Privacy policy
1. Data controller
- Controller
- Julio Rodríguez Cruz
- Tax ID
- 53194665N
- Registered address
- Vigo, Galicia, 36205
- Privacy contact
- soporte@mailshogun.com
- Data protection officer
- None appointed; not required in this case.
2. Two different roles, depending on the data
The distinction matters because the obligations are not the same:
- As controller we process your account data: who you are, which domains you own, what you have sent and what we bill you.
- As processor we process the data of the recipients you send to, on your instructions and only to deliver the message. You decide who you write to and on what legal basis. The article 28 GDPR data processing agreement (DPA) is available on request at soporte@mailshogun.com.
3. What data we process
- Account data: email, name and password (stored hashed, never in clear text).
- Billing data: company, tax ID, address, phone and billing email, when you fill them in.
- Payment methods: card details are held by the payment gateway. We store its encrypted reference, the brand, the last four digits and the expiry date so you can recognise the card.
- Technical and security data: IP address, date and action of logins and relevant operations (sign-ins, password changes, domain creation), open sessions and their declared device.
- Sending metadata: sender, recipient, subject, message identifiers, date, delivery status and the reason for a bounce or complaint.
- Domains and DNS: the domains you add and the result of checking their public records.
The queued message: the email you hand us is stored in full in our sending queue, because that is exactly what has to be delivered to the recipient and retried if the first attempt fails. From that message we only read the headers, which are what feeds the sending log. The body is never shown in the panel and we do not use it for any other purpose: not for profiling, not for training systems, not for anything other than delivering your email.
4. Purposes and legal bases
- Providing the service (delivering your email, verifying domains, applying limits)
- Performance of the contract, article 6.1.b GDPR.
- Invoicing and charging usage
- Performance of the contract and compliance with tax and accounting obligations (articles 6.1.b and 6.1.c).
- Account security and abuse prevention (access logs, alerts on sign-in from a new IP, bounce and complaint control)
- Legitimate interest in protecting the service and the sending reputation of every customer, article 6.1.f.
- Operational email (account verification, password reset, domain suspension)
- Performance of the contract, article 6.1.b. We do not send marketing email without your consent.
5. How long we keep it
- Account data: while the account is active. On closure it is deleted or anonymised, except what we must keep by law.
- Invoices and tax data: for the periods commercial and tax law require.
- Sending metadata and access logs: as long as needed for support, billing and security, after which they are purged automatically.
- The message in the sending queue: kept while it may still be needed to deliver it, retry it or investigate a delivery incident you report. We keep it for no other purpose, and you can ask us to delete the message of a specific send.
6. Who else is involved
To run the service we rely on providers acting as processors or sub-processors: hosting infrastructure, email delivery infrastructure and the payment gateway. Processing takes place in the European Union.
The named list of processors and sub-processors (purpose and country) is not published on this page; it is available on request at soporte@mailshogun.com and forms part of the DPA when signed with the customer.
We do not sell or share personal data with third parties for their own purposes. We only disclose it when a legal obligation or a competent authority requires it.
7. International transfers
The service is designed to operate in a European region. Should a transfer outside the European Economic Area ever be necessary, it would be made with the safeguards of chapter V GDPR and reflected in this policy before being applied.
8. Your rights
You can request access, rectification, erasure, restriction, portability and objection to the processing, and withdraw consent where that is the applicable basis. Write to the contact address above; we may ask you to prove your identity. We answer within one month.
If you believe your request was not handled properly, you can complain to the Spanish Data
Protection Agency (www.aepd.es).
9. Security
- Passwords stored with a hashing function, never in clear text.
- Second authentication factor (TOTP) with recovery codes.
- Sessions stored server side, revocable one by one from the panel.
- Access log with IP and an email alert on sign-in from an unrecognised IP.
- Encryption in transit on every connection and encryption at rest for sensitive secrets.
No system is infallible. If we detect a breach affecting your data we will tell you and notify the supervisory authority where required.
10. Changes to this policy
If the processing changes we will update this page and its date. When the change is material we will email you before applying it.