Merdot Mail Privacy Policy

Last updated 17 July 2026

Privacy Policy for Merdot Mail, a business email service operated by MERDOT and hosted in India (AWS Mumbai, ap-south-1). Written for the India context: DPDP Act 2023, GST, IT Act 2000, and the specific realities of business mailbox data. Founder note: this is a real, usable template, but you should have it reviewed by a qualified Indian lawyer before you publish and rely on it.

1. Who we are and what this policy covers

Merdot Mail is a business email service provided by MERDOT ("MERDOT", "we", "us", "our"), a company based in Ahmedabad, Gujarat, India. This Privacy Policy explains what personal data we collect when you use merdotmail.com and the Merdot Mail service (the "Service"), how we use and protect it, who we share it with, and the rights you have under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").

This policy applies to: - Visitors to our website, merdotmail.com. - Account owners and administrators who purchase and manage mailboxes. - Individual mailbox users whose email is hosted on the Service.

Under the DPDP Act, MERDOT is the Data Fiduciary for the account and billing data of our customers. For the contents of mailboxes, MERDOT acts as a processor on behalf of the business or organisation that owns the account (the customer). If your employer or organisation provides your mailbox, that organisation controls your mailbox and its policies also apply to you.

By using the Service you acknowledge this policy. Where the DPDP Act requires your consent, we ask for it separately and you may withdraw it as described in Section 11.

Effective date: 17 July 2026. Last updated: 17 July 2026.

2. Our core privacy promise

Merdot Mail is built on a simple principle: your email is yours.

  • You own your data. The contents of your mailboxes belong to you. We hold them so we can deliver the Service, nothing more.
  • We host your data in India. Your mailbox data is stored on infrastructure located in the Amazon Web Services Mumbai region (ap-south-1).
  • We do not read your mail. We do not read, monitor, or manually review the contents of your emails except in the narrow, lawful situations described in Section 6.
  • We do not scan your mail for advertising. We do not analyse the content of your email to build advertising or marketing profiles, and we never will.
  • We do not sell your data. We do not sell, rent, or trade your personal data or the contents of your mailboxes to anyone.

The rest of this policy explains how we keep these promises in practice.

3. Information we collect

We collect only what we need to run the Service, bill you correctly, keep the platform secure, and meet our legal obligations. We group it into four categories.

a) Account and administrative data. Name of the account owner and administrators, business or organisation name, email addresses, mobile number, the domain name you connect to the Service, mailbox usernames you create, and support correspondence you send us. This lets us set up your account, authenticate you, and provide support.

b) Billing data. GST Identification Number (GSTIN) where applicable, billing name and address, plan selected (Lite, Standard, or Pro), number of mailboxes, and invoices we issue. Card and payment-instrument details are collected and processed directly by our payment gateway, Razorpay, and are not stored on Merdot Mail servers. We receive only a transaction reference, payment status, and the amount, so we can confirm your subscription.

c) Mailbox contents you store. This is the data you and your users put into the Service: emails you send and receive (including subject lines, message bodies, and attachments), contacts and address books, folders and labels, calendar and settings data where offered, and message metadata such as sender, recipient, timestamps, and delivery status. We store this so the Service works. We do not read it for our own purposes.

d) Technical and log data. To operate and secure the platform we automatically record technical information such as IP addresses, login times, device and browser type, mail-server connection and delivery logs (SMTP, IMAP, POP), authentication events, spam and malware filtering results, and error and performance logs. These logs describe how the Service is being used and are used for security, troubleshooting, deliverability, and abuse prevention. Wherever practical we minimise the personal data held in logs and retain it only as long as needed (see Section 9).

Website data collected through cookies is described in Section 12.

