Privacy Notice

Last updated: 2026-07-25

Permanent version: 2026-07-25

1. Who we are and the scope of this notice

Mikheit AB (PayloadRelay, we, or us) is responsible for the processing that this Privacy Notice describes. Section 2 gives the exception, where we act as a processor for a customer. Mikheit AB has organisation number 559548-6225. It is registered at Köpmangatan 63, 972 34 LULEÅ, and it has its registered office in Luleå.

This notice applies to visitors, account users, members of an organization, billing contacts, business contacts, support requesters, and other people. We process the personal data of these people for our own purposes in connection with PayloadRelay. The notice explains what we process, why we process it, how long we keep it, and who receives it. It also explains the rights that the EU General Data Protection Regulation (GDPR) and the applicable Swedish law give.

2. When we are controller and processor

PayloadRelay acts as controller for account registration, authentication, the administration of an organization, billing, fraud prevention, abuse prevention, service security, support, legal compliance, and our own business communications and website.

A business customer usually determines why and how we process the personal data in its relay events, templates, destinations, and related instructions. For that Customer Data, the customer is controller and PayloadRelay acts as processor. Our Data Processing Addendum governs that processing. A destination that the customer configures receives Customer Data on the instruction of the customer. Such a destination can have its own controller role or processor role.

3. Personal data we process

Account data and organization data

  • The name, the email address, the account status, the membership of an organization, the role, and the preferences.
  • The password hash, or the OAuth provider and the provider identifier.
  • The session information, the authentication information, the security-event information, the IP address, and the device information and browser information.
  • The support messages and other information that you give.

Service configuration and operational data

  • The configuration of an endpoint, of the authentication, of a filter, of a transformation, of a template, of a destination, and of the retries.
  • The encrypted or otherwise protected secrets, credentials, and destination tokens that the configured features need.
  • The activity that holds metadata only, and the delivery outcomes. These include the originating IP address, the HTTP method, the SMTP envelope sender, the identifiers, the timestamps, the status, and the failure reason.
  • The accepted-event counts, the limits, the alerts, the audit entries, and the security reports or error reports.
  • The relay request bodies and the message bodies, but only while PayloadRelay delivers the event. If the delivery fails permanently, a body stays for a maximum of 7 days more, for diagnosis or a new delivery.

Billing and commercial data

  • The billing contact, the business name, the billing address, and the tax identifiers.
  • The Stripe identifiers for the customer, the subscription, the invoice, the payment status, and the transaction.
  • The plan, the billing interval, the previews, the scheduled changes, the cancellation state, and the optional cancellation feedback.
  • The commercial correspondence and the contract records.

Stripe collects and stores the payment-card details. PayloadRelay does not receive a complete payment-card number, and it does not store one.

4. Purposes and legal bases
PurposeLegal basis
Create and operate the accounts, the organizations, the authentication, the subscriptions, and the requested featuresContract, where the individual is a contracting party. If not, the legitimate interests of us and of the customer in the supply of the business service
Secure the Service, prevent abuse and fraud, enforce the limits, troubleshoot, and keep the reliabilityOur legitimate interests in the protection of PayloadRelay, the customers, the recipients, and the public
Process the payments, the tax, the invoices, the accounting records, and a valid legal requestContract, legitimate interests, and compliance with a legal obligation
Supply support, service notices, billing notices, and the requested communicationsContract and legitimate interests in the operation and the support of the Service
Improve the usability and the capacity of the product with the configuration and with aggregate or metadata-only operational informationOur legitimate interests in the improvement of the Service, with no storage of a relay body
Send an optional communication where a separate opt-in is necessaryConsent. You can withdraw consent at any time, and the withdrawal does not affect the earlier lawful processing

When we depend on legitimate interests, we consider the business context, the necessity, the impact, the reasonable expectations, and the available safeguards. We do not infer consent from acceptance of the Terms or use of the Service.

5. Recipients and disclosures

We disclose personal data only as the purposes above need. The recipients are:

  • An authorised member of the same organization, according to the role of that member.
  • An infrastructure, hosting, content-delivery, security, email-delivery, or support provider that acts under a contract.
  • Stripe, for payment processing, invoicing, tax, payment recovery, and subscription administration.
  • Google, Microsoft, or Apple, when an account user selects the OAuth service of that provider.
  • The webhook, email, collaboration, incident-management, spreadsheet, or other destination that the customer configures.
  • A professional adviser, an auditor, an insurer, a prospective transaction party under appropriate safeguards, and an authority where the law requires this.
  • Another entity, as part of a merger, a financing, a reorganisation, or a sale of the relevant business assets.

