top of page

Your Privacy Matters

We believe transparency builds trust. Learn how MailSecurity.ai collects, uses, protects, and processes information while delivering enterprise-grade email security services and cloud integration

Privacy Policy Last Updated: June 25, 2026 MailSecurity.ai ("MailSecurity", "we", "our", or "us") is committed to protecting your privacy and safeguarding the personal information entrusted to us. This Privacy Policy explains how we collect, use, disclose, process, store, and protect personal information when you access our website, products, and email security services. [developers.google](https://developers.google.com/terms/api-services-user-data-policy) This Privacy Policy applies to all visitors, customers, administrators, end users, and partners using MailSecurity.ai services. [developers.google](https://developers.google.com/terms/api-services-user-data-policy) By using our website or services, you agree to the collection and use of information in accordance with this Privacy Policy. [developers.google](https://developers.google.com/terms/api-services-user-data-policy) [...] Cloud Directory & Platform Integrations To provide automated directory synchronization and email signature management, MailSecurity.ai integrates with cloud identity platforms using official APIs, including Google Workspace Admin SDK Directory API and Microsoft Graph API. [developers.google](https://developers.google.com/workspace/workspace-api-user-data-developer-policy) MailSecurity requests read-only permissions to access: - Primary Email Addresses - Email Aliases - Distribution List Memberships - User Names - Job Titles - Departments - Office Locations - Business Telephone Numbers - Other business profile attributes required for directory synchronization MailSecurity.ai does not access Gmail message content or Google Drive file content via Google APIs for these directory and signature features. [developers.google](https://developers.google.com/workspace/workspace-api-user-data-developer-policy) Purpose of Processing Directory information is used solely for: Recipient Validation To verify that inbound email is addressed to valid recipients, reducing directory harvesting attacks, spam, and invalid message delivery. Email Signature Management To automatically generate and synchronize accurate corporate email signatures using approved organizational information. Directory Synchronization To maintain accurate user records within MailSecurity.ai and ensure security policies are correctly applied. Google API Services MailSecurity.ai integrates with Google Workspace using official Google APIs, including the Google Workspace Admin SDK Directory API, to provide directory synchronization, recipient validation, and email signature management services. We request only the minimum, read-only permissions required to deliver these features. [developers.google](https://developers.google.com/workspace/workspace-api-user-data-developer-policy) Through these integrations, MailSecurity.ai may access the following business directory information from your Google Workspace environment: [developers.google](https://developers.google.com/workspace/workspace-api-user-data-developer-policy) - Primary email addresses - Email aliases - Distribution list and group memberships - User names - Job titles - Departments - Office locations - Business telephone numbers - Other business profile attributes required for directory synchronization and email signature rendering Information obtained via Google APIs is used solely to: - Synchronize directory data with MailSecurity.ai - Validate email recipients - Generate and synchronize corporate email signatures - Apply customer-configured security policies and controls [developers.google](https://developers.google.com/terms/api-services-user-data-policy) We do not use information obtained from Google APIs for advertising, marketing, or profiling unrelated to the contracted email security and directory services. We do not sell or rent information obtained from Google APIs, and we do not share it with third parties for their independent use. [developers.google](https://developers.google.com/terms/api-services-user-data-policy) Access to Google-derived directory data is restricted based on the principle of least privilege and enforced through role-based access control, multi-factor authentication, and audit logging. Human access to Google-derived data is limited to specific operational needs such as troubleshooting, security investigations, and support requests, and only where authorized and logged. [developers.google](https://developers.google.com/workspace/workspace-api-user-data-developer-policy) MailSecurity.ai's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. MailSecurity.ai’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Information obtained through Google APIs is used only to provide or improve user-facing features that are part of MailSecurity.ai’s email security and directory synchronization services and is never sold or used for advertising purposes. [help.cloudsponge](https://help.cloudsponge.com/portal/en/kb/articles/what-does-google-require-my-privacy-policy-to-contain) MailSecurity.ai requests only the minimum permissions necessary to deliver the services requested by customers. [developers.google](https://developers.google.com/terms/api-services-user-data-policy) Microsoft 365 Integrations MailSecurity.ai integrates with Microsoft 365 using Microsoft Graph APIs and follows Microsoft's least-privilege security model. MailSecurity requests only the read-only permissions necessary to provide: - Directory Synchronization - Recipient Validation - Email Signature Synchronization MailSecurity.ai never modifies, creates, deletes, or writes information to Microsoft 365 unless explicitly