1. General Provisions
This Privacy Policy (hereinafter referred to as the "Policy") defines the procedure for processing and protecting personal data of lock.lat service users (hereinafter referred to as the "Service", "We"). The Policy is developed in accordance with the requirements of personal data legislation.
By using the Service, the user expresses consent to the terms of this Policy. In case of disagreement, the user must immediately stop using the Service.
The Administration reserves the right to make changes to the Policy without prior notice. The new version comes into force from the moment of publication on the website.
2. User Personal Data
2.1. Data provided during registration:
- Username (login) — chosen when creating an account and used to form an email address in the lock.lat domain.
- Password — stored in encrypted form using the bcrypt algorithm with salt. The password is not stored in plain text. The Administration does not have the technical ability to know the user's password.
2.2. Technical data collected automatically:
- IP address — recorded with each request to the server, including registration, authorization, sending and receiving emails. The IP address is used to ensure security and prevent unauthorized access.
- Date and time — recorded for all operations: registration time, last login time, time of sending and receiving each email, time of deleting emails.
2.3. Content of email messages:
- Attachments — files attached to emails are stored on the server.
- Email metadata — sender and recipient addresses, email subject, date and time of sending, technical headers.
3. Purposes of Collecting and Processing Personal Data
3.1. Personal data is processed for the following purposes:
- Providing access to the mail service functionality;
- User identification during authorization and account protection;
- Detection, prevention and suppression of fraudulent activities, spam, phishing;
- Investigation of security incidents;
- Compliance with applicable legislation;
- Technical support of users;
- Improving the quality of service.
4. Conditions for Processing and Storing Personal Data
4.1. Processing of personal data is carried out using the following technical protection measures:
- User passwords are stored as bcrypt cryptographic hashes. Reverse transformation is impossible.
- Data transfer is carried out via the secure TLS protocol (HTTPS, STARTTLS).
- Physical access to servers is restricted and controlled by the hosting provider.
- Regular software updates.
4.2. Data retention periods:
- IP addresses and technical logs — at least 12 months;
- Email metadata — at least 12 months;
- Content of deleted emails — up to 30 days in backup, then permanently deleted;
- Account data — until the account is deleted.
5. Transfer of Personal Data to Third Parties
5.1. The Service does not transfer personal data to third parties, except in the following cases:
- Receipt of an official request from authorized government agencies;
- Investigation of security incidents (spam, fraud, prohibited content);
- Protection of the rights and legitimate interests of the Service in court;
- Transfer of data to a successor in case of reorganization.
5.2. Data is transferred only in the necessary volume. Transfer of data to commercial organizations for marketing purposes is not carried out.
6. User Rights
6.1. The user has the right to:
- Right of access — obtain information about what data is being processed. Request is sent to legal@lock.lat.
- Right to erasure — demand deletion of the account and all related data. Deletion is carried out within 30 days.
- Right to rectification — make changes to data (password change). Login change is impossible, requires creating a new account.
- Right to restriction of processing — temporary account blocking through support request.
- Right to data portability — obtain data for transfer to another service (export via IMAP).
6.2. To exercise rights, you must send a request to legal@lock.lat indicating the email address in the lock.lat domain and describing the required action.
6.3. Request processing time — no more than 30 days.
7. Use of Cookies
7.1. The Service uses cookies to maintain the authorization session.
7.2. The Service does not use third-party analytics systems, advertising cookies and trackers.
7.3. The user can disable cookies in browser settings, but in this case authorization in the web interface will become impossible.
8. Children's Safety
The Service is not intended for use by persons under 16 years of age. We do not knowingly collect data from minors.
9. Changes to the Privacy Policy
9.1. The Administration reserves the right to make changes to the Policy. Changes take effect from the moment of publication.
9.2. In case of significant changes, users may be notified through posting an announcement on the website or sending a notification by email.
10. Contact Information
For questions regarding the processing of personal data:
- Privacy: legal@lock.lat
- Abuse: abuse@lock.lat
- Support: support@lock.lat
Last updated: 05.03.2026