4. How we use your information

We use the data described above only for these purposes:

  • To provide the Service: create and run your mailboxes, send and receive email, apply your settings, and store your data reliably.
  • To authenticate and secure access: verify logins, support two-factor authentication (2FA), and detect suspicious or unauthorised activity.
  • To deliver and protect email: route outbound mail, apply anti-spam, anti-phishing, and anti-malware filtering, manage sender reputation, and handle bounces and delivery reports.
  • To bill you and comply with tax law: issue invoices, apply 18% GST, process yearly or six-monthly subscription payments through Razorpay, and maintain financial records required under Indian law.
  • To support you: respond to your questions, diagnose faults, and act on your requests.
  • To maintain and improve reliability: monitor uptime, capacity, and performance using technical logs and aggregated, non-content usage metrics.
  • To meet legal obligations: respond to valid legal process and comply with the DPDP Act, the Information Technology Act, 2000, GST law, and other applicable Indian law.
  • To communicate service and account matters: send you transactional and administrative notices such as renewal reminders, security alerts, invoices, and important changes to the Service.

We do not use the contents of your mailboxes to profile you, target advertising, or train systems for unrelated purposes.

5. Legal basis for processing

Under the DPDP Act we process your personal data on the following bases:

  • Consent. When you create an account, subscribe, or submit a form, you consent to the processing described in this policy for the stated purposes. Our request for consent is specific, informed, and unambiguous, and you can withdraw it at any time (see Section 11).
  • Performance of a contract and legitimate uses. We process account, mailbox, and technical data as necessary to deliver the Service you have subscribed to and to keep it secure and reliable.
  • Legal compliance. We process certain data to comply with tax, accounting, and other statutory obligations, and to respond to lawful requests from authorities.

Where we act as a processor for mailbox contents on behalf of your organisation, the organisation is responsible for having a lawful basis to place that data in the Service.

6. We do not read, scan, or sell your mail

This commitment is central to Merdot Mail, so we set out its limits plainly.

We do not: - Read or manually review your emails for our own purposes. - Scan the content of your emails to build advertising, marketing, or behavioural profiles. - Sell, rent, or share your personal data or mailbox contents with data brokers, advertisers, or any third party for their own use.

Automated processing that does happen. Like all email systems, the Service applies automated, content-aware processing that is necessary to deliver mail safely: spam, phishing, and malware filtering; virus scanning of attachments; and indexing so that your own search works. This processing is automated, is used only to run the Service for you, and does not involve a person reading your mail.

The narrow situations where access may occur. A MERDOT staff member may access mailbox data only when it is strictly necessary and lawful, for example: - To resolve a specific technical fault or support request you have raised, and only to the extent needed. - To investigate a genuine, evidenced security incident or abuse of the Service. - To comply with a valid, legally binding order from a competent Indian authority or court.

Any such access is limited to what is necessary, is restricted to authorised personnel, and is logged. Where we can lawfully do so, we will inform the affected customer.

7. Where your data is hosted

Your mailbox data and account data are stored and processed on infrastructure located in India, in the Amazon Web Services (AWS) Asia Pacific (Mumbai) region, ap-south-1. Outbound email is delivered through Amazon SES infrastructure in the same India region wherever the service permits.

We keep your data in India by design. We do not routinely transfer your mailbox contents outside India. Email is a global system, so a message you send will naturally travel to and be stored on the recipient's mail server, wherever that is located; that is inherent to how email works and is outside our control once the message leaves our platform. If any transfer of personal data outside India ever becomes necessary, we will do so only in accordance with the DPDP Act and any restrictions notified by the Government of India.

8. Sub-processors we rely on

To run the Service we use a small number of trusted infrastructure providers, called sub-processors, who process data on our behalf under contract. We keep this list deliberately short.

  • Amazon Web Services (AWS): hosting, storage, and compute for the Service, in the Mumbai region (ap-south-1), India.
  • Amazon Simple Email Service (Amazon SES): outbound email delivery.
  • Razorpay: payment processing for subscriptions. Razorpay collects and handles your payment-instrument details directly under its own privacy policy; we do not store card details.

