Privacy Policy
Last updated: August 2026
This privacy policy explains how personal data is processed when using the Astreo web application (app.astreo.de) and this website (astreo.de). Astreo is an email client: it connects your existing mailboxes and is not an email provider - your mailboxes remain with your respective provider (e.g. Microsoft 365/Outlook or an IMAP mailbox).
1. Controller
becom Systemhaus GmbH & Co. KGAm Feldkreuz 16a, 35578 Wetzlar, Germany
Email: datenschutz@becom.net · Phone: +49 6441 96500
No data protection officer is required by law. Please direct requests to the address above.
2. What data we process
a) Account & sign-in
Several sign-in methods are available: single sign-on via Google or Microsoft, a magic link by email (a one-time sign-in link), and email and password with mandatory two-factor authentication (TOTP). We process your name, email address, the respective provider identifier (when using SSO) and, if available, your profile picture. A password is stored solely as an argon2 hash (never in plain text); the two-factor secret is stored encrypted at rest.
b) Connected mailboxes
To retrieve and send mail, you connect your mailboxes via OAuth (Microsoft 365/Outlook) or via IMAP/SMTP with any other provider. Astreo currently does not access Gmail mailboxes (see section 8). The required credentials (OAuth tokens or IMAP/SMTP credentials) are stored encrypted at rest (AES-256-GCM). Credentials are never logged in plain text.
c) Mail content, threads & attachments
To display, search and group (thread) your mail, we store email content, metadata and attachments as part of the service. Email content is processed solely to provide the service, not for advertising or analytics, and message content is not logged. Attachments are automatically scanned for malware (ClamAV).
d) AI features (optional)
For reply suggestions, translation and grammar correction we use Mistral AI SAS, Paris, France as a processor; no key of your own is required. Which model is used can be seen in the application’s AI settings. Processing takes place in the European Union; inputs and outputs are kept there for 30 rolling days for abuse detection and are not used to train models. The data processing agreement under Art. 28 GDPR forms part of the API terms: Data Processing Agreement (Mistral AI). Only the context selected for the respective function is transmitted to the provider you chose. AI output is always an editable draft and is never sent automatically.
d1) Processing on behalf of our customers
Where a company uses Astreo, we process the contents of the mailboxes it connects on its behalf. The controller is then that company, not us. The basis is the Data Processing Agreement under Art. 28 GDPR, which also lists the sub-processors engaged. Data subjects should address their rights to the company concerned - requests that reach us are forwarded there.
e) Billing
For paid plans we use the payment provider Mollie B.V. (Keizersgracht 126, 1015 CW Amsterdam, Netherlands). Payment details such as bank or card data are processed there only and never reach us; we receive just the information required for contract and invoicing. Invoices are issued and sent by becom Systemhaus GmbH & Co. KG itself. As Astreo is offered to business customers only, we additionally process the company name, billing address, country of establishment and - for customers established elsewhere in the EU - the VAT identification number. The VAT identification number is transmitted to the EU verification service (VIES) for validation. The legal basis is Art. 6(1)(b) and (c) GDPR (performance of the contract and tax/commercial law obligations); retention follows the statutory periods (generally 10 years).
f) Website & cookies
When you visit the website, technically necessary access data is processed server-side. In the application we set a strictly necessary session cookie for sign-in. On this website we set no cookies for analytics or advertising and embed no third-party service for audience measurement. That is why there is no cookie banner here - there would be nothing to consent to.
g) Audience measurement (cookieless, on our own server)
To understand which pages are read and what we need to improve, we count page views with Umami, open-source analytics software running on a server we operate in Germany. No cookies are set, no identifiers are stored that would recognise you beyond the page view, and no data is passed to third parties - nor to any third country.
Collected are only: the page viewed, the referring page, approximate origin at country level, browser, operating system, device type and screen size. The IP address is not stored; it is used only transiently in a daily-rotating, non-reversible hash so that several views on one day are not counted twice. Beyond that day no recognition is possible. Legal basis is our legitimate interest in data-minimising audience measurement (Art. 6(1)(f) GDPR). You can object by enabling “Do Not Track” in your browser or by blocking the script.
Until 24 August 2026 this was Google Analytics 4, loaded only after consent via a cookie banner. The service has been switched off; the data collected there is not used further.
h) Demo access (demo.astreo.de)
At demo.astreo.de we provide a non-binding test environment. To use it you give us your company, name and email address and receive a one-time sign-in link. We process these three details in order to give you access to the demo. The legal basis is Art. 6(1)(b) GDPR - a step taken at your request prior to entering into a contract.
