Legal
Privacy Policy
How we process personal data on our website and in the portal – clearly structured and easy to follow.
This is a translation for your convenience. Only the German version is legally binding: Datenschutzerklärung.
This policy covers the website (mailsecurity24.com) and the portal (app.mailsecurity24.com); for report data of business customers, the data processing agreement applies in addition.
1. Controller
Highlight PC, owner Günter Geisler, Emil-Pahl-Weg 4a, 85659 Forstern, Germany, email: office@mailsecurity24.com, phone: +49 8124 5268188. A data protection officer has not been appointed.
2. Roles
- For accounts, contracts, billing and the website, we are the controller.
- For the report data of business customers’ domains, we process data on behalf of the customer (Art. 28 GDPR). The customer is the controller for this data.
- For the report data of private customers, we are the controller ourselves.
3. Website
- Server logs: When the website is accessed, the server stores IP address, time, requested page, browser type and referrer for at most 14 days for security and troubleshooting (Art. 6 (1) (f) GDPR).
- Contact form: We use name, email address, company, subject, domain and message to handle your enquiry (Art. 6 (1) (b) or (f) GDPR). Messages are also stored in our system and deleted after 6 months.
- Free domain check: When you enter a domain, your browser queries its public DNS records via our portal (app.mailsecurity24.com). We process the domain entered and your IP address (Art. 6 (1) (b) or (f) GDPR). We cache the result for at most 10 minutes so that repeated queries do not burden the DNS servers. To limit abuse we count queries per IP address only as an encrypted short value (hash) that expires after 10 minutes. To see how the domain check is used, we store the checked domain together with the time, language, check result and whether the query came from our website – without your IP address and without any link to you. We delete these entries automatically after 30 days (Art. 6 (1) (f) GDPR; our legitimate interest is developing our service further).
- Free BIMI logo preview: When you upload a logo on our website, we transfer the file to our portal (app.mailsecurity24.com), convert it to the BIMI format there and show you the result as a watermarked image. We process the uploaded file, the title you enter and your IP address (Art. 6(1)(b) or (f) GDPR). The file and the result are deleted immediately after the conversion; we do not hand out the converted SVG file. To limit misuse, we count previews per IP address only as an encrypted short value (hash) that expires after one hour. We also count previews per day – without the IP address and without any link to you. Please only upload logos for which you hold the necessary rights.
- Audience measurement: To understand which content is read, we count visits with the analytics tool Independent Analytics, which runs exclusively on our own server. It sets no cookies and does not transfer any data to third parties. We record the page viewed, the referring page, time and duration of the visit, device type, browser and operating system, and the country and city derived from the IP address. We do not store the IP address itself: a hashed value is formed from the IP address and browser identifier using a key that changes daily, so visits cannot be attributed to the same person beyond that day. Logged-in users are not tracked. We delete the analytics data automatically after two years. The legal basis is our legitimate interest in improving our services (Art. 6 (1) (f) GDPR); you can object at any time (section 13).
- Cookies and embedded content: The website sets no cookies and does not store anything else on your device. Fonts and all content are loaded from our own server; we do not embed services of other providers. Only the portal (app.mailsecurity24.com) uses technically necessary cookies for signing in (see section 4).
4. Portal and account
- Account data: Name, email address, encrypted password, language, optional two-factor settings; organisation and role in the team (Art. 6 (1) (b) GDPR).
- Cookies: Sign-in cookies plus one cookie each for the language and the intermediate step of two-factor sign-in. All are technically necessary (§ 25 (2) TDDDG); consent is not required.
- Trusted devices: If your organisation allows it and you use two-factor sign-in, you can mark a device as trusted after entering the code. We then set the cookie “ms24_trust” with a random value for 60 days; your password is still required, only the code is skipped. We store only a cryptographic check value (HMAC) of it, plus a rough device label derived from browser and operating system (e.g. “Firefox on Windows”) and the times it was set up and last used. At most five devices per account are possible; you can remove them in the portal at any time. Changing your password, any change to two-factor sign-in or the organisation switching the feature off revokes all devices. We set this cookie only at your request; it is necessary for the function you chose (§ 25 (2) no. 2 TDDDG, Art. 6 (1) (b) GDPR).
- Log: Security-relevant actions (sign-in, changes to team, domains, plan) are logged with time and user (Art. 6 (1) (f) GDPR) and deleted after 12 months.
- Emails: We send confirmations, sign-in codes, alerts, billing notices and messages about support requests via our own mail server. Email programs load the logo in our emails from our server; we do not analyse these requests and do not use tracking pixels. For troubleshooting, sending can be logged with recipient, subject and content for a limited period of at most 14 days (Art. 6 (1) (f) GDPR); the log is deleted afterwards.
- Protection report: From the Premium plan, we send owners and administrators of an organisation a protection report on the previous month by email at the beginning of each month, with a PDF attached. It contains summarised figures and results for the organisation’s domains; for this we use the recipients’ name and email address (Art. 6 (1) (b) GDPR). We generate the PDF only for sending and delete it afterwards; we only store for which month, when and to how many recipients the report was sent. You can unsubscribe via the link in every report email without signing in, or in the settings; the report remains available in the portal. If your organisation is managed by an agency, the report may carry the agency’s name and logo.