These providers are bound by their own security and data-protection commitments and may process personal data only to provide their service to us. We do not permit them to use your data for their own purposes. In keeping with our white-label approach, we do not name the underlying open-source mail software that powers the Service. If we add or change a sub-processor, we will update this policy (see Section 15).

9. How long we keep your data

We keep personal data only for as long as it is needed for the purposes in this policy or as required by law.

  • Mailbox contents: retained for as long as your account is active. You control your own mail and may delete messages at any time. Deleted items may remain in trash and in routine encrypted backups for a limited period before they are permanently removed.
  • After cancellation or non-renewal: we retain your mailbox data for a limited grace period so you can reactivate or export it, after which it is deleted from our active systems. Residual copies in backups are overwritten on our normal backup rotation cycle. On written request during the grace period we will delete your data sooner, subject to any legal retention duty.
  • Account and billing records: invoices and tax records are retained for the period required under GST law, the Income-tax Act, and other applicable Indian law, even after your account closes.
  • Technical and security logs: retained for a limited period appropriate to security, deliverability, and troubleshooting, then deleted or aggregated so they no longer identify you.

Exact retention periods are set out in your service agreement and may be provided on request to contact@merdotmail.com.

10. How we protect your data

We apply reasonable security safeguards appropriate to the sensitivity of email data, in line with the DPDP Act and the Information Technology Act, 2000.

  • Encryption in transit: connections to the Service and email transmission use TLS (Transport Layer Security). Where a receiving server supports it, mail is delivered over encrypted channels.
  • Encryption at rest: stored mailbox data and backups are encrypted on our infrastructure.
  • Email authentication: we support and encourage SPF, DKIM (DomainKeys Identified Mail), and DMARC on your domain to protect against spoofing and to improve deliverability.
  • Access controls: administrative access to systems is restricted to authorised personnel on a need-to-know basis, and privileged actions are logged.
  • Two-factor authentication (2FA): available on accounts to add a second layer of protection to logins. We strongly recommend enabling it.
  • Filtering and monitoring: automated spam, phishing, and malware protection, plus monitoring for unusual or unauthorised activity.

No system can be guaranteed to be perfectly secure. You are responsible for keeping your passwords confidential, enabling 2FA, and telling us promptly if you suspect any unauthorised access. If a personal data breach occurs that is likely to affect you, we will act in accordance with our legal obligations, including notifying the Data Protection Board of India and affected Data Principals as required by the DPDP Act.

11. Your rights under the DPDP Act

As a Data Principal under the DPDP Act, 2023, you have the following rights in respect of the personal data we hold about you:

  • Right to access: obtain a summary of the personal data we process about you and the processing activities.
  • Right to correction and completion: ask us to correct inaccurate or misleading data and complete incomplete data.
  • Right to erasure: ask us to delete personal data that is no longer needed for the purpose it was collected, subject to legal retention duties.
  • Right to withdraw consent: withdraw consent you previously gave, at any time, as easily as you gave it. Withdrawal does not affect processing already carried out, and may mean we can no longer provide part or all of the Service.
  • Right to grievance redressal: raise a complaint with us and receive a timely response (see Section 16).
  • Right to nominate: nominate another individual to exercise your rights in the event of your death or incapacity.

How to exercise your rights. Email contact@merdotmail.com or write to our Grievance Officer (Section 16). We may need to verify your identity before acting. We will respond within the timelines required by the DPDP Act.

A note on mailbox data. If your mailbox is provided by your employer or organisation, that organisation controls your mailbox. We will forward your request to them or ask you to contact them directly, as they are best placed to action it.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

12. Cookies and our website

Our website, merdotmail.com, and the webmail login use cookies and similar technologies. We keep these to a minimum.

  • Strictly necessary cookies: required for the site and webmail to work, for example to keep you logged in, maintain your session, and protect against cross-site request forgery. These cannot be switched off.
  • Preference cookies: remember choices such as language or display settings.
  • Analytics: where we measure website usage, we use privacy-respecting, aggregated analytics to understand traffic and improve the site. We do not use advertising or cross-site tracking cookies, and we do not sell website analytics data.

