Privacy Policy
Effective from: 22 September 2026
Contents
- 1. DEFINITIONS
- 2. HOW WE APPROACH THE PROCESSING OF PERSONAL DATA
- 3. IN WHAT ROLE WE ACT IN RELATION TO PERSONAL DATA
- 4. WHAT PERSONAL DATA DO WE PROCESS ABOUT YOU?
- 5. IN WHICH CASES DO WE PROCESS PERSONAL DATA AND HOW?
- 6. CHILDREN AND MINORS
- 7. WHO ARE OUR PROCESSORS?
- 8. WHAT MEASURES HAVE WE TAKEN TO PROTECT YOUR PERSONAL DATA?
- 9. PROVISION OF SERVICES AND YOUR RIGHTS
- 10. CONCLUSION
of the company ECOMAIL.CZ, s.r.o., Company ID (IČO): 027 62 943, with its registered office at Na příkopě 388/1, Staré Město, 110 00 Praha 1, represented by Ing. Jakub Stupka, Managing Director, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 223183 (for simplicity hereinafter referred to as "we" or the "Controller" or "DMARCeye").
We do not take personal data protection lightly. In this Privacy Policy, you will learn for what purpose, on what grounds, and in what way we Process your Personal Data. You will also find information about your rights in connection with personal data protection.
If you have any further questions about the Processing of your Personal Data, please contact us by email at support@dmarceye.com or by post at the address of our registered office.
1. DEFINITIONS
To make this text easier to follow, we will simplify your reading with a few terms that we use in this Privacy Policy:
| Application | the online platform for DMARC monitoring, available electronically at https://app.dmarceye.com/, which DMARCeye operates and which is its exclusive property; we provide the Application to you together with related services as the Service, so whenever we talk about rules that apply to the Service, they also apply to the Application; |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council; |
| CCPA | the California consumer privacy act of 2018 (California Consumer Protection Act of 2018); |
| EEA | the European Economic Area; |
| Commercial Communications | typically an email message or SMS sent for the purpose of promoting our services; |
| Personal Data | any information about a User on the basis of which the User can be directly or indirectly identified; |
| Recipient's Personal Data | any information about a Recipient on the basis of which the Recipient can be directly or indirectly identified; we process this information for our customer in the role of a processor; |
| Recipient | a third party (natural or legal person) whose technical identifiers (e.g. IP address, domain name) may appear in DMARC reports processed by the Service on the User's instructions; |
| Service | a service provided in the form of software-as-a-service, which DMARCeye operates and which consists of providing tools for DMARC monitoring, XML report analysis, management of email authentication policies, and protection of a domain against abuse, accessible at https://app.dmarceye.com/; |
| Agreement | the agreement on the provision of Services in the wording of the DMARCeye Terms of Service, concluded between us and a registered User, or an agreement concluded on individually negotiated terms; |
| User / you | a natural person to whom Personal Data relates, most often a customer (a person who has signed the Agreement with us and a person who has subsequently created a user account with us and is provided with the Service) or a potential customer, or a user of our website who is simply browsing it; |
| Controller | the entity (in relation to your data, this is us) that alone or jointly with others determines the purposes and means of the Processing of Personal Data; |
| Processor | we use other entities, for example, to provide secure data storage for us or so that we can send you a newsletter. During this cooperation, they may process the Personal Data you have provided to us; |
| Processing of Personal Data | put simply, this is any handling of Personal Data - whether storing, sharing, deleting, or changing it; |
| Special Categories of Personal Data | data that we understand as more sensitive. This data concerns, for example, your ethnic origin, your sexual orientation, whether you are a member of a trade union, the state of your health, and your religious beliefs. Genetic and biometric data are also considered a special category of data when they are processed for the purpose of uniquely identifying a natural person. |
If terms appear in this document that are not specified above, they are governed by the interpretation set out in the DMARCeye Terms of Service.
