Privacy Notice
Last updated 2026-07-08.
1. Who we are
DMARCHub is a service operated by Inside Technology Ltd, a company registered in England and Wales (company number 10442174, VAT number GB239614981), whose registered office is Fairways House Offices, Mount Pleasant Road, Southampton, Hampshire, SO14 0QB.
We are registered with the Information Commissioner's Office under registration number ZA281920. This notice should be read alongside our Cookie Notice, which explains how we use cookies and similar technologies.
2. Our role: when we are controller and when we are processor
DMARCHub processes personal data in two different capacities:
- As data controller for your account and identity data, your company and billing profile, your support tickets, and the communications and security records we keep about your use of the service. For this data we decide why and how it is processed, and this notice governs it.
- As data processor, acting on your instructions, for the personal data contained within the DMARC aggregate and forensic reports you direct to us (for example sending IP addresses, and any personal data in a forensic report before it is scrubbed). For that data you are the controller: you decide that the reporting should come to us, and you remain responsible for the lawful basis on which it is collected.
3. What personal data we process
DMARCHub is a DMARC monitoring service. Most of what we hold is technical metadata about your domains' mail flows rather than information about identifiable people. The categories are:
- Account and identity data: your name, email address, display name, and the stable identifier your identity provider (Microsoft Entra ID or Google Workspace) returns when you sign in. Sign-in is single sign-on only - we never see, store, or process a password. For organisations that sign in with Google Workspace, we also make a read-only directory lookup, authorised by your Workspace administrator, to read back your organisation's immutable Google customer ID; we use it only to keep your organisation's data isolated from other organisations. We also keep your sign-in timestamps and your notification preferences.
- Company and billing profile: your organisation's legal name, company registration number, VAT number (if provided), postal address, and contact name, email and phone. We collect these during onboarding to verify your account, raise correct invoices, and meet our record-keeping obligations.
- DMARC aggregate (RUA) report data: the aggregate reports mail receivers send about your domain. These contain sending IP addresses, the message counts, and the authentication (SPF/DKIM/DMARC) results for mail claiming to be from your domain. They are metadata about senders, not the content of any message.
- DMARC forensic (RUF) report data: where a receiver sends a forensic failure report, we scrub the personal content - message body, subject, message-id, and the local-part of any recipient address - at the point of ingest, before anything is stored. We keep only the sending IP, authentication results, and the domains involved.
- TLS-RPT report data: aggregate reports about the success and failure of encrypted (STARTTLS) delivery to your domain. These contain no message content or recipient data.
- Support data: the content of any support ticket you raise, including messages and any files you choose to attach. If you cannot sign in, you can also send us a support request from our public support page; there we collect your name, organisation, email address, and a description of your issue, so that we can help you.
- Communications log: a record of the emails we send you (such as sign-in, billing, alert, and product-update messages) - the recipient, subject, delivery status, and the rendered message - so we can prove what we sent and diagnose delivery problems.
- Usage and security data: how you use the service, and an audit log of security-relevant actions that records who did what and when, including the IP address and browser used for the action. To keep the service reliable we also collect operational telemetry (such as the pages requested and the connecting IP address) within our UK hosting environment. On our public website pages we also use a privacy-first, cookieless analytics tool (Plausible) to measure aggregate visitor numbers; it sets no cookies, collects no personal data, and does not track you across sites, and it is not used on the signed-in dashboard or the administration area. We do not use advertising cookies or cross-site profiling trackers.
- Prospect and marketing data: if you join our beta waitlist or ask to be kept informed, we hold your name, organisation, and email address. Where you have agreed to receive product or marketing updates we keep a record of that and of any later opt-out. You can opt out at any time.
4. Lawful basis
We rely on the following lawful bases under UK data protection law. The personal data inside the DMARC reports you direct to us is processed in our role as your processor, so the lawful basis for that data is yours to determine as controller (see section 2).
| Data category | Lawful basis | Is providing it a requirement? |
|---|---|---|
| Account and identity | Performance of a contract | Yes - needed to create and operate your account (a contractual requirement). |
| Company and billing profile | Performance of a contract; legal obligation (retained invoices) | Yes for paid plans - contractual for billing, and a statutory requirement for the invoices we must keep. |
| DMARC aggregate, forensic, and TLS-RPT report data | Processed as your processor on your instructions - you, as controller, set the basis. | You direct this data to us; we do not require it to operate your account. |
| Support data | Performance of a contract; legitimate interests (answering your request) | Only if you contact support - provided at your choice. |
| Communications log | Performance of a contract; legitimate interests (proof of delivery, diagnostics) | Generated by us when we email you; not separately provided by you. |
| Usage, security and operational telemetry | Legitimate interests (keeping the service secure and reliable) | Generated by us as you use the service; not separately provided by you. |
| Prospect and marketing | Consent, or legitimate interests where a soft opt-in applies | Optional - provided when you join the waitlist or sign up; you can opt out anytime. |
5. Automated decision-making and profiling
DMARCHub does not carry out automated decision-making or profiling on personal data. We do not make decisions that produce legal or similarly significant effects about you, your account, or any other individual solely by automated means, and we do not profile individuals. Report data is processed and displayed without any automated decision being taken about a person. Decisions that affect your account - for example approving a new account - are made by a person. Where we map a sending IP address in a report to a country, that is enrichment of mail-flow metadata, not a decision about an individual.
