Skip to content
Legal — Data Processing

What we process for you, and on what terms.

DMARC reports carry counts and metadata, not message content, so this is a shorter document than most. Everything below is a commitment already made elsewhere in the product — this page just puts it in one place.

Last updated September 10, 2026GDPR Art. 28 · SCCs (template in preparation)
What this page is
These are the terms we operate to today, and they bind us as part of the Terms of Service. A countersignable copy for your procurement file is still in preparation. If your procurement needs one, tell us through the security packet form and we will give you a date, not a form letter. When the signed template exists, it governs wherever it differs from this page.
01Which of us is which

Which of us is which

You are the controller. You decide which domains to monitor, who in your organization has access, and what happens to the output. We are the processor: we act on your instructions and do not decide the purposes the data is used for.

If you process on behalf of someone else — for example a partner monitoring a client’s domains — you remain the controller of your own account, but when you process for your own clients we act as your sub-processor and the flow-down in this agreement applies: you are responsible for holding your client’s authorization and for giving them the information in this agreement and the privacy policy.

ControllerYou, or the organization whose account it is
ProcessorDDMARC, operated by PlatOps Security, LLC
StatusThese are the terms we operate to today. The signable template is in preparation
02What reaches us

What reaches us

Less than most vendors, because of what DMARC is. Aggregate reports are counts and metadata generated by receiving mail providers — they carry no message content, no recipient addresses and no subject lines, because the report format has no field for them.

Aggregate reportsSending domain, source IP, message counts, SPF and DKIM results, policy applied
DNS recordsYour published SPF, DKIM, DMARC, MTA-STS and TLSA records — public by definition
Account dataNames, work email addresses and roles of the people you invite
Forensic samplesOnly if you publish a ruf= tag. Message headers including the mail-from and rcpt-to addresses of the failing message, and occasionally a body fragment the receiver chose to include. Kept 90 days, then deleted
BillingHandled by Stripe. Card numbers never reach our systems
The category that needs attention
Forensic samples are the only place identifying detail can appear, and they arrive only because you asked for them in your own DNS. Remove the ruf= tag and collection stops at the source, not at a setting of ours.
03Where it sits, and where it does not move to

Where it sits, and where it does not move to

Residency is chosen when your tenant is created and cannot be changed afterwards, so it is worth deciding before provisioning, not after. Reports, forensic samples and the audit log all stay in the region you pick.

Regions availableUnited States, European Union
Chosen atTenant provisioning
Movable laterNo
On requestTokyo, HIPAA-eligible (US) and AWS GovCloud (US), as part of an Enterprise agreement
What residency covers, and what it does not
Account and billing data, support access, and the subprocessors listed in section 04 are not bound to your chosen region — several of them operate from the United States regardless of which region you pick. What stays in-region is reports, forensic samples and the audit log.
04Everyone else who touches it

Everyone else who touches it

The current list, dated and published, not supplied on request. We will give you at least 30 days’ notice by email before adding or replacing one, and you may object on reasonable data-protection grounds.

Amazon Web ServicesHosting, storage and database — multi-AZ. Backups and support access are described in the data processing agreement.US or EU; Tokyo, HIPAA-eligible (US) and AWS GovCloud (US) on request
Amazon SESEmail delivery for alerts, digests and the newsletterUS
StripePayment processing. Card numbers never reach our systems.US / global
GoogleGoogle Analytics 4 (consent-gated) and Google Public DNS as a fallback resolver for the DMARC lookup and DKIM checker, which query DNS from the browserUS
MicrosoftClarity session replay (consent-gated)US
SentryError and performance monitoringUS
CloudflareTurnstile bot challenge on our forms; the DNS-over-HTTPS resolver for the DMARC lookup and DKIM checkerUS / global
Google WorkspaceMailbox for contact, security-packet and support submissionsUS

Each is bound by terms no weaker than these. Where a transfer leaves the EEA we rely on Standard Contractual Clauses. Support access to your tenant is logged, limited to what the support request or security investigation needs, and covered by the confidentiality terms in this agreement.

05How long we keep it

How long we keep it

Report retention is a function of your plan, and these are the same figures the pricing page bills on.

Monitor30 days retained
Protect365 days retained
Growth365 days retained
Professional365 days retained
EnterpriseCustom retention, agreed in the order form
After you leaveData is retained 30 days after closure for export, then deleted from the live service within a further 30 days. Encrypted backup copies are overwritten on a rolling schedule and are gone within 12 months; a backup is restored only to recover from a disaster.

The full retention schedule — every category, including billing, server logs, analytics and marketing email — is the single source on the privacy policy.

06The technical and organizational measures

The technical and organizational measures

In transitTLS 1.3
At restAES-256-GCM, keys in AWS KMS hardware security modules (FIPS 140-validated)
Tenant separationAt the storage layer, not in application filters
Access controlNamed individual accounts with admin, member and viewer roles. No shared logins
Audit logEvery configuration and policy change with actor, timestamp and source IP
Infrastructure certificationPlatOps Security holds SOC 2 Type II and ISO 27001
Stated as a gap, not buried
DDMARC’s own SOC 2 Type II certification is in progress and does not exist yet — the certified controls are the infrastructure operator’s. SAML single sign-on is provisioned on Enterprise agreements only, not on self-serve plans. Both are the kind of thing a reviewer finds late and expensively, so they are here. The security page says the same.
07What happens if something goes wrong

What happens if something goes wrong

For any incident affecting customer data we notify affected customers without undue delay, and in any case within 72 hours of confirming a breach affecting your data. The notice states which data categories were involved, which accounts, and what remains unknown at the time of writing — including when that is most of it.

We will not wait for a complete picture before telling you, because the point of the notice is to let you start your own clock.

08Helping you answer a data subject

Helping you answer a data subject

Access, correction, deletion and export are self-service for the account data we hold, and report data can be exported as CSV. Where a request needs something the dashboard cannot do, we will assist within the statutory window at no charge.

You may audit our compliance with this agreement once a year, or after an incident, on reasonable notice. In practice most reviewers are satisfied by the security packet — the subprocessor list, the encryption and key-management statement, and the most recent penetration test summary under NDA.