✉ your data rights

GDPR & CCPA

Last updated 26 September 2026

This page sets out how Letter Mail, Inc. handles personal data under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA). It supplements our Privacy Policy.

Our role

For personal data about our users, Letter acts as a data controller. When we handle mailbox data on behalf of business customers under a contract, we act as a processor (see our Data Processing Agreement).

Your GDPR rights

Legal bases

We rely on: performance of our contract with you; our legitimate interests in securing and improving the Service; compliance with legal obligations; and consent where required.

Data Protection Officer and EU representative

You can contact our Data Protection Officer at dpo@letter.click. Where required by Article 27 GDPR, our EU representative can be reached at the same address.

International transfers

Letter is based in the United States. For transfers of EEA, UK or Swiss data, we use the European Commission's Standard Contractual Clauses and additional safeguards where needed.

California (CCPA/CPRA)

How to submit a request

Email privacy@letter.click. We will verify your identity and respond within the time limits set by the applicable law (generally one month under GDPR, 45 days under CCPA).

← Back to letter.click