authorized through separate administrative functionality. How We Use Information We process information to: - Deliver email security services - Detect spam, phishing, and malware - Validate recipients - Generate corporate email signatures - Authenticate users - Protect customer environments - Monitor platform health - Troubleshoot technical issues - Respond to support requests - Meet contractual obligations - Comply with legal requirements - Improve product functionality and service reliability MailSecurity.ai does not sell personal information. [...] Data Storage and Retention Directory information is securely cached to improve platform performance and ensure efficient recipient validation and signature rendering. Directory information synchronized from Google Workspace is cached only for as long as necessary to provide directory synchronization, recipient validation, and email signature services and is deleted in accordance with our retention procedures when Google Workspace integrations are removed or no longer required, unless retention is required by law. [developers.google](https://developers.google.com/workspace/workspace-api-user-data-developer-policy) Cached data is refreshed regularly to maintain accuracy. We retain personal information only for as long as necessary to: - Deliver contracted services - Meet legal obligations - Resolve disputes - Enforce contractual agreements Upon termination of services or removal of an integration, associated cached directory information (including Google Workspace directory data) is securely deleted in accordance with our retention procedures unless retention is required by law. [developers.google](https://developers.google.com/terms/api-services-user-data-policy) [...] Our Commitment Privacy and security are foundational principles of MailSecurity.ai. We collect only the minimum information necessary to deliver our services, apply the principle of least privilege to all cloud integrations, protect customer information using industry-standard security controls, and never sell customer data. Our mission is to help organizations secure their communications while maintaining the confidentiality, integrity, and privacy of their information.

Terms of Service Effective Date: June 25, 2026 Agreement Welcome to MailSecurity.ai ("MailSecurity", "we", "our", or "us"). These Terms of Service ("Terms") govern your access to and use of the MailSecurity.ai website, platform, software, APIs, and related services (collectively, the "Services"). By accessing or using our Services, you agree to be bound by these Terms. If you are accepting these Terms on behalf of an organization, you represent that you have the authority to bind that organization. If you do not agree with these Terms, you must not use the Services. Eligibility To use the Services you must: • Be at least 18 years of age. • Have the legal authority to enter into binding agreements. • Use the Services only for lawful business purposes. Services MailSecurity.ai provides cloud-based cybersecurity services, including but not limited to: • Email Security Gateway • Anti-Spam Protection • Anti-Malware Protection • Phishing Protection • Business Email Compromise (BEC) Detection • Email Continuity • Email Encryption • Email Archiving • Data Loss Prevention (where applicable) • Email Signature Management • Directory Synchronization • Threat Intelligence • Reporting and Analytics • API Integrations • Security Monitoring Our Services may evolve over time as we improve functionality, security, and performance. Customer Responsibilities You agree to: • Maintain accurate account information. • Protect administrator credentials. • Enable Multi-Factor Authentication where available. • Ensure authorized use of administrator accounts. • Maintain appropriate backups where required. • Promptly report suspected security incidents. • Configure your environment in accordance with our implementation guidance. • Obtain all necessary permissions from your users before connecting cloud services. You remain responsible for your organization's users, accounts, and data. Acceptable Use You agree not to: • Use the Services for unlawful purposes. • Attempt unauthorized access to our systems. • Reverse engineer, decompile, or disassemble the platform except where permitted by law. • Introduce malware or malicious code. • Interfere with service availability. • Circumvent security controls. • Abuse APIs or automated interfaces. • Resell the Services unless authorized under a separate reseller agreement. Customer Data You retain ownership of all data submitted to MailSecurity.ai. MailSecurity.ai processes customer data solely for the purpose of delivering the contracted Services. We do not acquire ownership rights over your data. Directory Integrations Where customers authorize Google Workspace, Microsoft 365, or other directory integrations: • MailSecurity.ai requests only the permissions necessary to provide the requested functionality. • Directory information is accessed on a read-only basis unless otherwise expressly documented. • Customers may revoke integration permissions at any time. • Removing an integration may disable related platform features. Security MailSecurity.ai maintains administrative, technical, and organizational safeguards designed to protect customer information. These safeguards include: • Encryption in transit. • Encryption at rest. • Role-Based Access Control (RBAC). • Audit Logging. • Security Monitoring. • Least-Privilege Administrative Access. • Multi-Factor Authentication (MFA). • Vulnerability Management. While we employ industry-standard security measures, no system can be guaranteed to be completely secure. Artificial Intelligence MailSecurity.ai may use artificial intelligence and machine learning technologies to enhance