Legal

Privacy Policy

Effective: 17 July 2026

PostMTA Inc. ("PostMTA", "we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard data in compliance with GDPR, UK GDPR, and CCPA.

1. Information We Collect

1.1 Information You Provide

  • Account registration: name, email address, company name, job title, phone number
  • Payment information: processed and tokenised by Stripe — we never store card numbers or bank details
  • Email content & metadata: subject lines, from/to addresses, message body, headers, engagement events (opens, clicks, bounces, complaints)
  • Support communications: tickets, chat transcripts, and any files you upload when requesting help

1.2 Information Collected Automatically

  • IP address, browser type, operating system, and device identifiers
  • Pages visited, referring URLs, and interaction events on our marketing site and dashboard
  • Email delivery events (sent, delivered, bounced, complained) — associated with your sending domain

2. Purpose & Lawful Basis for Processing (GDPR)

PurposeLawful BasisData Categories
Provide email delivery servicesContract (Art. 6(1)(b))Account info, email content/metadata, API keys
Billing and subscription managementContract (Art. 6(1)(b))Payment tokens (Stripe), usage records
Customer supportLegitimate interests (Art. 6(1)(f)) — our interests in resolving issuesSupport tickets, account history
Security, fraud detection, abuse preventionLegitimate interests (Art. 6(1)(f))IP logs, API call records, engagement events
Marketing emails (product updates, tips)Consent (Art. 6(1)(a)) — you can withdraw at any timeEmail address, name
Analytics and product improvementLegitimate interests (Art. 6(1)(f)) — you may object at any timeAggregated, anonymised usage data

3. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with the following trusted sub-processors, each acting only on our instructions:

Sub-processorPurposeData Shared
Supabase (PostgreSQL)Primary data store — account records, email metadata, usage logsAccount info, email metadata, support tickets
StripePayment processing and subscription managementPayment tokens only — no card data
AWS / GCPCloud infrastructure hosting (your choice of region)Email content/metadata stored in your selected region
Mailgun / Amazon SESOptional upstream MTA relay (EU regions)Email content/metadata for relay only
Plausible AnalyticsPrivacy-first website analytics (no cookies, GDPR-compliant)Anonymous page-view data

Any new sub-processor will be listed in our DPA and notified 30 days in advance.

4. Retention Periods

  • Account data: Duration of your subscription + 90 days after closure
  • Email metadata & delivery events: 13 months from the event date
  • Billing records: 7 years (tax and accounting obligations)
  • Support tickets: 3 years after resolution
  • Marketing consent records: Until you withdraw consent + 2 years

After account closure, all personal data is deleted within 30 days except billing records retained under legal obligation.

5. Your Rights

Depending on your jurisdiction, you may have the following rights. To exercise any of them, email privacy@netwit.ca. We respond within 30 days.

  • Access (GDPR Art. 15): Receive a copy of all personal data we hold about you
  • Rectification (Art. 16): Correct inaccurate or incomplete data
  • Erasure ("Right to be Forgotten", Art. 17): Delete your data, where no legal obligation prevents it
  • Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON)
  • Objection (Art. 21): Object to processing based on legitimate interests; we will cease unless we have a compelling legal basis
  • Restriction (Art. 18): Request we restrict processing during a dispute
  • Withdraw consent: At any time, for consent-based processing — this does not affect lawfulness prior to withdrawal

6. Data Processing Agreement (DPA)

We offer a signed DPA for customers subject to GDPR or UK GDPR. It includes:

  • Data Processing Addendum incorporating Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreement (IDTA) for UK transfers
  • Full list of sub-processors with their processing locations and security certifications
  • Audit rights: provide SOC 2 Type II report upon request
  • Data breach notification within 72 hours of becoming aware

Request a DPA by emailing privacy@netwit.ca with your company details and VAT/tax ID if applicable.

7. Data Security

We implement a defence-in-depth security model:

  • TLS 1.3 in transit; AES-256 encryption at rest
  • MFA enforced on all dashboard accounts
  • API keys are hashed — we never store plaintext keys
  • Annual third-party penetration testing (SOC 2 Type II report available under NDA)
  • Role-based access control (RBAC); least-privilege principle
  • Infrastructure DDoS protection via Cloudflare

8. California Consumer Privacy Act (CCPA) Rights

California residents have additional rights under the CCPA (as amended by CPRA):

  • Right to Know: What personal information is collected, its business purpose, and third parties involved
  • Right to Delete: Request deletion of personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information (we do not sell or share your data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

We do not sell personal information and have not done so in the preceding 12 months. To submit a verified CCPA request, contact privacy@netwit.ca.

9. Changes to This Policy

We will notify you of material changes via email at least 30 days before they take effect. Non-material changes (e.g., updating sub-processor details) will be reflected in the "Effective" date at the top of this page.

10. Contact

PostMTA Inc.

Data Protection Officer

privacy@netwit.ca

123 Mail Street, Suite 400
San Francisco, CA 94107
USA