Mail Guardian – Privacy Policy
Mail Guardian
Privacy Policy
Safe Online ApS · CVR 38589962 · bysafeonline.com
Last updated 15 September 2026
Last updated on 15 September 2026.
Introduction
Thank you for using Mail Guardian. This cookie and privacy policy govern the Mail Guardian add-in and the website provided by bysafeonline.com ("Website") owned and operated by Safe Online ApS ("Safe Online") located at Nørrebrogade 47, 1, 2200 Copenhagen N, Denmark.
In the following, the term "Add-in" will refer to the use of Mail Guardian's add-in, which is available as a Microsoft Outlook Add-in.
Mail Guardian checks an email for Danish personal identification numbers (CPR-numre) and other personal identifiers before it is sent, and warns the person writing it. Because it reads what you are about to send, we think you are entitled to a precise account of what happens to it. That is what this page is.
Cookie Policy
What are cookies?
When you visit Safe Online's Websites you will automatically receive one or more cookies. Cookies are small text files that are stored on your browser or device. Cookies are used to recognize users and to remember you from time to time.
Does the Add-in use cookies?
No. The Mail Guardian Add-in sets no cookies and performs no tracking of your behaviour. It runs inside Outlook, does the check described below, and stops. The cookie section of this policy concerns our Website only.
What type of cookies do we use on the Website?
- Necessary cookies: placed in order to make sure that the Website works properly.
- Preference cookies: used to remember your preferences from previous sessions.
- Statistical cookies: used to measure, understand and improve the Website.
- Marketing cookies: used to market our products and measure the impact of advertisements.
How long do we store cookies?
Some cookies remain on your device for a set period specified in the cookie and are reactivated each time you visit. Others are temporary and stored only during a browser session; once you close the browser, all session cookies are deleted.
How to avoid and delete cookies
Most browsers offer private browsing, and all browsers allow you to delete cookies individually or all at once, in the browser's settings. If you use more than one browser, remember to do so in each.
Cookies from third parties and business partners
When you visit our Website, we place cookies on behalf of third parties and business partners, including analytics and advertising services. None of these operate in the Add-in.
Privacy Policy
Introduction
This privacy policy describes how Safe Online collects and processes the personal data you provide, and the data we collect when you use our Website and the Mail Guardian Add-in.
Safe Online respects all wishes for the confidentiality of personal data and we strive to ensure that all personal data is processed securely and appropriately.
Who is responsible for your data
Mail Guardian is deployed by an organisation for its own staff. That organisation decides why and how the Add-in is used and is the data controller. Safe Online operates the service on its instructions and is the data processor. The terms are set out in a Data Processing Agreement between Safe Online and your organisation.
In practice this means that if you want to see, correct or object to data held about you through the Add-in, the request goes to your employer, not to us. We assist them in answering it.
For the Website, and for the contact details you give us directly, Safe Online is the controller.
What is personal data?
Personal data is any kind of information that can be attributed to a natural person, even though this requires knowledge of, for example, a personal identification number or an address.
A distinction is made between "Sensitive Personal Data", "Personal Data" and "Personal Data About Criminal Offences and Convictions". Sensitive Personal Data is information about race or ethnic origin, political, religious or philosophical beliefs or union affiliation, genetic or biometric data used to identify a person, health data, and sexual orientation.
What the Add-in reads
At the moment you press Send, and only then, the Add-in reads:
- the body of the message you are sending, and
- the contents of its attachments.
It does not read your inbox, your other messages, your calendar, or anything you have already sent. It does not run when you are not sending.
What leaves your device
The text of the message body and of its attachments is sent to Safe Online's service for analysis. That service runs in the European Union (Stockholm, Sweden). The text is analysed in memory and discarded when the answer comes back. It is not written to storage, and it is not written to our logs.
Attachments that cannot be read as text — a scanned document or a photograph — are additionally sent to Microsoft's Azure AI Document Intelligence service (West Europe region) to convert the image into text. Word documents, spreadsheets and ordinary PDFs are read directly and do not go through this step. Microsoft retains a submitted document for up to 24 hours, encrypted and in the same region, in order to return the result, and states that customer data is not used to train Microsoft's models.
What never leaves your device: the recipients of the message, its subject line, its message identifier, and the filenames of its attachments. None of these is sent to us, and none is stored.
What Personal Data do we collect and keep?
If no warning appears, nothing is kept. A check that finds nothing leaves no record of any kind.
Where a warning is shown, we keep:
- Warning Data: the category of what was detected — for example "CPR number" — never the number itself; a short masked extract in which the detected identifier is replaced by a placeholder; the team, an internal identifier for the user, and the time.
- Feedback Data: where a user sends feedback on a detection or acknowledges a specific finding, that action, in the same masked form.
- Coverage Data: where a message was sent without being checked — because a sign-in failed or the check timed out — the fact that it happened and why, so your organisation can tell whether the protection was working. This contains no message content of any kind.
- Profile Data: for the Website and for support, the name and email address you provide.
