Privacy and Cookie Policy
Last updated: 1 October 2026
This policy applies to everyone who creates an EmailOctopus account on or after 1 October 2026. If your account was created before then, our previous Privacy Policy and Cookie Policy apply until 1 November 2026. From that date, this policy applies to everyone.
About this policy
1. Introduction
This Privacy and Cookie Policy is provided by Three Hearts Digital Ltd trading as EmailOctopus, a company registered in England and Wales under company number 09897211 with registered office at 86-90 Paul Street Shoreditch, London EC2A 4NE ('we', 'our' or 'us') for use of our products and services including our email marketing platform and our websites at emailoctopus.com and its subdomains (Services).
We take your privacy very seriously. Please read this policy carefully as it contains important information on how and why we collect, store, use and share any information relating to you (your personal data).
It also explains your rights in relation to your personal data and how to contact us or the relevant regulator in the event you have a complaint. Our collection, storage, use and sharing of your personal data is regulated by law, including under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR).
We are the controller of personal data about our customers and our website visitors obtained via the Services, meaning we are the organisation legally responsible for deciding how and for what purposes it is used. We are a processor, not a controller, of the contact lists and content (the emails, landing pages and forms they create, and the results of sending them) our customers upload — see ‘Who this policy is about’ below.
2. Who this policy is about
When we refer to “you” in this policy we mean a customer of our Services, a person who signs up for a free account, or a visitor to our websites. We are the controller of that personal data.
We are not referring to a person who receives an email sent by one of our customers, or who is on a mailing list maintained by one of our customers. We call those people Contacts. Our customer is the controller of a Contact’s personal data and we process it only as that customer’s processor, on their instructions, under the data processing schedule in our Terms of Use. If you are a Contact and want to stop receiving emails, please use the unsubscribe link in the email or contact the sender directly. If a Contact asks us directly to be removed, we may action that request on our customer’s behalf.
We will never use Contact email addresses to send our own marketing.
3. What this policy applies to
This policy relates to your use of the Services only.
The Services may link to or rely on other apps, websites, APIs or services owned and operated by us or by certain trusted third parties to enable us to provide you with Services. These other apps, websites, APIs or services may also gather information about you in accordance with their own separate privacy policies. For privacy information relating to these other apps, websites or services, please consult their privacy policies as appropriate. For more information see the section ‘Who we share your personal data with’ below.
How we use your personal data
4. Personal data we collect about you
The personal data we collect about you depends on the particular activities carried out through the Services. We will collect and use the following personal data about you:
Category of data | In more detail |
|---|---|
Identity and account data you input into the Services. Registration is mandatory in order to use the Services | Your first and last name, email address, password (stored in hashed form), business or organisation name, industry, billing address and country, and the preferences and settings you choose in your account. |
Data collected when you use specific functions in the Services | Data you store online with us using the Services including your usage history or preferences (while such data may not always be personal data as defined at law in all cases we will assume it is and treat it in accordance with this policy as if it were), and the contact lists and content you upload (which we process as your processor — see the section ‘Who this policy is about’) |
Other data the Services collects automatically when you use it | Your activities on, and use of, the Services which reveal your preferences, interests or manner of use of the Services and the times of use; your IP address (which we use for fraud and abuse detection and to suggest a billing currency); device, browser and operating system information; and the information described in the section ‘Cookies and similar technologies’ below. |
Data collected when you make an enquiry with us | The content of your correspondence with our support team, including any attachments and any data you ask us to add to the platform on your behalf, together with your name, email address and information about the device and browser you contacted us from. |
Payment data | Your billing name, address and country, IP address, the date and amount of your last payment and a payment card token. Payments are processed by Stripe. We do not store full card numbers on our systems. |
If you do not provide personal data we ask for where it is required, it may prevent us from providing services and/or the Services to you.
We collect and use this personal data for the purposes described in the section ‘How and why we use your personal data’ below.
