How we collect, use, share and safeguard personal data when you use TenbaMail.
This Privacy Policy explains how TenbaMail ("we", "us", "our") handles personal data in connection with our email sending and marketing platform, websites and related services (the "Service"). It applies to visitors of our website, users of our platform, and individuals whose data our customers process through the Service.
When we handle data about our own account holders and website visitors, we act as a data controller. When our customers upload contact lists and send campaigns, they are the controller of that data and we act as a data processor acting on their instructions. Customers are responsible for having a lawful basis to send messages to their recipients. See our GDPR page for our processor commitments.
We use personal data to provide, maintain and improve the Service; to authenticate accounts and process payments; to monitor and protect deliverability and prevent abuse; to provide support; to send service and, where permitted, marketing communications; and to comply with legal obligations.
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to deliver the Service), legitimate interests (to secure and improve the Service and prevent abuse), consent (for certain marketing and cookies), and compliance with legal obligations.
We do not sell personal data. We share it only with: service providers and subprocessors who host infrastructure, process payments or deliver email on our behalf under written agreements; parties involved in a corporate transaction such as a merger or acquisition; and authorities where required by law. A current list of subprocessors is available on request.
We may process data in countries other than your own. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Customer Data is retained while your account is active and deleted within a reasonable period after account closure, subject to backups and legal retention requirements.
We use technical and organizational measures designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, network protection and continuous monitoring. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address incidents.
Our security program is independently validated. We maintain:
Copies of our current SOC 2 report and ISO 27001 certificate are available to customers under a non-disclosure agreement — contact [email protected].
Depending on your location, you may have the right to access, correct, delete or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact [email protected]. If your data is processed by one of our customers (as controller), please direct your request to that customer; we will assist them as processor. You also have the right to lodge a complaint with a supervisory authority.
California residents (CCPA/CPRA). If you are a California resident, you have the right to know what personal information we collect and how it is used, to request access to or deletion of that information, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell personal information. You will not be discriminated against for exercising these rights. Submit a request at [email protected].
We use strictly necessary cookies to operate the Service and, with your consent where required, analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
For privacy questions or requests, contact us at [email protected] or through our Support page.