Users from California. If you are based in the State of California, terms such as "Personal Data", "Data Subject", "Controller", and "Processor" used in this Privacy Policy are the equivalents of the terms "Personal information", "Consumer", "Business", and "Service provider" under the CCPA. In connection with the CCPA, we also state that under no circumstances do we sell, rent, or otherwise disclose your Personal Data for financial or other consideration. If we make your Personal Data available to a third party in any way, we do so in order to provide our Services or to fulfill our legal obligations, and in accordance with this Privacy Policy.
2. HOW WE APPROACH THE PROCESSING OF PERSONAL DATA
Your privacy is our priority, which is why we only require from you the Personal Data that is necessary for providing the Services. Our Services meet the standards required by the GDPR. If you entrust us with your data, we commit to handling it in accordance with the applicable legal framework that applies to you (GDPR, CCPA, and similar). We provide information below about the rights you have in connection with Personal Data.
3. IN WHAT ROLE WE ACT IN RELATION TO PERSONAL DATA
Given the Services we provide, we may find ourselves in the position of both Controller and Processor in relation to Personal Data.
When this Privacy Policy applies. This Privacy Policy applies only to situations where we act as Controller, unless stated otherwise in the text of this Privacy Policy. Please note that this Privacy Policy applies to the Processing of the Personal Data of our Users, not of Recipients.
A. DMARCEYE AS CONTROLLER
When is DMARCeye the Controller? In relation to Users, we are the Controller of Personal Data. You have entrusted us with certain data about yourself (e.g. your name and email) so that we could, for example, register an account for you. An overview of the Personal Data we Process, including the reasons for Processing it, can be found below. If anything is unclear, do not hesitate to contact us at support@dmarceye.com.
Other Processors. So that we can provide our Service to you at the highest possible quality, we use other entities for this purpose. We have concluded the necessary agreements with all of them and require the highest possible level of protection and security of Personal Data. You can find all our processors in Section 7 of this Privacy Policy.
B. DMARCEYE AS PROCESSOR
When is DMARCeye in the position of a processor? DMARCeye acts as a processor in relation to the data contained in DMARC reports, which are delivered automatically based on the User's DNS settings. This data may contain technical identifiers (in particular IP addresses) of third parties. The processing of this data takes place solely for the purpose of providing the Service and is governed by the Data Processing Agreement (DPA), which is an annex to the DMARCeye Terms of Service. The scope and conditions of the processing are fully within the control of the User as controller.
Sub-processors. In providing the Services, we use other entities. If we find ourselves in the position of a processor of Personal Data, we may use additional sub-processors, in accordance with the Data Processing Agreement (DPA), which is an annex to the DMARCeye Terms of Service. We and our sub-processors have very limited access to the data you store in the system, i.e. the data of your clients; even so, we make sure that our sub-processors are bound to ensure the protection of Personal Data at the same level as the protection we provide.
4. WHAT PERSONAL DATA DO WE PROCESS ABOUT YOU?
How do we Process Personal Data? We Process your Personal Data only to the extent necessary to achieve the purpose for which the data was collected, and we follow technical and organizational security rules when Processing it. The process of Processing Personal Data is automated, but we do not perform profiling. The specific purposes of data processing and the categories of personal data we process for each purpose are set out in the following section.
| → First name and surname → Contact details (in particular email, phone number) and other data you voluntarily provide in your user interface |
→ User account name and login and behavior in the user account (in particular data filled in by the User in the user account, time of registration, date of the last profile update) |
| → IP addresses and technical identifiers contained in DMARC reports, which may constitute personal data | → Data in an inquiry sent by a customer or another person |
| → Billing details and bank account details (data necessary for keeping accounts and executing payments) | → Information you share with us in the course of communicating with us (this will mainly be your questions, the answers to your questions, and our communication with you) |
| → Comments you add to our posts on social media (in particular X, LinkedIn), as well as the name (nickname) of your profile on these social media and the publicly available information on your profiles | → Cookies and IP address, activity data (including information about your device or operating system) → Operational data mainly indicating the occurrence of an error state of the Application (time and address of the error incident) |
Special Categories of Personal Data. We do not Process any Personal Data of a sensitive nature about you.