5. Sensitive Data
Sensitive personal data (also known as special category data) means information related to personal data revealing racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data (where used for identification purposes); data concerning health; data concerning a person’s sex life; and data concerning a person’s sexual orientation.
Please note that we do not knowingly or intentionally collect sensitive personal data or information about criminal convictions from individuals and that you should not submit sensitive data to us. Our Acceptable Use Policy prohibits you from using the Services to send or collect special category or criminal offence data about your Contacts.
If you submit sensitive data to us in breach of our Terms of Use, we may delete it and may suspend or close your account.
6. How your personal data is collected
We collect personal data from you directly when you sign up to the Services, contact us directly or reach out to us via social media, make submissions via the Services, or indirectly, such as your activity while using the Services. We also receive personal data about you from third parties, including our sign-up fraud screening, referral, analytics and advertising providers, and the location and brand-asset providers named in ‘Who we share your personal data with’ below.
We may collect personal information about you using cookies or similar technologies. Please refer to the section ‘Cookies and similar technologies’ below for details about the cookies and similar technologies we use and how you can control them.
7. How and why we use your personal data
Under data protection law, we can only use your personal data if we have a proper reason, e.g.:
- where you have given consent
- to comply with our legal and regulatory obligations
- for the performance of a contract with you or to take steps at your request before entering into a contract;
- for our legitimate interests or those of a third party; or
- for a recognised legitimate interest listed in Annex 1 to the UK GDPR (for example, detecting, investigating or preventing crime), where no balancing test is required.
A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests against your own. You can obtain details of this assessment by contacting us (see ‘How to contact us’ below).
The table below explains what we use your personal data for and why.
What we use your personal data for | Our reasons |
|---|---|
Create and manage your account with us | To perform our contract with you or to take steps at your request before entering into a contract |
Providing services and/or the functionalities of the Services to you | To perform our contract with you or to take steps at your request before entering into a contract (in this case, the contract means the Terms of Use which apply to the Services) |
Sending and delivering the emails and other content you create, and reporting on the results | To perform our contract with you |
Screening content for phishing, fraud, spam and other abuse, including using automated and AI tools | To comply with our legal and regulatory obligations; and for our legitimate interests and those of third parties, being the protection of recipients, our platform and our sending reputation. Some of this processing is also a recognised legitimate interest (detecting and preventing crime) |
Accessing your account through administrative tools in order to provide support, check the platform is working correctly, investigate faults or investigate abuse | To perform our contract with you; and for our legitimate interests, being the efficient provision of support and the prevention of misuse |
To enforce legal rights or defend or undertake legal proceedings | Depending on the circumstances: to comply with our legal and regulatory obligations; in other cases, for our legitimate interests or those of a third party, i.e. to protect our business, interests and rights or those of others |
Communications with you not related to marketing, including about changes to our terms or policies or changes to the Services or service or other important notices | Depending on the circumstances: to comply with our legal and regulatory obligations; in other cases, for our legitimate interests or those of a third party, i.e. to provide the best service to you |
Protect the security of systems and data | To comply with our legal and regulatory obligations. We may also use your personal data to ensure the security of systems and data to a standard that goes beyond our legal obligations, and in those cases our reasons are for our legitimate interests or those of a third party, i.e. to protect systems and data and to prevent and detect criminal activity that could be damaging for you and/or us |
Operational reasons, such as improving efficiency, training, and quality control or to provide support to you | For our legitimate interests or those of a third party, i.e. to be as efficient as we can so we can deliver the best service to you |
Statistical analysis to help us manage our business, e.g. in relation to our performance, customer base, app and functionalities and offerings or other efficiency measures | For our legitimate interests or those of a third party, i.e. to be as efficient as we can so we can deliver the best service to you and improve and develop our Services |
Updating and enhancing user records | Depending on the circumstances: to perform our contract with you or to take steps at your request before entering into a contract; to comply with our legal and regulatory obligations; where neither of the above apply, for our legitimate interests or those of a third party, e.g. making sure that we can keep in touch with our customers about their accounts and new products or functionalities related to the Services and our services |
Marketing our Services to you | Where you have given consent, or for our legitimate interests in promoting our Services to people who have signed up for an account with us, subject to your right to object at any time |
Keeping records to show that we comply with data protection, tax, accounting and other legal requirements | To comply with our legal and regulatory obligations |
To share your personal data with members of our group and third parties in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency. In such cases information will be anonymised where possible and only shared where necessary | Depending on the circumstances: to comply with our legal and regulatory obligations; in other cases, for our legitimate interests or those of a third party, i.e. to protect, realise or grow the value in our business and assets |
See ‘Who we share your personal data with’ for further information on the steps we will take to protect your personal data where we need to share it with others.
