Privacy Policy

SealedMail Privacy Policy - Version 1.4, last updated 15 June 2026. UK GDPR compliant.

Version 1.8 - Last updated 8th July 2026

This policy explains what personal data SealedMail collects, why, and what your rights are. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

The data controller is Shaun Cooke, trading as SealedMail, of Bellingham House, 2 Huntingdon Street, St Neots, Cambridgeshire, PE19 1BG. Contact for all data protection matters: [email protected]. SealedMail is registered with the Information Commissioner’s Office.

2. What data SealedMail collects, and why

Subscribers

  • Data: name, business name, email address(es) including your nominated report recipient, subscribed domain name(s), and billing information. Payment card details are collected and held by Stripe; SealedMail never sees or stores card data.
  • Lawful basis: performance of a contract (UK GDPR Article 6(1)(b)) - this data is needed to provide the service and bill for it.
  • Retention: for the duration of your subscription, then for 30 days after cancellation before deletion, except billing records, which are retained for 6 years to meet HMRC record-keeping requirements (legal obligation, Article 6(1)(c)).

Free health check requestees

  • Data: first name, business name, email address, domain name.
  • Lawful basis: performance of a contract / steps taken at your request (Article 6(1)(b)) - the data is needed to produce and deliver your health check. We also keep an anonymised, hashed record of checked domains for 90 days to operate a fair-use limit (legitimate interests, Article 6(1)(f)).
  • Retention: 90 days from delivery of the certificate, then deleted. Your details are not added to any marketing list and you will not receive a sales follow-up.

Website visitors

  • Data: privacy-focused, self-hosted analytics (Umami, on SealedMail’s own UK infrastructure) - pages visited, referrer, country, and device/browser type - and, on a sampled (~15%), masked basis, session replays of on-page interactions (mouse movement, clicks, scrolling, and masked form activity) used solely to find and fix usability problems. Umami does not track you across other sites and does not retain IP addresses; the page-analytics script stores a small token in your browser’s local storage, while the replay script stores nothing on your device. Contact form submissions (name, email address, message) are also collected.
  • Lawful basis: consent (Article 6(1)(a)) for analytics and session replay - they load only after you opt in via the on-site banner, and you can withdraw at any time; legitimate interests (Article 6(1)(f)) for responding to enquiries.
  • Retention: aggregated analytics statistics are retained indefinitely as they contain no personal data; session replays are retained for 30 days then deleted; contact form correspondence is retained for 12 months after the enquiry is closed.

DMARC and TLS report data

For subscribed domains, SealedMail receives DMARC aggregate reports and TLS reports generated by email receivers. These are sent to a dedicated, receive-only address for your domain on our own subdomain (reports.sealedmail.co.uk) and are received, parsed, and stored entirely on SealedMail’s own UK infrastructure. They contain technical data about email flows - sending server IP addresses, authentication results (SPF/DKIM/DMARC), message counts and policy outcomes. They do not contain email content, subject lines, or the personal data of the people sending or receiving your email.

The sending-server IP addresses within these reports can, in some circumstances, constitute the personal data of third parties (email senders worldwide) with whom SealedMail has no relationship. SealedMail processes those IP addresses on the basis of legitimate interests (Article 6(1)(f)) - email security and fraud prevention - supported by a legitimate interests assessment held on file. Report data relating to a customer’s own domain is processed to deliver the contracted service (Article 6(1)(b)). Report data is retained for 13 months to allow year-on-year comparison; for a cancelled domain, the report address is disabled immediately and the data is purged 30 days after cancellation.

Operational monitoring and alerts

To run the service reliably, SealedMail’s automation sends its operator an internal alert when something needs attention - for example, that a payment has failed for a domain, that a weekly report needs review, or that a support message has arrived. These alerts are sent by email to SealedMail’s own operational mailbox and may include a customer’s domain name and the type of event, but never the content of any email or report. They are processed on the basis of legitimate interests (Article 6(1)(f)) - operating the service and not missing important events - and are held only in that operational mailbox under standard mail retention. SealedMail does not keep a separate operational-event database.

