Skip to content

Privacy notice

Last updated 2026-09-10

This notice covers the Veltic Send website and the sending service. It is written to be read, not to be survived.

Who is responsible

For this website, the controller is Kerem Sinecek, Eugen-Richter-Straße 11k, 44359 Dortmund, reachable at info@veltic.app.

For the addresses you send email to, you are the controller and Veltic Send is your processor. That relationship is governed by the data processing agreement, not by this notice.

What the service stores about a message

For every message we keep the message identifier, the sending and recipient addresses, the number of recipients, timestamps and the delivery status reported by the receiving server.

We deliberately do not store the subject line or the body. Section 3 TDDDG binds anyone involved in providing a communications service to telecommunications secrecy and permits knowledge of content only as far as operating the service requires. A subject line is content, and a delivery proof does not need it.

  • No open tracking. We do not embed pixels in your mail.
  • No click tracking. We do not rewrite your links.
  • Delivery events are kept for 90 days and then deleted.

Legal basis

Processing for the purpose of operating the service and fulfilling the contract rests on article 6(1)(b) GDPR. Storing delivery events, suppression lists and abuse signals rests on article 6(1)(f) GDPR: without them the service cannot keep its sending reputation intact, which is a legitimate interest of every customer on the platform.

Where the processing happens

Email is handed to Amazon Simple Email Service in AWS eu-north-1, Stockholm, Sweden. Message metadata is stored in Cloudflare D1 in the European Union. Both are inside the EEA, so no third country transfer takes place for the ordinary operation of the service.

Sub-processors: Amazon Web Services EMEA SARL, Luxembourg and Cloudflare Germany GmbH. Changes to this list are announced at least 30 days in advance to customers under a data processing agreement.

Your rights

You may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest. Write to the address above. You may also complain to a supervisory authority; for this operator that is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.

This website

The public Veltic Send pages set exactly one cookie, and only if you use it: choosing the light or dark theme stores that choice in a cookie named velticTheme for a year. It is strictly necessary to deliver the page you asked for in the appearance you asked for, contains no identifier and is not read anywhere else, so section 25(2) TDDDG applies and no consent banner is required.

The dashboard on send.veltic.app additionally sets a session cookie once you connect your Veltic account. That one is httpOnly, secure and holds a random value that maps to a session record; it is deleted when you sign out.

No analytics, no third party resources and no fonts loaded from anyone else's server. Server logs of the hosting provider are kept for a short period for security purposes and are not combined with anything else.