What we collect, where it is stored, who can reach it, and the rights you have over it.
Last updated: 10 September 2026. This policy covers both this website and the email service.
Asia Mail Services operates the email hosting service and this website, and is responsible for the personal data described below. For questions about this policy, or to exercise any of the rights in section 9, write to contact@asiamailservices.com.
Where we host mailboxes for a company, that company is the controller of the correspondence in those mailboxes and we act as its processor, handling that content on its instructions and to provide the service.
Company name and registration details, the verification document provided at signup, contact name, email address and telephone number, billing details, and the domains you host with us.
The messages, attachments, calendar entries and contacts stored in your mailboxes. We store this in order to deliver the service. We do not read it for advertising, we do not analyse it to build profiles, and we do not sell or share it.
Mail server logs recording the sender, recipient, timestamp, size, IP address and delivery result of each message; authentication logs recording connections to mailboxes; and spam and malware filtering results. These are necessary to operate a mail service, to diagnose delivery problems and to detect abuse.
This website sets no cookies, runs no analytics, and loads no fonts, scripts or resources from third parties. Our web server keeps standard access logs — IP address, timestamp, page requested — for security purposes.
We publish this in full because it is verifiable, and because for some of our customers it is a condition of doing business at all.
We are working to move mailbox storage to Hong Kong so that message content remains in Asia end to end. Until that work is complete, the description above is accurate and we will not present it otherwise. If the current storage location is incompatible with your requirements, tell us before you subscribe.
Because your correspondence crosses borders by its nature — that is the service — personal data is transferred internationally: between Hong Kong, the United States, and wherever your recipients' mail providers are located. Where we rely on a service provider outside your jurisdiction, we do so under contractual terms requiring confidentiality and appropriate security measures.
If you are subject to the PIPL in mainland China, note that using any email service hosted outside the mainland involves a cross-border transfer of personal information, and that you remain responsible for the consents and assessments the PIPL requires of you as the controller of your correspondence.
We use a small number of infrastructure providers: a hosting provider in Hong Kong for the mail gateway, a hosting provider in the United States for mailbox storage, an encrypted backup storage provider, and Cloudflare for DNS. They act on our instructions and have no right to use your data for their own purposes. We will identify each of them by name on request from a customer.
We do not use advertising networks, analytics providers or data brokers, and we do not sell personal data to anyone.
We disclose customer data to an authority only where we are legally required to do so, and only to the extent required. Where we are lawfully permitted to inform the customer of a request, we will do so, so that the customer can respond to it. We do not provide bulk or voluntary access to correspondence.
Depending on where you are, you have rights to access the personal data we hold about you, to have it corrected, to have it deleted, to obtain a copy in a portable format, to object to certain processing, and to know with whom it has been shared. This includes rights under the Brazilian LGPD and, for individuals in mainland China, under the PIPL.
Write to contact@asiamailservices.com and we will respond within 30 days. If you are an employee of a customer company, we will normally direct your request to that company, since it controls the mailbox — and we will tell you that we have done so.
Mail is encrypted in transit using TLS wherever the receiving server supports it, and all client connections require encryption. Mailbox storage is encrypted at rest and backups are encrypted before leaving the server. Administrative access is restricted to named individuals using key-based authentication, and the storage system does not accept connections from the public internet.
If a breach occurs that is likely to affect your rights, we will notify affected customers and the relevant authority without undue delay, with what we know and what we are doing about it.
We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect. The date at the top of this page always shows the current version.
Privacy questions and rights requests:
contact@asiamailservices.com
Abuse and security: abuse@asiamailservices.com