5. IN WHICH CASES DO WE PROCESS PERSONAL DATA AND HOW?
We Process your Personal Data if you are a user of our website or our customer. We Process your Personal Data only for the necessary period; its length may vary, however, depending on the applicable legal framework in the place where we provide our Services to you. The information on the length of processing is therefore indicative only.
A. USERS OF OUR WEBSITE
If you visit our website, we Process your Personal Data for the purposes listed in this table.
| Why? | What data? | How? | How long? |
|---|---|---|---|
| Visiting our website. Ensuring the basic functions of our website, analytics, improving our services, and promoting our company. You can set your preferences in the cookie bar. |
Information about when and how you visit and browse our website. If you visit our website via a mobile phone, we may also process data about your phone. | Cookies or other technologies for tracking User behavior. | The length of processing varies by individual cookie type. Some process data only for the duration of the session (visit), some for a longer period. |
| Sending an inquiry. You can contact us with your questions at any time and we will answer them. You can contact us via the contact form on our website or by email. |
First name, surname, email, phone, and any other Personal Data you share with us. | For the purpose of handling an inquiry, we Process the Personal Data necessary to handle it. Communication takes place by phone, by email, or directly on our website. If we call you, the calls are recorded. | Closed inquiries are deleted regularly, at the latest 3.5 years after the inquiry was submitted. |
| Sending Commercial Communications (direct marketing). You have subscribed to our newsletter. If you no longer want to receive it, you can unsubscribe in the email footer. |
First name, surname, phone number, and email. | We send a newsletter in which we inform you about our services and news. | The data is processed for 2 years from the last active viewing of the newsletter, unless you unsubscribe earlier. |
| Blog and social media. Please note that any information you post in a comment on our blog or on our social media can be viewed by anyone. | First name and surname, address, date of birth, phone number, email address, username, and similar data | Any information, communications, or materials provided via a social media platform are also provided subject to the personal data processing policies of those platforms. | We keep your comments on a post for the entire time the post is published on our profile, unless you ask us earlier to delete your comment on our blog or social media. |
B. USERS OF THE DMARCEYE SERVICE
If you decide to use our Services or want to try them first, we will create a user account for you. We will Process your Personal Data to the extent necessary so that we can provide you with the Service under the DMARCeye Terms of Service.
| Why? | What data? | How? | How long? |
|---|---|---|---|
| Visiting our website. Ensuring the basic functions of our website, analytics, improving our services, and promoting our company. You can set your preferences in the cookie bar. |
Information about when and how you visit and browse our website. If you visit our website via a mobile phone, we may also process data about your phone. | Cookies or other technologies for tracking User behavior. | The length of processing varies by individual cookie type. Some process data only for the duration of the session (visit), some for a longer period. |
| Concluding the Agreement. To start using the Service fully, you first need to conclude the Agreement with us. |
To conclude the Agreement, we will need your first name, surname, and email address, and possibly other data. | You provide this data to us when filling in the registration form questionnaire and creating a user account, or in the course of our communication for the purpose of signing the Agreement. | The data is processed for the duration of the Agreement and subsequently for 3.5 years after the end of the Agreement. |
| Application. We may receive information about how and when you use the Application. We also process data related to the security of the Application. When you visit our website or use the Application, a situation may arise where access to a certain address is unauthorized or triggers an error state (incident). | This information may include, for example, your IP address, the time, the date, the browser used, and the actions you performed in the Application, as well as the content you uploaded to the Application. | We may store the obtained information in log files or other types of files associated with your account and link it to other information we collect about you. | For the duration of the customer's contractual relationship with us and subsequently for 3.5 years after the end of the Agreement. |
| User account. If you have concluded the Agreement with us, we will create a user account for you. Within the user account, you can allow a predetermined number of persons to access the Service. | The data filled in during registration or in the Agreement, in particular your email and other contact details (see above). The scope of the Processing of Personal Data may vary depending on which Personal Data you fill in to your user account and which features of the Service you use. |