8. How we use AI
We use artificial intelligence in three ways.
Content moderation. We screen content sent through the platform, and other activity on it, using automated tools including AI models, to detect phishing, scams, fraud and other abuse. Where we do this we may send the content concerned and the sender’s information to an AI provider. We do not describe in detail what we screen or how, because that would help bad actors evade it. We do not send contact lists to the AI provider, and we take reasonable steps to limit what is sent to what is necessary, but content may itself contain personal data. Our lawful basis is our legitimate interest, and that of recipients and other customers, in preventing fraud and abuse, together with the recognised legitimate interest in detecting and preventing crime. Where an AI model runs within our own cloud environment, we configure it so that inputs and outputs are not shared with the underlying model provider and are not used to train or improve their models.
Support and internal use. We may use AI tools to help our team triage and answer your support enquiries, and to analyse billing and support data about our customers. These tools may process personal data about you, such as your account email address, and billing and support data drawn from our payment, analytics and support systems. They are not used on your Contacts’ personal data or on our customers’ contact lists. The providers we use for this act as our processors, under contracts which do not allow them to use the data for their own purposes.
Generative features. We may offer features which help you create content, using material from your own account (such as past emails, brand colours, logos and images). Where these features are available they are described in the product, together with the AI provider used, where one is involved. Our lawful basis for these features is the performance of our contract with you. Where an AI Feature is optional, you may choose not to use it.
Our commitments. We do not use your personal data, your content or your Contact data to train generally available AI models, and we contract with our AI providers on terms which prevent them from doing so and which limit their retention of the data we send.
9. Staff access to your account
Our team can access your account using administrative tools, which allow them to see the platform as you see it. We use this only where it is reasonably necessary to answer a support request, to check that the platform is working correctly or investigate a fault, to investigate a suspected breach of our Terms of Use or Acceptable Use Policy, or where the law requires it. Access is limited to staff who need it, does not allow data to be exported, is logged, and is subject to confidentiality obligations.
10. Marketing
We intend to send you email marketing to inform you of our services such as promotions.
We will always ask you for your consent before sending you marketing communications, except where you have explicitly opted-in to receiving email marketing from us in the past or except where you were given the option to opt-out of email marketing when you initially signed up for your account with us and you did not do so, the marketing relates to our own similar products or services, and every message gives you a simple way to refuse further marketing. We rely on this soft opt-in when you sign up. You can opt out at any time.
You will have the right to opt out of receiving marketing communications at any time by contacting us at privacy@emailoctopus.com, using the ‘unsubscribe’ link included in all marketing emails you may receive from us, or through your account dashboard.
We will always treat your personal data with the utmost respect and never sell it. We do not share it with other organisations for their own marketing purposes. We do use advertising and analytics providers, including audience matching using a hashed version of your email address, as described in ‘Cookies and similar technologies’ below.
For more information on your right to object at any time to your personal data being used for marketing purposes, see ‘Your rights’ below.
