<!-- https://docs.elchi.dev/emx-authorities | EMX | Elchi Docs -->

# EMX and requests from authorities

Your mail is your business. We hand it to an authority only where Swiss
law obliges us to, and we tell you when we do, unless the law forbids it.
This page says how that works and, just as important, what data exists to
be handed over at all.

## Who answers, under which law

EMX is operated by Krauss Software, the sole proprietorship of Samuel
Krauss in Oberägeri ZG, under Swiss law. Requests go in writing to
**legal@elchi.dev**.

Under the Federal Act on the Surveillance of Post and Telecommunications
(BÜPF, SR 780.1), EMX is a provider of derived communication services
(Art. 2 lit. c BÜPF): a service that builds on telecommunications and lets
people communicate, as opposed to a telecommunications provider such as a
network operator. For such a provider there is no registration with the
Post and Telecommunications Surveillance Service (Dienst ÜPF). Further
duties to give information or to carry out surveillance apply only once the
Dienst ÜPF declares a provider subject to them, which it does on certain
sizes: for example 100 requests for information, or surveillance orders on
10 different targets, in twelve months, or CHF 100 million of turnover in
Switzerland in two consecutive years together with 5,000 subscribers
(Art. 22 and 52 of the ordinance, VÜPF, SR 780.11). EMX is far from these.

What the law requires of EMX, then, is this:

- to tolerate a surveillance ordered under the BÜPF against a person who
  uses EMX, to give the Dienst ÜPF access to its installations for it, and
  to give the information needed (Art. 27 para. 1 BÜPF);
- to deliver, on request, the metadata of the target's communications that
  it has, such as who wrote to whom and when (Art. 27 para. 2 BÜPF);
- to deliver the information it has that identifies the author of an
  offence committed over the internet (Art. 22 para. 3 BÜPF).

None of this obliges EMX to collect or keep data it does not otherwise
have, or to decrypt what it cannot decrypt.

## How we handle a request

1. **We check who is asking and through which channel.** A request by
   telephone, or by mail we cannot trace to the authority, is answered only
   with the address above.
2. **We check the legal basis and the scope.** We hand over only what an
   order of a competent Swiss authority covers, and nothing beyond it. Where
   an order seems to us unlawful or too broad, we ask the authority to
   narrow it and use the legal remedies open to us.
3. **We tell the customer** without delay, unless the law or the order
   forbids it. Where it is forbidden for a time, we tell the customer once
   that time has passed.
4. **We keep a record** of every request, what it asked for and what we
   handed over.

A lawyer, a company or anyone else who is not an authority acting under the
law gets no data about a customer from us without an order of a Swiss court
or the customer's consent.

## Requests from abroad

We do not answer foreign authorities directly. A foreign authority that
wants data from EMX must go through international mutual legal assistance
with Switzerland, and its request then reaches us, if at all, as an order
of a Swiss authority under Swiss law.

One limit should be said plainly. EMX runs on servers rented in Switzerland
and in the European Union (the [terms](https://elchi.dev/en/legal/emx-terms),
Annex A, list them). An authority of Germany, the Netherlands, France or
Bulgaria can, under its own law, reach data through the provider in its
country. The message bodies held there are encrypted with a key that is
not kept with the stored data. The database, with the senders, recipients and
subjects of mail that is not sealed, is not encrypted in that way.

## What data exists

| Data | Kept |
|---|---|
| The organisation, its people, their addresses and roles | while the contract runs, then 30 days |
| Mail in the mailboxes, with sender, recipients, subject and times | until a person deletes it, or the mailbox is deleted |
| Mail filed as junk, or held in the organisation's quarantine | the organisation's retention period, 30 days unless it set another |
| Mail of a person the customer removed | 30 days, unless an administrator turned the mailbox into a shared mailbox or handed its mail to a colleague |
| Records of outgoing mail: sender, recipient, time, outcome | a week after delivery |
| Security and access logs: sign-ins, administrative actions, the IP address they came from | the full IP address 90 days, then only its network (IPv4 /24, IPv6 /48) |
| Sessions of the web client, with IP address and browser | until they end, at most 90 days |
| Deliveries of the webhooks a customer set up, with what each carried | 30 days |
| Daily counts of recipients per person, for the limits | 30 days |
| Invoices and billing details | ten years, as the law requires (Art. 958f OR) |

The operating logs of the servers also record connections to the mail ports
with their IP address, and the sender of each message sent; they are used
only to run the service and to handle abuse. EMX keeps no other record of
who wrote to whom.

**Sealed mailboxes.** A sealed message, its subject, its sender and its
recipients included, is stored encrypted to the person's key, which we
keep only encrypted to their recovery code and to a passkey or a
passphrase we never see. We cannot decrypt it, and no order can make us
hand over what we cannot read. Mail that was in the mailbox before it was
sealed is not sealed. What we have of a sealed mailbox is the encrypted messages,
the time each arrived, its size and its folder, and for mail sent to other
servers the record of its delivery, kept a week.

## Transparency

Each year we publish on this page how many requests we received, from
which kind of authority, and how many we answered with data, as far as the
law allows us to say.

## Related

- [Acceptable use and abuse](/emx-abuse): how to report spam, phishing or
  malware sent from EMX.
- The [terms](https://elchi.dev/en/legal/emx-terms), Annex A, A.11, are the
  binding text for requests from authorities.
