Legal
Privacy Policy
This Privacy Policy describes how Notifiva (“we”, “us”, “our”) collects, uses, stores and shares information when you use our transactional email API, SMTP relay, website and related services (the “Service”).
1. Information we collect
We collect information in the following categories:
- Account data — name, email address, company name, billing details and authentication credentials when you create an account.
- Usage and technical data — API and SMTP activity (message IDs, timestamps, delivery events, IP addresses of your servers), browser and device information when you visit our website, and logs necessary to operate and secure the Service.
- Email content and metadata — content and headers of messages you submit for delivery, processed solely to send and track those messages. We do not use message content for advertising or training unrelated models.
- Communications — messages you send to support or sales.
2. How we use information
We use the information above to:
- Provide, operate and improve the Service (delivery, authentication, logging, webhooks, support).
- Authenticate users, prevent abuse and protect sender reputation (including bounce and complaint handling).
- Process payments and manage subscriptions.
- Comply with legal obligations and respond to lawful requests.
- Communicate with you about the Service, security notices and product updates.
3. Legal bases (EEA/UK)
Where applicable, we process personal data on the basis of contract performance, legitimate interests (security, product improvement, fraud prevention), consent where required, and legal obligation.
4. Sharing of information
We may share information with:
- Infrastructure and subprocessors that help us run the Service (hosting, email delivery partners, payment processors), under appropriate contracts.
- Authorities when required by law or to protect rights and safety.
- Successors in the event of a merger, acquisition or sale of assets, with notice where required.
We do not sell personal data.
5. Retention
Account data is retained for the life of the account and a reasonable period afterward for legal and operational reasons. Delivery logs are retained according to your plan (e.g. 3, 30 or 90 days) and then deleted or anonymized. Message content is retained only as needed to deliver and to support the log retention window you select.
6. Security
We implement technical and organizational measures designed to protect data against unauthorized access, loss and alteration. No method of transmission or storage is fully secure; please use strong credentials and restrict API keys.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or port your personal data, and to object to certain processing. Contact us at [email protected] to exercise these rights. You may also lodge a complaint with a supervisory authority.
8. International transfers
Data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers from the EEA/UK.
9. Children
The Service is not directed at individuals under 16. We do not knowingly collect personal data from children.
10. Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated date. Continued use of the Service after changes constitutes acceptance where permitted by law.
11. Contact
Questions about this policy: [email protected].