Skip to content
MailGuardHQ
Legal

Data Processing Addendum

The processor terms that apply to report data we handle on your behalf. This is a stub - the executable version is being prepared.

Draft - not yet reviewed by counsel

This document is a working draft written to be reviewed, not a binding agreement. It has not been through legal review and it does not yet govern any customer relationship. Do not rely on it. It is published here so the shape and the commitments can be checked before launch.

Last updated 9 August 2026 · Uniworld Technologies · MailGuardHQ

Status of this document

This is a stub, not an executable agreement. It sets out the shape of the addendum and the commitments it will contain, so they can be reviewed early. The signable version, including the subprocessor list, the standard contractual clauses and the security annex, is being prepared and will replace this page before launch.

If you need a signed DPA to proceed, contact us and we will handle it directly rather than making you wait for this page.

1. Why a DPA is required at all

DMARC aggregate reports list the IP addresses of servers that sent mail claiming to be from your domain. Under the GDPR an IP address is personal data. Processing it on your behalf makes you the controller and us the processor, and that relationship must be governed by a written agreement. This is not optional and we do not treat it as such.

2. Roles

  • Controller: you. You decide which domains are monitored and why.
  • Processor: Uniworld Technologies. We process report data only to provide the service, and only on your documented instructions - which include your use of the application and its API.
  • For your own account and billing data we are the controller. That is covered by the Privacy Policy, not by this addendum.

3. Subject matter and scope

  • Subject matter: collection, parsing, classification, enrichment, storage and presentation of DMARC aggregate reports, and related alerting.
  • Duration: for as long as your account is active, plus the retention period stated in your plan.
  • Categories of data subject: operators of the systems that sent mail referencing your domains. This includes your own staff and services, and third parties, including attackers.
  • Categories of personal data: IP addresses, and network and geographic attributes derived from them. Message content is not processed - aggregate reports do not contain it.
  • Special categories: none are expected or sought.

4. Our obligations

  • Process report data only on your instructions, and tell you if an instruction appears to breach data protection law.
  • Ensure personnel with access are bound by confidentiality.
  • Apply appropriate technical and organisational security measures, described in the security annex.
  • Isolate each tenant's data, and test that isolation rather than asserting it.
  • Assist you with data subject requests, impact assessments and regulator consultations, so far as is reasonable given the nature of the processing.
  • Notify you without undue delay on becoming aware of a personal data breach affecting your data.
  • Delete or return report data at the end of the relationship, subject to any retention required by law.
  • Make available the information needed to demonstrate compliance, and allow audits on reasonable notice.

5. Subprocessors

We use subprocessors to run the service - cloud hosting, payment processing, transactional email, error monitoring, and IP enrichment. Each is bound by terms no less protective than these.

A current subprocessor list will be published with the executable version. We will give notice before adding or replacing one, and you will be able to object.

6. International transfers

Where personal data is transferred outside its region of collection, an approved transfer mechanism will be relied on, and the relevant clauses will be incorporated into the executable version. Hosting regions will be stated explicitly.

7. Security measures

The full annex is being prepared. It will cover, at minimum:

  • Encryption in transit and at rest.
  • Tenant isolation enforced in the data layer, with tests asserting one tenant's data cannot appear in another's output.
  • Least-privilege access control, scoped tokens, and step-up authentication for the operations that can affect mail delivery.
  • Audit logging of every action that changes state, attributed to an actor.
  • Masking of personal data in application logs.
  • Backup, restore and tested recovery procedures.
  • Vulnerability management and a responsible disclosure route.

8. Retention and deletion

Retention periods for report data, derived aggregates and raw report files will be stated numerically in the executable version. Raw report files are retained at least as long as the billing dispute window because they are the evidence behind a usage invoice.

9. Contact

Data protection contact details will be published with the executable version.