recipient or other people, sometimes including sensitive information such as health or financial details. We don't need to know what your letter says, and we handle its content only as described in section 7.

3.4 Payment data

Card payments are processed by Stripe. You enter your card details in Stripe's payment form, and we never see or store your full card number or security code. From Stripe we receive and store a payment reference, a customer reference linked to your account, the amount, currency and status of the payment, and these card details: brand (for example Visa), issuing country, card type (credit, debit or prepaid) and the last four digits.

We use the issuing country, brand and card type to determine whether a card surcharge applies (see our Terms of Service). We use the brand and last four digits so you can recognise the payment on receipts. We also keep a record of your prepaid credit: top-ups, letters paid from credit, refunds, fees and any currency conversion rate applied.

3.5 Invoices and accounting records

For every payment and letter we issue an invoice or receipt. It shows the invoice number and date, your name and email address, the letter reference, the items charged (for example envelope, printing, postage zone and registered mail), VAT and the totals. Invoices do not contain the recipient's name or address.

3.6 Communications

When you contact us, we process your message, your contact details, any attachments and our reply. This also applies to reports of abuse or illegal content (see our Acceptable Use Policy) and to messages from people who received a letter sent through our service.

We send you service emails, for example sign-in links, payment confirmations and updates when a letter is paid, printed, posted, cancelled or returned. Status emails include the letter reference, the recipient's name and country and, for registered letters, the tracking number. We don't track whether you open our emails or click on links in them.

3.7 Technical data and logs

When you visit our website or use our API or MCP server, our hosting provider and our application process technical data: IP address, date and time, the address (URL) requested, the result of the request, browser and device information (user agent) and error details. We use this data to deliver the service, keep it secure, prevent abuse (for example by limiting the number of requests) and fix errors.

When you sign in, we store your IP address and user agent with your session. This lets us keep you signed in and detect unusual activity. We also keep a log of important actions in accounts, such as changes to a letter's status, refunds and actions taken by our staff, so that we can trace what happened.

3.8 Cookies

We only use cookies that are strictly necessary for our website, sign-in and payments. We will only use optional cookies, such as analytics cookies, with your consent, and at the moment we don't use any. Details are in our Cookie Policy.

3.9 AI assistants, OAuth and API connections

You can let an AI assistant or your own software use our service through our MCP server or REST API.

When you connect an AI assistant, it signs in with OAuth and you approve its access on a consent screen. We then store the connection: the assistant's registration details as provided by its software (for example its name, website and redirect addresses), the permissions you granted, when you granted them, and the access and refresh tokens. Access tokens expire after a short time.

If you create an API key, we store its name, its first characters (so you can recognise it), when it was created and last used, and usage counters. We store the key itself only in hashed form.

Everything an assistant does through our tools, such as price quotes, drafts, uploads and letters sent, is recorded in your account like any other activity. An AI assistant can only send a letter after you have explicitly confirmed it, and it can only pay with your prepaid credit.

Some tools work without signing in: price quotes, the list of destinations and the margin check. For these we process only what is needed to answer the request, such as the destination and page count or, for the margin check, the file submitted, which we use only to return the result.

Your AI provider is not our processor. The company that operates your AI assistant receives everything you share in the conversation and everything our tools return to it, for example prices, letter status or an address you entered. It processes this data as its own controller under its own privacy policy. We only receive what the assistant sends to our tools.

4. Why we process your data and on which legal basis

To perform our contract with you (Art. 6(1)(b) GDPR). We process your data to create and manage your account, provide price quotes and drafts, check, print, envelope and post your letters, keep you informed about their status, manage your prepaid credit and payments, handle cancellations and refunds, provide support and carry out the instructions you give through an AI assistant or our API. This includes steps you ask us to take before concluding a contract, such as a price quote.

To comply with legal obligations (Art. 6(1)(c) GDPR). We keep invoices and accounting records as required by Luxembourg commercial, accounting and VAT law. We also respond to lawful requests from courts and authorities, handle requests from people exercising their data protection rights, keep proof of consent and meet our obligations under the EU Digital Services Act when we deal with reports of illegal content.

