Introduction
SpamGuard Cloud ("we", "our") respects your privacy. This policy describes how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679).
For account and billing data, SpamGuard Cloud acts as the Data Controller. For data passing through the Service, SpamGuard Cloud operates as a Data Processor under Art. 28 GDPR.
1. Data Collected
We collect only the data necessary to provide the managed email security service:
- Personal Data: Name, surname, company name, VAT/Tax Code.
- Contact Data: Email address, phone number.
- Technical Data: Public IP address of the server, firewall configurations.
- Security Logs: Traffic logs for monitoring and troubleshooting.
- Billing Data: Payment method, transaction history.
SpamGuard Cloud does not collect or process special categories of data (Art. 9 GDPR) unless the Customer voluntarily transmits them through the Service, in which case the responsibility for processing remains with the Customer.
2. Purpose of Processing
We use your personal data for the following purposes:
- Providing the managed email security service.
- Providing technical support and customer assistance.
- Sending invoices and contractual communications.
- Monitoring security and preventing cyber attacks.
- Improving service quality.
- Fulfilling legal obligations (tax, accounting).
3. Legal Basis for Processing
The processing of personal data is necessary for:
- Contract execution: Art. 6(1)(b) GDPR.
- Legitimate interest: Art. 6(1)(f) GDPR (cybersecurity, fraud prevention).
- Legal obligations: Art. 6(1)(c) GDPR (tax data retention).
4. Data Retention
We retain personal data based on the following retention logic:
- Account and configuration data: Deleted within 30 days of service termination.
- Billing and accounting data: Retained for the time required by law.
- Security and audit logs: Up to 12 months.
Logs may be retained longer only in case of incident investigations, legal defense, or compliance obligations.
5. Data Sharing
We do not sell or transfer your data to third parties. We may share data only with:
- Infrastructure providers: Datacenters for hosting (with GDPR-compliant agreements).
- Payment service providers: To process transactions.
- Competent authorities: If required by law or to protect our rights.
6. Rights of the Data Subject
Under the GDPR, you have the right to:
- Access: Obtain a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of data ("right to be forgotten").
- Restriction: Limit processing in certain circumstances.
- Portability: Receive data in a structured and readable format.
- Objection: Object to processing for legitimate reasons.
- Complaint: Lodge a complaint with the Data Protection Authority.
To exercise your rights, contact: privacy@spamguard.cloud
7. Data Security
We adopt reasonable technical and organizational measures to protect personal data, which may include:
- Encryption of data in transit and, where applicable, at rest.
- Access to data limited only to authorized personnel.
- Encrypted backups with defined retention.
- Continuous monitoring to detect security anomalies.
8. Cookies
The SpamGuard Cloud website uses only essential technical cookies for the functioning of the site. We do not use profiling or tracking cookies for advertising purposes.
9. Changes to Privacy Policy
We reserve the right to modify this Privacy Policy. Changes will be published on this page with an updated "Last updated" date. We recommend consulting this page periodically.
10. Contacts
For questions or requests regarding privacy:
Email: privacy@spamguard.cloud
Data Controller: SpamGuard Cloud
03738170780