Privacy Policy
Last updated: 20 March 2026
Data Controller: Qytos SAS · yves@qytos.eu
Last updated: 20 March 2026
Data Controller: Qytos SAS · yves@qytos.eu
This Privacy Policy explains how Qytos SAS ("Qytos", "we", "us", "our"), the company behind the Mailflair email security service, collects, uses, stores and protects your personal data when you use our website at www.qytos.eu and our application at app.mailflair.com (collectively, the "Service").
We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Luxembourg data protection law.
The data controller responsible for your personal data is:
Qytos SAS
6 rue de l'École
L-7391 Blaschette, Luxembourg
Email: yves@qytos.eu
Phone: +33 6 70 48 45 84
For any data protection enquiries, you may contact us directly at the address above.
We collect the following categories of personal data:
When you connect your email account to Mailflair, we process the following data from your emails for the purpose of threat analysis:
We process your personal data only where we have a valid legal basis under Article 6 GDPR:
| Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|
| Providing the Mailflair email security service | Art. 6(1)(b) — Performance of a contract |
| Account creation and management | Art. 6(1)(b) — Performance of a contract |
| Processing payments | Art. 6(1)(b) — Performance of a contract |
| Sending service notifications and alerts | Art. 6(1)(b) — Performance of a contract |
| Improving and developing the service | Art. 6(1)(f) — Legitimate interests |
| Security monitoring and fraud prevention | Art. 6(1)(f) — Legitimate interests |
| Sending marketing communications (where consented) | Art. 6(1)(a) — Consent |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation |
We retain your personal data only for as long as necessary for the purposes described in this policy:
All personal data is processed and stored exclusively within the European Union. We use infrastructure located in ISO 27001-certified EU data centres.
We implement the following security measures:
Despite these measures, no internet transmission or storage system is 100% secure. If you suspect unauthorised access to your account, please contact us immediately at yves@qytos.eu.
We do not sell, rent or trade your personal data to third parties. We may share data in the following limited circumstances:
We use trusted third-party service providers who process data on our behalf, including:
All processors are bound by Data Processing Agreements (DPAs) and may only process your data on our documented instructions.
We may disclose your data to law enforcement or regulatory authorities if required by applicable law, a court order, or to protect the rights and safety of our users or the public.
In the event of a merger, acquisition or sale of assets, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website before your data becomes subject to a different privacy policy.
As a data subject, you have the following rights under the GDPR. To exercise any of these rights, contact us at yves@qytos.eu. We will respond within 30 days.
Our website uses cookies and similar tracking technologies. We use:
You can manage or disable cookies through your browser settings. Note that disabling cookies may affect the functionality of the service.
The Mailflair service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact us at yves@qytos.eu and we will promptly delete it.
All personal data is processed and stored within the European Union. We do not transfer personal data to countries outside the EU/EEA. If this changes in the future, we will ensure appropriate safeguards are in place (such as Standard Contractual Clauses) and will update this policy accordingly.
As Qytos SAS is established in Luxembourg, the competent supervisory authority is:
Commission Nationale pour la Protection des Données (CNPD)
15, boulevard du Jazz
L-4370 Belvaux, Luxembourg
Website: cnpd.public.lu
Phone: +352 26 10 60 1
You have the right to lodge a complaint with the CNPD if you believe we have processed your data unlawfully. You may also contact the data protection authority in your own country of residence.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. We will notify you of any significant changes by email and by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
If you have any questions, concerns or requests regarding this Privacy Policy or our data practices, please contact us:
Qytos SAS — Data Protection
Email: yves@qytos.eu
Phone: +33 6 70 48 45 84
Address: 6 rue de l'École, L-7391 Blaschette, Luxembourg