We do not sell personal data. We do not use a third-party advertising cookie or analytics cookie. The subprocessor schedule of the DPA names the current processors for Customer Data.

6. International transfers

We can process personal data outside the country where we collected it. If we transfer GDPR-protected data outside the European Economic Area to a country without an adequacy decision, we use an available lawful safeguard. One such safeguard is the Standard Contractual Clauses of the European Commission. We add supplementary measures where these are appropriate. A delivery that the customer directs to a destination outside the EEA occurs on the documented instruction of the customer under the DPA.

7. Retention and deletion
  • Account data: PayloadRelay keeps it while the account is active. The deletion process below then applies, together with any limited legal retention.
  • Configuration: PayloadRelay keeps it until the customer deletes it, or until the permanent deletion of the organization that owns it. If a member who is not the owner deletes only their own account, the resources stay with the organization.
  • Activity metadata and delivery outcomes: 30 days.
  • Relay request and message bodies: PayloadRelay does not store a customer relay request body or a customer message body in its databases, activity logs, object storage, application logs, traces, metrics, files, caches, or backups. A body stays only in process memory, and in the trusted MTA queues and the queues for delivery, retry, and dead letters. It stays there only while PayloadRelay delivers the event. If the delivery fails permanently, the message stays in a dead-letter queue for a maximum of 7 days. This period lets us diagnose the failure, and it lets the customer instruct a new delivery. The broker then discards the message.
  • Verified Stripe webhook inbox: 30 days, for billing processing, recovery, and investigation. This inbox is separate from the customer relay traffic.
  • Billing records: PayloadRelay keeps a limited archive until 1 January after five complete years that follow the relevant financial year. A legal hold or the applicable law can require a longer period.
  • Backups: the encrypted database backups rotate after 35 days. Deleted data can stay isolated in a backup until that backup expires. PayloadRelay does not restore such data to the active service before it applies the completed deletions again.
  • Deletion safeguards: limited timestamps, scope identifiers and organization identifiers, a detached former user identifier, and non-reversible hashes of the email address and the recovery token can stay for a maximum of 45 days. These keep the deletion outcomes through the backup rotation.

Self-service deletion disables the access immediately. An emailed single-use link usually permits recovery for 30 days. The permanent deletion runs after that grace period. An erasure request that we complete after an identity check can skip the grace period where this applies, and nobody can recover it. This is subject to the data that we must keep.

A closure of an organization cancels its paid subscription immediately, and it gives no automatic refund. Recovery returns the organization on Sandbox, and it does not restore the subscription.

8. Security

We use technical measures and organisational measures that match the processing risk. These include access controls, authentication safeguards, tenant isolation, transport protection, protection of the sensitive configuration at rest, bounded metadata retention, backup controls, dependency monitoring and operational monitoring, and procedures for a security incident and for deletion. No online service can guarantee absolute security.

9. Your GDPR rights

The applicable conditions and exceptions apply to the rights below. You can request access to your personal data, its correction, its deletion, a restriction on it, or its portability. You can object to processing that depends on legitimate interests. You can withdraw consent where consent is the legal basis. You can also complain to a supervisory authority. In Sweden, that authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

To exercise a right about data for which PayloadRelay is the controller, contact us. For Customer Data, contact the relevant customer first. We help that customer as the DPA requires. We make sure of the identity and the authority before we act on a request.

10. Cookies and local storage

The application uses only the storage that it needs to operate the Service and to secure it. This storage includes a secure HttpOnly authentication cookie, a CSRF-protection cookie, and limited browser storage for the active flows and the preferences. We do not use an advertising cookie or an analytics cookie. If you block the necessary storage, the authenticated features stop working.

11. Business accounts and children

A PayloadRelay account is for an adult who acts for a business purpose or a professional purpose. PayloadRelay does not direct an account to a child or to a private consumer. Customer Data can concern other individuals, and this includes an individual who is not an account user. The customer stays responsible for its lawful instructions and for the necessary notices to those people.

12. Changes and contact

We can update this notice to show a change in the processing or in the law. We will publish the current version. When the law requires this, we will tell the account contacts about a material change. The earlier versions stay available through their permanent version links.

Mikheit AB

Organisation number: 559548-6225

Köpmangatan 63, 972 34 LULEÅ

Registered office: Luleå

[email protected]