Privacy Policy
Last updated: August 2026
This privacy policy explains how personal data is processed when using the Astreo web application (app.astreo.de) and this website (astreo.de). Astreo is an email client: it connects your existing mailboxes and is not an email provider — your mailboxes remain with your respective provider (e.g. Microsoft 365/Outlook or an IMAP mailbox).
1. Controller
becom Systemhaus GmbH & Co. KGAm Feldkreuz 16a, 35578 Wetzlar, Germany
Email: datenschutz@becom.net · Phone: +49 6441 96500
No data protection officer is required by law. Please direct requests to the address above.
2. What data we process
a) Account & sign-in
Several sign-in methods are available: single sign-on via Google or Microsoft, a magic link by email (a one-time sign-in link), and email and password with mandatory two-factor authentication (TOTP). We process your name, email address, the respective provider identifier (when using SSO) and, if available, your profile picture. A password is stored solely as an argon2 hash (never in plain text); the two-factor secret is stored encrypted at rest.
b) Connected mailboxes
To retrieve and send mail, you connect your mailboxes via OAuth (Microsoft 365/Outlook) or via IMAP/SMTP with any other provider. Astreo currently does not access Gmail mailboxes (see section 8). The required credentials (OAuth tokens or IMAP/SMTP credentials) are stored encrypted at rest (AES-256-GCM). Credentials are never logged in plain text.
c) Mail content, threads & attachments
To display, search and group (thread) your mail, we store email content, metadata and attachments as part of the service. Email content is processed solely to provide the service, not for advertising or analytics, and message content is not logged. Attachments are automatically scanned for malware (ClamAV).
d) AI features (optional)
For reply suggestions, translation and grammar correction you may optionally use an AI provider of your choice with your own key (e.g. Anthropic, OpenAI/OpenRouter, DeepSeek). Only the context selected for the respective function is transmitted to the provider you chose. AI output is always an editable draft and is never sent automatically.
e) Billing
For paid plans we use the payment provider Stripe. Payment data is processed directly by Stripe; we receive the information required for contract and invoicing. As Astreo is offered to business customers only, we additionally process the company name, billing address, country of establishment and — for customers established elsewhere in the EU — the VAT identification number. The VAT identification number is transmitted to the EU verification service (VIES) for validation. The legal basis is Art. 6(1)(b) and (c) GDPR (performance of the contract and tax/commercial law obligations); retention follows the statutory periods (generally 10 years).
f) Website & cookies
When you visit the website, technically necessary access data is processed server-side. In the application we set a strictly necessary session cookie for sign-in. Beyond that, no tracking takes place without your consent; in particular, Google Analytics is loaded only after active consent (see g).
g) Web analytics with Google Analytics (only with consent)
With your consent we use Google Analytics 4, a service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Only when you click “Accept” in the cookie banner is the Analytics script loaded and cookies/identifiers set. Without consent — or on “Decline” — none of this happens. Usage data (e.g. pages viewed, approximate location, device and browser info) may be transmitted to Google; the IP address is truncated (anonymize_ip). Legal basis is your consent (Art. 6(1)(a) GDPR); you may withdraw it at any time with future effect. More info: policies.google.com/privacy.
3. Hosting
Astreo is hosted in the European Union. The service itself does not process data in a US cloud. When using external mailboxes and self-chosen AI providers, their locations and terms additionally apply.
4. Legal bases
- Art. 6(1)(b) GDPR – performance of the usage contract (providing the email client, connected mailboxes, billing).
- Art. 6(1)(f) GDPR – legitimate interest (secure and stable operation, malware scanning).
- Art. 6(1)(a) GDPR – consent (e.g. optional AI features, web analytics with Google Analytics).
5. Recipients / processors
We share personal data only where necessary to perform the contract or where a legal basis exists. This includes in particular our EU hosting provider and the payment provider Stripe. When using OAuth mailboxes and AI features, data is transmitted to the provider you selected. Data processing agreements under Art. 28 GDPR are in place with processors.
6. Retention
We store personal data only as long as necessary for the stated purposes or as required by statutory retention periods. You can disconnect or delete connected mailboxes, content and your account at any time; the associated data is then deleted.
7. Your rights
Under the GDPR you have, in particular, the following rights:
- access (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction (Art. 18),
- data portability (Art. 20),
- objection to processing based on legitimate interests (Art. 21),
- withdrawal of consent with future effect (Art. 7(3)).
