Privacy policy
Last updated 8 October 2026.
CySo Solutions Ltd, Cyprus ("CySo", "we") runs CySo Mail at mail-connect.cysosolutions.com. This policy explains what we process when you use it. Contact: legal@cysosolutions.com.
Our roles
For your CySo account (who you are, your company name, sign-in) we are the controller. For the email in the mailboxes you connect, your company is the controller and we act as its processor under our Data Processing Agreement.
What we process
- Account: your email address, company name, user and company identifiers; for Microsoft or Google sign-in, that provider's fixed account identifiers and the email address it reports.
- Mailbox connections: each mailbox's address and mail server names, and its app password or, for "Connect with Google/Microsoft", the access key that Google or Microsoft issued, encrypted (AES-256-GCM, a separate key for each).
- Email content: read from your mail server only when your AI app asks, and passed to that AI app. CySo does not keep copies of your emails. Drafts are saved in your own mailbox.
- Approval requests: what was asked (for example recipients, subject, which messages). The text of an email waiting to be sent is read from your Drafts when the approver looks at it.
- Security records: an activity log of what each AI app did (tool, time, result; message identifiers are hashed, no content), and keyed fingerprints of addresses and values seen in email, used to require approval when an AI tries to reuse them. They contain no readable email text.
- AI app access: which AI apps you allowed and at what level; access tokens are stored only as hashes.
- Billing: your subscription status and Stripe's customer and subscription identifiers. Payments, card details, billing address and VAT number are handled by Stripe (Stripe Payments Europe, Ireland) under its own privacy policy; CySo never sees your card number.
- Drive (optional): if you connect Google Drive or OneDrive, an access key limited to CySo's own folder in your Drive, encrypted. Attachments you or your AI save are copied straight into that folder (or a sub-folder you name); CySo does not keep a copy.
Where
CySo Mail runs on Cloudflare. Account, mailbox, approval and log data are stored in Cloudflare's EU jurisdiction. AI app access records are kept in Cloudflare's global key-value store (hashed tokens and identifiers). Sign-in and alert emails are sent from CySo's own mail server in the EU.
If you connect Telegram, approval requests, including the text of an email waiting to be sent, are delivered to your Telegram chat. Telegram is operated outside the EU. Connecting it is optional; without it, approvals work by email and on this website.
The AI app you connect (for example Claude or ChatGPT) receives the email content you ask it to read, under your own agreement with that provider.
How long
- Sign-in links: 15 minutes. Telegram pairing codes: 10 minutes.
- Approval requests: up to 7 days while open; decided requests are kept up to 30 days without their details.
- Activity log: 90 days.
- Mailbox passwords and access keys: until you disconnect the mailbox, then deleted at once.
- Account data: until you close the account (Settings, Your data), then deleted at once. Stripe keeps invoices for as long as tax law requires.
Why (legal basis)
To provide the service you asked for (contract), to keep it secure and prevent abuse (legitimate interest), and to meet legal duties.
Your rights
You can ask for access, correction, deletion, restriction, portability, or object to processing, by writing to legal@cysosolutions.com. You may also complain to the Commissioner for Personal Data Protection in Cyprus.
Security
Mailbox passwords are encrypted before they leave your browser and stored encrypted. Every company's data is kept apart. Sending, permanent deletion and new mailboxes always need a person's approval.