Sharing and keeping your data
11. Who we share your personal data with
We routinely share personal data with service providers we use to help us run our business or provide the services or functionalities in the Services. The main ones are:
Provider | What they do | Where |
|---|---|---|
Amazon Web Services EMEA SARL | Cloud hosting and storage of account data and contact lists, and the AI models we use for content moderation | European Union (primarily Ireland). AI content moderation may run in other AWS regions, including the United States |
Twilio SendGrid and Bird B.V. (formerly SparkPost) | Email delivery | Bird: European Union. Twilio SendGrid: United States |
Automattic, Inc. (Gravatar) | Hashed email addresses, to provide contact profile images | United States |
Cloudflare, Inc. | Content delivery network, DNS and security | United States and global |
Datadog, Inc. | Infrastructure monitoring and logs | European Union |
Google LLC | Google Workspace (email and documents), reCAPTCHA spam protection on sign-up forms, and Google Fonts | United States |
Help Scout PBC | Customer support ticketing | United States |
Sentry (Functional Software, Inc.) | Error monitoring | United States and European Union |
Stripe Payments Europe, Ltd. | Payment processing and billing records | Ireland and United States |
PostHog | Website and product analytics | European Union |
Those which handle our customers’ contact lists on our behalf are also listed on our sub-processor page at https://emailoctopus.com/legal/subprocessors.
We use Google, Meta, Microsoft, LinkedIn, Reddit, Quora, OpenAI, X and ContactLevel for website analytics and advertising. These providers are described in the section ‘Cookies and similar technologies’ below. We also use a number of providers for specific product features, including Brandfetch (brand assets), ip-api (approximate location from IP address), Pexels (stock imagery), Google Fonts, E-Hawk (sign-up fraud screening) and Tolt (referral tracking). The providers who process our customers’ contact lists and content on our behalf (our sub-processors) are listed at https://emailoctopus.com/legal/subprocessors.
We only allow service providers to handle your personal data if we are satisfied they take appropriate measures to protect your personal data. We also impose contractual obligations on service providers to ensure they can only use your personal data to provide services to us and to you, except where a provider acts as an independent or joint controller for its own purposes, which we identify in ‘Cookies and similar technologies’ below.
We or the third parties mentioned above may occasionally also need to share your personal data with external auditors, e.g. in relation to the audit of our accounts and our company; professional advisors (such as lawyers and other advisors); law enforcement agencies, courts or tribunals and regulatory bodies to comply with legal and regulatory obligations; internet service providers and anti-spam organisations, where we detect abusive or illegal behaviour relating to a contact list; and other parties in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency. Except where we are required to disclose information by law, the recipient of the information will be bound by confidentiality obligations.
If you would like more information about who we share our data with and why, please contact us (see ‘How to contact us’ below). We will not share your personal data with any other third party except as described in this policy.
12. How long your personal data will be kept
We keep your personal data only for as long as we need it:
- Account data — for as long as your account is open, and for up to 25 months after your last sign-in or use of the Services. We close free accounts that have not been used for 24 months, and delete the data in them within a month of closure, as explained in our Terms of Use. Before we close an inactive account and delete its data we will try to email you at your account email address so that you can keep the account open or export anything you need. You can delete your account and your data at any time through your dashboard.
- Contact lists and content — we hold these as our customer’s processor. Customers can export or delete them at any time while their account is open, and they are deleted when the account is deleted, in line with the data processing schedule in our Terms of Use.
- Backups — copies of your data may remain in backup storage for up to 90 days after deletion, after which they are overwritten.
- Invoices and accounting records — 6 years from the closure of your account, to comply with our accounting and tax obligations, after which we delete or anonymise them unless we are required to keep them for longer.
- Support correspondence — up to 5 years after a conversation is closed, where we need it for customer service history, resolving disputes, security or legal reasons. We review it periodically, and delete or irreversibly anonymise it sooner once those reasons no longer apply.
- Records needed to pursue or defend legal claims, and records of abuse and suspension — for as long as necessary for that purpose and no longer than 6 years, unless a claim is live.
