fluctuat

Privacy policy

Courtesy translation. The French version is authoritative: Politique de confidentialité.

Last updated: July 2026

Data controller

Dizzus GmbH, Zug (Switzerland), UID CHE-469.903.322, is the controller for account data and the processor for the metadata of relayed messages. Contact: through the contact form.

Data processed

Account data: email address, password (kept as an argon2 hash, never in clear text), tenant identifier, configured senders and SMTP credentials, billing data managed by Stripe.

Metadata of relayed messages: sender, recipients, subject, timestamp and delivery status, retained for traceability and debugging. The content of messages passes through encrypted and is not retained beyond delivery; metadata is retained according to the retention period of the subscribed plan (see Retention).

Purposes and legal basis

Data is processed to provide the Service (performance of the contract), to ensure security, billing and support. No data is sold or used for advertising purposes.

Processors

The contractual framework is the data processing agreement (DPA) (French), an integral part of the Terms of Service. The security measures are detailed on the Security page.

Location and transfers

Data is hosted in the United Kingdom (OVHcloud, London), a country recognised as offering an adequate level of protection by Switzerland and the EU. Infrastructure backups are kept in France. Any other transfer outside Switzerland or the EEA is governed by appropriate safeguards.

Retention

The content of messages is retained only for the duration of delivery (7 days at most in the event of failure), then purged. Metadata and logs are retained according to the subscribed plan (30 days on Free, 90 days on Team, 12 months on Business and Compliance), then purged. Account data is retained for the duration of the contractual relationship, then deleted upon account closure.

Your rights

In accordance with the Swiss FADP (nLPD) and the GDPR, you have a right of access, rectification, erasure, restriction and portability. You may delete your account from the console, or exercise your rights through the contact form. Upon account closure, the encryption key unique to your organization is destroyed: the encrypted content, including backup copies, becomes unreadable and is purged within 7 days (erasure by key destruction).

Security

Exchanges are encrypted (TLS), passwords are hashed, data is partitioned by customer. Access to the Service requires authentication.