Privacy Policy
This Privacy Policy explains how Email Foundry (“Email Foundry”, “we”, “us” or “our”) collects, uses and protects personal information when you visit this website, contact us, buy an Email Foundry plan, or receive setup and support from us.
1. Who we are
Email Foundry provides email marketing software, dedicated installations, setup and related support services.
Privacy contact: info@emailfoundry.co.uk
Business address:
St Agnes, Cornwall.
2. What this policy covers
This policy covers personal data we process for our own website, sales, billing, provisioning and support activities. If your organisation uses an Email Foundry installation to manage its own contacts, subscribers, customers or prospects, your organisation will normally decide why and how that recipient data is used and is responsible for complying with the data-protection and direct-marketing laws that apply to it.
Where we need temporary access to a customer installation to provide setup, maintenance or support, we only use that access for the service requested, security, troubleshooting, backups or other agreed operational purposes.
3. Personal information we may collect
Information you give us
- Your name, email address, company name, phone number and message when you contact us.
- Order and account information, including the plan purchased, billing details, payment status and transaction identifiers.
- Setup information such as domains, sender details, DNS-related information, technical preferences and service configuration.
- Support communications, diagnostic information and any information you choose to send us when asking for help.
Payment information
Payments may be processed through Stripe or PayPal, depending on the checkout route selected for the plan and the payment method chosen at checkout. We receive information needed to confirm and administer the order, such as payment status, customer details, transaction identifiers and subscription information. Stripe-hosted discounts or promotion codes may also be reflected in the order information we receive. We do not need to store your full payment-card number or card security code on this website.
Website and technical information
Our systems may record information such as your IP address, browser and device information, referring page, requested pages, date and time, security events and server logs. If optional analytics or advertising measurement is enabled, additional usage and attribution information may be collected through technologies described in our Cookie Policy.
4. Why we use personal information
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries and pre-sale questions | Legitimate interests and, where relevant, steps requested before entering into a contract |
| Processing orders, provisioning an installation and providing the purchased service | Performance of a contract |
| Billing, accounting, fraud prevention and legal record-keeping | Contract, legitimate interests and legal obligations |
| Providing support, maintaining service security and investigating technical problems | Contract and legitimate interests |
| Improving our website, products and customer experience | Legitimate interests, or consent where required for non-essential tracking |
| Sending service notices and important account information | Contract and legitimate interests |
| Sending marketing about Email Foundry | Consent or legitimate interests where the law permits, with an easy way to opt out |
Where we rely on legitimate interests, we consider the impact on the people concerned and do not use that basis where their rights and interests override ours.
5. Marketing communications
We may send relevant marketing where you have asked to receive it or where applicable law allows us to contact an existing or prospective business customer on another lawful basis. You can unsubscribe from marketing at any time using the unsubscribe link in an email or by contacting info@emailfoundry.co.uk. Service messages about an active order, security issue, payment or support matter are not marketing messages.
6. Who we may share information with
We only share personal information where it is necessary for the service, required by law, or supported by another lawful basis. Depending on the features in use, recipients may include:
- Stripe and PayPal, for checkout, payments, subscriptions, payment administration, security and fraud-prevention checks. Stripe may also process Stripe-hosted discounts or promotion codes where those are used.
- Hosting and infrastructure providers, where needed to operate the website or provision and maintain a customer installation.
- Email delivery providers such as Postmark, where a customer chooses or configures that sending route.
- Email verification providers such as Reoon, where verification is configured and an address needs to be checked.
- Google Analytics and Meta, if the relevant optional measurement tools are enabled and lawfully used.
- Professional advisers, payment or fraud specialists, regulators, law-enforcement bodies or courts where necessary or legally required.
Third-party services may have their own privacy terms and may act as processors, sub-processors or independent controllers depending on the service and circumstances.
7. International transfers
Some service providers may process personal data outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, we expect the relevant provider or transfer arrangement to use an approved mechanism, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard.
8. How long we keep information
We keep personal information only for as long as reasonably needed for the purpose for which it was collected, including to provide the service, resolve disputes, maintain security, and meet tax, accounting and legal obligations.
- Enquiry and ordinary support records are normally kept only while they remain useful for the relationship and a reasonable period afterwards.
- Order, invoice and financial records may be retained for the period required by applicable tax, accounting and legal rules, commonly up to six years or longer where a dispute or legal obligation requires it.
- Security and server logs are generally retained for shorter operational periods unless they are needed to investigate abuse, fraud or a security incident.
- Analytics and advertising data is subject to the retention settings and policies of the relevant provider and our account configuration.
9. Security
We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration or disclosure. No internet service can be guaranteed to be completely secure, so customers should also protect their account credentials, domains, email accounts and connected third-party services.
10. Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to:
- ask for access to your personal data;
- ask us to correct inaccurate or incomplete data;
- ask us to delete personal data in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to certain processing, including direct marketing;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent; and
- raise a complaint with the Information Commissioner’s Office.
To exercise a right, contact info@emailfoundry.co.uk. We may need to verify your identity before completing a request.
You can also find information about raising a data-protection complaint at ico.org.uk.
11. Children
Email Foundry is a business email marketing service and is not intended for children. We do not knowingly market the service to children.
12. Changes to this policy
We may update this Privacy Policy when our services, suppliers or legal obligations change. The latest version will be published on this page with the updated date shown above.