For our legitimate interests (Art. 6(1)(f) GDPR). We rely on legitimate interests where processing is necessary for the following purposes and your interests and rights do not override them:

  • keeping our systems, accounts and payments secure;
  • preventing and investigating fraud, payment abuse and misuse of our service, for example to send threatening or deceptive letters;
  • enforcing our Terms of Service and Acceptable Use Policy;
  • establishing, exercising or defending legal claims;
  • delivering letters for customers who use our service privately. In that case we process the recipient's data in our interest and the customer's interest in having the letter delivered as requested (see section 5);
  • running the service reliably, for example by analysing error logs.

You can object to processing based on legitimate interests at any time (see section 13).

With your consent (Art. 6(1)(a) GDPR). We ask for your consent before using optional cookies and before sending you our newsletter. You can withdraw your consent at any time with effect for the future, through "Cookie settings" in the footer of our website or the unsubscribe link in every newsletter.

We don't use personal data for purposes other than those described in this policy. If we plan to use data for a new purpose that is compatible with the original one, we will inform you beforehand.

5. Our role for recipient data and letter content

Who is responsible for recipient data and letter content depends on how you use our service.

Business customers. If you use our service for your trade, business, craft or profession, or on behalf of a company, association, public body or other organisation, you decide which letters are sent, to whom and why. You are then the controller of the recipient data and the letter content, and we act as your processor. We process this data only on your instructions and under our Data Processing Agreement, which applies automatically and forms part of our contract with you. You are responsible for having a legal basis for your letters and for informing the people you write to.

Private customers. If you send letters as a private individual for purely personal or household purposes, for example to your landlord, insurer, gym or family, the GDPR does not apply to your own activity, but it does apply to us. We are then responsible for the way we process the recipient data and the letter content. We process them only as far as necessary to provide the service you asked for: printing, enveloping and posting the letter, showing you its status, supporting you and handling claims. We don't use them for any other purpose, apart from the limited purposes in the next paragraph.

Purposes for which we are always responsible. Whatever kind of customer you are, we act as an independent controller where we need to process limited letter data for our own legal obligations or legitimate interests: invoicing and accounting (invoices show the letter reference and postage zone, but not the recipient's name or address), responding to lawful requests from authorities, handling reports of abuse or illegal content, and establishing, exercising or defending legal claims.

6. Information for letter recipients and other people named in letters

If you received a letter that we printed and posted, or if you are mentioned in one, this section explains how we handle your data.

  • Why you received the letter. One of our customers asked us to print and post it. We don't write letters, choose recipients or check what letters say. If our address appears as the return address, the sender chose not to add their own; it does not mean that we wrote the letter.
  • What data we have. Your name and postal address as entered by the sender, the letter content, the date and status of the letter and, for registered letters, the tracking number and delivery status.
  • Where the data comes from. The sender, who is our customer, gave it to us.
  • Purpose and legal basis. We use your data only to print, envelope and post the letter, to show the sender its status and to handle support and claims. For business senders we act as their processor; the sender is responsible for the letter and you can exercise your rights with them. For private senders we rely on our legitimate interest and the sender's legitimate interest in having the letter delivered (Art. 6(1)(f) GDPR).
  • Delivery. POST Luxembourg and, for letters abroad, the postal operator in your country deliver the letter as independent controllers. For registered letters this includes recording your signature on delivery.
  • How long we keep it. The letter content is deleted 30 days after posting. Your name and address are deleted or anonymised 12 months after posting (see section 10).
  • Your rights. You have the rights described in section 13. Write to privacy@printandmailcompany.com. If the sender is a business customer, we will pass your request on to them and help them answer it.
  • Reporting a letter. If you believe a letter you received is illegal, threatening or fraudulent, please report it to support@printandmailcompany.com as described in our Acceptable Use Policy.

7. Confidentiality of letter content

We treat every letter as confidential.

  • We process letter content only to check its format, print it, put it in an envelope and post it.
  • Our production staff handle printed pages physically: they print, fold and insert them, and check print quality and that the right pages go into the right envelope. They are bound by confidentiality obligations and do not read letters beyond what these tasks technically require.
  • We don't use letter content for profiling, advertising or any other purpose of our own, we don't sell it and we don't use it to train AI models. Our service providers may only process it on our instructions.
  • We look at a specific letter more closely only if you ask us to (for example for support), if we receive a report about it or have concrete indications of illegal use (see our Acceptable Use Policy), or if the law requires it.
  • Misprints and spoiled pages are shredded. If POST Luxembourg returns a letter to us as undeliverable, we identify it by the small reference code printed on the envelope without opening it, inform you by email and securely destroy the letter after 30 days.