Following the end of the aforementioned retention period, we will delete or anonymise your personal data.
13. De-identified information
The personal data we collect may have analytical, educational, or commercial value to us. Where we have de-identified the information we have collected so that no individual can be identified from it, we reserve the right to process and distribute such information, including to improve our spam detection.
14. Automated decision-making
We use automated systems to screen accounts and content for spam, fraud and other abuse. If we take a significant decision about you solely by automated means, we will tell you about it as soon as reasonably practicable, you may make representations about it, you may ask for a person to review it, and you may contest it, as required by Articles 22A to 22D of the UK GDPR.
Some decisions are automated. For example, where our fraud-screening tools score a new sign-up as high risk, we may suspend the account before it has been used. You can ask us to review any such decision and a person will do so.
15. Transferring your personal data out of the UK
As part of providing the Services, we share your personal data with third parties based outside of the UK, as shown in the table in ‘Who we share your personal data with’ above.
Under UK data protection laws, we can only transfer your personal data to a country outside the UK where: the UK government has decided the particular country ensures an adequate level of protection of personal data (known as an ‘adequacy regulation’) further to Article 45 of the UK GDPR; there are appropriate safeguards in place, together with enforceable rights and effective legal remedies for you; or a specific exception applies under relevant data protection law. The mechanisms we rely on are:
- Transfers to the European Economic Area — UK adequacy regulations for the EEA.
- Transfers to the United States — for providers certified under the EU-US Data Privacy Framework and its UK Extension (the UK-US Data Bridge), the UK adequacy regulations for the United States. Otherwise, the International Data Transfer Agreement issued by the Information Commissioner, or the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses.
- Transfers elsewhere — the International Data Transfer Agreement or the UK Addendum, supported by a transfer risk assessment.
If a mechanism we rely on ceases to be valid, we will put an alternative in place or stop the transfer. You can ask us for a copy of the safeguards we use by contacting us.
Your rights
16. Your rights
You generally have the following rights, which you can usually exercise free of charge. For more information regarding these rights, please visit the ICO website at https://ico.org.uk.
Right | What it means |
|---|---|
Access to a copy of your personal data | The right to be provided with a copy of your personal data. |
Correction (also known as rectification) | The right to require us to correct any mistakes in your personal data. |
Erasure (also known as the right to be forgotten) | The right to require us to delete your personal data — in certain situations. |
Restriction of use | The right to require us to restrict use of your personal data in certain circumstances, e.g. if you contest the accuracy of the data. |
Data portability | The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party — in certain situations. |
Withdraw consent | Where we rely on your consent, the right to withdraw it at any time. Withdrawing consent does not affect the lawfulness of anything we did before you withdrew it. |
To object to use | The right to object at any time to your personal data being used for direct marketing (including profiling); and in certain other situations to our continued use of your personal data, e.g. where we use your personal data for our legitimate interests. |
Not to be subject to decisions without human involvement | The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. See ‘Automated decision-making’ above. |
For further information on each of those rights, including the circumstances in which they do and do not apply, please contact us (see ‘How to contact us’ below). You may also find it helpful to refer to the guidance from the UK’s Information Commissioner on your rights under the UK GDPR.
If you would like to exercise any of those rights, please email us at privacy@emailoctopus.com or write to us using the contact details below. When contacting us please provide enough information to identify yourself (e.g. your full name and username) and any additional identity information we may reasonably request from you, and let us know which right(s) you want to exercise and the information to which your request relates.
We will respond within one month of receiving your request. Where we reasonably need more information from you to identify you or to identify what your request relates to, that period does not run until we receive it. Where a request is complex or you have made a number of requests, we may extend the period by up to two further months and will tell you within the first month if we do. We will carry out a reasonable and proportionate search for the information you ask for. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse to act on it, and we will tell you why.
