This policy explains what personal data SenderLedger collects, why we collect it, how long we keep it and what rights you have over it. It covers the public website, account holders, and the DMARC report data our customers send us to process.

Data controller

SenderLedger is a product of Justni Ltd, a private limited company registered in Northern Ireland. Justni Ltd is the data controller for the personal data described in this policy.

  • Privacy and data protection contact: legal@senderledger.com
  • Postal contact available on request via the address above.

What we collect, why, and on what basis

Access requests and inbound contact

When you fill in the request access form or email us directly, we collect the name, email address, organisation and any free-text details you provide.

Why: to respond to your enquiry and, if a commercial conversation follows, to maintain that record.

Lawful basis: legitimate interest in responding to inbound business enquiries. You can object at any time by emailing legal@senderledger.com.

Customer accounts

If your organisation becomes a SenderLedger customer, we collect the name and email address of each user we issue account credentials to, plus authentication metadata such as session timestamps and IP address at login, kept for account security and audit.

Why: to provide the contracted service and keep it secure.

Lawful basis: performance of a contract between Justni Ltd and the customer organisation.

DMARC report data

SenderLedger's core function is processing DMARC reports that mail receivers send to your domain's configured reporting address. This data is submitted by you (or generated automatically by receiving mail servers on your behalf) and processed by us on your instructions as a data processor, not a controller, for this category of data. Our processing terms are set out in the customer agreement and, where applicable, a data processing addendum.

  • Aggregate reports contain sending IP addresses, message volumes and authentication results. They do not contain message content or recipient addresses.
  • Failure (forensic) reports can contain message fragments, including headers and, depending on the sending receiver's configuration, portions of message content. Ingesting failure reports is an explicit, per-organisation opt-in available on plans that support it, controlled from your account's privacy settings.

Report data is retained for the period your organisation selects, subject to a 30-day minimum, and is deleted from live systems accordingly. Backups age out on a 35-day cycle, so a deleted record can persist in backups for up to that period before it is fully purged.

Website analytics

The SenderLedger public website uses Matomo, an analytics platform we run on our own infrastructure. Analytics data is not shared with any third party or advertising network.

Our Matomo installation currently places standard first-party analytics cookies in your browser to recognise repeat visits, and does not read or respond to a browser's Do Not Track signal. We collect page views, referrers and approximate location derived from IP address; we do not collect page content or form input through this tool.

On your first visit you will see a cookie banner where you can accept or decline analytics cookies. Declining means Matomo will not set a cookie in your browser and your visit will not be tracked. You can change your choice at any time by clearing the sl_analytics_consent cookie in your browser settings and reloading the page.

Lawful basis: consent, collected through the cookie banner described above.

Who else handles your data (sub-processors)

We rely on a small number of infrastructure providers to operate SenderLedger. None of them have unrestricted access to your data; they process it solely on our instructions.

Provider Purpose Location
Hetzner Online GmbH Infrastructure hosting Germany (EU)
Stripe Payments Europe Billing & payments Ireland (EU)
Resend Transactional email United States
Matomo Website analytics Self-hosted on our own infrastructure; listed here for transparency

We do not use third-party advertising trackers, marketing pixels or session-replay tools. We do not sell, rent or trade personal data.

Where your data is held

SenderLedger's application and report data are hosted in European Union (eu-west). Transactional email delivery may transit infrastructure located outside the EU, as set out in the sub-processor table above, under an appropriate transfer mechanism.

Your rights

Depending on your jurisdiction, you may have the right to:

  • Request a copy of the personal data we hold about you.
  • Ask us to correct inaccurate data.
  • Ask us to delete data we no longer need a lawful basis to hold.
  • Object to processing based on legitimate interest.
  • Restrict processing in certain circumstances.
  • Receive a portable copy of data you have provided to us.

Account owners can also request deletion of their organisation's report data directly from the privacy settings in the product, which triggers erasure on the processing infrastructure rather than a manual request.

Email legal@senderledger.com to exercise any of these rights. We aim to respond within one calendar month.

If you are not satisfied with our response and you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk/make-a-complaint. If you are in the EU, you may complain to your local data protection authority.

Children

SenderLedger is a business-to-business product. We do not knowingly collect personal data from anyone under 18, and our service is not directed to children.

Changes to this policy

We may update this policy from time to time. We will not retroactively reduce the protections that applied when you provided your data.