- You only receive marketing follow-up emails if you tick that box separately. The checkbox is not pre-selected, and access to the demo does not depend on it. In that case the legal basis is your consent (Art. 6(1)(a) GDPR). You may withdraw it at any time - via the unsubscribe link in any email or informally to datenschutz@becom.net. This does not affect the lawfulness of processing carried out before the withdrawal.
- We delete your details no later than 30 days after sign-up, automatically, unless another legal basis requires us to keep them. If you consented to follow-up emails, we keep your address and the record of that consent until you withdraw it.
- We keep the address in our own CRM at crm.becom.net. This is not a transfer to a third party: it is operated by the same controller named under 1.
- We accept at most three demo sign-ups per address. If you already have access, you can keep signing in via the login link.
- Everything inside the demo - mailboxes, messages, names - is made up. Real mailboxes cannot be connected there, and no email leaves the demo.
- What you do inside the demo is not analysed and not combined into a profile.
i) Online appointment booking (Brevo)
The “Book an online appointment” button lets you arrange a call with us. The link goes to meet.brevo.com, a service provided by Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany (Amtsgericht Charlottenburg, HRB 133191). Brevo GmbH is a subsidiary of Sendinblue SAS, Paris. The booking tool is not embedded in our website: simply visiting our pages loads nothing from Brevo, sends no data to Brevo and sets no cookies. You only leave our website once you click the link.
- If you book an appointment there, Brevo processes the details you enter - typically name, email address and preferred time plus any message - and the technical connection data of your visit.
- The purpose is arranging and holding the appointment, including the confirmation and reminder emails. The legal basis is Art. 6(1)(b) GDPR (a step taken at your request) or Art. 6(1)(f) GDPR (our legitimate interest in a simple way to arrange appointments).
- Brevo acts as a processor on our behalf; see section 5 below.
- Brevo's own privacy policy applies in addition to processing on their pages.
3. Hosting
Astreo runs on servers we rent from netcup GmbH (Daimlerstrasse 25, 76185 Karlsruhe, Germany); the data centres are located in Nuremberg, Germany. netcup GmbH processes the data arising from operations solely on our behalf and on our instructions, under a data processing agreement pursuant to Art. 28 GDPR.
An off-site copy of the backup is held with Hetzner Online GmbH (Industriestrasse 25, 91710 Gunzenhausen) in Germany - deliberately with a different provider, so that an outage at the hosting provider does not take the backup with it. This copy is encrypted by us before transfer; Hetzner receives no key and cannot read the contents. A data processing agreement pursuant to Art. 28 GDPR is in place for this as well.
The AI processing also takes place in the EU. The service itself does not process data in a US cloud. When using external mailboxes, the location and terms of the respective mailbox provider additionally apply.
4. Legal bases
- Art. 6(1)(b) GDPR - performance of the usage contract (providing the email client, connected mailboxes, billing).
- Art. 6(1)(f) GDPR - legitimate interest (secure and stable operation, malware scanning).
- Art. 6(1)(a) GDPR - consent (e.g. optional AI features).
5. Recipients / processors
We share personal data only where necessary to perform the contract or where a legal basis exists. This includes in particular our hosting provider netcup GmbH (Germany), Hetzner Online GmbH (Germany) for the off-site backup, the payment provider Mollie B.V. (Netherlands) and, for the AI features, Mistral AI SAS (France) and, for online appointment booking, Brevo GmbH (Germany). When using OAuth mailboxes, data is transmitted to the mailbox provider you connected. Data processing agreements under Art. 28 GDPR are in place with processors.
6. Retention
We store personal data only as long as necessary for the stated purposes or as required by statutory retention periods. You can disconnect or delete connected mailboxes, content and your account at any time; the associated data is then deleted.
Separately for demo access: the test environment itself is reset and its contents are deleted. We delete company, name and email address no later than 30 days after sign-up, automatically, unless another legal basis requires us to keep them. If you separately consented to marketing follow-up emails, we keep your address and the record of that consent until you withdraw it - after that we delete them.
7. Your rights
Under the GDPR you have, in particular, the following rights:
- access (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction (Art. 18),
- data portability (Art. 20),
- objection to processing based on legitimate interests (Art. 21),
- withdrawal of consent with future effect (Art. 7(3)).
You also have the right to lodge a complaint with a supervisory authority, e.g. the Hessian Commissioner for Data Protection and Freedom of Information.