17. Keeping your personal data secure
We have appropriate security measures to prevent personal data from being accidentally lost, or used or accessed unlawfully. We limit access to your personal data to those who have a genuine business need to access it. These measures include encryption in transit and at rest, role-based access control, multi-factor authentication for administrative access, logging, vulnerability scanning and penetration testing.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
18. How to complain
Please contact us if you have any queries or concerns about our use of your information (see below ‘How to contact us’). We hope we will be able to resolve any issues you may have.
You have the right to complain to us about the way we have handled your personal data. You can do so by emailing privacy@emailoctopus.com with “Data protection complaint” in the subject line. We will:
- acknowledge your complaint within 30 days of receiving it;
- make appropriate enquiries into the subject matter of your complaint, without undue delay, and keep you informed of our progress; and
- tell you the outcome of your complaint.
This procedure is provided under section 164A of the Data Protection Act 2018.
You also have the right to lodge a complaint with the Information Commissioner under section 165 of the Data Protection Act 2018. You are encouraged to complain to us first, but you do not have to. The Information Commissioner can be contacted at https://ico.org.uk/make-a-complaint/data-protection-complaints/ or by telephone on 0303 123 1113.
Cookies
19. Cookies and similar technologies
A cookie is a small file containing an identifier that is sent by a web server to your browser and stored there, and sent back to the server each time your browser requests a page. A session cookie expires when you close your browser; a persistent cookie remains until its expiry date or until you delete it. We also use similar technologies such as web beacons, pixels and local storage. References to cookies in this section include those technologies.
Your consent. Cookies that are strictly necessary to provide the service you have asked for are set without your consent, because the law permits this. Where the law requires consent for other cookies, which always includes visitors in the UK and the European Economic Area, we show you a cookie banner when you first visit, and we set analytics, advertising and other non-essential cookies (including our promotional and referral cookies) only if you agree. Where the law doesn’t require consent, we may set these cookies straight away, and you can turn them off. Wherever you are, you can change or withdraw your consent, or opt out, at any time using the “Manage cookie preferences” link in the footer of every page of our website, and doing so is as easy as giving consent. We store your choice in the “eoCookieConsent” cookie so that we can honour it. UK law now allows some low-risk cookies used only for statistical or appearance purposes to be set without consent, provided we tell you about them and you can object; we have chosen not to rely on that exception, and in the UK and EEA we ask for consent for every non-essential cookie.
Cookies we set. These are our own (first party) cookies:
Cookie | Purpose | Type and duration |
|---|---|---|
PHPSESSID | Recognises your device during a visit and maintains application state, such as whether you are signed in | Strictly necessary — session (expires when you close your browser) |
REMEMBERME | Keeps you signed in if you choose to persist your session | Strictly necessary — persistent (14 days) |
eoHasAuthenticated | Recognises that you are logged in when you view our marketing website | Strictly necessary — session, or 14 days if you choose to stay signed in |
eoCookieConsent | Records your cookie preferences | Strictly necessary — persistent (12 months, refreshed each time you visit) |
eht | E-Hawk's Talon cookie, set by our sign-up fraud screening provider on pages containing a sign-up form. It records device characteristics so that we can identify repeat, suspicious or fraudulent registrations | Security — persistent (up to 10 years, though your browser may limit this). The same identifier is also kept in your browser’s local storage |
eoCoupon | Remembers whether you have used a promotion or discount | Consent (functional) — persistent (31 days) |
__Host-csrf-token_* | Protects our forms against cross-site request forgery | Strictly necessary — session |
eoReferredByUserReferralLinkId, eoReferredByUtm, eoReferredByAffiliateLinkId, eoReferredByPartner | Recognise that you were referred to our website by another user or by a partner, so that referrals and affiliate commissions can be attributed | Consent (marketing attribution) — persistent (31 days) |
Third party cookies. The following third parties set cookies through our website. Except where a cookie is marked strictly necessary, these are set only with your consent where the law requires it (see “Your consent” above). Some of these providers act as our processors (for example PostHog, Cloudflare and Help Scout, and Google in respect of Google Analytics); the advertising providers act as independent or joint controllers for their own purposes. You should consult their own privacy policies.