You provide this data to us when creating your user account or when updating it. | The data is processed for the duration of the Agreement and subsequently for 3.5 years after the end of the Agreement. |
| Communication with customer support, requests, and complaints. You can send us an inquiry by email or via our website. |
First name, surname, phone number, email, user account. | For the purpose of handling an inquiry, request, or complaint, we Process the Personal Data necessary to handle it. Communication with customer support takes place by phone, by email, or directly on our website. We record our phone calls. | Closed inquiries and complaints are deleted regularly, at the latest 3.5 years after the inquiry was submitted or the complaint was resolved. |
| Direct marketing, in particular sending Commercial Communications. If you use our Services or have subscribed, we will send you our newsletter. If you no longer want to receive it, you can unsubscribe in the email footer. |
First name, surname, phone number, and email. | We send a newsletter in which we inform you about our services and news. | The data is processed for 2 years from the last active viewing of the newsletter, unless you unsubscribe earlier. |
| Blog and social media. Please note that any information you post in a comment on our blog or on our social media can be viewed by anyone. | First name and surname, address, date of birth, phone number, email address, username, and similar data | Any information, communications, or materials provided via a social media platform are also provided subject to the personal data processing policies of those platforms. | We keep your comments on a post for the entire time the post is published on our profile, unless you ask us earlier to delete your comment on our blog or social media. |
| Accounting. We receive remuneration for providing the Services and issue you accounting and tax documents, which we then archive and further work with for the purposes of properly keeping our accounts and complying with legal obligations. If you enter your credit card details, we do not have access to the complete details. We only know that you are paying by card, and the card details are processed by the recipients of this data, who process the payment for us. |
The details on the invoice - first name, surname, email address, billing address, or other identification of the User, and the details of performance under the Agreement. | After you fill in the payment information in your profile, we store this data in order to create an invoice. | We have a legal obligation to archive or retain the relevant document; the period depends on what the law requires (3 - 10 years). |
| Sending information related to the performance of the Agreement. This will include new features, planned outages, changes to the price list, and more. Sometimes you may receive such an email from our contractual partner as well. | First name, surname, email address, billing address, or other identification of the User, and the details of performance under the Agreement. | We also Process your Personal Data for the purpose of sending information related to our contractual relationship. This may include a change to the terms of service or to the price list. | The data is processed for the duration of the contractual relationship and subsequently for 3.5 years after the end of the Agreement. |
| Handling a request to send backed-up data. We understand that data is very valuable, which is why we back it up regularly and will send it to you on request. To do this, we will need to verify your contact details and, if necessary, your identity as well. | First name, surname, user account. | Based on your request, we export the backed-up data and send it to you. | The data is processed for the duration of the contractual relationship, and additionally for a period of 3.5 years after the end of the Agreement. |
| Compliance with legal obligations. In certain cases, we must process your Personal Data in order to comply with obligations laid down by law. |
This may include, in particular, the first name, surname, email address, billing details, or other identification of the User. | In this case, we Process your Personal Data so that we comply with applicable legal regulations (compliance with a legal obligation). | We Process your Personal Data for the period laid down by the applicable legal regulations. |
6. CHILDREN AND MINORS
Our Service may be used by persons over 18 years of age. Under no circumstances do we knowingly process the personal data of children and minors below this age limit. If we discover that we have received personal data from a child without parental consent or other lawful consent, we will take reasonable steps to remove this information as quickly as possible.
We have drafted this Privacy Policy to be as clear as possible. If, however, this Privacy Policy is not sufficiently understandable for you, contact us at support@dmarceye.com.