You also have the right to lodge a complaint with a supervisory authority, e.g. the Hessian Commissioner for Data Protection and Freedom of Information.
8. Use of Google user data (Google API Services User Data Policy / “Limited Use”)
When you connect a Google account (sign-in, Google Contacts or Google Calendar), Astreo accesses certain data of your Google account via the Google APIs. Astreo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Depending on the feature you connect, we access the following data:
- Sign-in (email, profile): name, email address, Google identifier and, if available, profile picture — for authentication.
- Google Contacts (.../auth/contacts): reading and writing your contacts for the address book and contact management in the client.
- Google Calendar (.../auth/calendar): reading and writing events for the calendar features in the client.
No access to Gmail mailboxes: Astreo currently requests no Gmail permissions and does not read, send or store any email from a Google mailbox. The email part of the service works exclusively with mailboxes you connect via Microsoft 365/Outlook (Microsoft Graph) or via IMAP/SMTP with another provider. Should a Gmail connection be offered in the future, it would require your separate consent and a prior update of this privacy policy.
For this data, in particular:
- We use it solely to provide and improve the user-facing features of Astreo that you use.
- We do not transfer it to third parties except as necessary to provide or improve these features, to comply with applicable law, for security purposes (e.g. abuse/malware prevention), or with your explicit consent.
- We do not use it for advertising and do not transfer it for advertising purposes.
- Humans do not read this data unless you have given explicit consent, it is necessary for security or to comply with applicable law, or the data is aggregated and anonymized.
This data is encrypted in transit and at rest and is subject to the same safeguards as all other sensitive data — the details are set out in section 9 (“Data security — how we protect sensitive data”).
You can disconnect connected Google accounts in Astreo at any time; you can additionally revoke granted permissions at myaccount.google.com/permissions.
9. Data security — how we protect sensitive data
We treat email content, attachments, contacts, calendar entries and all credentials — including all user data obtained through the Google APIs (Google Contacts, Google Calendar) — as sensitive data. We protect it with the following technical and organizational measures (Art. 32 GDPR):
- Encryption in transit: All traffic between your browser and Astreo uses HTTPS/TLS (TLS 1.2 or higher) only; plain HTTP requests are force-redirected to HTTPS. Mail retrieval and sending against Microsoft Graph and IMAP/SMTP servers, as well as all calls to the Google APIs (Contacts, Calendar), are likewise TLS-encrypted throughout (IMAPS/SMTPS or STARTTLS).
- Encryption at rest: OAuth tokens (including Google tokens), IMAP/SMTP passwords and two-factor secrets are stored encrypted with AES-256-GCM. The key is held outside the database in the server configuration with file permissions restricted to the service account. Account passwords are stored only as an argon2 hash.
- Strict tenant isolation: Every record is bound to a single user account, and all data access goes through one central layer that filters server-side by the authenticated account. Accessing another user's data through the application is technically not possible.
- Restricted access and least privilege: Server and database access is limited to a small number of named administrators via SSH key pairs only. The database is not reachable from the internet. Administrative access happens solely for operations, troubleshooting or security purposes; our staff do not read mail, contact or calendar content (see section 8). Everyone with access is bound by confidentiality obligations.
- Application hardening: Security headers (including HSTS, Content-Security-Policy, X-Content-Type-Options), session cookies set as httpOnly, secure and SameSite, revocable sessions, mandatory two-factor authentication for password sign-in, and rate limiting against automated access.
- Data minimization: We request only the scopes required for the feature you actively connect. Message content, attachments and credentials are never logged; error messages and logs contain no content data. Only the context selected for the invoked feature is sent to an AI provider.
- Malware scanning: Attachments are automatically scanned with ClamAV.
- Backups: Database backups stay on the same access-restricted server inside the EU, are deleted automatically after 14 days, and continue to hold credentials in encrypted form only.
- Deletion: When you disconnect a mailbox or delete your account, the associated content and the stored credentials/tokens are deleted. You can additionally revoke access directly at Google via myaccount.google.com/permissions.
- Operations and incident response: The service runs exclusively in the European Union and is patched regularly. In the event of a personal data breach we notify the competent supervisory authority within 72 hours and the affected individuals where legally required (Art. 33, 34 GDPR). Security reports are welcome at datenschutz@becom.net.
10. Changes to this privacy policy
We update this privacy policy when changes to the service or the legal situation require it. The version published on this page applies.