Spamexx

Privacy Policy

1. Controller

The controller for the data processing in connection with this website and the Spamexx service is:

sareba Computer & Software e.U.
Vorgartenstraße 441, 2145 Hausbrunn, Austria
Email: support@spamexx.com

2. What data we process and why

2.1 Registration and account

On registration we process the email address, a hashed password and organisational account information. Purpose: provision and administration of access. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

2.2 Email processing through the gateway

To provide the spam and virus filtering, we process the email passing through the gateway for the domains managed by the customer. This includes, among other things, sender and recipient addresses, subject, timestamp, size, technical headers, the filtering result and – in case of quarantine – the email content so the recipient can review it. Retention follows the booked plan or the configured quarantine and log periods. Purpose: provision of the agreed security service. Legal basis: performance of a contract and legitimate interest in email security (Art. 6(1)(b) and (f) GDPR).

Where we process email data on behalf of a customer, that customer is the controller and we act as a processor (Art. 28 GDPR); a data processing agreement is concluded on request.

2.3 Visiting the website

When the website is accessed, technically necessary server log data is processed (e.g. IP address, timestamp, requested resource, browser identifier). Purpose: secure operation and error analysis. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

2.4 Payments

Payments are handled through the payment provider Stripe or by bank transfer. We do not store full card data. For invoicing we process the master and invoice data required for that purpose. Legal basis: performance of a contract and legal obligation (Art. 6(1)(b) and (c) GDPR).

3. Recipients and processors

We use carefully selected service providers that receive data only for their respective function, in particular:

  • Hosting / data centre: Hetzner Online GmbH (server operation within the EU).
  • Payment processing: Stripe.
  • Email delivery for system and notification messages.

Disclosure to other third parties takes place only where legally required.

4. Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Requests can be sent to support@spamexx.com. You also have the right to lodge a complaint with the supervisory authority (in Austria: Austrian Data Protection Authority, www.dsb.gv.at).

5. Retention

Account data is stored for the duration of the contractual relationship. Email logs and quarantine content are retained according to the booked plan or the configured periods and then deleted. Invoice data is retained in accordance with statutory retention periods.

6. Cookies and tracking

For operation we use only technically necessary cookies (e.g. for login). No tracking for advertising purposes takes place.

7. Security

We take appropriate technical and organisational measures to protect the data, including transport encryption (TLS), encryption of sensitive data at rest, secure password hashing and optional two-factor authentication.

8. Changes to this policy

We adapt this privacy policy when the processing or the legal situation changes. The version published on this page at the time applies.