Third party | Purpose and role |
|---|---|
Google (Google Analytics and Google Ads) | Analytics (Google acts as our processor for Google Analytics) and advertising (Google acts as a controller) |
Meta (Facebook pixel) | Analytics and advertising. We and Meta act as joint controllers for the collection and transmission of pixel data |
Microsoft | Analytics and advertising. Microsoft Clarity records how visitors use our website and dashboard, with account content such as contact lists masked |
Analytics and advertising | |
Analytics and advertising | |
Quora | Analytics and advertising |
X | Analytics and advertising |
ContactLevel | Advertising audiences and re-targeting. If you visit our website after clicking one of our adverts, ContactLevel can identify you (for example your name, job title, company and LinkedIn profile) and record how you use our pages. ContactLevel acts as an independent controller for its own identity data |
PostHog | Analytics, including recording how visitors interact with pages. Data relating to your Contacts is redacted and is not recorded. PostHog acts as our processor |
OpenAI | Advertising on the ChatGPT platform, including audience matching using a hashed version of your email address and name |
Stripe | Payment processing and fraud prevention at checkout. Stripe acts as our processor for payment data |
E-Hawk | Security, including verification of sign-ups. E-Hawk acts as our processor |
Tolt | Tracking of referral source for our affiliate programme |
Cloudflare | Security, including managing access based on the IP address a visitor comes from. Strictly necessary; Cloudflare acts as our processor |
Help Scout | Providing customer support chat. Strictly necessary when you use the chat; Help Scout acts as our processor |
We may also share your email address with Meta, Google or OpenAI in hashed form (with OpenAI, also your name and account ID) so that we can show you, and people like you, advertisements for our Services. Where the law requires consent, including in the UK and EEA, we do this only if you have consented. You can withdraw your consent, or opt out, at any time.
Controlling cookies in your browser. Most browsers let you block or delete cookies through their settings — usually under “Privacy and security”, “Cookies and site data” or similar. Blocking all cookies will affect the usability of many websites, and if you block our strictly necessary cookies you will not be able to sign in to or use the Services. Current instructions are published by each browser: Google Chrome, Microsoft Edge, Mozilla Firefox, Apple Safari and Brave each explain how to manage and delete cookies in their own help pages.
Do Not Track and Global Privacy Control. Browsers may send a “Do Not Track” signal. There is no agreed standard for responding to it and our website does not respond to it. Where your browser sends a Global Privacy Control signal we treat it as a withdrawal of consent to, or an opt-out from, non-essential cookies.
Changes and contact
20. Changes to this policy
We may change this policy from time to time. When we make significant changes we will take steps to inform you, for example via the Services or by other means, such as email. A significant change is one that materially affects what we do with your personal data or your rights — for example a new purpose, a new category of recipient or a materially longer retention period. Routine updates to the cookie and provider tables are not significant changes, and we make those by updating this page. The date at the top of this policy tells you when it was last updated.
21. How to contact us
For further information about our policy or practices, or to access or correct your personal data, or make a complaint, please contact us using the details set out below:
Three Hearts Digital Ltd (trading as EmailOctopus), 86-90 Paul Street, Shoreditch, London EC2A 4NE, United Kingdom
Email: privacy@emailoctopus.com. To report spam or other abuse of our platform, email abuse@emailoctopus.com
If you are in the European Economic Area, the EU GDPR may also apply to our processing of your personal data. Our representative in the European Union for the purposes of Article 27 of the EU GDPR is BizLegal Ltd, trading as EU Rep (company number 635921), whose registered office is at 27 Cork Road, Midleton, Co. Cork, Ireland. If you are in the EU, you or a data protection authority can contact EU Rep about GDPR matters using the form at https://eurep.ie. You may also complain to the supervisory authority in the EEA country in which you live or work.