8. Who receives your data

Within our company, only the people who need it for their tasks (for example production, support or accounting) can access personal data. We share data with others only where necessary for the purposes described in this policy. We don't sell personal data.

Service providers acting on our behalf (processors). These providers process personal data only on our instructions and under data processing agreements:

Provider Service Where the data is stored
Vercel Inc. (USA) Hosting of our website, application, API and MCP server EU (Frankfurt, Germany); some content and requests are handled by Vercel's global network
Neon Inc. (USA) Database EU
Cloudflare, Inc. (USA) Storage of uploaded PDFs and print files (Cloudflare R2) EU (R2 EU jurisdiction)
Resend (USA) Sending service emails USA or EU, depending on the sending region
Stripe Payments Europe, Limited (Ireland) Processing card payments EU and other Stripe locations

Independent controllers. These recipients process data for their own purposes and under their own privacy policies:

  • POST Luxembourg (Entreprise des Postes et Télécommunications) receives the sealed letter with the recipient's address and the return address printed on the envelope, and delivers it. For registered letters it also processes the tracking number and the delivery confirmation, including the recipient's signature. POST Luxembourg handles the sealed envelope and does not receive the content of your letter in any other form. For letters to other countries, POST Luxembourg passes the letter to the postal operator of the destination country.
  • Stripe also acts as an independent controller for its own purposes, such as fraud prevention and compliance with financial regulations.
  • Google (Google Ireland Limited for users in the EEA and Switzerland), only if you choose to sign in with Google.
  • The provider of your AI assistant, if you connect one (see section 3.9).
  • Authorities, courts and professional advisers, where the law requires us to disclose data or where this is necessary to establish, exercise or defend legal claims. Examples are tax authorities, police or courts acting under a legal order, and our lawyers, accountants and auditors, who are bound by professional secrecy.

9. Transfers outside the EU and EEA

We store your data in the EU. Some of our providers are based in the USA or belong to groups with offices outside the EU. They may access or process data outside the EU, for example for support, security monitoring, email delivery or delivering web content through a global network.

When personal data is transferred to a country for which the European Commission has not issued an adequacy decision, we rely on appropriate safeguards:

  • the EU–US Data Privacy Framework, for US companies certified under it (European Commission adequacy decision of 10 July 2023); or
  • the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with additional measures where needed.

You can ask for more information or a copy of the relevant safeguards at privacy@printandmailcompany.com.

Letters to other countries. We hand every letter to POST Luxembourg in Luxembourg. For letters to other countries, POST Luxembourg forwards them to the postal operator of the destination country as part of the international postal service, and that operator delivers them under its own rules.

10. How long we keep your data

We keep personal data only as long as we need it for the purposes described in this policy, and then delete or anonymise it.

  • Uploaded PDFs, composed letters and print files: deleted automatically 30 days after the letter was posted, or 30 days after upload if the letter is never sent (for example because you cancelled it or did not complete it). Please keep your own copy of every letter you send.
  • Letter details (recipient's name and address, return address, options, status, dates, tracking number): kept for 12 months after posting or cancellation to handle questions and claims. We then delete or anonymise the recipient's name and address and keep only what our accounting records need, such as the letter reference, date, postage zone and price.
  • Account data and address book: until you delete your account. Saved addresses: until you delete them.
  • Payment records, credit transactions and invoices: 10 years from the end of the financial year in which they were created, as required by Luxembourg accounting and VAT law (including Article 16 of the Commercial Code). This also applies after you delete your account.
  • Communications with us: up to 3 years after your request has been dealt with.
  • Reports of abuse or illegal content and related evidence: as long as needed to handle the case, normally no longer than 3 years after it is closed, and longer while legal proceedings are pending.
  • Server logs: 30 days.
  • Session data: until you sign out or the session expires after 30 days without activity.
  • AI assistant and API connections: until you revoke them or delete your account. Access tokens expire automatically after a short time.
  • Newsletter: until you unsubscribe. We then keep your email address on a suppression list so that we don't email you again.
  • Records of consent (cookie choices and newsletter consent): as long as the consent applies and for 3 years afterwards, so that we can prove it.
  • Closed accounts after fraud or abuse: we may keep the minimum data needed to prevent the person from registering again, such as the email address and the reason for closure, for up to 3 years.

