Skip to content
MailGuardHQ
Legal

Privacy Policy

What personal data we hold, why we hold it, how long we keep it, and what you can ask us to do with it.

Draft - not yet reviewed by counsel

This document is a working draft written to be reviewed, not a binding agreement. It has not been through legal review and it does not yet govern any customer relationship. Do not rely on it. It is published here so the shape and the commitments can be checked before launch.

Last updated 9 August 2026 · Uniworld Technologies · MailGuardHQ

1. The two kinds of data here

This service handles personal data in two distinct roles, and the distinction matters for your rights and for our obligations.

  • Account data - we are the controller. Your name, email address, organisation, billing details and how you use the application. We decide why and how this is processed.
  • Report data - we are the processor. The DMARC aggregate reports collected for your domains. These contain source IP addresses, which are personal data under the GDPR. We process them on your instructions, as described in the Data Processing Addendum.

2. Account data we collect

  • Identity and contact: name, email address, organisation name.
  • Authentication: password hash, or the identifier returned by Google sign-in. We never receive your Google password.
  • Billing: plan, seats, invoices, and a payment profile token held by our payment processor. We do not store full card numbers.
  • Usage: which pages and API endpoints you use, timestamps, and the domains in your tenant. Used for support, abuse prevention and metering.
  • Technical: IP address, browser and device type, in server and security logs.

3. Why we process it

  • To provide the service you asked for - performance of a contract.
  • To bill you and to prevent abuse of the free tier - legitimate interests and contract.
  • To keep the service secure and to investigate incidents - legitimate interests.
  • To send service notices you cannot opt out of, such as billing and security notifications - contract.
  • To send product or marketing email, where you have opted in - consent, withdrawable at any time.

4. The public domain check

The free domain check can be used without an account. We record the domain checked, a timestamp, and a truncated or hashed form of the requesting IP address, for rate limiting and abuse detection only. We do not build a profile of anonymous visitors and we do not sell this data.

5. Report data and IP addresses

DMARC aggregate reports name the IP addresses that sent mail claiming to be from your domain. Under the GDPR an IP address is personal data, so this is handled accordingly.

  • Report data is isolated per tenant. Another customer cannot see yours.
  • We enrich source IP addresses with network and geographic information from a local database and, where necessary, third-party providers. Enrichment results are cached and reused, so the same IP is rarely looked up twice.
  • We do not process message content. Aggregate reports contain counts and authentication outcomes, not the text of anyone's email.
  • Raw report files are retained as the evidence behind usage invoices and so that history can be reprocessed if our analysis improves.

6. Logging and minimisation

Email addresses are masked in application logs and job records; the unmasked value exists only where it is genuinely required. We do not log request or response bodies, and we do not log secrets or tokens.

7. Who we share it with

We do not sell personal data. We share it only with the processors needed to run the service - cloud hosting, payment processing, transactional email, and error monitoring - each under a contract that restricts them to acting on our instructions. A current list of subprocessors will be published with the Data Processing Addendum.

We may disclose data where we are legally required to, and will notify you unless prohibited from doing so.

8. Where it is stored

Data is hosted on Microsoft Azure. The specific regions will be stated before launch, along with the transfer mechanism relied on for any transfer outside the region of collection.

9. How long we keep it

  • Account data: for the life of the account, then deleted after a short grace period.
  • Report data and derived aggregates: for the retention period included in your plan.
  • Raw report files: retained at least as long as the billing dispute window, because they are the evidence behind an invoice.
  • Security and audit logs: retained for a fixed period, then deleted.

The exact periods are stated in the Data Processing Addendum and will be finalised before launch.

10. Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable format, and to withdraw consent where consent is the basis.

To exercise a right, contact us using the details below. We respond within the period the applicable law requires. You may also complain to your local data protection authority.

11. Cookies

The public website uses no advertising or cross-site tracking cookies. The application uses cookies that are strictly necessary for signing in and keeping you signed in. If we later add analytics, it will be behind a consent banner and off until you accept.

Your colour theme preference is stored in your browser's local storage. It never leaves your device.

12. Children

The service is not directed at children and we do not knowingly collect their personal data.

13. Contact

Data protection contact details will be published before launch. A data protection officer will be named if one is required.