Skip to content

This document is published in English only. It is the authoritative version.

ObsidianCorps | Legal & Privacy

Privacy Notice

Managed Email Hosting Service

How personal data is processed when you buy, administer or use email hosting supplied by Obsidiancorps and powered by Qboxmail.

Version 1.0 · Effective 6 August 2026

Who is responsible

Controller and provider
Obsidiancorps S.à r.l.-S.
Registered office
1, rue Pasteur, L-4642 Differdange, Luxembourg
Registration
RCS B294975  |  VAT LU36465320
Privacy contact
info@obsidiancorps.com  |  +352 691 165 856
Applies to
Customers, account administrators, mailbox users and external correspondents
Related documents
Email Hosting Terms and Conditions, accepted Order and website Privacy Policy

Purpose of this notice

This notice is specific to the managed email hosting service. It complements the general Privacy Policy published on obsidiancorps.com and explains the different data-protection roles that apply to business customers, private subscribers, mailbox users and Qboxmail.

Please read this notice before ordering or using the Service. Business customers must also provide their own privacy information to employees, contractors, customers and other individuals whose personal data they process through hosted mailboxes.

Privacy at a glance

Contract, billing and support
Obsidiancorps is the data controller for customer details, orders, invoices, support communications and the security of its own service administration.
Business mailbox content
The business or professional customer normally decides why mailbox content is processed. It is therefore normally the controller, Obsidiancorps is its processor, and Qboxmail is a sub-processor.
Personal-use subscriptions
For an individual using the Service mainly for personal purposes, Obsidiancorps is the controller for processing needed to provide, manage and secure the Service. Qboxmail processes hosted content on our behalf.
Qboxmail technical processing
Qboxmail separately acts as controller for limited platform-use information and logs that it processes for technical support, antispam, antivirus, fraud prevention and platform security.
Storage location
Qboxmail commits to hosting mailbox data and backups in facilities located in the European Economic Area.
Data sales and profiling
Obsidiancorps does not sell hosted personal data and does not use mailbox content for behavioural advertising or automated decisions producing legal or similarly significant effects.
Your contact point
Privacy requests concerning Obsidiancorps processing can be sent to info@obsidiancorps.com. Business mailbox users should normally contact their employer or the organisation that provided the mailbox first.

How to use this notice

The correct contact and legal role depend on the context in which the mailbox is used:

  • A customer buying the Service directly should contact Obsidiancorps about orders, invoices, support, account administration and personal-use mailbox processing.
  • An employee, contractor or other user of a business mailbox should normally contact the organisation that issued the mailbox, because that organisation decides the purposes of the mailbox processing.
  • An external sender or recipient should contact the owner of the relevant mailbox or domain. Obsidiancorps will assist the controlling customer where required by the GDPR and the applicable data-processing agreement.

NO CHANGE TO CONFIDENTIALITY

Obsidiancorps and Qboxmail process mailbox data only as necessary to provide, secure, maintain and support the Service, to follow the controlling customer’s documented instructions, or to comply with binding law. Human access to message content is restricted and is not part of routine service monitoring.

1. Who we are

1.1 Obsidiancorps S.à r.l.-S. is a Luxembourg company registered with the Luxembourg Trade and Companies Register under number B294975, with registered office at 1, rue Pasteur, L-4642 Differdange, Luxembourg. Its VAT number is LU36465320.

1.2 Obsidiancorps supplies and manages email hosting services, including account creation, secure configuration, customer administration, monitoring, log review, support, migration assistance and optional archive or restore services.

1.3 Privacy questions and requests may be sent to info@obsidiancorps.com or by post to the registered office above. Please mark postal correspondence for the attention of Privacy.

2. Scope and data-protection roles

2.1 This notice applies to personal data processed in connection with quotations, orders, account setup, domain configuration, hosted email, contacts, calendars, tasks, webmail, mobile synchronisation, administration, monitoring, support, migration, backup restore and the optional Security Email Archive.

2.2 Obsidiancorps acts as data controller when it determines why and how personal data is used for its own contract management, invoicing, customer communications, service security, legal compliance, service improvement and direct relationship with a personal-use subscriber.

2.3 For a business or professional customer, the customer normally acts as data controller for mailbox content, address books, calendars, tasks, employee account data and other personal data processed through the Service. In that context, Obsidiancorps acts as data processor and Qboxmail acts as sub-processor.

2.4 The customer is responsible for determining lawful purposes and legal bases, providing required notices, managing user permissions, selecting suitable security settings, handling data-subject requests and deciding retention periods for the personal data it controls.