We may keep specific data longer if the law requires it or if we need it to establish, exercise or defend legal claims, for example while an investigation, dispute or request from an authority is ongoing. In that case we use the data only for that purpose.

Deleted data may remain in encrypted backups for a limited time until it is overwritten in the normal backup cycle, normally within 30 days.

11. How we protect your data

We use technical and organisational measures appropriate to the risk, including:

  • encryption in transit (TLS) for all connections to our website, API and MCP server;
  • encryption at rest by our hosting, database and storage providers;
  • access control based on the principle of least privilege: only authorised people who need personal data for their work can access it;
  • passwords and API keys stored only in hashed form;
  • logging of security-relevant events and staff actions, and limits on the number of requests to protect against attacks;
  • automatic deletion of letter files after 30 days;
  • a secure production area with restricted physical access, confidential handling of printed letters and shredding of misprints;
  • confidentiality obligations for everyone who works for us.

No system is completely secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the CNPD and, where required, inform you, as the GDPR requires.

12. Automated decisions and profiling

We don't make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR), and we don't use your data for profiling.

Some steps in our service are automated, but they are not decisions of that kind:

  • Card surcharge. Whether a surcharge applies is calculated by fixed rules based on the card's issuing country, brand and type. It is a price component shown to you before you pay, not a decision about you as a person, and you can choose another payment method.
  • Format check. Our automatic PDF check only verifies technical requirements such as margins and page size.
  • Security limits. Automatic limits on the number of requests protect our systems.

Decisions to refuse a letter or to suspend or close an account are made by a person. Stripe may automatically decline a payment that it considers fraudulent; Stripe makes that decision as its own controller. If a payment is declined, contact us and we will help where we can.

13. Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy of it (Art. 15);
  • rectification of inaccurate or incomplete data (Art. 16);
  • erasure of your data, unless we must keep it, for example for accounting (Art. 17);
  • restriction of processing, for example while we check whether your data is accurate (Art. 18);
  • data portability, meaning you can receive the data you gave us in a structured, commonly used and machine-readable format or have it sent to another provider, where we process it by automated means on the basis of your consent or our contract (Art. 20);
  • object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 21). We will then stop, unless we have compelling legitimate grounds or need the data for legal claims. You can object to direct marketing at any time without giving reasons;
  • withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal (Art. 7(3)).

How to exercise your rights. You can view and correct much of your data in your account, delete saved addresses and unsubscribe from the newsletter using the link in each newsletter. For everything else, including deleting your account or revoking an AI assistant's access, write to privacy@printandmailcompany.com.

We will respond within one month of receiving your request. If a request is complex or we receive many requests, we may extend this period by up to two further months; we will tell you about the extension within the first month. Exercising your rights is free of charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse it, and we will explain why. We may ask for information to confirm your identity before we act on a request.

If your request concerns data we process for a business customer (see section 5), we will forward it to that customer and help them respond.

14. Right to lodge a complaint

If you believe that we process your personal data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work or where the alleged infringement took place. The authority responsible for us is:

Commission nationale pour la protection des données (CNPD)
15, Boulevard du Jazz
L-4370 Belvaux
Luxembourg
www.cnpd.lu

Please check the current address and complaint procedure on cnpd.lu before you write. We would welcome the chance to address your concern first, so feel free to contact us at privacy@printandmailcompany.com.

15. Do you have to provide your data?

You are not legally obliged to give us personal data. However, we need your account details, the recipient's address, the letter content and your payment details to provide our service. Without them we cannot send letters for you. Once you pay, the law requires us to record the data needed for invoicing. Optional data, such as your own return address, saved addresses, Google sign-in and the newsletter, is up to you.

16. Children

Our service is not directed at children under 16. You must be at least 18 years old to create an account (see our Terms of Service). If we learn that we hold personal data of a child who used our service in breach of these rules, we will delete it unless the law requires us to keep it. If you believe a child has given us personal data, please contact privacy@printandmailcompany.com.

17. Changes to this policy

We update this policy when our processing or the law changes. The date at the top shows when it was last updated. If we make significant changes, we will inform registered customers by email or in their account before the changes take effect, and we will ask for your consent where a change requires it. Previous versions are available on request.