MessageWarden — Privacy Policy
Effective date: [EFFECTIVE DATE]
Controller: [OPERATOR LEGAL NAME], [OPERATOR ADDRESS],
[OPERATOR REG ID]. Contact: [CONTACT EMAIL].
This policy explains how we process personal data when you visit messagewarden.com, use the free domain checker, join the waitlist, or use the MessageWarden dashboard as a customer user. It is written under Articles 13 and 14 of the GDPR.
An important boundary: most of the data inside the product — DMARC aggregate-report content about our customers' monitored domains — is processed by us on behalf of our customers as a processor, governed by our Data Processing Agreement, not this policy. Section 6 explains what that data is; for requests about it, the responsible controller is the customer (typically the IT provider managing the domain).
1. Website and free checker
When you use the public domain checker:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Your IP address | Rate limiting (abuse prevention) | Legitimate interest (Art. 6(1)(f)) — service protection | Held transiently in an in-memory counter (~minutes); not written to a database |
| The domain you check + results | Producing the result; serving repeat checks from cache | Legitimate interest — operating the tool | Result cache ~10 minutes |
| Server logs (IP, path, timestamp, user agent) | Security, diagnostics | Legitimate interest | Up to 30 days in system logs |
Checked domain names are usually not personal data; where a domain identifies a person, the table above applies to it.
2. Waitlist / access requests
If you leave your email asking for access or monitoring of a domain, we store the email address, the domain, and the timestamp to contact you about the Service (Art. 6(1)(b) — steps prior to a contract, at your request). Kept until we onboard you or you ask us to delete it, at most 12 months.
3. Customer account users (the dashboard)
For people who sign in to a customer account (MSP admins and technicians):
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, work email | Account operation, sign-in links, alert and report delivery | Contract performance (Art. 6(1)(b)); for users added by their employer, legitimate interest | Life of the account + 30 days |
| Sign-in tokens and sessions (stored hashed), timestamps | Passwordless authentication | Contract performance / legitimate interest (security) | Tokens minutes; sessions ≤ 30 days |
| IP address at sign-in | Rate limiting, abuse detection | Legitimate interest (security) | Transient / logs ≤ 30 days |
| Billing details (company, VAT ID, invoice email) | Subscription, invoicing, tax | Contract; legal obligation (Art. 6(1)(c)) for tax records | Tax-law retention (5 years in Poland) |
Card data goes directly to Stripe and never reaches our systems.
4. Transactional email
We send sign-in links, alerts and reports from our own domain via Amazon SES (EU region, Frankfurt). We do not send marketing email without a separate basis, and we never send email on customers' behalf or from customers' domains.
5. Cookies
The dashboard sets only strictly necessary cookies: a session cookie (HttpOnly, expires ≤ 30 days) and a CSRF token. No analytics, advertising or third-party cookies — hence no consent banner.
6. Data inside the product (we are processor, not controller)
The Service receives DMARC aggregate reports for domains our customers monitor. These contain source IP addresses of email-sending servers, message counts, authentication results and domain names — IP addresses can be personal data. We also fetch public DNS data (SPF/DKIM/DMARC records, PTR records) for monitored domains and their senders. Aggregate reports contain no message content, subjects, or recipient addresses — and we deliberately do not ingest DMARC forensic (RUF) reports, which could.
For this data the controller is our customer (or their client); we process it solely under their instructions per the DPA. If you believe data about you is in a customer's monitored-domain data, contact the domain's operator; we will assist them as our DPA requires.
7. Recipients and international transfers
We share personal data only with the sub-processors and recipients listed in the sub-processor list (hosting and storage: Hetzner, Germany; payments: Stripe; transactional email: AWS SES, Frankfurt; error monitoring: Sentry, EU data residency), plus authorities where the law requires. Services are hosted in the EU. Where a provider's parent company is outside the EEA, transfers rely on adequacy decisions (EU–US Data Privacy Framework) and/or Standard Contractual Clauses, as listed there.
8. Your rights
You have the rights of access, rectification, erasure, restriction,
portability, and objection (Arts. 15–21 GDPR), exercisable at
[CONTACT EMAIL]. We answer within one month. You may complain to a
supervisory authority — in Poland, the President of the Personal Data
Protection Office (PUODO), ul. Stawki 2, 00-193 Warszawa.
9. Security
Measures include EU-only hosting, TLS everywhere, tenant isolation enforced at the database level, passwordless authentication with hashed tokens, hardened parsing of untrusted input, least-privilege access (a single operator), and daily encrypted off-site backups. Details for customers: DPA Annex II.
10. Changes
We will post changes here and, for material changes affecting customers, give email notice. Previous versions available on request.