Privacy Policy

Last updated: August 19, 2026

Who is responsible for your data

ControllerBartinsoft S.L.
Tax ID (NIF)B56799588
Registered addressCalle Hilados 20, 28850 Torrejón de Ardoz, Madrid, Spain
Contactprivacy@dmarc-examiner.com

Bartinsoft S.L. operates DMARC Examiner. We have not appointed a Data Protection Officer: our processing does not meet the criteria in Article 37 of the GDPR. Write to the address above for anything on this page.

What we process, why, and under which legal basis

Your account

Email address, password (stored as an Argon2 hash, never in clear text), first and last name when you provide them, language preference, and — if you sign in with Google — your Google account identifier and avatar URL. If you enable two-factor authentication we also store your TOTP secret and backup codes.

Legal basis: performance of the contract (Article 6.1.b). Without these we cannot give you an account.

Your domains and their reports

The domain names you monitor, their DMARC, SPF and DKIM DNS records, and the reports mailbox providers send about them. Aggregate (RUA) reports contain the IP addresses of the servers that sent mail using your domain, together with authentication results per source.

Legal basis: performance of the contract (Article 6.1.b).

Forensic reports, and the third parties in them

If you enable forensic (RUF) reports, mailbox providers send us individual failure reports. These contain data about people who are not our users: the sending IP address, the envelope sender and recipient addresses, the message subject, and the original message headers.

We receive this data from the reporting mailbox provider, not from the people it describes — this is the situation Article 14 of the GDPR covers. We process it only to show you why a specific message failed authentication on your own domain. We do not use it to profile anyone, we do not enrich it with other sources, and we do not sell or share it.

Legal basis: legitimate interest (Article 6.1.f) in detecting the abuse and impersonation of your domain, which is also the interest of the people being impersonated. Forensic reports are off by default and you choose whether to enable them.

How you found us

On sign-up we record the source, medium, campaign and referrer that brought you to the site, so we know which channels work.

Legal basis: legitimate interest (Article 6.1.f) in understanding how the service is discovered. You can object at any time.

Analytics and session recording

On our public pages we use Google Analytics 4 and Microsoft Clarity. Clarity records navigation sessions — clicks, scrolling and mouse movement — to show us where pages confuse people. Neither is used inside your account dashboard.

Legal basis: your consent (Article 6.1.a), which you may withdraw at any time without affecting anything you did before withdrawing it.

Support and email

The content of messages you send us, and the alerts and notifications we send you about your domains.

Legal basis: performance of the contract for service notifications (Article 6.1.b), and legitimate interest in answering you for support (Article 6.1.f).

Where your data lives, and who else touches it

Our application and database run on servers located in Spain. The providers below act as our processors under Article 28 of the GDPR.

ProviderWhat it doesWhere
IONOS SEApplication and database hostingSpain
Amazon Web Services (S3)Stores branding assets and exportsSpain (eu-south-2)
Google Ireland Ltd.Google Analytics 4; sign-in with Google; web fontsEU, with transfers to the United States
Microsoft Ireland Operations Ltd.Clarity session analyticsEU, with transfers to the United States

International transfers. Google and Microsoft may transfer data to the United States. Both are certified under the EU–US Data Privacy Framework, which the European Commission recognised as providing an adequate level of protection in its decision of 10 July 2023, and both also offer the Standard Contractual Clauses. Your account data and your reports are not transferred outside the European Union.

How long we keep it

DataRetention
AccountWhile the account is open, and 30 days after you delete it
Aggregate (RUA) reportsAccording to your plan's retention window
Forensic (RUF) reportsSame window, and deleted with the domain
Invoices and billing records6 years, as required by Spanish commercial law
Support messages2 years from the last reply
Analytics14 months (Google Analytics), 30 days (Clarity)

Your rights

You may ask us for access to your data, its rectification or erasure, the restriction of its processing, its portability in a machine-readable format, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time.

Write to privacy@dmarc-examiner.com. We answer within one month, extendable by two more if the request is complex, and we will tell you if that happens. Exercising these rights is free.

If you believe we have handled your data badly, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid, aepd.es). We would rather you told us first, but it is your right either way.

If you are a person named in a forensic report

You may be in our systems without ever having used DMARC Examiner, because a mailbox provider sent our customer a report about a message involving your address. You have the same rights listed above. Write to privacy@dmarc-examiner.com with the domain and approximate date and we will locate the records.

Note that for these reports our customer is the controller and we act as their processor, so we may need to refer your request to them. We will tell you when that is the case.

Security

Traffic runs over TLS. Passwords are hashed with Argon2. Two-factor authentication is available on every account. Each organisation's data is isolated, and API and webhook traffic is signed. No system is perfect: if a breach affects your rights and freedoms we will notify the AEPD within 72 hours and tell you directly when the law requires it.

Automated decisions

We do not make automated decisions with legal or similarly significant effects on you, and we do not profile you.

Children

The service is for organisations and is not directed at anyone under 14, the age of digital consent in Spain.

Changes to this policy

When we change something material we will update the date at the top and tell registered users by email before it takes effect.