Last updated: 09.04.2026

This statement explains how AtrioSolutions LLC (“AtrioMail”, “we”, “our”, “us”) handles personal data that is protected by United Kingdom data protection law. It applies to atriomail.com, system.atriomail.com, and any other subdomains we operate.

It sits alongside our Privacy Policy, Cookie Policy and Data Processing Agreement, and adds the detail that UK law requires. Where this statement and the Privacy Policy say different things about personal data protected by UK law, this statement governs.


1. The law this statement covers

We refer to the following together as “UK data protection law”:

  • the UK GDPR, being Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland;
  • the Data Protection Act 2018;
  • the Data (Use and Access) Act 2025, which amends both of the above rather than replacing them. Its main data protection provisions took effect on 5 February 2026, and the direct complaints right described in section 8 took effect on 19 June 2026;
  • the Privacy and Electronic Communications Regulations 2003 (PECR), which govern cookies and electronic marketing in the UK.

The supervisory authority for UK data protection law is the Information Commissioner’s Office (ICO).


2. When UK law applies to us

AtrioSolutions LLC is incorporated in Delaware, United States, with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States. We have no establishment in the United Kingdom.

UK data protection law nonetheless applies to us in two situations, and this statement covers both:

  • Article 3(2) UK GDPR: where we offer our services to people in the United Kingdom, or monitor their behaviour in the United Kingdom.
  • As a processor for a UK customer: where a customer established in the UK, or otherwise subject to UK GDPR, is the controller and we process personal data on their behalf.

3. Our role: controller or processor

Which role we hold depends on the data, and it determines who you should approach about it:

  • We are the controller for the data we collect to run our own business: your account details, billing and payment records, support correspondence, security and service logs, and website analytics.
  • We are the processor for the contents of the mailboxes you create and for the personal data of the people who use them. You are the controller of that data, and we process it only on your documented instructions under our Data Processing Agreement, including its UK annex.
  • Where a reseller sells AtrioMail under their own brand, the reseller is the controller in relation to their own customers, and we remain the processor of the underlying mailbox data.

4. What we process

  • Account information: name, company name, email address, billing address, phone number, payment details.
  • Service information: domain names you connect, email accounts created, DNS records configured.
  • Mailbox content: the messages, attachments, contacts and addresses held in the mailboxes you create. We process this only to deliver and store your email, and we do not read it, mine it, or use it to train anything.
  • Usage data: logs of service use, such as login attempts and account changes.
  • Technical data: IP addresses, browser type, operating system, and similar system information.

We do not knowingly collect or process the personal data of children under 18. Our services are intended for business use only. We do not sell or rent personal data, and we do not carry out solely automated decision-making that produces legal effects concerning you or similarly significantly affects you.


5. Our lawful bases under UK GDPR

Where we act as controller, we rely on the following lawful bases in Article 6 UK GDPR:

  • Performance of a contract: to create your account, provide and support the service, and bill you for it.
  • Legal obligation: to meet financial, tax and accounting requirements, and to respond to lawful requests.
  • Legitimate interests: to keep the platform secure, prevent fraud and abuse, protect the sending reputation that every customer shares, and improve the service. You may ask us for our assessment of any of these interests.
  • Consent: for non-essential cookies, analytics and advertising, as described in our Cookie Policy. You can withdraw consent at any time, and withdrawing it is as easy as giving it.

6. Where your data is stored, and UK international transfers

We store and process customer data in the European Union, not in the United States. Our infrastructure and core processors are:

  • Hetzner Online GmbH (Germany), hosting infrastructure;
  • Amazon Web Services SES (EU region), email delivery;
  • Sentry (EU), error logging;
  • PostHog (EU), product analytics;
  • Stripe, Inc. (US and EU, depending on customer location), payment processing.

UK data protection law restricts transfers of personal data out of the UK. The safeguards we rely on are these:

  • UK to the EEA. The United Kingdom’s adequacy regulations cover the EEA, so moving your data from the UK to our European infrastructure needs no further safeguard.
  • UK to the United States. For providers in the United States, including Stripe and, where you have consented to them, Google and Meta, we rely either on the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”) where the recipient is certified under it, or on the ICO’s International Data Transfer Agreement (IDTA), or on the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses. Where we rely on the IDTA or the Addendum we carry out a transfer risk assessment.
  • Updated ICO documents. The ICO has said it will publish updated versions of the IDTA and the Addendum during 2026, following the Data (Use and Access) Act 2025. We will move to the updated documents once they are issued.

