Privacy policy
This document describes how Northbound Mail Systems Limited processes personal data, both as a data controller for our own website and business activities, and as a data processor for messages entrusted to us by clients.
Last updated: 1 April 2026. This document supersedes all previous versions.
1. Who we are
Northbound Mail Systems Limited (company registration 08432119) is a private limited company incorporated in England and Wales, with its registered office at 27 Old Gloucester Street, London WC1N 3AX. In this policy, "Northbound", "we", "our" and "us" refer to Northbound Mail Systems Limited.
2. When we act as a data controller
We act as a data controller for personal data we collect directly, including: information submitted via our contact form; correspondence sent to us by email, Telegram, Signal, WhatsApp or telephone; information provided during commercial negotiations; and technical information logged when you use this website.
Website logs include IP address, user-agent, requested URL and timestamp. Retention: 30 days. Lawful basis: legitimate interest in operating and securing the website.
3. When we act as a data processor
When we operate email infrastructure on behalf of a client, we act as a data processor. The client remains the data controller for the personal data of message recipients. The scope, purposes, retention and safeguards are defined in the Data Processing Agreement (DPA) forming part of the master services agreement between us and the client.
4. Data we handle as processor
Message envelope data (sender, recipient, timestamp, message ID), delivery-response metadata (SMTP responses, feedback loop reports, bounce categorisation), and full message content in transit. Full message bodies are not retained after delivery except where a client explicitly instructs retention for a defined operational purpose. Envelope and delivery metadata are retained per the client's DPA, defaulting to 60 days hot and 12 months archived.
5. Subprocessors
We use a limited set of subprocessors for infrastructure hosting, DNS, monitoring and finance. A current list is available to clients on request and is enumerated in the DPA. Changes to the subprocessor list are notified to affected clients not less than 30 days in advance.
6. International transfers
Personal data may be transferred between our operational regions (US, UK, EU and Singapore). All intra-Northbound transfers rely on Standard Contractual Clauses where a formal transfer mechanism is required.
7. Security
All personal data is encrypted in transit (TLS 1.2+) and at rest (LUKS). Access is restricted on a role-basis and audited. Credentials and cryptographic material are held in a segregated secret store. Physical infrastructure is co-located in ISO 27001-certified facilities.
8. Your rights
Under the UK GDPR and EU GDPR you have rights of access, rectification, erasure, restriction, portability and objection. Requests concerning data for which we act as processor should in the first instance be directed to the relevant data controller (the client). Requests concerning data for which we act as controller may be sent to legal@northboundmail.net.
9. Complaints
You have the right to lodge a complaint with a supervisory authority. In the UK, that is the Information Commissioner's Office (ico.org.uk).
10. Changes
Material changes to this policy are notified to clients under their master services agreement and reflected in the "last updated" date at the top of this page.