You can control or delete cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site or webmail from working. Where the law requires consent for non-essential cookies, we will ask for it and default to the most privacy-preserving option.

13. Children and minors

Merdot Mail is a business email service intended for use by businesses, organisations, and their staff. It is not directed at children.

Under the DPDP Act, we do not knowingly process the personal data of a child (an individual under 18 years of age) without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. We rely on the account owner to confirm that mailboxes are created for adult staff or authorised users. If you believe a mailbox has been created for a child without proper consent, contact us at contact@merdotmail.com and we will take appropriate action.

14. Organisations and institutions

When a business, organisation, or institution subscribes and creates mailboxes for its staff or members, that organisation is the customer and controls those mailboxes. In that relationship, MERDOT processes mailbox contents on the organisation's instructions under our service agreement, and the organisation is responsible for:

  • Having a lawful basis to place its users' data into the Service and to inform those users.
  • Managing user access, deprovisioning departing staff, and handling data-subject requests from its own users.
  • Its own internal privacy and acceptable-use policies, which apply alongside this one.

Institutions requiring a tailored arrangement can request a quote and a data-processing agreement by contacting contact@merdotmail.com. Individual mailbox users in an organisation should direct requests about their mailbox to their organisation first; we will support the organisation in responding.

15. Sharing, disclosure, and your email obligations

We share personal data only in these limited circumstances:

  • With our sub-processors (Section 8), strictly to run the Service.
  • To comply with the law, in response to a valid, legally binding request from a competent Indian court or authority. We disclose only what is required, and where lawful and reasonable we will notify the affected customer.
  • To protect rights and safety, to prevent fraud, abuse, or a security threat, or to enforce our terms.
  • In a business transfer, if MERDOT is involved in a merger, acquisition, or sale of assets, in which case data may transfer to the successor under the same protections, and we will notify you.

We never sell your data or share it for third-party advertising.

Your obligations as a sender. Because this is business email, you are responsible for using it lawfully. You must not use the Service to send spam or unsolicited bulk email, to send unlawful, deceptive, or infringing content, or to breach anti-spam, telecom, or data-protection rules. We apply outbound controls and reserve the right to suspend accounts that harm the platform's sending reputation or violate our acceptable-use policy or applicable law.

16. Grievance Officer and contact

In line with the DPDP Act, 2023 and the Information Technology Act, 2000, we have designated a Grievance Officer to address your questions and complaints about how we handle your personal data.

Grievance Officer MERDOT Email: contact@merdotmail.com Address: MERDOT, Ahmedabad, Gujarat, India

Please include enough detail to identify your account and describe your concern. We will acknowledge your grievance promptly and respond within the timelines required by law. If you are not satisfied with our resolution, you may escalate to the Data Protection Board of India.

For any other privacy question, email contact@merdotmail.com.

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our sub-processors, or the law. When we make a material change, we will update the "Last updated" date at the top and, where appropriate, notify account owners by email or through the Service. The current version is always available at merdotmail.com. Your continued use of the Service after a change takes effect means you accept the updated policy, subject to your rights under the DPDP Act.

18. Governing law and legal note

This Privacy Policy is governed by the laws of India. Any disputes relating to it are subject to the exclusive jurisdiction of the courts at Ahmedabad, Gujarat, India. It should be read together with the Merdot Mail Terms of Service and any data-processing agreement in place with your organisation.

Legal note: this policy is provided as a working template that reflects MERDOT's stated practices and the requirements of the DPDP Act, 2023, GST law, and the IT Act, 2000 as understood at the date above. Before publishing and relying on it, MERDOT should have it reviewed by a qualified Indian lawyer to confirm it fits the company's actual data flows, contracts, and obligations, and to keep it current as the DPDP Rules and enforcement guidance evolve.