threat detection, malware identification, phishing detection, reporting, analytics, and automation. Customer information is never used to train publicly available or shared artificial intelligence models. AI-generated insights should be considered decision-support information and may require human review. Availability We strive to provide reliable and continuously available Services. Scheduled maintenance, emergency maintenance, internet outages, third-party provider failures, force majeure events, or circumstances beyond our reasonable control may affect service availability. Unless otherwise agreed in writing, no specific uptime guarantee is provided under these Terms. Support Support services are provided in accordance with your purchased subscription or service agreement. Support response times may vary depending on your service tier and the severity of the issue. Fees and Payment Subscription fees are payable in accordance with your quotation, order, subscription, or executed agreement. Failure to pay invoices when due may result in suspension or termination of Services. All fees are exclusive of applicable taxes unless expressly stated otherwise. Intellectual Property MailSecurity.ai and its licensors retain all intellectual property rights in the Services, including: • Software • Source Code • Documentation • APIs • Logos • Trademarks • Reports • Designs • Threat Intelligence • Platform Improvements No ownership rights are transferred to customers. Confidentiality Each party agrees to protect confidential information received from the other party. Confidential information includes technical information, business information, pricing, customer information, security documentation, and proprietary methodologies. Confidential information shall not be disclosed except where required by law. Third-Party Services MailSecurity.ai integrates with third-party platforms including: • Google Workspace • Microsoft 365 • Cloud Hosting Providers • DNS Providers • Identity Providers • Email Service Providers Availability and functionality of these integrations may depend on third-party services outside our control. Suspension MailSecurity.ai may suspend Services immediately where necessary to: • Protect platform security. • Prevent abuse. • Investigate suspected fraud. • Comply with legal obligations. • Prevent harm to customers or third parties. Where practical, reasonable notice will be provided. Termination Either party may terminate Services in accordance with the applicable subscription agreement. Upon termination: • Customer access may cease. • Integrations may be disconnected. • Customer data will be retained only as required by law or contractual obligations. • Obligations relating to confidentiality, payment, and intellectual property survive termination. Warranties MailSecurity.ai warrants that the Services will be provided using commercially reasonable skill and care. Except as expressly stated, the Services are provided on an "as is" and "as available" basis. To the fullest extent permitted by law, all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement, are excluded. Limitation of Liability To the fullest extent permitted by applicable law: • MailSecurity.ai shall not be liable for indirect, incidental, consequential, punitive, or special damages. • MailSecurity.ai shall not be liable for loss of profits, business interruption, loss of goodwill, or loss of data except where prohibited by law. MailSecurity.ai's total aggregate liability arising from the Services shall not exceed the fees paid by the customer during the twelve (12) months immediately preceding the event giving rise to the claim. Nothing in these Terms excludes liability that cannot legally be excluded. Indemnification You agree to indemnify and hold MailSecurity.ai harmless against claims arising from: • Misuse of the Services. • Violation of these Terms. • Violation of applicable law. • Infringement of third-party rights resulting from your use of the Services. Export Compliance You agree to comply with all applicable export control and sanctions laws. The Services may not be used in jurisdictions where prohibited by applicable law. Privacy Our collection and processing of personal information is governed by our Privacy Policy. Governing Law Unless otherwise agreed in a written contract, these Terms shall be governed by the laws specified in the applicable service agreement. If no separate agreement exists, these Terms shall be governed by the laws of the Republic of South Africa, excluding its conflict of law principles. Changes to the Terms MailSecurity.ai may update these Terms from time to time. Material changes will be published on our website together with the updated Effective Date. Continued use of the Services after changes become effective constitutes acceptance of the revised Terms. Severability If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. Entire Agreement These Terms, together with our Privacy Policy, Data Processing Addendum (DPA), Service Level Agreement (SLA), Subscription Agreement, and any applicable Order Forms, constitute the entire agreement between the parties regarding the Services. Contact Information MailSecurity.ai Email: [legal@mailsecurity.ai](mailto:legal@mailsecurity.ai) Website: [https://mailsecurity.ai](https://mailsecurity.ai) Questions regarding these Terms may be directed to the contact details above. Enterprise Security Commitment MailSecurity.ai is committed to protecting customer information through secure-by-design engineering, least-privilege architecture, strong encryption, continuous security monitoring, and responsible data governance. Our objective is to provide resilient, enterprise-grade email security while respecting customer privacy, confidentiality, and regulatory obligations.