6. How we use your data
We use your data to run DMARCHub: to ingest and parse your DMARC reports, show you a dashboard and trends, notify you about anomalies, provision and poll the dedicated reporting mailbox for your domain, answer your support requests, and bill you for paid plans. We do not sell your data, share it with advertisers, or use it to train machine-learning models.
7. Who we share it with
We use a small set of suppliers to run the service. Each acts as our data processor under our instructions:
- Microsoft Azure (UK South region): our hosting, managed database, object storage, secrets, operational monitoring, and the DNS for our reporting domain (dmcrpt.io).
- Microsoft 365 / Microsoft Graph: the dedicated reporting mailbox we provision per organisation, which receives the DMARC reports for your domain.
- Google (Google Workspace / Google Admin SDK Directory API): for organisations that sign in with Google Workspace, Google is your identity provider. When you sign in we make a read-only directory lookup, authorised by your Workspace administrator, that sends your verified email address to Google's Directory API and reads back only your organisation's immutable Google customer ID. We use it to keep your organisation's data isolated from other organisations; we do not read any other directory data.
- Cloudflare: TLS termination, proxying, and protection for our application edge. Your connection to the dashboard passes through Cloudflare, so it sees connecting IP addresses and requested URLs in transit.
- Stripe: payment processing. Card details are entered directly with Stripe and never reach our servers.
- Xero: accounting. We sync invoice records (organisation name, our internal account reference, billing email, amounts, dates, and references) to our Xero ledger.
- SMTP2GO: delivery of our transactional and product email (the recipient address, subject, and the rendered message).
- DigitalOcean: off-cloud backups of our database, held in their London region. Only an encrypted copy is stored, and we hold the decryption key - DigitalOcean cannot read the contents.
- Plausible: privacy-first, cookieless website analytics for our public pages only (never the signed-in dashboard or the administration area). It counts aggregate page views without cookies, without personal data, and without tracking you across sites. Provided by Plausible Insights OU and hosted in the European Union.
We have data-processing agreements in place with these suppliers and have reviewed their security posture.
We also use MaxMind's GeoLite2 country database to show which country a sending IP address is in. We download the database and run every lookup locally on our own infrastructure; we do not send any IP address or other personal data to MaxMind, so MaxMind does not act as a processor of your personal data.
8. International data transfers
The core service data - your reports, account data, statistics, and backups - is held in the UK: Microsoft Azure UK South for hosting, database and storage, with database backups in Azure's UK West region and our off-cloud encrypted backups in DigitalOcean's London region. Some of our suppliers are headquartered outside the UK, so where they process personal data on our behalf a transfer may take place. Where it does, it is protected by appropriate safeguards:
| Supplier | Based in | How transfers are protected |
|---|---|---|
| Microsoft (Azure, Microsoft 365, Entra ID) | United States (data hosted in the UK) | Microsoft's data-protection terms, typically the UK Addendum to the EU Standard Contractual Clauses. |
| Google (Google Workspace directory lookup) | United States | Google's data-protection terms, typically the UK Addendum to the EU Standard Contractual Clauses and/or the UK Extension to the EU-US Data Privacy Framework. |
| Cloudflare | United States | Cloudflare's data-protection terms, typically the UK Addendum to the EU Standard Contractual Clauses. |
| Stripe | United States (EU entity in Ireland) | Stripe's data-protection terms, typically the UK Addendum to the EU Standard Contractual Clauses. |
| Xero | New Zealand | UK recognition of New Zealand's data-protection adequacy. |
| SMTP2GO | Outside the UK | Appropriate safeguards under SMTP2GO's data-processing agreement. |
| DigitalOcean | United States (backups stored in London, encrypted) | DigitalOcean's data-protection terms, typically the UK Addendum to the EU Standard Contractual Clauses. |
| Plausible | European Union (Plausible Insights OU; data hosted in the EU) | Kept within the European Economic Area; the UK recognises the EEA's data-protection adequacy, so no additional transfer safeguard is required. No transfer to the United States. |
We will update this notice before making any change that introduces a new transfer outside the UK.
