Privacy Policy
Last updated: 2026-07-26
This Privacy Policy explains how SieveGuard ("SieveGuard", "we", "us") collects, uses, and protects personal data when you visit https://sieveguard.com or use the SieveGuard service.
1. Who is the data controller
For data we collect about you as a visitor or customer (account, billing, usage), SieveGuard is the Controller. For email data you submit through the SieveGuard service to verify or analyse, you (the customer) are the Controller and SieveGuard is the Processor — see the DPA for that relationship.
2. What personal data we collect
- Account data: name, email address, hashed password, role within your workspace.
- Billing data: billing email, VAT ID, billing country, the last four digits of your payment card (handled by Stripe — we never store card numbers).
- Usage data: API requests, IP address, browser user-agent, response status codes — stored for security, debugging, and quota enforcement.
- Submitted email data: email addresses you submit for screening (raw + canonical), plus any cluster/score we compute. Processed under the DPA.
- Cookies / local storage: a session cookie for authentication and a local-storage value for your theme preference. We do not run third-party trackers.
3. Lawful basis for processing
- Contract (GDPR Art. 6(1)(b)): to provide you the SieveGuard service you subscribed to.
- Legitimate interests (GDPR Art. 6(1)(f)): to secure the service, detect abuse, and improve the product. We do not use this basis for advertising.
- Legal obligation (GDPR Art. 6(1)(c)): VAT records, tax filings, accounting compliance.
4. Who we share data with
We use a small number of vetted sub-processors to deliver the service. The current list is available on request to [email protected]. Each is bound by a written data processing agreement and offers at least the same level of protection as this policy.
5. International transfers
All customer data is stored in AWS Frankfurt (eu-central-1). Where a sub-processor (e.g. Stripe, Cloudflare) operates partly outside the EEA, transfers are protected by the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), incorporated by reference in each provider's own DPA.
6. How long we keep data
- Account & billing data: kept while your subscription is active, plus 7 years for VAT/tax compliance after termination.
- Submitted email data: kept while your subscription is active. On termination, deleted within 30 days. You can request immediate purge from the portal at any time.
- Verification cache: deliverability results are cached up to 7 days, keyed by canonical address (no tenant linkage).
- Audit + API request logs: kept for 90 days.
7. Your rights under GDPR
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Portability (export your data in a machine-readable format)
- Object to processing
- Withdraw consent at any time where consent is the basis
- Lodge a complaint with a supervisory authority
To exercise any of these, contact [email protected]. We respond within 30 days (extendable by a further 60 in complex cases per GDPR Art. 12(3)).
8. Security
TLS 1.3 in transit, AES-256 at rest. Tenant data is isolated at the database layer via row-level security. Access to production systems is limited to authorised personnel under confidentiality obligations. We notify affected customers within 72 hours of becoming aware of a personal data breach.
9. Cookies
We use strictly-necessary cookies to run the site and app (authentication session, theme preference, your cookie choices, affiliate attribution). On our public pages, and only with your consent, we use Google Analytics to understand aggregate, anonymous traffic — it is never loaded until you accept, and you can withdraw consent at any time via "Cookie settings" in the footer. We run no advertising pixels or marketing trackers. See our Cookie Policy for the full list and controls.
10. Children
The SieveGuard service is not directed at individuals under 16. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. Material changes are announced via email to the address on file and on the homepage. Continued use of the service after the effective date constitutes acceptance.
12. Contact
General: [email protected] · Privacy / GDPR: [email protected].