Privacy Policy
Last updated: [date]
Who we are
ASMTP is run by Clive Marshall, trading as RMD World, [postal address]. ICO registration number [ICO number]. Contact for anything about your data: support@asmtp.com.
This policy covers two situations
- You are our customer. We are the "controller" of the details we hold about you.
- You send email through us. The people you write to are not our customers. For their details in your messages, you are the controller and we are your "processor": we handle their data only to deliver your mail. The Data Processing section below is our agreement with you for that.
What we collect about you, our customer
- Your name, business name, email address, and postal address if you give it.
- The addresses and domains you verify for sending, and the DNS records we check.
- Payment details are handled by our payment provider and our billing system; we see the payer name, the last four digits of a card, and the amount. We never see full card numbers.
- Sign-up checks: the IP address you signed up from and its approximate location, whether your domain or IP appears on public blocklists, your domain's age, and a risk score we build from these. We use these to decide whether to approve your account. We do not make fully automated decisions about you: a person reviews every sign-up.
- Your logins to the customer area: time and IP address.
- Messages you send us for support.
What we collect when you send email
For every message: date and time, the login used, the IP address it came from, the sender address, the recipient addresses, message size, our spam score, and the delivery result (delivered, bounced, complained, held). We do not store the message content, except that a message held as likely spam is kept for 14 days so you can see why and ask for its release.
Why we collect it (our lawful basis)
- To provide the service you bought (contract).
- To keep the service safe and our sending addresses trusted, including approving accounts and detecting stolen logins (legitimate interests).
- To meet our legal duties, including accounting records (legal obligation).
- To reply to you (contract or legitimate interests).
How long we keep it
- Account details: while you are a customer and for 6 years after your last payment, because tax law requires us to keep business records that long.
- Sending logs: 90 days in our live system, where you can see them in your customer area. After 90 days they are moved to a restricted archive that only the owner can open, kept for up to 12 months more to investigate abuse and answer legal requests, and then reviewed for deletion.
- Held messages: 14 days, then moved to the restricted archive under the same rule.
- Sign-up checks and risk scores: for as long as your account exists, so we can see the history if there is a problem.
- Customer-area login records: 12 months.
- Support emails are kept for 30 days after your request is closed, then deleted, usually within a week. Reports of abuse are kept for as long as they are needed to deal with the abuse. Copies may remain in our secure backups, which are used only to restore the service if something goes wrong.
Who we share it with
- Amazon Web Services (Amazon SES), London region, which delivers your messages. Amazon sees the sender, recipients and content of each message in order to deliver it, and reports bounces and complaints back to us.
- Contabo GmbH, which hosts our server in the United Kingdom.
- Our text-message provider, if we send you a verification code.
- Our billing system, hosted on our own servers, for invoices and renewals.
- Public blocklist operators, when we check whether your domain or IP address is listed. They see the domain or IP being queried, nothing more.
- The police or a court, if the law requires it.
We do not sell your data and we do not use it for advertising.
Where it is kept
Our server is in the United Kingdom. Amazon SES is used in its London region. Some blocklist operators are outside the UK; the only data they receive is the domain or IP being checked.
Cookies
We use only the cookies needed to keep you signed in and to protect forms from misuse. We do not use analytics or advertising cookies, so we do not show a cookie banner.
Your rights
You can ask to see the data we hold about you, to correct it, to have it deleted where we no longer need it, to limit how we use it, or to receive it in a portable form. Email support@asmtp.com. You can complain to the Information Commissioner's Office at ico.org.uk if you are not happy with our answer.
Data Processing section (our agreement with you as a processor)
- Subject and purpose: we process the personal data in your outgoing email (recipient addresses, names in messages, and the message content in transit) only to deliver that email and to keep the service safe.
- Duration: for as long as you have an account, plus the retention periods above for logs.
- Your instructions: we act only on your instruction, which is the act of sending a message through us, and on the law.
- Security: encrypted connections, hashed passwords, access limited to the owner, audit logging of administrative actions, and regular backups. Message content is not stored after delivery except for held messages, as above.
- Sub-processors: Amazon Web Services (delivery), Contabo (hosting), our text-message provider (verification codes). We will tell you by email at least 30 days before adding a new sub-processor, and you may end your account if you object.
- Help with your duties: we will help you respond to a request from one of your recipients about their data, as far as our logs allow.
- Breaches: we will tell you without undue delay if we become aware of a breach affecting your data.
- On ending: your logs remain under the retention rule above and are not used for any other purpose. You can export your sending log from the customer area at any time before closing.
- Audit: on reasonable request we will give you the information you need to show that we meet these obligations.