Terms of service
The rules under which we operate the Mailows e-mail service — what you can expect from us and what we expect from you.
1. Who operates the service
The Mailows service is operated by DW Technology LLC, registered in the state of New Mexico, USA (the “operator” or “we”). Contact for questions, complaints and for exercising the rights under section 10: support@namailu.cz.
Invoicing is handled by a Czech invoicing company under a contract with the operator — it issues the tax documents and is named on them. This does not change who provides the service and who is the contracting party: that remains the operator named above. Payment details are in section 8.
2. What the service is
Mailows is e-mail hosting for people and automated agents. It includes:
- e-mail mailboxes on the shared domain
mailows.comor on the customer's own domain; - access over webmail, IMAP, SMTP and JMAP;
- a REST API for agent mailboxes (receiving, sending, attachments, webhooks);
- management of domains, mailboxes, users and access keys in the portal.
The scope of individual plans is in the pricing. The pricing page is part of these terms.
3. Account and sign-in
- An account is created by registering and verifying a contact e-mail address.
- A single password applies to the web, IMAP and SMTP. The customer is responsible for keeping it secret.
- Two-factor authentication (TOTP) is available to everyone and is mandatory for the more sensitive features — own domain, agent mailbox, API key, managing other users, paid plan. Once switched on, the requirement stays with the account.
- The customer is responsible for the activity of all users and agents in their account.
4. Acceptable use
The service must not be used for:
- sending unsolicited mail, bulk marketing without demonstrable recipient consent, or circumventing limits by creating additional accounts;
- phishing, fraud, distributing malware or other unlawful conduct;
- traffic that endangers the deliverability of other customers on the shared outbound IP address.
Outbound mail has hourly, daily and monthly limits according to the plan; incoming and outgoing messages are checked for malicious content. If we suspect abuse we may suspend sending — this does not interrupt incoming mail and we inform the customer.
5. Encryption
- Transport is always encrypted — the web, IMAP, SMTP and JMAP run exclusively over TLS, and we hand off outgoing mail encrypted whenever the other side supports it.
- Encrypted message content is supported in the standard OpenPGP (PGP/MIME) format. The sender encrypts the message and the recipient decrypts it; we never hold or see private keys, so we cannot read the content of such a message either.
- Encryption is available to agents over the API. An agent can send a ready PGP/MIME ciphertext, and for an encrypted message it receives the original form for download and decryption in its own environment. Encryption is never silently downgraded to unencrypted sending.
- What is not encrypted: the sender and recipient addresses, the date and the subject remain transport data, because the mail system needs them for delivery. Content encryption also does not replace malicious-content scanning — it cannot be performed on a message we cannot see into.
6. Outbound spam
Outbound spam harms deliverability for every customer on the shared IP address, so we react to it firmly and regardless of plan:
- We monitor sending automatically — volume, the share of undelivered messages and recipient complaints. When a threshold is exceeded, sending from the account is suspended immediately, including on paid plans. This is not a termination of service: incoming mail keeps arriving and you keep access to your data.
- We announce the suspension and state the reason.
- Restoring sending is not automatic. We require an explanation of the cause and evidence of measures preventing recurrence — typically a fix on the side of your application or agent, a reduction of sending volume, or a narrower list of allowed recipients. Until then sending stays suspended.
- In case of repeated or deliberate abuse we will terminate the account under section 9.
- We recommend setting your own hourly and daily sending cap for each agent. It is the cheapest insurance against a mistake in your own automation.
7. Availability and backups
- We operate the service with due care, but without a contractually guaranteed availability (SLA) unless the customer arranges one individually on the Enterprise plan.
- We back up data several times a day; backups are encrypted and a copy is kept off the service's server. We verify that backups are restorable on a regular basis.
- We announce planned outages in advance where their nature allows it.
8. Payments and term
- Free plans are provided without any claim to availability and may be limited or discontinued.