5. DMARC and TLS reports
Content: Reports contain IP addresses of the servers that sent emails on behalf of your domains, counts and check results (SPF, DKIM, DMARC), the domains concerned, and the name and contact address of the reporting organisation. Aggregate reports do not contain content or recipients of individual emails; we do not process forensic reports (ruf).
TLS reports: From the Premium plan, we additionally receive SMTP TLS reports (RFC 8460) once you set them up for a domain. They show whether emails to your domains could be delivered encrypted and contain the number of successful and failed delivery attempts, the type of failure, the IP address of the sending server, the names of the receiving mail servers and the name and contact address of the reporting organisation. They do not contain content, senders or recipients of individual emails. The reports reach us by email or via an encrypted web interface.
Enrichment and checks: To classify senders, we pass individual data to the following parties via DNS lookup:
| Recipient | Data | Purpose |
|---|---|---|
| Team Cymru (USA) | IP address of the sending server | Determine network operator and country |
| SpamCop, PSBL, UCEPROTECT | IP address of the sending server | Blocklist check |
| SURBL, URIBL | Domain name | Domain blocklist check |
| 1blu GmbH (hosting provider) | Names looked up | DNS resolution |
The IP addresses mostly belong to mail servers of companies and providers; only in exceptional cases can they be attributed to a person.
Retention: DMARC and TLS reports and their analyses are deleted automatically after the retention period of your plan (trial 30, Basic 45, Premium 90, Business and Agency 365 days).
6. DNS tools and mail server checks
We look up entered domains publicly in the DNS. We do not store results permanently; to limit lookups, we count them per user for ten minutes. A private DKIM key generated in the portal is shown only once and is not stored.
Mail server checks: For your domains we regularly connect to the mail servers listed in the DNS to check encryption (STARTTLS) and certificate, and we retrieve a published MTA-STS policy from https://mta-sts.<your domain>. We do not transmit any messages. We only store the technical results (server name, IP address, TLS version, certificate details, content of the policy); they are replaced at the next check and deleted when the domain is removed.
BIMI logo studio in the portal: We store uploaded logos, source images and results in your organisation until you delete them or the organisation is deleted. Hosted logos can be retrieved at a public address because mailboxes load them from there (Art. 6(1)(b) GDPR).
7. Payment via Stripe
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. We transmit name, email address, billing address and, where applicable, VAT ID; the customer enters payment details such as card numbers directly with Stripe, and we do not receive them (Art. 6 (1) (b) and (c) GDPR). Stripe is an independent controller for payment processing; a transfer to Stripe, Inc. in the USA is possible and is based on the EU-US Data Privacy Framework.
8. VAT ID check
If businesses from other EU states provide a VAT ID, we check it via the VAT Information Exchange System (VIES) of the European Commission. We store the result, name and request identifier as tax evidence (Art. 6 (1) (c) GDPR).
9. Accounting
We transfer invoices and credit notes with invoice number, amounts, tax details and customer name to our accounting software Lexware Office (Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany). For businesses in other EU countries with reverse charge, a contact with address and VAT ID is also created there (Art. 6 (1) (c) GDPR).
10. Support requests
Requests you submit in the portal under “Support” are stored in the portal and handled in our ticket system Atera, provided by Atera Networks Ltd., 45 Rothschild Ave., Tel Aviv 6578403, Israel. Atera processes the data on our behalf (Art. 28 GDPR); a data processing agreement is in place with Atera.
- Data: Your name, your email address, name and identifier of your organisation, and subject, urgency and content of your messages and our replies. At Atera, your email address appears only as information in the ticket and in your contact; as the delivery address we store a portal-specific relay address there so that Atera does not contact you directly.
- Legal basis: Art. 6 (1) (b) GDPR insofar as the request concerns your contract, otherwise Art. 6 (1) (f) GDPR (handling of enquiries).
- Third country: The European Commission has adopted an adequacy decision for Israel (2011/61/EU). Atera stores data in data centres in the EU and the USA; according to Atera, transfers to the USA are safeguarded by adequacy decisions or EU standard contractual clauses.
- Emails: Only we send notifications about your requests, via our own mail server; Atera does not contact you.
- Retention: Requests are kept as long as your account exists and are deleted together with your organisation – in the portal and at Atera. If you delete your personal account, we remove your name and email address there.
11. Hosting
Website and portal are operated by 1blu GmbH, Riedemannweg 60, 13627 Berlin, Germany, on servers in Germany. A data processing agreement is in place with the hosting provider.
12. Retention
We delete account data 30 days after the end of the contract or after the end of a trial without booking. We retain invoices and accounting records for eight years in accordance with tax regulations.
13. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests (Art. 15–21 GDPR). You can lodge a complaint with a supervisory authority, for example the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany. We do not make automated decisions within the meaning of Art. 22 GDPR.
Last updated: 30 September 2026
