What we process for you, and on what terms.
DMARC reports carry counts and metadata, not message content, so this is a shorter document than most. Everything below is a commitment already made elsewhere in the product — this page just puts it in one place.
Which of us is which
You are the controller. You decide which domains to monitor, who in your organization has access, and what happens to the output. We are the processor: we act on your instructions and do not decide the purposes the data is used for.
If you process on behalf of someone else — for example a partner monitoring a client’s domains — you remain the controller of your own account, but when you process for your own clients we act as your sub-processor and the flow-down in this agreement applies: you are responsible for holding your client’s authorization and for giving them the information in this agreement and the privacy policy.
What reaches us
Less than most vendors, because of what DMARC is. Aggregate reports are counts and metadata generated by receiving mail providers — they carry no message content, no recipient addresses and no subject lines, because the report format has no field for them.
ruf= tag. Message headers including the mail-from and rcpt-to addresses of the failing message, and occasionally a body fragment the receiver chose to include. Kept 90 days, then deletedruf= tag and collection stops at the source, not at a setting of ours.Where it sits, and where it does not move to
Residency is chosen when your tenant is created and cannot be changed afterwards, so it is worth deciding before provisioning, not after. Reports, forensic samples and the audit log all stay in the region you pick.
Everyone else who touches it
The current list, dated and published, not supplied on request. We will give you at least 30 days’ notice by email before adding or replacing one, and you may object on reasonable data-protection grounds.
Each is bound by terms no weaker than these. Where a transfer leaves the EEA we rely on Standard Contractual Clauses. Support access to your tenant is logged, limited to what the support request or security investigation needs, and covered by the confidentiality terms in this agreement.
How long we keep it
Report retention is a function of your plan, and these are the same figures the pricing page bills on.
The full retention schedule — every category, including billing, server logs, analytics and marketing email — is the single source on the privacy policy.
The technical and organizational measures
What happens if something goes wrong
For any incident affecting customer data we notify affected customers without undue delay, and in any case within 72 hours of confirming a breach affecting your data. The notice states which data categories were involved, which accounts, and what remains unknown at the time of writing — including when that is most of it.
We will not wait for a complete picture before telling you, because the point of the notice is to let you start your own clock.
Helping you answer a data subject
Access, correction, deletion and export are self-service for the account data we hold, and report data can be exported as CSV. Where a request needs something the dashboard cannot do, we will assist within the statutory window at no charge.
You may audit our compliance with this agreement once a year, or after an incident, on reasonable notice. In practice most reviewers are satisfied by the security packet — the subprocessor list, the encryption and key-management statement, and the most recent penetration test summary under NDA.