7. WHO ARE OUR PROCESSORS?
Processors. We only use vetted Processors with whom we have a written agreement in place and who provide us with at least the same guarantees as we provide to you. The data that the Processors may process, including the purpose and legal basis of the processing, is set out above. We use these Processors in our role as Controller, which means they do not process the data you enter into the system while using the Service.
| Standard website traffic analysis | Google Analytics |
|---|---|
| Provision of the Service | Amazon, Google, Twilio Inc., MessageBird, ChatGPT, Claude, HubSpot, SmartBear, IPinfo, Reditus |
| Creation and administration of the User account | X, Amazon, Google Ads, Bing Ads, Sklik |
| Payments and accounting | ABRA Software, Paddle, Freelo Bay, Google |
| Communication with customer support, handling of inquiries | Google, ABRA Software |
| Marketing | LinkedIn, Google, X |
| Social media | LinkedIn, Google, X |
| In-person meetings | Amazon, Google |
| Job applicants | StartupJobs, Google |
Google API. If, when using the Service, information and Personal Data is transferred from the Google API interface to any other application, the use of that service will be governed by the Google API Services User Data Policy, including the requirements on the limited use of that service.
Legal obligations. In addition to the Processors listed above, we may transfer Personal Data to third parties if required by law, or in response to lawful requests by public authorities, or when requested by a court in legal proceedings.
8. WHAT MEASURES HAVE WE TAKEN TO PROTECT YOUR PERSONAL DATA?
Our customers can influence the scope of processing within the provision of the Service through their own settings in the User account.
Technical measures. Security is very important to us, which is why we continuously work on keeping your Personal Data protected. When choosing measures, we take into account the scope of the processing, the riskiness of the processing, and the state of our technology.
- We back up data regularly;
- we keep our antivirus software systems up to date;
- we encrypt data using SSL/TLS ("secure sockets layer / transport layer security") for all data transmission;
- we use the secure https protocol;
- our data on servers is encrypted;
- we develop our technology with personal data protection in mind (privacy by design);
- access passwords to information systems (where Personal Data will be processed) and access permissions are controlled at the level of individuals.
Organizational measures. We have adopted, and commit to complying with, the following measures:
- Our employees and our service suppliers are bound by confidentiality;
- Our employees are properly trained, and also regularly retrained, on the GDPR and familiarized with the rules of safe work on work devices;
- When storing API keys, we remove authorization data;
- Access to all systems, including the information system, is personalized and protected by secure passwords;
- We keep passwords in the production environment in a separate location (Safe store), where access logs are kept, so that we can monitor employees' access to individual Users' Personal Data.
9. PROVISION OF SERVICES AND YOUR RIGHTS
If we use Processors based abroad, we ensure that we comply with the requirements of the applicable legal framework. In particular, where data is transferred from the EEA to other countries, we ensure a high standard of Personal Data protection through standard contractual clauses approved by the European Commission, or the equivalent standard contractual clauses for the United Kingdom, for transfers to countries that are not subject to an adequacy decision by the European Commission or your local legislator.
We follow the standards of the GDPR and the protection of Personal Data is very important to us. We also provide our Services outside the EEA market, so your rights connected with the protection of Personal Data depend on the applicable legal framework that applies to you.
A. CALIFORNIA CONSUMER PRIVACY ACT
If you are a citizen of the State of California, the rules of the CCPA apply to you and you therefore have the right to information about how we handle your data.
What data do we process? To provide our Service to you, we need your data. The personal data concerned and the purposes for which we process it are set out above. We may retain this personal data for as long as needed for the purposes for which it was collected, and only for the necessary period. That period depends on our business, legal, and regulatory needs, but it is always a reasonably long period.