8. Use of Google user data (Google API Services User Data Policy / “Limited Use”)
When you connect a Google account (sign-in, Google Contacts or Google Calendar), Astreo accesses certain data of your Google account via the Google APIs. Astreo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Depending on the feature you connect, we access the following data:
- Sign-in (email, profile): name, email address, Google identifier and, if available, profile picture - for authentication.
- Google Contacts (.../auth/contacts): reading and writing your contacts for the address book and contact management in the client.
- Google Calendar (.../auth/calendar): reading and writing events for the calendar features in the client.
No access to Gmail mailboxes: Astreo currently requests no Gmail permissions and does not read, send or store any email from a Google mailbox. The email part of the service works exclusively with mailboxes you connect via Microsoft 365/Outlook (Microsoft Graph) or via IMAP/SMTP with another provider. Should a Gmail connection be offered in the future, it would require your separate consent and a prior update of this privacy policy.
For this data, in particular:
- We use it solely to provide and improve the user-facing features of Astreo that you use.
- We do not transfer it to third parties except as necessary to provide or improve these features, to comply with applicable law, for security purposes (e.g. abuse/malware prevention), or with your explicit consent.
- We do not use it for advertising and do not transfer it for advertising purposes.
- Humans do not read this data unless you have given explicit consent, it is necessary for security or to comply with applicable law, or the data is aggregated and anonymized.
This data is encrypted in transit (TLS) and is subject to the same safeguards as all other sensitive data. The associated credentials (Google OAuth tokens) are stored encrypted (AES-256-GCM). Which measures apply in detail, and what each of them covers, is set out in section 9 (“Data security - how we protect sensitive data”).
You can disconnect connected Google accounts in Astreo at any time; you can additionally revoke granted permissions at myaccount.google.com/permissions.
9. Data security - how we protect sensitive data
We treat email content, attachments, contacts, calendar entries and all credentials - including all user data obtained through the Google APIs (Google Contacts, Google Calendar) - as sensitive data. We protect it with the following technical and organizational measures (Art. 32 GDPR):
- Encryption in transit: All traffic between your browser and Astreo uses HTTPS/TLS (TLS 1.2 or higher) only; plain HTTP requests are force-redirected to HTTPS. Mail retrieval and sending against Microsoft Graph and IMAP/SMTP servers, as well as all calls to the Google APIs (Contacts, Calendar), are likewise TLS-encrypted throughout (IMAPS/SMTPS or STARTTLS).
- Encryption at rest: OAuth tokens (including Google tokens), IMAP/SMTP passwords and two-factor secrets are stored encrypted with AES-256-GCM. The key is held outside the database in the server configuration with file permissions restricted to the service account. Account passwords are stored only as an argon2 hash.
- Strict tenant isolation: Every record is bound to a single user account, and all data access goes through one central layer that filters server-side by the authenticated account. Accessing another user's data through the application is technically not possible.
- Restricted access and least privilege: Server and database access is limited to a small number of named administrators via SSH key pairs only. The database is not reachable from the internet. Administrative access happens solely for operations, troubleshooting or security purposes; our staff do not read mail, contact or calendar content (see section 8). Everyone with access is bound by confidentiality obligations.
- Application hardening: Security headers (including HSTS, Content-Security-Policy, X-Content-Type-Options), session cookies set as httpOnly, secure and SameSite, revocable sessions, mandatory two-factor authentication for password sign-in, and rate limiting against automated access.
- Data minimization: We request only the scopes required for the feature you actively connect. Message content, attachments and credentials are never logged; error messages and logs contain no content data. Only the context selected for the invoked feature is sent to an AI provider.
- Malware scanning: Attachments are automatically scanned with ClamAV.
- Backups: Database backups stay on the same access-restricted server inside the EU, are deleted automatically after 14 days, and continue to hold credentials in encrypted form only.
- Deletion: When you disconnect a mailbox or delete your account, the associated content and the stored credentials/tokens are deleted. You can additionally revoke access directly at Google via myaccount.google.com/permissions.
- Operations and incident response: The service runs exclusively in the European Union and is patched regularly. In the event of a personal data breach we notify the competent supervisory authority within 72 hours and the affected individuals where legally required (Art. 33, 34 GDPR). Security reports are welcome at datenschutz@becom.net.
10. Changes to this privacy policy
We update this privacy policy when changes to the service or the legal situation require it. The version published on this page applies.