Privacy Policy
Last updated: July 27, 2026
This Privacy Policy describes how Developer Friendly OÜ ("we", "us", or "our"), the operator of the DMARCguard product, collects, uses, and shares information when you use our website at https://dmarcguard.io, our application at https://app.dmarcguard.io, and related services (collectively, the "Service").
Our Roles: Controller and Processor
This policy covers processing for which Developer Friendly OÜ is the data controller: our website, your account, billing, support, and product analytics.
For personal data contained in DMARC and TLS-RPT reports that we process on behalf of our customers (for example, identifiers of senders, recipients, or mail-infrastructure operators appearing in report data), we act as a data processor under our Data Processing Agreement — the customer whose domain the reports concern is the controller. If your personal data appears in such reports, please direct requests to the relevant customer; we will assist them in responding as their processor.
1. Information We Collect
1.1 Information You Provide
- Account information: When you create an account, we collect your email address and authentication credentials (or receive them via your identity provider if you use single sign-on).
- Domain configuration: Domain names you add for monitoring, DNS records you configure, and DMARC/TLS-RPT reporting addresses.
- Payment information: If you subscribe to a paid plan, purchases are processed by Polar Software, Inc. (Delaware, USA), acting as merchant of record and an independent controller of payment-related data under its own privacy policy. We receive billing and subscription metadata only and never store your payment card number.
- Support communications: Content of any messages you send to our support channels.
1.2 Information Collected Automatically
- DMARC and TLS-RPT reports: Aggregate and forensic reports sent to our processing addresses on your behalf. These reports contain IP addresses, domain names, email authentication results, and metadata about email delivery.
- Usage data: Pages visited, features used, timestamps, and interactions with the Service.
- Device and browser information: Browser type, operating system, device type, and screen resolution.
- IP address: Your IP address when accessing the Service, used for security and analytics purposes.
1.3 Information from Third Parties
- Identity providers: If you sign in via a third-party identity provider (e.g., Google, GitHub), we receive your name, email address, and profile information as authorized by you.
- IP enrichment: We enrich IP addresses found in DMARC reports with geolocation and network data from databases hosted on our own infrastructure (no data is transmitted to those database providers), with abuse-reputation data by querying AbuseIPDB (Marathon Studios, Inc., USA), to which the report source IP being checked is transmitted, and with a blocklist status check by querying the Spamhaus DNSBL (Andorra/Switzerland — jurisdictions with EU adequacy decisions), which processes the report source IP for its own anti-abuse purposes as an independent controller. See our sub-processor list.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Process and display DMARC, SPF, DKIM, BIMI, MTA-STS, and TLS-RPT data for your domains.
- Send you alerts, notifications, and reports you configure (unless you opt out of the corresponding email stream — see Section 2.2).
- Generate compliance scores, trend analytics, and actionable recommendations.
- Process payments and manage your subscription.
- Respond to support requests and communicate about the Service.
- Detect, prevent, and address security incidents and abuse.
- Comply with legal obligations.
2.1 Legal Bases (GDPR Article 6)
Where we act as controller, we rely on the following bases:
- Contract performance (Art. 6(1)(b)): account creation and management, delivering the Service, billing, and support.
- Legitimate interests (Art. 6(1)(f)): securing the Service and preventing abuse; product and website analytics, including marketing attribution (see Section 5); service-operation telemetry; and the email communications described in Section 2.2. Our legitimate interests are the security, reliability, and improvement of the Service, and knowing which of our channels bring users to it. You may object at any time.
- Legal obligation (Art. 6(1)(c)): tax and accounting record-keeping.
- Consent (Art. 6(1)(a)): any optional processing we expressly ask you to opt into. You may withdraw consent at any time.
Account information is needed to enter into and perform our contract with you — without it we cannot provide the Service. Providing any other personal data is optional. We do not make automated decisions producing legal or similarly significant effects about you.
2.2 Email Communications
We send two kinds of email. Essential emails — account, security, billing, and data-retention notices — are part of operating the Service and cannot be opted out of. Subscription streams — alert notifications, weekly digests, onboarding tips, the DMARC learning series, and product-usage reminders — each carry a one-click unsubscribe link and can be managed per stream in your notification settings. When you unsubscribe, we keep your email address on a suppression list indefinitely, so your opt-out is honored permanently.
3. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
- Service providers: With third-party vendors who assist in operating the Service (hosting, analytics, email delivery, support). These providers are contractually obligated to protect your information. The authoritative, always-current list is our sub-processor page.
- Merchant of record: Polar Software, Inc. processes purchases as an independent controller (see Section 1.1) — it is not a sub-processor.
- Legal requirements: When required by law, regulation, legal process, or governmental request.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- Integrations you configure: If you connect webhook destinations (for example Slack, Discord, Microsoft Teams, or a SIEM), alert content — which can include report data — is sent to those services at your instruction, under your agreements with them.
- With your consent: When you have given us explicit permission to share your information.
4. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS), encryption at rest, and access controls. However, no method of transmission or storage is 100% secure. Our Security & Data Protection Overview is available on request.
5. Cookies and Tracking
We use the following types of cookies and tracking technologies:
- Essential cookies: Required for the Service to function (authentication, session management).
- Analytics: We use PostHog (PostHog, Inc., a US company; our instance is hosted in the EU) to understand how the Service is used and which channels bring people to it. Analytics runs by default and includes a first-party attribution cookie (
dg_attr, 90 days,.dmarcguard.io) recording the campaign or referrer that first brought you here. The notice on your first visit lets you decline — declining stops analytics capture — and you can object at any time. Our backend also records service-operation events (billing lifecycle, error reports) keyed to pseudonymous account identifiers. We're a bootstrapped company: analytics tells us which door you came in through so we invest in the right ones. That's the whole story — no ad networks, no data brokers, no resale. PostHog processes data in accordance with their privacy policy. - Support chat: The Crisp chat widget (Crisp IM SAS, France) loads only inside the application after you sign in — never for anonymous website visitors — and sets its own identifiers to keep your support conversation continuous.
We do not use advertising cookies or sell data to advertisers.
6. Your Rights (GDPR and Applicable Law)
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format (CSV/JSON export is available in the Service).
- Restriction: Request that we limit processing of your data under certain circumstances.
- Objection: Object to processing of your data for certain purposes.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at the address below. We will respond within one month, or any shorter period required by applicable law.
7. Data Retention
We retain your data as follows:
- Account data: Retained for as long as your account is active. When you delete your account, personal data is removed from live systems immediately; residual copies in encrypted backups expire on our backup-rotation schedule.
- DMARC/TLS-RPT report data: Retained according to your plan's data history limits (Free: 30 days, Pro: 1 year, Enterprise: customer-configurable, including indefinite retention at your instruction).
- Logs and analytics: Retained for up to 1 year for security, auditing, and debugging purposes.
- Payment records: Retained as required by tax and accounting regulations.
- Support communications: Retained for as long as needed to resolve your request and for reasonable follow-up reference; you may ask us to delete them at any time.
- Email suppression list: When you unsubscribe from an email stream, we retain your email address on the suppression list indefinitely so that your opt-out is honored permanently.
8. International Data Transfers
Your service data is stored and processed in the EU (primary region: Germany), and product analytics and transactional email are hosted in the EU. Where a sub-processor is a US-incorporated company (for example our CDN provider), customer data stays stored at rest in the EU under appropriate safeguards such as the EU–US Data Privacy Framework and/or Standard Contractual Clauses. Two exceptions involve US processing: billing data is handled by our merchant of record, Polar Software, Inc. (USA), under its own privacy policy; and — as processor on our customers' behalf — we query AbuseIPDB (USA) with the bare report IP being checked (see the DPA and our sub-processor page for the per-vendor transfer details). You can obtain a copy of the applicable safeguards by contacting privacy@dmarcguard.io.
9. Children's Privacy
The Service is offered for business and professional use only and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date; for significant changes we will also notify you by email or in-app notice. This policy is a transparency notice, not a contract.
11. Contact Us / Data Controller
If you have questions about this Privacy Policy or wish to exercise your data rights, contact the data controller:
Developer Friendly OÜ
Address: Jõe tn 3-305, Kesklinna linnaosa, 10151 Tallinn, Harju maakond, Estonia
Email: privacy@dmarcguard.io
EU residents may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority in your country of residence.