Privacy Policy
1.Who We Are & Our Role
This Policy explains how [MOXSEND OPERATING ENTITY] processes personal data for MoxWarm. For mailbox data processed to run warmup on your instructions we act as your processor under the Moxsend Data Processing Addendum [DPA required before launch]; for account, network-integrity, and billing data we act as controller. Your account data is otherwise governed by the Moxsend Privacy Policy.
2.Data Processed by MoxWarm
- Mailbox authorisation data: OAuth tokens and connected-account identifiers for the mailboxes you connect. Tokens are stored encrypted and used solely to operate warmup. [COUNSEL REVIEW: token storage, encryption standard, and scope minimisation statement]
- Warmup traffic: the synthetic warmup messages exchanged with network participants, and the headers/labels needed to route and file them. We access mailbox content only to the extent required to send, receive, identify, and organise warmup messages — not to read your correspondence. [COUNSEL REVIEW: Google Limited-Use disclosure wording]
- Placement & reputation signals: seed-test results, provider responses, authentication-record checks, complaint and bounce telemetry for warming domains.
- Network participation data: the minimum identifiers required to pair mailboxes for mutual warmup.
3.Purposes & Legal Basis
| PURPOSE | ROLE | BASIS |
|---|---|---|
| Running warmup exchanges and ramps you configure | Processor | Your documented instructions / contract |
| Placement testing and reputation monitoring for your domains | Processor | Your instructions |
| Protecting the warmup network (pairing integrity, abuse detection, throttling) | Controller | Legitimate interests |
| Billing, plan enforcement, support | Controller | Contract; legal obligation |
4.What We Do Not Do
- We do not read, analyse, or use your non-warmup correspondence.
- We do not sell mailbox data or expose your address to network participants beyond the warmup messages themselves.
- We do not use mailbox data to train models or for advertising. [COUNSEL REVIEW: confirm against Google Limited-Use requirements verbatim]
5.Retention
- OAuth tokens: until you disconnect the mailbox or close the account, then revoked and deleted within [N] days.
- Warmup message content: retained [N] days for pairing integrity and debugging, then deleted.
- Placement and reputation telemetry: [N] months for trend reporting, then aggregated or deleted.
6.Recipients, Transfers, Security & Regional Laws
Subprocessors under contract are listed at [SUBPROCESSOR LIST URL]. Cross-border transfers use appropriate safeguards (SCCs, PDPL-compliant mechanisms). We apply encryption in transit and at rest for tokens, access controls, and audit logging, and notify breaches as required. Processing is intended to be consistent with the EU/UK GDPR, Saudi PDPL, UAE data-protection law, and India's DPDP Act 2023. [COUNSEL REVIEW: jurisdiction obligations and transfer assessments]
7.Your Rights & Contact
Rights of access, correction, deletion, portability, restriction, and objection apply per your jurisdiction; for warmup data your organisation is typically the controller and we assist promptly. Contact: hello@moxsend.ai · DPO: [DPO NAME & EMAIL — COUNSEL REVIEW]. Cookies are covered in the Cookie Policy.