Warning Data records that a warning was displayed. It does not record what you then chose to do. If you corrected the message, sent it anyway, or cancelled, the record is identical. The Add-in cannot observe that choice and we do not infer it.
Why do we collect personal data?
To provide the Add-in; to enable your organisation to measure how often warnings occur and report on it internally; to tell your organisation whether the protection was working; and to improve detection accuracy for your organisation.
What we do not do
- We do not use these records to build a profile of you or to assess your performance.
- We do not use your organisation's Content, masked extracts, or any record relating to a user to improve detection for any other customer. Aggregate detection statistics — how often a rule fires and how accurate it proves to be — are used to improve the detection engine that all customers use. Nothing that identifies your organisation, and no content of any kind, is used for that purpose.
- We do not sell data, and Warning, Feedback and Coverage Data are never used for advertising.
- We do not store any unmasked personal identifier at any point.
Who do we share your personal data with?
- Hosting and storage: all Add-in data is stored and processed by Supabase Pte. Ltd, in the European Union — Amazon Web Services region eu-north-1, Stockholm, Sweden.
- Optical character recognition: attachments that cannot be read as text are processed by Microsoft (Azure AI Document Intelligence), European Union — West Europe region.
- Sign-in: the Add-in authenticates you against your own organisation's Microsoft Entra directory. That is your employer's Microsoft environment under their own agreement with Microsoft, not ours.
- Legal compliance or dispute: we may share data where required by applicable law, regulation, legal process or governmental request.
No artificial-intelligence or machine-learning provider analyses your message for personal data. The detection itself is performed by Safe Online's own software running in the environment above. Microsoft's role is limited to turning a scanned image into text, and only for attachments that cannot be read any other way.
Legal basis
For data processed through the Add-in, your organisation determines the legal basis as data controller, and states it in its own information to staff. For the Website and for direct contact with us, Safe Online processes your personal data on the basis of your consent or where processing is necessary to perform a contract to which you are a party.
How long do we keep personal data?
After 90 days, no record identifies you. The internal user identifier is permanently removed and the time of the event is reduced to a date, so what remains says only that a warning of a given category was displayed somewhere in your organisation on a given day.
Your organisation may configure shorter periods than the ones above, but not longer ones. All personal data is deleted when it is no longer relevant for the purpose for which it was collected.
Protection of personal data
Personal data is encrypted in transit using TLS 1.2 or above, and at rest using AES-256.
Every record is scoped to the team that produced it, and that scoping is enforced by the database itself rather than by application code alone. The identity a record belongs to is established by our service from a verified sign-in token — it cannot be asserted by the Add-in. Access to production data is limited to named Safe Online personnel under confidentiality obligations, reviewed periodically.
Pseudonymisation is applied by design: detected identifiers are replaced by placeholders before storage, feedback records are keyed by a salted value that does not contain the detected data, and user identifiers are removed entirely after 90 days.
Cross-border transfers
All Add-in data is stored in the EU. Supabase Pte. Ltd is established in Singapore, for which the European Commission has not issued an adequacy decision; where its staff access the hosting environment from outside the European Economic Area for support, that access is covered by the EU standard contractual clauses in Supabase's own Data Processing Addendum.
Your rights as a Mail Guardian user
- You are entitled to insight into what personal data we process about you, and to request an extract.
- You are entitled to have inaccurate data about you corrected.
- You are entitled to have your personal data deleted, subject to any legal obligation on us to retain it or to defend a legal claim.
- You are entitled to have your data transferred to another data controller.
- You are entitled to object to, or request restriction of, the processing.
Because your organisation is the data controller for Add-in data, exercise these rights with your organisation; we assist them. Once a record has been de-identified after 90 days we can no longer tell which records relate to which person, and Article 11(2) GDPR applies.
After deletion we may not immediately remove residual copies from active servers or from backup systems; backups are deleted on their own cycle.
Notification of breach of the protection of your personal data
In case of a security breach that may compromise personal data, Safe Online will notify the affected organisation without undue delay, and in any case within 48 hours of becoming aware of it, with information about the extent of the breach, what data is affected, and what has been done to limit possible harm.
Inquiries about personal data
If you want to know more about the personal data we hold or have questions about the processing, please contact Safe Online's privacy officer, Sebastian Allerelli, at sal@safeonline.dk.
Complaint
If you wish to complain about Safe Online's processing and/or use of your personal data, you can do so by contacting the authorities. In Denmark, the relevant government body is Datatilsynet, Borgergade 28, 5, 1300 Kbh K, tel. +45 33 19 32 00. See more at https://www.datatilsynet.dk
Changes to our Cookie and Privacy Policy
Safe Online reserves the right to change or update this Cookie and Privacy Policy. The latest update will always be displayed at the bottom of this page. Where a change materially alters what the Add-in records or for how long, the affected organisations are notified in advance under the Data Processing Agreement.
Contact
Safe Online ApS Nørrebrogade 47, 1, 2200 Copenhagen N, Denmark Phone: +45 27772737 E-mail: support@safeonline.dk CVR-no.: DK38589962