Data Processing Addendum (DPA) Effective Date: June 25, 2026 This Data Processing Addendum ("DPA") forms part of the agreement between MailSecurity.ai ("Processor", "MailSecurity", "we", "our", or "us") and the Customer ("Controller") for the provision of MailSecurity services. This DPA applies where MailSecurity.ai processes Personal Data on behalf of the Customer in connection with the Services. This DPA is intended to satisfy the requirements of: • General Data Protection Regulation (GDPR) • UK GDPR • Protection of Personal Information Act (POPIA) – South Africa • California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) • Other applicable privacy and data protection laws Definitions Unless otherwise defined in this DPA, terms such as Personal Data, Processing, Controller, Processor, Data Subject, Subprocessor, Personal Data Breach and Supervisory Authority have the meanings assigned under applicable data protection legislation. Scope This DPA governs MailSecurity.ai's processing of Personal Data when providing: • Email Security Gateway • Spam Filtering • Malware Protection • Phishing Detection • Business Email Compromise (BEC) Protection • Email Encryption • Email Continuity • Email Signature Management • Directory Synchronization • Email Archiving • API Integrations • Security Monitoring • Reporting and Analytics Roles of the Parties For the purposes of applicable privacy legislation: • The Customer acts as the Data Controller. • MailSecurity.ai acts as the Data Processor. MailSecurity.ai processes Personal Data solely on documented instructions from the Customer except where required by applicable law. Categories of Personal Data Depending on the Services used, MailSecurity.ai may process: • Names • Business Email Addresses • Email Aliases • Distribution Lists • Job Titles • Departments • Telephone Numbers • Office Locations • Authentication Information • IP Addresses • Email Headers • Email Routing Information • Email Metadata • Email Content (only where required to provide the contracted Services) • Security Event Logs • Threat Detection Information MailSecurity.ai does not intentionally collect special category personal data unless such information is contained within customer email traffic and processing is necessary to provide the Services. Categories of Data Subjects Data Subjects may include: • Employees • Contractors • Consultants • Customers • Suppliers • Partners • Prospective Customers • Authorized Users • Other individuals whose information is processed within customer email communications. Nature and Purpose of Processing MailSecurity.ai processes Personal Data solely for the purpose of delivering contracted cybersecurity services, including: • Email Routing • Spam Filtering • Malware Detection • Phishing Prevention • Recipient Validation • Signature Synchronization • Security Monitoring • Threat Intelligence • Incident Investigation • Reporting • Customer Support • Platform Administration MailSecurity.ai will not process Personal Data for advertising, profiling, or unrelated commercial purposes. Customer Instructions MailSecurity.ai shall process Personal Data only: • On documented instructions from the Customer. • As necessary to provide the Services. • As required by applicable law. Where legally permitted, MailSecurity.ai will notify the Customer if it believes an instruction infringes applicable privacy legislation. Confidentiality MailSecurity.ai ensures that all personnel authorized to process Personal Data: • Are subject to confidentiality obligations. • Receive security and privacy training. • Access Personal Data only where required for their job responsibilities. • Operate under least-privilege access controls. Security Measures MailSecurity.ai maintains appropriate technical and organizational measures including: • Encryption in transit using TLS 1.2 or higher • Encryption at rest using industry-standard encryption • Role-Based Access Control (RBAC) • Multi-Factor Authentication (MFA) • Security Monitoring • Audit Logging • Vulnerability Management • Secure Software Development Lifecycle • Patch Management • Incident Response Procedures • Backup and Recovery Procedures • Business Continuity Planning • Principle of Least Privilege These measures are regularly reviewed and updated to address evolving cybersecurity threats. Artificial Intelligence Where artificial intelligence or machine learning technologies are used, they are employed solely to deliver contracted security services such as: • Spam Detection • Malware Classification • Threat Analysis • Phishing Detection Customer Personal Data is never used to train publicly available or shared artificial intelligence models. Subprocessors MailSecurity.ai may engage carefully selected subprocessors to support service delivery. Categories of subprocessors may include: • Cloud Infrastructure Providers • Identity Providers • Monitoring Providers • Backup Providers • Payment Processors • Customer Support Platforms • Analytics Providers MailSecurity.ai will: • Select subprocessors using appropriate due diligence. • Require equivalent contractual privacy and security obligations. • Remain responsible for the performance of its subprocessors. A current list of subprocessors will be made available upon request or published on the MailSecurity.ai website. International Data Transfers Where Personal Data is transferred internationally, MailSecurity.ai will implement appropriate safeguards including: • Standard Contractual Clauses (SCCs) • UK International Data Transfer Addendum where applicable • Contractual Safeguards • Technical Safeguards • Organizational Safeguards Assistance to the Customer MailSecurity.ai will provide reasonable assistance to enable the Customer to comply with applicable privacy legislation, including requests relating to: • Data Subject Rights • Data Protection Impact Assessments (DPIAs) • Prior Consultations with Regulators • Security Assessments • Compliance Audits Data Subject Requests Where MailSecurity.ai receives a request directly from a Data Subject regarding Personal Data processed on behalf of a Customer, MailSecurity.ai will: • Promptly notify the Customer where legally permitted. • Not respond directly unless authorized by the Customer or required by law. Personal Data Breaches MailSecurity.ai maintains documented incident response procedures. Following confirmation of a Personal Data Breach affecting Customer Personal Data, MailSecurity.ai will: • Notify the Customer without undue delay. • Provide available information regarding the incident. • Describe the likely impact. • Outline containment measures. • Provide updates as additional information becomes available. • Cooperate with the Customer in meeting applicable legal obligations. Data Retention and Deletion MailSecurity.ai retains Personal Data only for as long as necessary to provide the Services or comply with legal obligations. Upon termination of the Services, MailSecurity.ai will, at the Customer's election and subject to applicable law: • Return Customer Personal Data where technically feasible. • Securely delete Customer Personal Data. Certain information may be retained where required by law or necessary to establish, exercise, or defend legal claims. Audit Rights Upon reasonable written notice, and no more than once annually unless required by law or following a confirmed security incident, the Customer may request reasonable information demonstrating MailSecurity.ai's compliance with this DPA. MailSecurity.ai may satisfy audit requests through: • Independent Audit Reports • Security Certifications • Compliance Documentation • Security Questionnaires • Reasonable Virtual or On-Site Assessments, subject to confidentiality and operational security requirements. Liability Liability arising under this DPA shall be governed by the liability provisions contained within the applicable Master Services Agreement, Subscription Agreement, or Terms of Service. Term This DPA remains in effect for the duration of the Services and continues for as long as MailSecurity.ai processes Personal Data on behalf of the Customer. Order of Precedence If a conflict exists between this DPA and another agreement governing the Services: • This DPA shall prevail with respect to Personal Data processing obligations. • All remaining provisions of the applicable agreement remain unaffected. Governing Law This DPA shall be governed by the governing law specified in the applicable service agreement unless otherwise required by mandatory privacy legislation. Processing Details Subject Matter of Processing Provision of cloud-based email security and related services. Duration For the duration of the Customer's subscription and any legally required retention period. Nature of Processing Collection, storage, organization, consultation, transmission, analysis, synchronization, retrieval, deletion, and other processing necessary to deliver the Services. Purpose Delivery of contracted cybersecurity services. Categories of Personal Data As described in the "Categories of Personal Data" section of this DPA. Categories of Data Subjects As described in the "Categories of Data Subjects" section of this DPA. Technical and Organizational Security Measures MailSecurity.ai maintains security controls including: • Encryption in Transit • Encryption at Rest • Role-Based Access Control • Multi-Factor Authentication • Security Monitoring • Continuous Logging • Secure Software Development Lifecycle • Regular Vulnerability Assessments • Patch Management • Backup and Disaster Recovery • Business Continuity Planning • Incident Response Procedures • Least-Privilege Administrative Access • Vendor Risk Management • Personnel Confidentiality Obligations • Security Awareness Training These measures are reviewed periodically to ensure continued effectiveness against evolving cybersecurity threats. Contact MailSecurity.ai Email: [privacy@mailsecurity.ai](mailto:privacy@mailsecurity.ai) Website: [https://mailsecurity.ai](https://mailsecurity.ai)

bottom of page