Privacy Policy
grimDMARC Platform (app.grimdmarc.com) · Last updated 2 August 2026
This policy covers the grimDMARC hosted platform only. It does not cover grimdmarc.com's own privacy policy, which is a separate document for a separate site.
1. Who we are
grimDMARC is operated by Grim & Strössel Invest AB (org.nr 559386-7822), Ekerö, Sweden — see grimstrossel.se for company-level information. grimDMARC provides a hosted DMARC/email-security platform for managed service providers (MSPs).
Contact for privacy matters: [email protected].
2. Roles: who controls this data
grimDMARC's direct customer is an MSP. The MSP is the data controller for its own end-customers' contact data and its own staff accounts; grimDMARC acts as data processor on the MSP's behalf. This is the standard SaaS controller/processor model.
If you are an individual whose contact details were entered into grimDMARC by an MSP (e.g. as a customer contact person), the MSP is who you should contact to exercise your rights — see Section 7.
3. What data we process
| Category | Examples | Source |
|---|---|---|
| Account/user data | Email address, display name, login timestamps | You, at account creation |
| Organization (MSP) data | Company name, VAT/org number, contact person, billing contact, address | You, in Organization Settings |
| Customer data (your end-customers) | Company name, contact person, contact email, billing/reporting email, address, notes | You, manually or via CSV import |
| Domain & DNS configuration | Domain names, DNS record status, DMARC/SPF/MTA-STS/TLS-RPT/BIMI posture | Automated DNS scans of domains you add |
| DMARC report metadata | Reporting mail server organization name, report file size/timestamp, storage reference | Automated, via Cloudflare Email Routing |
| Audit/security data | IP address, user agent, action performed, timestamp | Automated, on every account/domain action |
| Authentication data | Magic Link token hash (never the raw token), expiry | Automated, at login |
We do not knowingly process DMARC aggregate report content as personal data — that data describes mail servers and sending infrastructure, not individuals.
4. Why we process it (legal basis, GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): account provisioning, domain onboarding, DMARC hosting — delivering the service the MSP signed up for.
- Legitimate interest (Art. 6(1)(f)): audit logging and IP-address logging, for platform security and abuse prevention.
We do not currently rely on consent as a legal basis for any processing described in this policy, and we do not use the data described here for marketing, profiling, or advertising.
5. Sub-processors
| Sub-processor | Purpose | Data location |
|---|---|---|
| Cloudflare, Inc. | Hosting (Pages), database (D1), file storage (R2), DNS, email routing | EU — Western Europe (D1), EU jurisdiction (R2) |
| SMTP2GO | Delivery of Magic Link login emails | EU |
| GitHub, Inc. | Source code hosting only — no customer data stored in source control | — |
We do not use Google Analytics, Google Tag Manager, or any other analytics/advertising third party on the platform itself (grimDMARC Platform, app.grimdmarc.com) today. This is separate from grimdmarc.com and grimstrossel.se, which are different sites with their own analytics setup covered by their own privacy policies. This table will be updated, and this policy re-versioned, if that changes.
6. International data transfers
Cloudflare is a US-headquartered company; the data stores we use (D1, R2) are configured to EU regions, but Cloudflare's group-wide operations may still involve limited cross-border access (e.g. support). We rely on Cloudflare's published Data Processing Addendum and Standard Contractual Clauses for this.
7. Your rights
Under GDPR, data subjects have the right to access, rectify, erase, restrict, or port their personal data, and to object to processing based on legitimate interest.
- If you are an MSP user: contact [email protected].
- If you are an individual whose data was provided by an MSP customer: the MSP is the data controller for that relationship (Section 2) — contact them directly. grimDMARC will assist the MSP in fulfilling such requests.
8. Data retention
- Account data: retained while the account is active, deleted or anonymized within 6 months of account closure.
- Audit logs: retained indefinitely by design — the hash-chain tamper-evidence model depends on an unbroken history.
- DMARC report files: no automatic deletion is configured today; retained for the duration of the account.
- Soft-deleted records (domains/customers you remove): removed from view in the product immediately, and physically purged within 6 months.
9. Data security
- HTTPS-only (Cloudflare Pages — no plaintext HTTP path exists)
- Encryption in transit and at rest (Cloudflare platform defaults for D1/R2)
- Application-level tenant isolation (
organization_idscoping on every database query) — logical, not physical, separation between MSPs - Tamper-evident, hash-chained audit logging
- No passwords stored anywhere — authentication is passwordless (Magic Link only)
- HTTP security headers (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) are deployed on every response, both static pages and the API
Known gap as of this version, tracked in our internal security roadmap and being worked on: backup/restore has not yet been formally tested. We disclose this rather than imply a stronger posture than exists today.
10. Changes to this policy
We will update the “Last updated” date above and note material changes when they occur. Continued use of the platform after a change constitutes acceptance of the updated policy.