EMX and requests from authorities
Your mail is your business. We hand it to an authority only where Swiss law obliges us to, and we tell you when we do, unless the law forbids it. This page says how that works and, just as important, what data exists to be handed over at all.
Who answers, under which law
EMX is operated by Krauss Software, the sole proprietorship of Samuel Krauss in Oberägeri ZG, under Swiss law. Requests go in writing to legal@elchi.dev.
Under the Federal Act on the Surveillance of Post and Telecommunications (BÜPF, SR 780.1), EMX is a provider of derived communication services (Art. 2 lit. c BÜPF): a service that builds on telecommunications and lets people communicate, as opposed to a telecommunications provider such as a network operator. For such a provider there is no registration with the Post and Telecommunications Surveillance Service (Dienst ÜPF). Further duties to give information or to carry out surveillance apply only once the Dienst ÜPF declares a provider subject to them, which it does on certain sizes: for example 100 requests for information, or surveillance orders on 10 different targets, in twelve months, or CHF 100 million of turnover in Switzerland in two consecutive years together with 5,000 subscribers (Art. 22 and 52 of the ordinance, VÜPF, SR 780.11). EMX is far from these.
What the law requires of EMX, then, is this:
- to tolerate a surveillance ordered under the BÜPF against a person who uses EMX, to give the Dienst ÜPF access to its installations for it, and to give the information needed (Art. 27 para. 1 BÜPF);
- to deliver, on request, the metadata of the target's communications that it has, such as who wrote to whom and when (Art. 27 para. 2 BÜPF);
- to deliver the information it has that identifies the author of an offence committed over the internet (Art. 22 para. 3 BÜPF).
None of this obliges EMX to collect or keep data it does not otherwise have, or to decrypt what it cannot decrypt.
How we handle a request
- We check who is asking and through which channel. A request by telephone, or by mail we cannot trace to the authority, is answered only with the address above.
- We check the legal basis and the scope. We hand over only what an order of a competent Swiss authority covers, and nothing beyond it. Where an order seems to us unlawful or too broad, we ask the authority to narrow it and use the legal remedies open to us.
- We tell the customer without delay, unless the law or the order forbids it. Where it is forbidden for a time, we tell the customer once that time has passed.
- We keep a record of every request, what it asked for and what we handed over.
A lawyer, a company or anyone else who is not an authority acting under the law gets no data about a customer from us without an order of a Swiss court or the customer's consent.
Requests from abroad
We do not answer foreign authorities directly. A foreign authority that wants data from EMX must go through international mutual legal assistance with Switzerland, and its request then reaches us, if at all, as an order of a Swiss authority under Swiss law.
One limit should be said plainly. EMX runs on servers rented in Switzerland and in the European Union (the terms, Annex A, list them). An authority of Germany, the Netherlands, France or Bulgaria can, under its own law, reach data through the provider in its country. The message bodies held there are encrypted with a key that is not kept with the stored data. The database, with the senders, recipients and subjects of mail that is not sealed, is not encrypted in that way.
What data exists
| Data | Kept |
|---|---|
| The organisation, its people, their addresses and roles | while the contract runs, then 30 days |
| Mail in the mailboxes, with sender, recipients, subject and times | until a person deletes it, or the mailbox is deleted |
| Mail filed as junk, or held in the organisation's quarantine | the organisation's retention period, 30 days unless it set another |
| Mail of a person the customer removed | 30 days, unless an administrator turned the mailbox into a shared mailbox or handed its mail to a colleague |
| Records of outgoing mail: sender, recipient, time, outcome | a week after delivery |
| Security and access logs: sign-ins, administrative actions, the IP address they came from | the full IP address 90 days, then only its network (IPv4 /24, IPv6 /48) |
| Sessions of the web client, with IP address and browser | until they end, at most 90 days |
| Deliveries of the webhooks a customer set up, with what each carried | 30 days |
| Daily counts of recipients per person, for the limits | 30 days |
| Invoices and billing details | ten years, as the law requires (Art. 958f OR) |
The operating logs of the servers also record connections to the mail ports with their IP address, and the sender of each message sent; they are used only to run the service and to handle abuse. EMX keeps no other record of who wrote to whom.
Sealed mailboxes. A sealed message, its subject, its sender and its recipients included, is stored encrypted to the person's key, which we keep only encrypted to their recovery code and to a passkey or a passphrase we never see. We cannot decrypt it, and no order can make us hand over what we cannot read. Mail that was in the mailbox before it was sealed is not sealed. What we have of a sealed mailbox is the encrypted messages, the time each arrived, its size and its folder, and for mail sent to other servers the record of its delivery, kept a week.
Transparency
Each year we publish on this page how many requests we received, from which kind of authority, and how many we answered with data, as far as the law allows us to say.
Related
- Acceptable use and abuse: how to report spam, phishing or malware sent from EMX.
- The terms, Annex A, A.11, are the binding text for requests from authorities.