2.5 For an individual personal-use subscriber, the household exemption may mean that the individual is not acting as a GDPR controller. In that case, Obsidiancorps acts as controller for the processing needed to provide, administer and secure the Service, and Qboxmail acts as processor for hosted content except where Qboxmail independently determines limited technical processing described in section 7.

2.6 This notice does not replace a business customer’s own employee, customer, supplier or website privacy notice. It also does not govern websites, apps or integrations operated by third parties.

3. Personal data we process

Category Examples
Customer and account data Name, organisation, job title, billing address, service address, telephone number, email address, customer reference, domain name, authorised contacts and account administrator details.
Order and billing data Plan, mailbox quantity, storage option, optional services, prices, invoices, payment status, transaction references, VAT information and accounting correspondence. Full payment-card details are not intentionally stored by Obsidiancorps unless explicitly stated by the selected payment method.
Mailbox and collaboration data Email addresses, message content, attachments, drafts, folders, address books, contact entries, calendars, appointments, tasks, signatures, shared resources and ActiveSync data.
Message metadata Sender, recipients, subject line, message ID, routing information, IP addresses, sending and receipt date and time, delivery status, spam score, attachment indicators and message size.
Technical and security data Username, authentication events, IP address, approximate location inferred from IP, device or software characteristics, browser, protocol used, action performed, outcome, audit logs, password-policy events, two-factor authentication status and security alerts.
Support and administration data Support requests, configuration details, screenshots, diagnostic information, administrator instructions, log extracts, migration files, restore requests and communications with the customer or user.
Archive and backup data Read-only snapshots, archived sent and received messages, archive search criteria, export records, restore date, restore status and administrator approval records.
Preferences and communications Language, notification settings, service-message preferences, consent records and marketing choices where applicable.

4. Where the data comes from

We may obtain personal data directly from the customer or user, from an organisation’s authorised administrator, from the operation of the Service, from external senders and recipients, from a previous mail provider during an authorised migration, from domain or DNS records, from payment and accounting providers, or from public authorities where permitted by law.

When a business customer supplies personal data about mailbox users or other people, the customer confirms that it is authorised to do so and that it has provided any information required by Articles 13 or 14 of the GDPR.

SENSITIVE INFORMATION

Email can contain health information, political opinions, trade-union information, biometric data, criminal-offence data or other sensitive material. Obsidiancorps does not ask customers to place this information in email. The controlling customer or user must assess whether email is appropriate, apply additional safeguards where needed and avoid sending sensitive data when a safer method is required.

5. Why we process personal data and our legal bases

Purpose Main data Legal basis / role
Prepare a quotation, verify authority and create an order Customer, contact, domain, plan and billing details Steps before a contract and performance of a contract, Article 6(1)(b) GDPR.
Create, configure and administer domains, mailboxes and user permissions Account, domain, administrator, user identity and configuration data Contract performance for direct subscribers. For business mailbox data, documented controller instructions under Article 28 GDPR.
Provide email, webmail, contacts, calendars, tasks, synchronisation and related functions Mailbox content, collaboration data, metadata and credentials Contract performance or processing on behalf of the customer as controller.
Protect accounts and infrastructure, prevent abuse and investigate incidents Authentication, device, IP, message metadata, antispam and antivirus indicators, logs and alerts Contract performance, compliance with legal duties, and legitimate interests in confidentiality, integrity, availability, fraud prevention and service protection, Article 6(1)(f).
Provide support, migration, troubleshooting, monitoring and log review Support communications, configuration, logs, migration data and limited content where strictly necessary Contract performance or controller instructions. Legitimate interests in diagnosing faults and maintaining service quality.
Provide Security Email Archive and backup restore Messages, attachments, metadata, archive searches, exports and restore records Contract performance and customer instructions. Retention is selected by the customer within available limits.
Invoice, collect payment, keep accounts and meet tax obligations Order, billing, payment status, VAT and correspondence Legal obligations, Article 6(1)(c), and contract performance.
Send operational notices and manage renewals, price changes and service updates Customer contact, plan, renewal date and communication history Contract performance and legitimate interests in administering the customer relationship.
Defend legal claims, enforce acceptable use and respond to authorities Account, billing, logs, content and support data where relevant Legal obligation, Article 6(1)(c), and legitimate interests in establishing, exercising or defending legal claims, Article 6(1)(f).
Send optional marketing communications Contact details, preferences and consent record Consent, or another basis permitted by applicable electronic-communications law. Marketing can be stopped at any time.

Where processing is based on legitimate interests, Obsidiancorps balances those interests against the rights and freedoms of the individuals concerned. Further information about a specific balancing assessment may be requested.

