Policy
How we protect your data and keep CloudMailin secure.
Last updated 12th September 2024
At CloudMailin, safeguarding your security is our utmost priority. While this section outlines several of our key practices, we welcome you to reach out for a more comprehensive understanding or to obtain a copy of our detailed security whitepaper.
We maintain a rigorous approach to securing our applications, employing both automated and manual scans to identify and mitigate potential vulnerabilities and threats swiftly. While we are a small team, we are actively engaged in incorporating best practices inspired by globally recognized standards, such as ISO 27001 or SOC II, to fortify our security infrastructure.
CloudMailin uses AWS to host our server infrastructure.
AWS has a robust and dedicated team constantly monitoring their data centers and security.
AWS continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. AWS’s data center operations have been accredited under the following among others:
Plus a number of other local standards.
More details of the AWS Compliance Programs can be found here.
At CloudMailin, we prioritize securing communications by implementing encryption throughout our platform.
The following sections relate to CloudMailin's own servers:
Inbound data handling policies are as follows:
We retain the following metadata:
| Field | Description |
|---|---|
| Sender IP | The IP address of the sending server. |
| Message ID | The message ID taken from the message headers. |
| Sender | The SMTP transaction sender. |
| Recipient | The Recipient passed during the SMTP transaction. |
| Subject | The message subject taken from the message headers. |
| Date | The date the CloudMailin server’s received this message. |
| Server Response | The status code and HTTP body received in response to the message post from the recipient server. |
| Processing Time | The processing time of the server. |
For outbound emails, the following policies are applied:
Please contact us for any requests or further clarifications regarding data handling policies.
Upon request some of these fields can be redacted (please contact us to make this request). This data can be deleted upon customer request (please contact us to make this request).
CloudMailin is committed to adhering to regulatory standards to ensure the utmost safety of user data. Our operations are guided by the following frameworks:
Our infrastructure predominantly operates within the US and EU, ensuring stringent data protection standards. We may facilitate global operations by transferring and accessing data worldwide, always conforming to the highest legal and technical industry standards.
As mentioned above our Servers are located in the US, EU and Asia Pacific. We also have the ability to provision dedicated servers in other regions. Please contact us to discuss any requirements that you might have.
We remain transparent and cooperative in legal scenarios where personal information is required by law enforcement or other authorities pursuant to a lawful request. By utilizing CloudMailin services, users consent to the transfer and storage of personal and customer information in the specified locations. To date this has not been required, this section will be updated if such a request is received.
For any inquiries or specific requirements about data regions and compliance, feel free to contact us.
CloudMailin has a standard DPA available for customers that require it. Please contact us for a signed copy of our DPA.
For the purposes of our Data Protection Amendment, we currently make use of the following sub-processors:
| Name | Purpose | Server Location |
|---|---|---|
| Amazon Web Services | Various services including servers, databases, and storage | USA / EU / AP |
| Heroku (Salesforce) | Management Website | USA / EU |
| Crunchy Data | Database | USA / EU (data hosted in AWS) |
| OpenAI | Analysis and content detection | USA |
For more information on our sub-processors, please feel free to contact us.
The customer acknowledges that during the provision of services, CloudMailin employs the use of cookies, unique identifiers, web beacons, and similar tracking technologies (“Tracking Technologies”). The customer will maintain appropriate notice, consent, opt-in, and opt-out mechanisms as are required by Data Protection Laws to enable us to deploy Tracking Technologies lawfully on, and collect data from, the devices of recipients in accordance with and as described in the Privacy Policy found at CloudMailin Privacy Policy.
You may have clicked on an ad for this website that was delivered by Google.
Google measures the performance of the advertising it delivers. By providing a tool to more accurately measure the performance of the ads we deliver, Google (and advertisers) will be able to improve the quality and relevance of the ads that you see.
To measure performance, Google uses small strings of text (known as cookies) that are placed on your computer when you click on ads. Cookies typically remain active on your computer for about 30 days. If you visit certain pages of the advertiser's website during that period, Google and the advertiser will be able to tell that you saw the ad delivered by Google.
If you'd like to know more about how Google handles information gathered from the use of cookies, please read our privacy policy. If you want to disable the use of cookies, you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Be aware, however, that some websites may not function properly if you refuse to accept cookies.