Transfers into the UK are equally unrestricted. On 19 December 2025 the European Commission renewed its adequacy decisions for the United Kingdom, which now run until 27 December 2031. A UK customer’s data can therefore move between the UK and our European infrastructure without additional transfer paperwork.


7. Your rights under UK GDPR

If UK data protection law applies to your personal data, you have the right to:

  • be informed about how we use your data, which is what this statement is for;
  • access the personal data we hold about you;
  • rectification of inaccurate or incomplete data;
  • erasure of your data, the “right to be forgotten”;
  • restrict processing in certain circumstances;
  • data portability, receiving your data in a structured, commonly used, machine-readable format;
  • object to processing carried out on the basis of our legitimate interests, and to object to direct marketing at any time;
  • rights relating to automated decision-making and profiling, though as noted above we do not carry out solely automated decisions with legal or similarly significant effects;
  • withdraw consent at any time, where we rely on consent;
  • complain, both to us and to the ICO, as set out in section 8.

How to exercise a right. Email us at support@atriomail.com. We may ask you for information to confirm your identity before we act. We will respond within one month. For complex or numerous requests we may extend that by up to two further months, and we will tell you within the first month if we do, and why. We do not charge a fee unless a request is manifestly unfounded or excessive.

If your data is in a mailbox. When we act as processor, the controller is the customer or reseller who created the mailbox. Send your request to them. If you send it to us, we will pass it on promptly and assist them in answering it, but we cannot answer it for them.


8. Complaining about how we handle your data

Complain to us first. Since 19 June 2026, the Data (Use and Access) Act 2025 gives you a direct right to complain to us about our handling of your personal data, and obliges us to receive and deal with that complaint. Send it to support@atriomail.com with “Data protection complaint” in the subject line. We will:

  • acknowledge your complaint within 30 days of receiving it;
  • take appropriate steps to investigate it; and
  • tell you the outcome without undue delay.

Then, or instead, complain to the ICO. Complaining to us does not remove your right to complain to the supervisory authority, and you do not have to wait for our answer before doing so:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Helpline: 0303 123 1113
Online: ico.org.uk/make-a-complaint

You also retain the right to an effective judicial remedy.


9. Cookies and electronic marketing (PECR)

PECR governs cookies and electronic marketing for users in the UK, on top of UK GDPR.

  • Essential cookies are used without consent because the service cannot run without them, for example authentication and secure payment.
  • Analytics and advertising cookies are set only after you consent through our cookie banner. You can change or withdraw that consent at any time.
  • Marketing email is sent only where we have your consent or an applicable lawful basis, and every message carries a working unsubscribe link.

Full detail, including the individual cookies and providers, is in our Cookie Policy.


10. Security of your data

We apply technical and organisational measures appropriate to the risk, as Article 32 UK GDPR requires. These include:

  • Encryption in transit using TLS for the website, the panel, the API and mail delivery, and encryption at rest for stored credentials;
  • Access control: role-based access to the panel, two-factor authentication on administrative accounts, and access to production systems limited to the people who need it;
  • Tenant separation, so one customer’s mailboxes and domains are not reachable from another customer’s account;
  • Sending authentication through automated SPF, DKIM and DMARC configuration, which protects your domain against spoofing;
  • Regular backups and monitoring of service performance, errors and security events.

Personal data breaches. Where we are the controller and a breach is likely to result in a risk to people’s rights and freedoms, we will notify the ICO without undue delay and within 72 hours of becoming aware of it, and we will tell affected individuals directly where the risk is high. Where we are the processor, we will notify the controller without undue delay after becoming aware, and give them the information they need to make their own notification.


11. How long we keep data

  • We keep your data for as long as your account is active.
  • When you cancel, your data is deleted immediately, including email accounts, logs and configurations.
  • We keep transaction and billing records for as long as financial and tax law requires us to.

12. Contact

Because we have no establishment in the United Kingdom, UK data protection enquiries reach our data protection contact directly at the address below. We aim to reply to every enquiry, and we are obliged to acknowledge complaints within 30 days as set out in section 8.

AtrioSolutions LLC
131 Continental Dr, Suite 305, Newark, DE 19713, United States
Phone: +1 (302) 520 3708
Email: support@atriomail.com


13. Changes to this statement

We update this statement when the law or our processing changes, and the date at the top always shows the current version. UK data protection law is itself changing as the Data (Use and Access) Act 2025 is brought fully into force, so we review this page as further provisions commence and as the ICO issues its updated transfer documents.