Effective Date: September 1, 2026 • Last Revised: September 7, 2026
1
Overview & Regulatory Roles
At MAILARCH LTD (trading as “mailarch.io”, Company No. 17444844, registered in England and Wales) (“MailArch”, “we”, “us”, or “our”), we take the security, confidentiality, and sovereign privacy of your business data seriously. This Privacy Policy describes how we handle information when you visit our website, connect your Microsoft 365 tenant, or use our automated attachment offloading and archiving services.
Important Distinction: Data Controller vs. Data Processor
Under the EU General Data Protection Regulation (GDPR), UK Data Protection Act 2018, and state privacy frameworks (such as CCPA/CPRA):
Customer is the Data Controller: For all email communications, messages, attachment files, and user directory information within your Microsoft 365 tenant (“Customer Data”), your business is the Controller.
MailArch is the Data Processor: We process Customer Data strictly on your documented instructions to deliver automated attachment offloading, stubbing, and retrieval.
MailArch is a Data Controller: Solely for account administrative details (admin work email, billing contact, invoices) and direct website inquiries submitted through our contact forms.
2
Information We Process
Depending on your interaction with MailArch, we process the following categories of information:
Administrator & Account Information: Name, work email address, company name, tenant name, country/currency preference, and authentication identifier provided during Microsoft Entra ID OAuth login.
Billing & Subscription Records: Billing address, plan selection (Starter, Growth, Business Pro, Enterprise), payment receipt records, and Stripe customer tokens. (Payment card details are tokenized and processed directly by Stripe; MailArch never stores full credit card numbers).
Support & Contact Inquiries: Messages, company size, and email correspondence submitted through our contact form or support channels.
Technical Telemetry: Anonymized server logs, browser type, operating system, and IP address for API rate-limiting, DDoS prevention, and service diagnostics.
3
Microsoft 365 Email Data & Attachment Processing
MailArch integrates directly with Exchange Online via the official Microsoft Graph API under explicit administrator authorization:
Directory & Mailbox Metrics: Scopes User.Read.All and Reports.Read.All allow MailArch to inspect active mailboxes, current mailbox storage consumption, and item counts to evaluate optimization candidates.
Email Attachments: When active offloading is enabled via Mail.ReadWrite, our automated workers identify emails matching your offload policy (e.g., attachments larger than 5 MB or older than 1 year). The binary attachment is transferred directly to your designated sovereign cloud storage bucket and replaced in Exchange Online with a lightweight, secure signed HTML stub.
Message Bodies: MailArch does not store full email message bodies. During stubbing, we modify the existing email record in Exchange Online to inject the stub banner, keeping original message text and threading intact.
Zero Artificial Intelligence Training
We do not use, analyze, or process your emails or attachments to train artificial intelligence (AI), machine learning (ML), or large language models (LLMs). Your data is never pooled or utilized for model improvement.
4
How We Use Your Information
We process information solely for the following legitimate business purposes:
To provision, maintain, and secure your MailArch tenant environment.
To execute attachment scanning, offloading, stubbing, and authenticated re-hydration as configured in your policy settings.
To verify user identity via Microsoft Entra ID Single Sign-On (SSO) during attachment retrieval.
To calculate storage savings and display dashboard metrics to authorized tenant administrators.
To process subscription invoices and send transactional notifications (e.g., storage capacity milestones, security notices).
To detect, prevent, and remediate security vulnerabilities, abuse, or API anomalies.
5
Legal Bases for Processing (GDPR & UK DPA)
For individuals located in the European Economic Area (EEA) and the United Kingdom, our lawful bases for processing personal data include:
Contractual Performance (Art. 6(1)(b) GDPR): Processing necessary to provide the services described in our Terms of Service and fulfill subscription commitments.
Legitimate Interests (Art. 6(1)(f) GDPR): Processing necessary for infrastructure defense, API fraud prevention, and communicating critical operational notices.
Legal Obligations (Art. 6(1)(c) GDPR): Retaining financial transaction records and invoices to satisfy statutory accounting and tax regulations.
Consent (Art. 6(1)(a) GDPR): Where you have granted explicit consent, such as opting into partner communications or authorizing Microsoft OAuth enterprise permissions.
6
Sovereign Data Residency & Bring Your Own Storage
We recognize that regulatory compliance requires strict data territoriality. Customer Data is never relocated outside your designated compliance boundary.
