1. What data we process
Account data: name, work email address, hashed password (irreversibly, so we cannot recover it either), organisation name and role (administrator or member). Payment data: we keep the billing address and VAT number ourselves; the IBAN mandate for direct debit is processed by Mollie and kept here only as a reference number that cannot be traced back to an account number. Service data: the domains you add, and the DMARC, TLS RPT and forensic reports that mailbox providers send about them. Aggregate and TLS RPT reports contain technical data such as sending IP addresses, volumes and authentication outcomes, and generally no data about individuals. Forensic reports may also contain a fragment of the original message (a sender or recipient address, for instance) and are therefore more likely to be personal data than the aggregate reports. Audit log data: which user carried out which action within the account, with a timestamp. Technical data: functional cookies and local storage, see article 6.
2. Purposes and legal basis
We process this data in order to perform the agreement with you (article 6(1)(b) GDPR): creating and managing an account, providing DMARC monitoring, invoicing, and offering support. Security logs are kept on the basis of our legitimate interest (point f), so that abuse of accounts can be traced.
3. Retention periods
We keep service data (DMARC reports and the overviews derived from them) for the period that comes with your subscription: 30, 90, 180 or 365 days, as described on the pricing page. We keep account data for as long as you have an active account. After you cancel, your data, backups included, is permanently deleted within a set period. You can export all your reports yourself beforehand through the settings page.
4. Who we share data with
We do not sell data and share nothing for marketing purposes. To keep DuzMarc running we work with a small number of subprocessors, all established within the EU, with one deliberate exception for a backup DNS resolver that records no data:
| Party | Role | Location |
|---|---|---|
| Etheron | VPS / server infrastructure | The Netherlands (EU) |
| Soverin | Domain registration and mail server for incoming DMARC/TLS RPT reports | The Netherlands (EU) |
| Mollie | Payment processing (SEPA direct debit, invoicing) | The Netherlands (EU) |
| Lettermint | Sending system email (registration, password reset, notifications) | The Netherlands (EU) |
| Actalis | Issuing the SSL/TLS certificate for app.duzmarc.nl | Italy (EU) |
| Statichost.eu | Hosting of this marketing website (duzmarc.nl) | EU |
| DNS4EU | DNS name resolution | EU |
| Quad9 | DNS name resolution (backup resolver, records no IP addresses) | Switzerland, GDPR adequacy country |
Quad9 is established in Switzerland, a country for which the European Commission has issued an adequacy decision (data protection equivalent to that in the EU). Quad9 also records no user IP addresses.
5. Transfers outside the EU
There is no structural transfer of personal data to countries outside the European Union, other than to the adequacy country named in article 4.
6. Cookies
DuzMarc uses only functional cookies and local storage: one session cookie to keep you logged in and to secure forms (it also holds a CSRF token), and a theme preference remembered locally in your browser (localStorage, not a cookie). No marketing, tracking or advertising cookies are used. Because we use only necessary cookies and local storage, no consent is required and we show no cookie banner.
7. Security
We protect data with, among other things, two-step verification for accounts, encrypted backups and access to production environments limited to our own team. See the transparency page for more detail.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest. You can export or delete your report data yourself through the settings page, or send a request to info@duzmarc.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Changes
We may amend this privacy policy, for instance when new functionality or a new subprocessor is added. We announce important changes by email or through the account.
10. Contact
Questions about this privacy policy or about your data can be sent to info@duzmarc.nl.