Providing information required to create and operate an account is generally necessary. Without it, Obsidiancorps may be unable to enter into the contract, activate the Service, maintain security or provide support.

6. Managed administration and access to data

6.1 The managed nature of the Service means that authorised Obsidiancorps personnel may access the Qboxmail control panel, account settings, domain configuration, audit information and logs to create accounts, apply secure settings, investigate faults, monitor service health, respond to security events and follow customer instructions.

6.2 Routine monitoring is designed around status information, metadata, audit events and logs. Obsidiancorps does not routinely read message content. Content may be accessed only where it is necessary for a specific support, migration, restore, security or legal task and where access is authorised or otherwise permitted by law.

6.3 Access is limited according to job responsibilities and the principle of least privilege. Personnel and contractors with access are subject to confidentiality obligations and security requirements.

6.4 A business customer is responsible for determining who may request account changes, password resets, exports, archive searches or restore operations. Obsidiancorps may require verification or administrator approval before acting.

6.5 When investigating suspected compromise, spam, malware, unlawful use or an abuse complaint, Obsidiancorps and Qboxmail may process relevant logs, message metadata, security indicators and, where strictly necessary, affected content. Accounts may be restricted or suspended as described in the Email Hosting Terms and Conditions.

7. Qboxmail and other recipients

7.1 Qboxmail

The underlying hosting platform is supplied by Qboxmail S.r.l., Via Pollative 111/o, 59100 Prato (PO), Italy, VAT number IT02338120971. Qboxmail provides the mail servers, webmail, control panel, backup, archive and related infrastructure.

For mailbox content and customer-controlled collaboration data, Qboxmail acts as a processor or sub-processor. It may store data, make backup copies, provide security functions and perform operations needed to deliver the service or requested by Obsidiancorps on the controlling customer’s behalf.

Qboxmail separately acts as data controller for limited service-user data that it determines is necessary for technical support, antispam, antivirus, service-use controls, technical inspections, maintenance, fraud and abuse prevention, cooperation with authorities and aggregate statistics. This may include IP addresses, device and browser information, usernames, actions and outcomes, and message metadata such as sender, recipient, subject and message ID.

7.2 Other recipient categories

  • Authorised Obsidiancorps employees, contractors and professional advisers who need access for service delivery, security, accounting, audit or legal advice.
  • Qboxmail providers involved in antispam, antivirus and user-trustworthiness verification, subject to Qboxmail’s own GDPR arrangements.
  • Banks, payment providers, accountants, auditors and tax advisers involved in billing, payment and legal compliance.
  • Domain registrars, DNS providers, migration sources and other technical providers where needed for a customer-requested setup or migration.
  • Third-party integration providers selected or enabled by the customer or user. Their own privacy notices apply to data they receive.
  • External email recipients and their mail providers, because sending an email necessarily discloses the message and addressing data to the intended recipients and the systems used to deliver it.
  • Courts, regulators, law-enforcement bodies and other competent authorities where disclosure is legally required or necessary to protect rights, users or infrastructure.

Obsidiancorps does not sell hosted personal data. It does not disclose mailbox content to advertisers or use mailbox content to build advertising profiles.

8. International transfers

8.1 Qboxmail’s Data Processing Agreement states that customer-hosted data and its backups are hosted only in facilities located in the European Economic Area. Qboxmail may provide the general area of the facilities on request, while withholding exact data-centre addresses for security reasons.

8.2 Qboxmail states that certain providers used for its independent service-user security processing may be located in the United States. Qboxmail states that it uses processor contracts and European Commission Standard Contractual Clauses for those transfers.

8.3 Email is a global communications system. When a user sends a message to a recipient outside the EEA, the message may be transmitted to and stored by that recipient or its mail provider in another country. That transfer is initiated by the user or controlling customer.

8.4 Customer-selected integrations or external clients may also transfer data outside the EEA. Customers should review the relevant provider’s privacy terms and ensure an appropriate transfer mechanism where they are acting as controller.

8.5 A copy or summary of applicable transfer safeguards may be requested, subject to necessary redactions for confidentiality and security.

9. How long we keep personal data

Personal data is kept only for as long as necessary for the purpose for which it is processed, subject to legal obligations, security needs, technical backup cycles and the controlling customer’s instructions.

