§ Privacy Policy

Privacy Policy

Version 1.1 Effective August 13, 2026 Data Controller Oliver DeNune INC

This Privacy Policy explains how Oliver DeNune INC ("Postmaster Ops," "we," "us"), operating the Postmaster Ops sending-infrastructure service ("Service"), collects and uses personal data. Postmaster Ops is a Pennsylvania corporation. This policy applies to (a) personal data of Customer representatives who interact with us in commercial dealings, and (b) recipient personal data processed on behalf of Customers as part of Service delivery.

§ 01 Roles & Definitions

For personal data of Customer representatives (name, business email, contact history), Postmaster Ops acts as the data controller.

For recipient personal data submitted per-send through the Service (recipient email addresses and delivery-outcome metadata such as SMTP response codes and rejection classifications), Postmaster Ops acts as the data processor on behalf of the Customer, who is the controller of that data. Where Customer's processing is subject to GDPR, UK GDPR, or comparable regimes, appropriate data- processing terms and transfer safeguards will be negotiated and executed before such processing begins. Postmaster Ops does not warrant that these frameworks are pre-built and does not currently represent readiness to sign a Data Processing Addendum without tailored review.

§ 02 Data We Collect — About Customers

When a prospective or active Customer interacts with us, we collect:

§ 03 Data We Process — About Recipients & Messages

When a Customer submits messages through the Service, the following recipient- and message-related data is processed on the Customer's behalf:

We do not accept uploaded subscriber files. Recipient email addresses are supplied per-message via SMTP submission by Customer and are not persisted as a standalone subscriber list. Suppression identifiers are stored as one-way hashes scoped to each Customer's account; the raw address is not retained after hashing.

§ 04 How We Use Data

Data collected above is used for:

We use recipient personal data only to provide, secure, monitor, and enforce the Service, investigate abuse, comply with law, and act on the Customer's documented instructions. We do not sell recipient personal data. We do not use recipient personal data for third-party advertising.

§ 05 Legal Basis (GDPR / UK GDPR)

Where Postmaster Ops is the controller and GDPR applies, the legal bases we rely on are:

Where Postmaster Ops is a processor, the lawful basis for processing recipient personal data is the Customer's responsibility.

§ 06 Data Retention

We retain data for the minimum period necessary to fulfill the purposes stated above and to satisfy legal or accounting obligations. Current defaults:

Transient operational copies. Standard operating infrastructure — MTA logs, backup snapshots, and exception traces — may transiently capture identifiable data that has been purged from primary storage. Current maximums: MTA and journald logs are rotated at 30 days; encrypted backup snapshots are retained up to 30 days; exception traces are retained up to 7 days. Access to these copies is restricted to authorized operators for security-forensics and disaster-recovery purposes only.

§ 07 Sub-processors & Third-Party Recipients

Postmaster Ops uses a limited set of sub-processors to deliver the Service. Categories include:

A current sub-processor list is provided as part of onboarding and updated as the sub-processor set changes. We do not otherwise disclose personal data to third parties except (a) as required by law or lawful regulatory request, (b) to enforce our rights or the safety of the Service, or (c) in connection with a merger or acquisition of Postmaster Ops or its assets, subject to the acquirer's continued compliance with this Policy.

Google Fonts. Pages served under postmasterops.com reference typefaces hosted by Google Fonts. When a visitor loads a page, the visitor's browser makes a request to Google's font servers, which necessarily discloses the visitor's IP address and user-agent string to Google as part of that request. This is a passive connection limited to font delivery. Visitors who prefer not to connect to Google Fonts may block that request via browser extensions or DNS filtering; the site remains readable in a fallback system font.

§ 08 International Transfers

Postmaster Ops operates infrastructure primarily in the United States. Postmaster Ops does not currently maintain a general international-transfer framework and does not represent operational readiness to receive personal data from the European Economic Area, United Kingdom, or Switzerland in the ordinary course. Customers whose intended processing would involve such transfers must raise this during the fit-review call so that appropriate transfer safeguards (Standard Contractual Clauses, UK International Data Transfer Agreement, or equivalent) can be executed before processing begins.

§ 09 Data-Subject Rights

Subject to applicable law, data subjects have the following rights in relation to their personal data:

For recipient personal data processed on behalf of a Customer, data subjects should first contact the Customer (as the controller of that data). Postmaster Ops will support Customer in fulfilling data-subject requests as required by our processor obligations.

Requests concerning personal data for which Postmaster Ops is the controller may be sent to privacy@postmasterops.com. We will respond within the timelines required by applicable law (typically 30 days).

§ 10 Security

Postmaster Ops implements administrative, physical, and technical safeguards designed to protect personal data against unauthorised access, disclosure, alteration, or destruction. Current practices include: encrypted transport for customer submission (TLS) and for inter-service traffic where technically feasible; strict access controls limiting operational access to a small number of authorised operators; multi-provider redundancy against single-carrier outage or compromise; and routine review of infrastructure logs for suspicious activity.

No security programme is proof against every risk. We do not represent that our safeguards are unfailing.

§ 11 Data-Breach Notification

Where Postmaster Ops becomes aware of a personal-data breach affecting data for which we are the controller, we will notify (a) the applicable supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of the breach, when the breach meets the reporting threshold under applicable law (for GDPR, where the breach is likely to result in a risk to individuals' rights and freedoms); and (b) affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms, in the manner and detail required by the applicable regime.

Where the breach affects personal data for which a Customer is the controller, Postmaster Ops will notify the affected Customer without undue delay upon becoming aware, and will provide reasonable assistance to the Customer in complying with the Customer's own notification obligations.

§ 12 Cookies & Tracking

The postmasterops.com marketing website does not set advertising cookies. Essential-only cookies may be used to remember interface preferences during a session. The Postmaster Ops operator dashboard (available to signed-in Customers only) uses functional cookies as necessary to maintain session state.

§ 13 Children

The Service is offered to businesses and other commercial operators and is not directed to children. Customers may not submit children's personal data through the Service where doing so would violate applicable law (including COPPA in the United States and the equivalent regimes elsewhere). Postmaster Ops does not knowingly seek to collect children's personal data for its own purposes; we cannot independently verify the age of every recipient address a Customer submits.

§ 14 Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active Customers by email; updates will be reflected in the version identifier at the top of this page. This Policy is a notice of our data-handling practices, not a contractual instrument; the terms binding you to the Service are the Terms of Service and your Service Order, which specify their own amendment procedures.

Data Controller Oliver DeNune INC (dba Postmaster Ops)

Jurisdiction Commonwealth of Pennsylvania, United States

Privacy contact privacy@postmasterops.com

GDPR / UK GDPR subject to prior review and execution of appropriate data-processing terms

Version 1.1 · effective August 13, 2026