Lette lette.io

Privacy Policy

How lette.io processes and protects personal data.

1. Scope and controller

This privacy policy explains how Raphael Bicker Services (“lette.io”, “we”, “us”) processes personal data when you visit our websites, create or use a lette.io account, subscribe to our services, contact us, or use the lette.io email proxy service.

The controller responsible for this processing is:

Raphael Bicker Services

Wächselacher 23

6370 Stans

Switzerland

Phone: +41 77 280 65 57

Email: hello@lette.io

This privacy policy primarily reflects the requirements of the Swiss Federal Act on Data Protection (FADP). Where applicable, we also process personal data in accordance with the EU General Data Protection Regulation (GDPR).

2. Personal data we process

Depending on how you interact with lette.io, we may process the following categories of personal data:

  • Account and contact data, such as your name, email address, organisation and contact details
  • Authentication data received through Microsoft sign-in, such as identifiers associated with your Microsoft account and tenant
  • Service configuration data, such as configured mailboxes, tenant identifiers, email addresses and authentication settings
  • Subscription and billing data, such as your selected plan, subscription status, billing address and payment history
  • Technical data, such as IP address, browser and device information, timestamps, requested URLs and diagnostic logs
  • Communications that you send to us, including support requests and related correspondence
  • Analytics data, where permitted and as described below

We do not receive or store complete payment-card details. Payment details are entered directly into the systems of our payment processor, Stripe.

3. How we use personal data

We process personal data for the following purposes:

  • Providing, operating and securing the lette.io services
  • Creating and administering user accounts and subscriptions
  • Authenticating users and connecting configured Microsoft tenants
  • Processing payments and maintaining accounting records
  • Responding to enquiries and providing technical support
  • Detecting abuse, operational failures and security incidents
  • Improving the reliability and usability of our services
  • Measuring website usage and conversions where the required consent has been provided
  • Complying with legal and regulatory obligations

Where the GDPR applies, we rely on the performance of a contract, steps taken before entering into a contract, compliance with legal obligations, our legitimate interests in operating and securing our services, or your consent, depending on the processing concerned.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawing consent does not affect processing that took place before the withdrawal.

4. Processing of email traffic

lette.io acts as an authentication and protocol proxy between configured legacy email applications or devices and Microsoft 365. To provide this service, lette.io processes the technical information required to authenticate connections and transmit IMAP and SMTP traffic.

Depending on the protocol and operation, transmitted data may include email addresses, message headers, message content and attachments. Such data is processed only as necessary to provide, secure and troubleshoot the requested service. It is not used for advertising or analytics.

Message data is not intended to be stored permanently by lette.io. Temporary processing or buffering may occur where technically necessary for transmission, error handling or service reliability. Technical logs are designed to avoid recording message content wherever reasonably possible.

When a business customer uses lette.io to process personal data under its own responsibility, that customer is generally the controller and Raphael Bicker Services acts as a processor on the customer's behalf. The customer remains responsible for informing its users and other affected individuals about that processing.

5. Microsoft authentication

We use Microsoft services to authenticate users and connect lette.io to Microsoft 365. When you sign in or authorise access, Microsoft may process information such as your account identifier, email address, tenant identifier, IP address and device information.

Authentication tokens and related technical information are processed as required to maintain the authorised connection. Access is limited to the permissions displayed during the Microsoft authorisation process.

Microsoft processes personal data under its own applicable privacy terms. Further information is available in the Microsoft Privacy Statement .

6. Payments through Stripe

We use Stripe to process subscriptions and payments. When you begin a checkout or manage your subscription, Stripe may process your name, contact details, billing address, payment information, IP address and information about the purchased service.

Stripe may process data in countries outside Switzerland or the European Economic Area. Stripe uses recognised safeguards for international data transfers where required.

Further information is available in the Stripe Privacy Policy .

7. Website analytics

Matomo

We use a self-hosted Matomo instance to obtain basic information about how our websites and applications are used. Matomo helps us understand information such as visited pages, approximate visitor numbers, referrers and technical errors.

Matomo is configured for privacy-friendly, cookieless measurement. It does not set tracking cookies for this basic measurement. IP addresses are anonymised, and the resulting information is not used to identify individual visitors or shared for advertising purposes.

Google Analytics

With your consent, we use Google Analytics 4, a service provided by Google, to measure website usage, user journeys and conversions across our website, console and billing application.

Google Analytics may process information about your browser, device, approximate location, visited pages, interactions, session and pseudonymous identifiers. We do not intentionally send names, email addresses, message content or other directly identifying information to Google Analytics.

Google Analytics is activated only after you consent to the analytics category in our cookie settings. If you reject analytics, we do not load Google Analytics, set Google Analytics cookies or send server-side Google Analytics events associated with your visit.

You can withdraw or change your consent at any time through the cookie settings available on our website. Google may process data outside Switzerland or the European Economic Area using applicable transfer safeguards.

Further information is available in Google's Privacy Policy .

8. Cookies and local storage

We use technically necessary browser storage to remember your privacy choices, maintain authenticated sessions and provide security-related functionality. These technologies are necessary for the requested services and cannot always be disabled through our cookie settings.

Optional analytics cookies are used only after you have provided the corresponding consent. You can change your selection at any time using the cookie settings.

9. Service providers and international transfers

We use selected service providers for hosting, infrastructure, authentication, payment processing, analytics and business communications. These providers receive only the data reasonably required for their respective tasks.

Our primary service infrastructure is hosted in Central Europe. Individual providers, including Microsoft, Google and Stripe, may process data in other countries, including the United States.

Where personal data is transferred to a country without an adequate level of data protection, we use appropriate safeguards where required, such as recognised data-transfer frameworks or standard contractual clauses.

10. Data retention

We retain personal data only for as long as it is required for the purposes described in this policy. The applicable period depends on the type of data, contractual requirements, security needs and legal retention obligations.

Account and service data is generally retained for the duration of the customer relationship and deleted or anonymised when it is no longer required. Billing and accounting records may be retained for the period required by applicable law. Security and diagnostic logs are retained for limited periods appropriate to their purpose.

Backup copies may remain for a limited additional period until they are overwritten as part of the normal backup lifecycle.

11. Data security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse and alteration. These measures include access controls, encrypted transport, secure authentication, monitoring, backups and procedures for handling security incidents.

Authentication secrets are stored using appropriate cryptographic protection, such as one-way password hashing where applicable. Nevertheless, no internet-based service can guarantee absolute security.

12. Your rights

Subject to the applicable law and its conditions, you may have the right to:

  • Request information about the personal data we process about you
  • Request access to or a copy of your personal data
  • Request the correction of inaccurate or incomplete data
  • Request the deletion of personal data
  • Request that processing be restricted
  • Object to certain processing
  • Withdraw previously granted consent
  • Request data portability where applicable

These rights are not absolute and may be limited by legal obligations, overriding interests or other exceptions under applicable law.

To exercise your rights, contact us at hello@lette.io . We may need to verify your identity before responding.

You may also contact the Swiss Federal Data Protection and Information Commissioner or another competent data-protection authority.

13. Changes to this privacy policy

We may update this privacy policy when our services, providers or legal obligations change. The version published on this page is the current version.

Last updated: July 31, 2026.