- Paid plans are billed in advance for the period stated in the pricing. Annual add-ons (agent slots) are not refunded pro rata, but the unused part is credited when upgrading to a higher plan.
- The customer may terminate the service at any time; a period already paid for is not refunded unless the law provides otherwise.
- Prices in the pricing page are stated including VAT.
- The tax document is issued by a Czech invoicing company under a contract with the operator; its identification details appear on the document. The provider of the service and the contracting party remains the operator under section 1.
9. Termination by the operator
We may restrict or terminate an account for breaches of sections 4 and 6, for non-payment of a due amount, or where the law requires it. Except in cases of serious abuse we give the customer reasonable advance notice to remedy the situation and an opportunity to export their data. After an account is terminated we delete the data in line with the retention periods in section 10.
10. Personal data and privacy
We process only what is necessary to run the service. Specifically:
- Mail content is processed solely in order to deliver and display it. We do not read it, analyse it, or use it for advertising.
- Cookies — we set only those necessary for sign-in and security; there is no analytics or advertising cookie on our pages.
- Operational logs (IP address, time, request address) are kept for roughly a month for security and diagnostics.
- Audit records of account changes are kept for 12 months, and metadata of mail sent and received by agent mailboxes for 90 days.
- We use no third-party analytics tools or tracking scripts.
The customer has the right to access their data and to its correction, erasure and portability. A request sent to support@namailu.cz is enough.
11. How long we keep mail
We do not delete mail in the mailbox. As long as the account exists and fits within its quota, a message stays. Only the following folders are cleaned up automatically, because otherwise they would grow without limit:
- Trash — messages older than 30 days are permanently removed. Until then they can be restored.
- Spam — messages older than 30 days are permanently removed.
Both periods run from the moment the message entered that folder. A message moved back into the mailbox stops being subject to deletion.
Older mail may be stored on slower storage. For mailboxes that have not been touched for a long time we reserve the right to move the content to cheaper capacity. This has no effect on what is in the mailbox — all messages remain available and searchable, they may just load more slowly.
After an account is terminated we keep the data for 30 days in case it was a mistake or the customer requests an export; afterwards we remove it, including from backups in the nearest rotation cycle.
The stated periods are maximums; the customer may delete anything sooner at any time. Shorter or longer retention for organisations is arranged individually.
12. Liability
We are not liable for indirect damages, lost profit, or for loss of data caused by the customer or a third party. Our liability is limited to the amount the customer paid for the service over the last twelve months. This does not affect consumer rights under applicable law that cannot be excluded by contract.
13. Source code (AGPL-3.0)
The service is built on two free software programs that we have modified. Both are distributed under the GNU Affero General Public License version 3, and under its section 13 you, as a user of the service, have the right to obtain the corresponding source code of the version you are using — including our modifications.
- The webmail interface — derived from the Bulwark Webmail project (AGPL-3.0). Our modifications concern sign-in through our own identity provider and the range of features offered.
- The mail server — derived from the Stalwart Mail Server project. It is offered under a dual licence (AGPL-3.0-only, or the commercial Stalwart Enterprise License); we use and distribute it under AGPL-3.0. Our modification makes it possible to verify the mailbox password against our identity provider, so that a user has one password for the web as well as for IMAP and SMTP.
Write to support@namailu.cz for a copy of the source code of either part and we will provide it free of charge. The AGPL-3.0 licence applies to those two parts; the other parts of the service (the control interface, the portal and the API) are our own work and are not covered by the AGPL.
14. Changes to the terms
We may change these terms. We will inform you of any substantial change by e-mail at least 30 days in advance; if the customer does not agree with the change, they may terminate the service before it takes effect. We keep a version history together with the effective date.
15. Governing law
The relationship is governed by the law of the state of New Mexico, USA. If the customer is a consumer resident in the European Union, this does not affect the mandatory provisions of their home law or their right to turn to the competent court or supervisory authority in their place of residence.