Data or service Typical retention
Customer, order and service-administration records For the active customer relationship and afterwards for as long as reasonably needed to resolve disputes, enforce the contract or comply with applicable limitation periods.
Accounting records, invoices and related business correspondence Generally 10 years from the end of the financial year to which the records relate, as required for Luxembourg accounting purposes.
Active mailbox, contact, calendar and task data For the active service period, until deleted by the authorised user or customer, or until the account is terminated and the deletion cycle is completed.
Trash and Quarantine / Spam items Items placed in Trash are automatically deleted after 30 calendar days. Quarantined messages are automatically and permanently deleted after 30 calendar days.
Mail Time Machine backup snapshots Automatic read-only snapshots are normally created daily and retained for 15 days. Recovery is not guaranteed and depends on the data being present on the server at the backup time.
Security Email Archive For the retention period selected in the Order or administration settings, up to a maximum of 10 years. Archive retention is separate from the ordinary mailbox lifecycle.
After service termination or definitive deletion Qboxmail’s DPA states that processor data is retained for an additional 30 days after the service contract ends and then erased, subject to technical backup limitations. Qboxmail also states that data subject to a definitive deletion request is removed from every system within 60 days unless law requires otherwise.
Qboxmail independent service-user logs Qboxmail states that relevant logs may be retained for up to 12 months to detect and suppress criminal offences and up to 72 months for prevention of terrorism and organised crime, where applicable law permits or requires this.
Support and incident records For the period needed to complete the request, document actions, maintain security and establish or defend legal claims. Unnecessary attachments and diagnostic data are removed or minimised where practical.
Marketing preferences Until consent is withdrawn or the marketing purpose ends. A minimal suppression record may be retained to respect an opt-out.

EXPORT BEFORE CANCELLATION

Customers and users should export required messages, contacts, calendars and other data before cancellation or deletion. Backup and archive services are not substitutes for a customer-controlled business continuity or records-management plan.

10. Security measures

Obsidiancorps and Qboxmail use technical and organisational measures designed to protect personal data against unauthorised access, unlawful use, accidental loss, destruction or alteration. Measures vary according to the selected plan and configuration and may include:

  • TLS encryption for webmail, POP, IMAP and SMTP connections, with encrypted authentication.
  • Antivirus, antispam, malware detection, reputation checks and quarantine controls for incoming and outgoing mail.
  • Two-factor authentication, IP restrictions, password expiry and password-reuse controls where available under the selected plan.
  • Role-based access, least privilege, authorised personnel, confidentiality duties and monitoring of administrator activity.
  • Firewalls, physical data-centre controls, redundancy, power and environmental protections, vulnerability management and incident procedures.
  • Automatic daily mailbox snapshots retained for 15 days and additional disaster-recovery backups not directly accessible by customers.

No internet or email service can be guaranteed to be completely secure or error-free. Users must protect credentials, enable available security features, keep devices and software supported and updated, avoid forwarding one-time codes, and promptly report suspected compromise.

11. Personal data breaches

Obsidiancorps maintains procedures for identifying, assessing and responding to personal data breaches. Qboxmail has contractually committed to notify Obsidiancorps promptly of a breach affecting data it processes on our behalf.

Where Obsidiancorps is the controller, it will notify the CNPD and affected individuals when required by the GDPR. Where a business customer is the controller, Obsidiancorps will provide reasonable information and assistance so the customer can meet its own notification duties. Customers must provide accurate incident contacts and cooperate promptly with investigations.

12. Your data-protection rights

Subject to the conditions and exceptions in the GDPR, you may have the right to:

Access
ask whether personal data is processed and obtain a copy and related information.
Rectification
ask for inaccurate or incomplete personal data to be corrected.
Erasure
ask for personal data to be deleted where there is no continuing lawful reason to keep it.
Restriction
ask for processing to be limited in specified circumstances.
Portability
receive data you provided in a structured, commonly used and machine-readable format where processing is automated and based on consent or contract.
Object
object to processing based on legitimate interests for reasons relating to your situation, and object at any time to direct marketing.
Withdraw consent
withdraw consent at any time without affecting processing that was lawful before withdrawal.
Complain
lodge a complaint with a supervisory authority, particularly in the country of habitual residence, place of work or alleged infringement.

12.1 Where to send a request

Requests concerning customer accounts, personal-use subscriptions, Obsidiancorps billing, support or service-administration processing should be sent to info@obsidiancorps.com. Please describe the request and identify the relevant account or mailbox without sending a password.

A user of a business mailbox should normally send the request to the business or organisation that issued the account. If the request is sent to Obsidiancorps and the business customer is the controller, Obsidiancorps may forward the request to that customer and assist it in responding.

Qboxmail requests concerning processing for which Qboxmail independently acts as controller can be directed to Qboxmail or its Data Protection Officer using the contact details published in Qboxmail’s service-user privacy policy.