3. Who SealedMail shares data with (sub-processors)

SealedMail does not sell personal data. Data is shared only with the service providers needed to run SealedMail:

  • Stripe - subscription billing and card processing. Privacy policy: stripe.com/gb/privacy
  • Contabo GmbH - hosting of SealedMail’s infrastructure, and encrypted off-server snapshot backups, on servers located in the United Kingdom. All report receipt, parsing, and storage, the website, and SealedMail’s form systems run on this self-managed infrastructure. Privacy policy: contabo.com/en/legal/privacy
  • Amazon Web Services (AWS) - encrypted, off-site backup storage in AWS’s United Kingdom (London) region. Backups are encrypted by SealedMail before upload using keys held only by SealedMail; AWS stores only encrypted data and cannot read it. Privacy policy: aws.amazon.com/privacy/
  • Fastmail Pty Ltd - email hosting for SealedMail's operational email (support, onboarding, outbound report delivery, and operator alerts), with data held in Fastmail's data centres. Privacy policy: fastmail.com/policies/privacy/
  • Anthropic - AI text generation, used only to draft the personalised opening line for business outreach (see §7). Only minimal business context is sent (company, role and sector); no names, email addresses, customer data or report content. Anthropic processes this under its data-processing terms and does not use it to train its models. It is based in the United States, with transfers covered by appropriate safeguards. Privacy policy: anthropic.com/legal/privacy
  • Google LLC (Google Analytics) - website analytics used, with your consent, to understand site traffic and how visitors find us. Loaded only after consent via the on-site banner; see the Cookie Policy for details. Google may process this data outside the UK under its standard contractual clauses. Privacy policy: policies.google.com/privacy
  • BabyLoveGrowth (babylovegrowth.ai) - SEO content automation tool with read access to the website's Google Analytics and Google Search Console data, and publishing access to the website's content management system to schedule blog articles. It has no access to customer, subscriber or billing data.

SealedMail’s automation and form tooling (n8n), report parsing (parsedmarc and Elasticsearch), and the inbound report mail server (Postfix/Dovecot on reports.sealedmail.co.uk) are all self-hosted on SealedMail’s own infrastructure - no third party processes that data.

4. Where data is stored

SealedMail’s core infrastructure and report data are hosted on servers located in the United Kingdom (Contabo). Backups are held in the United Kingdom across two independent providers - Contabo (server snapshots) and AWS’s London region (off-site, client-side-encrypted copies). Operational email passes through Fastmail, with data processed in the United States; these transfers are covered by Standard Contractual Clauses. The AI drafting feature for business outreach (Anthropic, see §3) processes minimal business context in the United States under appropriate transfer safeguards; no names or email addresses are sent. No personal data is transferred outside the UK or EEA without adequate safeguards in place.

5. Your rights

Under UK GDPR you have the right to:

  • access the personal data SealedMail holds about you;
  • rectification of inaccurate data;
  • erasure (“right to be forgotten”), subject to legal retention obligations such as billing records;
  • restriction of processing;
  • portability of data you provided, in a structured machine-readable format; and
  • object to processing based on legitimate interests.

To exercise any right, email [email protected]. Requests are answered within one calendar month.

6. Cookies and similar technologies

The SealedMail website sets no advertising cookies. Self-hosted Umami analytics is cookieless but stores a small analytics token in your browser’s local storage, and the optional session-replay tool records masked on-page interactions. With the same consent, the website also uses Google Analytics, which sets its own cookies. Because these are not strictly necessary, they load only with your consent via the on-site banner, which you can change or withdraw at any time. Strictly-necessary items (such as the operator’s admin session) are exempt. Full details and controls are in the Cookie Policy at sealedmail.co.uk/cookies.

7. Marketing

SealedMail does not use the email address you give us as a customer or health-check requestee for marketing without your explicit consent. Requesting a free health check does not opt you in to anything, and weekly reports to subscribers are service communications, not marketing.

Business outreach. Separately, SealedMail carries out limited business-to-business outreach. We may contact people in their professional capacity at UK companies and other corporate bodies (for example, at a work email address published on a company website) where we have a reasonable basis to believe SealedMail’s email-security service, or a relevant article, is genuinely relevant to their organisation. This is done on the basis of legitimate interests (Article 6(1)(f)), promoting a relevant service to relevant businesses, supported by a legitimate interests assessment held on file, and within the Privacy and Electronic Communications Regulations (PECR) for corporate subscribers. We do not contact sole traders or individuals on this basis. Every such email identifies SealedMail, explains why you received it, links this policy, and carries a one-click unsubscribe that takes effect immediately and permanently. You can object at any time, or email [email protected], and we will stop. We process only business contact details (name, work email, company, role) and the public source they came from; we keep them only while the outreach remains relevant, and if you unsubscribe we keep a minimal record of your email on a suppression list indefinitely so that we never contact you again.

8. Complaints

If you are unhappy with how your data has been handled, please contact [email protected] first so it can be put right. You also have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk · 0303 123 1113 · Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

9. Changes to this policy

Material changes are announced on the website and, for subscribers, by email. The version and date at the top of this page always reflect the current policy.