9. How long we keep it
Physical retention (how long we store data) is set centrally and applies to every customer regardless of plan. How far back you can view your reports inside the portal (visible history) depends on your subscription; upgrading reveals older history instantly, because nothing was ever deleted - it was only hidden.
- Parsed DMARC reports (aggregate and forensic) and TLS-RPT reports: physically retained for around 3 years from receipt. Visible history per plan - Free 3 months, Starter 12 months, Pro 3 years. Forensic reports have personal content removed at ingest.
- Summary statistics (used for the dashboard and trend charts): retained around 5 years (60 months).
- Raw report files (the original XML/EML attachments): 30 days from receipt - a short-term safety net for reprocessing, not surfaced in the portal.
- Communications log: 36 months from sending.
- Account and support data: kept while your account is active. On closure your account is soft-deleted with a 30-day recovery window, then permanently torn down (see section 10). A support request sent from our public support page is kept as part of our communications log (above).
- Prospect and marketing records (beta/waitlist sign-ups, marketing email records): kept until you unsubscribe or ask us to remove them.
- Financial records (invoices and the related accounting audit trail): kept for the statutory retention period - around 7 years - because tax law requires it. After an account is torn down these are retained only as anonymised, contact-stripped records, and are deleted once the retention period ends.
10. Erasure and account closure
When you close your account it is soft-deleted and recoverable for 30 days. After that, an automated teardown permanently erases your organisation's data - DMARC reports and their raw files, the reporting mailbox and its DNS records, support tickets and attachments, communications, and the personal data of your users - and then verifies that nothing org-scoped remains before completing. The only exception is the financial records we are legally required to keep: those are retained as an anonymised record (with personal contact details stripped) for the statutory period and then deleted. If you have joined our waitlist or received marketing from us, you can ask us to remove that record separately at any time.
11. How we protect your data
We apply appropriate technical and organisational measures to protect personal data. These include hosting in the UK (Microsoft Azure UK South); encryption of data at rest (AES-256) and in transit (TLS 1.2 or higher); database-level access controls that isolate each organisation's data; single sign-on with no password ever stored by us; an append-only audit log of administrative actions; removal of personal content from forensic reports at the point of ingest; encrypted off-cloud backups; secrets held in a dedicated key vault; and a fail-closed allowlist on administrative access. Inside Technology Ltd holds Cyber Essentials Plus, the UK government-backed certification with a hands-on technical audit. There is more detail on our Security page.
12. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, subject to records we are required by law to keep;
- restrict our processing of your data;
- object to processing we carry out on the basis of our legitimate interests - we will stop unless we have compelling legitimate grounds that override your interests, or need to continue to establish or defend legal claims;
- data portability;
- withdraw your consent at any time where we rely on consent (for example for marketing emails) - withdrawing does not affect any processing we carried out before you withdrew it.
Where we rely on consent for marketing, you can opt out at any time using the unsubscribe link in any marketing email, or by contacting us. To exercise any of these rights, email privacy@dmarchub.io. We respond within one calendar month.
You have the right to complain to us, as the controller, about how we handle your personal data under the Data (Use and Access) Act 2025 - please contact us first so we can put things right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
13. Changes to this notice
We may change this notice from time to time - for example if we add a feature, a supplier, or a new category of data. Where a change is significant we will notify affected individuals where appropriate, by email or a notice in the portal. The "last updated" date at the top of this page always reflects the current version.
| Date | What changed |
|---|---|
| 8 July 2026 | Added a public support page with a contact form for people who cannot sign in, and disclosed the personal data it collects (name, organisation, email address, and a description of your issue) and that it is emailed to our support admins. Also added privacy-first, cookieless analytics (Plausible) on our public website pages, used to measure aggregate visitor numbers without cookies or personal data, and added Plausible as an EU-based processor. |
| 6 July 2026 | Added Google Workspace as a supported identity provider; disclosed the read-only Google directory lookup we use to keep organisations isolated; added Google as a sub-processor and a Google (United States) international-transfer entry. |
| 29 June 2026 | Set out our controller and processor roles; added a lawful-basis table; added a statement that we do not carry out automated decision-making or profiling; described international transfers per supplier; added our beta/waitlist and marketing data and the marketing opt-out; added how we protect your data; removed MaxMind from our processor list (geo-IP lookups run locally) and added DigitalOcean (encrypted off-cloud backups); and expanded your rights. |
| 23 June 2026 | First full published version of this notice. |
14. Contact
Privacy questions: privacy@dmarchub.io
General contact: hello@dmarchub.io