12.2 Verification and response time

Obsidiancorps may request information needed to verify identity and authority, particularly where a request concerns mailbox content or administrator access. Requests are generally answered within one month. That period may be extended by up to two additional months for complex or numerous requests, with notice of the extension and reasons.

Rights are not absolute. A request may be limited where necessary to protect another person’s rights, preserve confidentiality of correspondence, comply with law, maintain security, protect legal privilege or retain records required for accounting or legal claims. Reasons will be provided where required.

13. Complaints to the CNPD

You may lodge a complaint with the Luxembourg National Commission for Data Protection if you believe personal data has been processed in breach of the GDPR. The CNPD recommends contacting the controller first where practical.

Authority
Commission nationale pour la protection des données (CNPD)
Complaints service
Service des réclamations
Address
15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg
Website
cnpd.public.lu

You may also complain to another competent supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement.

14. Children and authorised users

The Service is not offered for a child to purchase directly. A parent, guardian or organisation must create and administer an account for a minor where lawful and appropriate. Business customers are responsible for determining whether users may include minors and for providing age-appropriate notices and safeguards.

If you believe a child’s personal data has been provided without appropriate authority, contact Obsidiancorps so the circumstances can be reviewed.

15. Automated decision-making

Obsidiancorps does not use personal data from the Service to make decisions based solely on automated processing that produce legal effects or similarly significant effects for an individual. Automated antispam, antivirus, reputation and security systems classify or restrict messages and sessions to protect the Service. Users or administrators can review quarantine and support outcomes as described in the Service documentation.

16. Changes to this notice

This notice may be updated when the Service, suppliers, legal requirements or processing activities change. The current version will be published on obsidiancorps.com with its effective date. Material changes may also be communicated to the customer contact by email or through the customer area where appropriate.

A change to this notice does not by itself change the price or annual term of the Service. Pricing changes remain governed by the Email Hosting Terms and Conditions and apply only as stated there.

Schedule 1 — Business customer privacy responsibilities

This Schedule is a practical summary for a business or professional customer acting as controller. It does not replace the customer’s own legal assessment or the applicable data-processing agreement.

Privacy notice
Tell employees, contractors, customers and other relevant individuals how their personal data is processed through hosted email, identify Obsidiancorps as processor and identify Qboxmail as a sub-processor where required.
Lawful purpose and basis
Determine why each mailbox and related feature is used and identify a lawful basis for the processing, including any special-category or criminal-offence data.
Data-processing terms
Ensure an Article 28 GDPR agreement is in place with Obsidiancorps and authorise the appointment of Qboxmail and any other approved sub-processors.
Access and permissions
Authorise administrators, assign mailboxes only to appropriate users, promptly remove leavers, apply least privilege and keep contact and escalation details current.
Security settings
Choose a plan and configuration suitable for the risks, enable two-factor authentication and other available controls, protect devices and provide security awareness training.
Retention and archive
Set business retention rules, select archive periods, export required records before deletion and avoid relying solely on operational backups.
Rights requests
Provide a channel for users and correspondents to exercise their rights and instruct Obsidiancorps when assistance is needed.
Incident response
Notify Obsidiancorps promptly of suspected compromise, preserve relevant information, cooperate with investigation and make any controller notifications required by law.
Third-party integrations
Assess privacy, security and transfer implications before enabling external clients, applications, connectors or forwarding arrangements.
End of service
Plan migration or export, revoke access, confirm deletion instructions and communicate the end of service to affected users.

Schedule 2 — Contact summary

Obsidiancorps privacy requests
info@obsidiancorps.com
Obsidiancorps postal address
1, rue Pasteur, L-4642 Differdange, Luxembourg
Obsidiancorps telephone
+352 691 165 856
Qboxmail service-user privacy
See the current Privacy and Cookie Policy for users of Qboxmail services at qboxmail.com
Qboxmail Data Protection Officer
dpo@qboxmail.com
Luxembourg supervisory authority
CNPD, 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg

End of email hosting privacy notice

CONTATTACI

Contattaci

Da Obsidiancorps, fondiamo tecnologia innovativa e pratiche di sicurezza affidabili per creare soluzioni personalizzate che proteggono e valorizzano il tuo business. Contattaci e costruiamo insieme un futuro più sicuro.

Indirizzo Email

info [at] obsidiancorps.com

Posizione

Differdange, Luxembourg

Di solito rispondiamo entro 24 ore

Inviaci un Messaggio

Ci piacerebbe sentirti! Compila il modulo sottostante e il nostro team ti risponderà il prima possibile.

captcha