Last updated: 28 May 2026
Draft — under review by legal counsel. This document reflects the service's current data-handling practices and is published for transparency. Final binding terms will be confirmed before commercial launch.
Mailbuttons is operated by Code Cutter Limited, a company registered in England and Wales (company number 08453060) with registered office at Unit 96 The Maltings Business Centre, Stanstead Abbotts, Ware, Herts, SG12 8HG ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Mailbuttons platform.
For information collected by us about you on our own behalf — including account, billing, and support data — Code Cutter Limited (trading as Mailbuttons) acts as the data controller. We comply with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the UK Data Protection Act 2018, and operate security controls aligned with ISO/IEC 27001.
Customers acting as Data Controllers and using the Service to process personal data of third parties are additionally subject to our Data Processing Agreement (DPA), which sets out the relationship between Code Cutter Limited (as Processor) and the Customer (as Controller) in respect of such processing.
We may collect the following types of personal information:
We use your information for the following purposes:
We implement comprehensive security measures to protect your information:
We do not sell, trade, or rent your personal information. We engage a small, carefully-vetted set of sub-processors to deliver the Service. Each is bound by a written data processing agreement with terms equivalent to those we offer our Customers.
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe Payments UK | Payment card processing | UK / EU |
| Stalwart Labs | Email server software (operated by us) | UK |
| Fasthosts Internet Ltd | VPS hosting (UK data centres) | UK |
| Cloudflare, Inc. | DNS and edge protection | Global; data terms apply |
| Anthropic, PBC | LLM inference for hosted agents (opt-in) | US; SCCs in place |
| Backblaze, Inc. | Encrypted off-site backup (client-side encryption) | EU Central (Amsterdam); UK Addendum / SCCs |
Beyond these sub-processors, we share information only in the following limited circumstances:
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
Under UK GDPR and EU GDPR you have the following rights in respect of personal data we hold about you:
To exercise these rights, contact our Data Protection Officer at dpo@mailbuttons.com. We respond to verified requests within one month, as required by UK and EU GDPR.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or, if you are based in the European Union, your local supervisory authority.
We use cookies and similar technologies to enhance your experience, analyze usage patterns, and provide personalized content. You can control cookie preferences through your browser settings. For detailed information about our cookie usage, please see our Cookie Policy.
Mailbuttons operates with UK and EU data residency by default. Customer data, including the contents of email passing through your mailboxes and the audit logs derived from it, is stored within the United Kingdom and European Economic Area.
Where a sub-processor located outside the UK/EEA is used (notably Cloudflare for DNS / edge protection and, for opt-in hosted-agent features, Anthropic for LLM inference), transfers are made on the basis of UK Addendum / EU Standard Contractual Clauses and supplementary safeguards as required by UK and EU GDPR. A customer can elect to disable the hosted-agent LLM feature, in which case no customer email content leaves the UK/EEA.
Off-site backups are held by Backblaze, Inc. (US-incorporated) in their EU Central region (Amsterdam, Netherlands). All backup data is encrypted client-side with a key we control before leaving our infrastructure; Backblaze cannot read backup contents in plaintext. The transfer relationship is governed by UK Addendum / EU Standard Contractual Clauses.
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or our data practices, please contact us:
Privacy enquiries: privacy@mailbuttons.com
Data Protection Officer: dpo@mailbuttons.com
UK supervisory authority: Information Commissioner's Office, ico.org.uk
Postal address: Code Cutter Limited (trading as Mailbuttons), Unit 96 The Maltings Business Centre, Stanstead Abbotts, Ware, Herts, SG12 8HG, United Kingdom