21 June 2026 · 2 min read
Yes. DMARC Engine is built to support GDPR compliance, and we act as a data processor for the operational data your domains generate. The personal data we touch is limited and specific. For your account we hold the email address you sign up with, billing details handled by our payment provider, and standard security metadata such as login timestamps and the IP addresses used to access app.dmarcengine.com. For the service itself we ingest DMARC aggregate (RUA) reports, which are sent by receiving mail servers and describe authentication results per source IP, not message content. Aggregate reports can contain sending IP addresses, which may be personal data in some contexts, so we treat them accordingly. We do not read, store or analyse the bodies, subjects or recipients of your actual emails; DMARC reporting works on metadata about authentication, not on the mail you send.
Where the data lives matters for GDPR, and our answer is straightforward: the platform runs on Cloudflare, and report processing happens in Cloudflare Workers with storage in Cloudflare's infrastructure. Cloudflare is a sub-processor and offers EU data-handling commitments and Standard Contractual Clauses for any transfers outside the EEA. We keep the data we hold to a minimum, separate per-account so one customer's reports are never visible to another, and we apply encryption in transit. Access to production data is restricted to the small number of people who operate the service, and account security features such as two-factor authentication and IP allowlisting let you reduce the risk of unauthorised access on your side too.
Retention is deliberately bounded rather than indefinite. Parsed aggregate report data is retained for a defined rolling window so you can see trends and reach p=reject with confidence, after which older detail is aged out. If you close your account, we delete or anonymise the associated personal data within our documented timescales, except where we are legally required to keep certain records (for example, billing and tax records). The exact periods, the categories of data, and our list of sub-processors are set out in our data-retention and privacy notice, which is the authoritative reference and is kept current as the service evolves.
To support your own obligations as the data controller, we provide the practical controls GDPR expects:
- Right of access and erasure: request a copy of your account data or its deletion, handled within statutory timescales.
- Data minimisation: we collect only what the service needs, and we never store your email content.
- A Data Processing Agreement (DPA): available for customers who need one in writing, covering processing scope, sub-processors and SCCs.
- Security controls: encryption in transit, per-account isolation, restricted production access, plus optional 2FA and IP allowlisting on your account.
- Breach process: we will notify affected customers without undue delay if a personal-data breach affecting your data occurs.
If you have a specific clause to satisfy, a security questionnaire, or a request to exercise a data subject right, contact our support team and we will point you to the relevant documentation or sign the paperwork. For the full detail on categories, locations and retention periods, start with the data-retention and privacy notice.