Region Code
Physical Location
Jurisdictional Framework
europe-west1
Belgium, European Union
EU GDPR (Default EU)
europe-west2
London, United Kingdom
UK Data Protection Act 2018 / UK GDPR
europe-west3
Frankfurt, Germany
EU GDPR / German Federal Data Protection (BDSG)
us-central1
Iowa, United States
US Privacy Frameworks & HIPAA Compliant
us-east1
South Carolina, United States
US East Coast Sovereignty
asia-east1
Taiwan, APAC
Asia-Pacific Regional Compliance
Bring Your Own Storage (BYOS): Enterprise customers may configure direct storage inside their own Microsoft Azure tenant (Azure Blob Storage). Under BYOS, 100% of archived attachment files reside entirely inside your organization’s cloud boundary.
7
Security Measures & Technical Safeguards
MailArch implements enterprise-grade technical and organizational safeguards:
AES-256 Encryption at Rest: All archived attachments and database records are encrypted with military-grade AES-256 keys.
TLS 1.3 in Transit: End-to-end transport layer encryption is enforced for all communications between Microsoft Graph API, MailArch engines, and client browsers.
Cryptographic Isolation: Tenant data is segregated into distinct storage namespaces with tenant-specific encryption keys, preventing any multi-tenant data cross-talk.
Role-Based Access Control (RBAC): MailArch employees have zero access to customer email content. Access to underlying production infrastructure is gated behind multi-factor authentication (MFA) and strict zero-trust audit logging.
WORM Compliance: Compatible with SEC Rule 17a-4 and CFTC Rule 1.31 Write-Once-Read-Many retention locks when configured for compliance accounts.
8
Sub-processors & Third-Party Disclosures
We do not sell, rent, or trade your personal information or Customer Data. We engage only vetted third-party sub-processors bound by strict Data Processing Agreements:
Sub-processor
Role / Service
Location
Google Cloud Platform
Sovereign cloud compute & object storage infrastructure
Upon subscription cancellation or termination, MailArch maintains your archived attachments for a 30-day grace period. During this window, you may export all files or run automated re-hydration back into Exchange Online. After 30 days, all attachment binaries and tenant keys are permanently and irrecoverably wiped using cryptographic deletion.
10
Your Privacy Rights (GDPR, UK DPA & CCPA/CPRA)
Depending on your geographic location, you enjoy statutory privacy rights regarding your personal information:
Right of Access: Request a copy of the personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete personal information.
Right to Erasure (“Right to be Forgotten”): Request deletion of your personal information where no statutory retention obligations apply.
Right to Restrict Processing: Request temporary restriction of data processing while a dispute is resolved.
Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format.
Right to Non-Discrimination: We will never discriminate against you for exercising any statutory privacy rights under CCPA/CPRA.
To exercise any of these rights, contact us at info@mailarch.io. For requests regarding email content managed on behalf of a Customer, please contact the respective Microsoft 365 tenant administrator directly.
11
Cookies & Local Storage
MailArch maintains a minimalist, privacy-first posture regarding cookies:
Essential Session Cookies: Used strictly to authenticate administrator sessions and secure CSRF tokens during dashboard navigation.
Local Storage (Theme Preference): Stores your light or dark mode UI preference (mailarch_theme) directly on your device.
No Invasive Advertising Trackers: We do not deploy third-party advertising cookies, cross-site trackers, or behavioral surveillance pixels.
12
International Data Transfers
Where administrative data or technical metadata is transferred across jurisdictional boundaries, MailArch relies on standard recognized transfer mechanisms:
European Commission Standard Contractual Clauses (SCCs) as set forth under Decision (EU) 2021/914.
UK International Data Transfer Addendum (UK IDTA) to the EU SCCs.
Data privacy adequacy decisions where approved by competent authorities.
13
Updates to this Privacy Policy
We may periodically update this Privacy Policy to reflect modifications to our platform, changes in statutory requirements, or enhancements to our security controls. If we introduce material alterations, we will provide at least thirty (30) days prior notification via email to registered tenant administrators or through a prominent notice on our website.
14
Contact Our Privacy & Compliance Team
If you have questions, feedback, or requests regarding this Privacy Policy or our data protection practices, please contact us:
Data Controller Entity: MAILARCH LTD (Company No. 17444844, registered in England and Wales)
Registered Office: 31 Courtfield Rise, West Wickham, England, BR4 9BD