What are your rights? The CCPA guarantees you the following rights:
| Right to know | You have the right to request information about what personal data we collect, use, disclose, share, and sell about you, where we obtained it, and for what purpose we process it. |
| Right to deletion | You have the right to require us to delete your Personal Data and to require our Processors to do the same. We will delete your data unless we have a legal obligation to retain it, or unless one of the other exceptions applies. |
| Right to opt out of sale or sharing | You have the right to opt out of us, as a company, selling your data. Since we share personal data with our Processors, this operation may be considered a "sale" of personal data under the CCPA. |
| Right to correction | You have the right to request the correction of inaccurate personal data. You can correct some data in your user profile. |
| Right to limit the use and disclosure of sensitive personal data | You can require us to use your sensitive data (personal identification number, information about your bank account, and similar) only for the purpose of providing services. |
| Prohibition of discrimination | You have the right not to be subject to discriminatory treatment as a result of exercising your rights. |
How can you exercise your rights? You can exercise your rights by email at support@dmarceye.com or by post at the address of our registered office.
In order to handle your request, we may require verification of your identity, depending on the nature of the right you are exercising. If a representative exercises your rights on your behalf, we will need proof of their authorization to act for you in this way. We will also require your representative to identify themselves. We take these steps to ensure the highest possible standard of protection of your Personal Data.
B. GDPR AND YOUR RIGHTS AND THE OPTION TO SUBMIT A REQUEST CONCERNING PERSONAL DATA PROTECTION
If you are located in the EEA, you can exercise with us the rights listed below arising from the GDPR.
You can exercise your rights by email at support@dmarceye.com or by post at the address of our registered office.
How quickly will we handle your request? We will respond to you within one month at the latest. If providing the information would endanger the privacy of other persons, or if providing it would be disproportionate to the risks or costs of providing it, we may not be able to comply with your request. So that we can handle your request as quickly as possible, we may need to verify your identity. In the case of a repeated request, the Controller will be entitled to charge a reasonable fee for a copy of the Personal Data.
| Right of access | We will confirm whether we Process your Personal Data. You have the right to information about the purposes of the processing, the categories of personal data, the recipients to whom it is disclosed, and the period of processing. You have the right to know whether any right has already been exercised. You are also entitled to a copy of the Personal Data, provided that the rights and freedoms of other persons are not adversely affected. |
| Right to rectification | You have the right to request the rectification of inaccurate personal data. You can correct some data in your user profile. |
| Right to erasure | If there is no other reason to continue processing this data, we will delete or anonymize the data you request. |
| Right to restriction of processing | Please contact us if you believe we are processing data incorrectly, whether it concerns the grounds for the processing or its scope. |
| Right to notification of rectification, erasure, or restriction of processing | If you contact us with a request, we will inform you of the outcome. It may sometimes happen that we cannot comply (e.g. the email address you wrote to us from no longer works). |
| Right to data portability | On your request, we will provide the Personal Data you have given us in a structured and machine-readable format to another controller. |
| Right to object | This right applies if we process your data on the basis of a legitimate interest (e.g. sending the newsletter to Users). It is up to us to demonstrate our legitimate interest. If your objection is justified, we will stop carrying out the Processing of the Personal Data. |
| Right to withdraw consent | If you have changed your mind, please let us know. Consent to processing for marketing and commercial purposes can be withdrawn at any time. |
| Automated individual decision-making, including profiling | You do not want decisions about you to be made by a computer? We respect your right, which is why we do not perform profiling. We provide the Service, and your Personal Data may be processed by automated means. |
10. CONCLUSION
This Privacy Policy may only be amended in writing. You will be informed of any amendment via our website or in the Application. Please therefore check this Privacy Policy regularly. By continuing to use our Service, you agree to the changes to this Privacy Policy.
If you have any questions regarding this Privacy Policy, please contact us at support@dmarceye.com.
If you are dissatisfied, you can at any time submit a suggestion or complaint to:
- the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), with its registered office at Pplk. Sochora 727/27, 170 00 Praha 7 – Holešovice (more at https://www.uoou.cz/), or
- another personal data protection authority located in the place of your habitual residence.
This Privacy Policy is effective as of 22 September 2026.
This is a translation. The governing version is the Czech original.