Privacy and Data Protection Policy

Strict transparency regarding data governance, LGPD/GDPR compliance roles, and email infrastructure security.

1. Scope and Identity

H2E Mail is an enterprise email hosting and communication platform operated by HM&C Soluções de TI, located in Brazil. This policy governs our personal data processing practices in full alignment with the Brazilian General Data Protection Law (LGPD - Law 13,709/2018).

2. Legal Roles: Controller vs. Processor

Under LGPD guidelines, responsibilities are distinct:

  • H2E Mail as Data Controller: for customer registration and billing information (contact name, company identification, phone, billing address), processed for contract performance and legal accounting obligations.
  • H2E Mail as Data Processor: for the contents of customer email boxes, attachments, and routed communications. The customer is the Data Controller, while H2E Mail acts as an infrastructure processor under contractual instructions.

3. Data Categories & Purpose

  • Billing & Account Data: account provisioning, automated renewal, customer service, and payments processed securely via PCI-compliant gateways.
  • Technical Connection Logs: origin IP addresses, timestamps, connection ports, and SMTP/IMAP transaction logs retained for 6 months as legally mandated by the Brazilian Internet Civil Rights Framework (Law 12,965/2014, Art. 15).
  • LGPD Audit Scanner (Optional): when toggled on by administrators, inbound/outbound content is scanned against regex patterns for sensitive identifiers (ID numbers, credit card sequences) strictly to trigger security alerts.

4. Message Retention & Disposal

  • Active messages: maintained throughout the active subscription term.
  • Deleted messages (Plan Retention): deleted mail is preserved in the encrypted retention store for the duration defined by the customer's plan (3 months for Essential, 1 year for Professional, 2 years for Advanced). Once expired, messages are permanently purged.
  • Account termination: mailbox data remains available for customer export for up to 30 days after cancellation, after which all mail stores are securely erased.

5. Security Measures

  • TLS 1.3 / TLS 1.2 transmission encryption for all connections;
  • Mandatory SPF, DKIM, and DMARC alignment;
  • Data at rest encryption and NVMe redundancy;
  • Automated daily snapshot backups with logical tenant isolation.

6. Data Protection Officer (DPO) Contact

To exercise privacy rights or address data governance queries, reach out directly to our Data Protection Officer:

Data Protection Officer (DPO) — H2E Mail

Email: privacidade@hmcsolucoes.com

HM&C Soluções de TI · Pindamonhangaba, São Paulo - Brazil