At MailMatic (referred also as "we", "us", "our" and "MailMatic.co"), are committed to protect the privacy and keeping personal information of our Members and anyone receiving our Members' emails. We take data privacy very seriously.

This policy explains who we are, how we collect, share and use Personal Information, how it applies to our email marketing services, our associated sites and it includes MailMatic.co (and its subdomains) and to all our sites where you find this Privacy Policy linked to in the footer.

This policy (with our Anti Spam and Terms of Use policy and any other document referring to it) specifies:

- Personal information and details that we may collect from you
- Information on how we use your personal information
- Information about the ways we share your information with our partners
- Information on how we store your information
- Information about your rights

Please read this policy carefully to understand our views and practices regarding your personal data and how we will treat it.

Last update December 31, 2021 

Key takeaways to note:
- Our websites use cookies 
- We use analytics tools, such as Google Analytics to track user behaviour on our website
- We use third party email services providers who will have access to your data

Who is this policy addressed to?
MailMatic is an online email platform operated by QBeat headquartered in Singapore ("we", "us", "our" and "MailMatic"). For the purpose of data protection legislation including the Singapore Personal Data Protection Act 2012 (‘PDPA’) and General Data Protection Regulation ('GDPR'), the data controller of your personal data is QBeat - 7 Temasek Boulevard #12-07 - Suntec City Tower One - Singapore 038987 - (registered in the Republic of Singapore with UEN53261209D)

When we refer within this policy to 'you', we are referring to a customer of our services, or a person visiting our website. We are not referring to a person receiving an email sent by a customer using our service, or a person on a mailing list maintained by one of our customers. We refer to those people in this policy as 'Contacts'. We do not have any relationship with Contacts, and process information relating to them solely for the purposes of providing our service to our customers.

When we refer to a 'contact list' in this policy, we are referring to details of Contacts (including their email addresses) processed by us on your behalf to provide you with our MailMatic service.

If you are a Contact and wish to cease receiving emails from one of our customers, please unsubscribe directly using the unsubscribe link in the customer's email, or contact the customer directly.

If a Contact makes a direct request to be removed from the contact list of one of our customers, we may do so on behalf of our customer, while providing notice to the customer of the Contact's request. Our customer is the data controller in respect of Contacts' personal data, and Contacts should consult our customer's own Privacy Policy for details on the customer's data protection practices. We will never use the Contact email addresses to send our own informational and promotional content. We may refer to Contact's personal data when generating usage reports and analysis as data processor for our data controller customers. This may involve analysis on the events (such as bounces, unsubscribes, clicks, and opens) arising from emails sent to Contacts using our service.

Information we may collect from you
We may collect and process the following data about you:

Information that you provide to us. You may give us your information by filling in forms on our website or by corresponding with us by email, live chat, phone or otherwise. This includes information you provide when you register to use our service, respond to any surveys that we send to you to complete, and when you contact us for any reason. When you register for our service we will ask for a range of information we need to collect in order to set up your account and engage one or more of our upstream email service providers to handle your emails. If you contact us, we may keep a record of any information contained in the correspondence.

Your IP address: This information is used for fraud and abuse detection.
Data for the purposes of advertising and targeting – see the 'Advertising and targeting' section below.

Payment information: When using our paid service, you will be asked for financial details such as credit/debit card information. The processing of these payments is carried out by our payment processor, Stripe. We do not store any credit or debit card information on our servers. Stripe has been audited by a PCI-certified auditor, and is certified to PCI Service Provider Level 1. (This is the most stringent level of certification available). Their security assurances and Privacy Policy are available on their website.

How we use your personal information
We use information held about you for the following purposes:
- to provide you with information or services that you request from us, including responding to any requests for assistance with the service;
- to send you newsletters about our service and notify you about any changes to the service;
- to carry out our obligations arising from any contracts entered into between you and us;
- to administer our site and for internal operations, including troubleshooting;
- to help optimise and develop our service, for example through statistical analysis and research on your use of our service;
- as part of our efforts to keep our website safe and secure and to monitor actual or suspected fraudulent activity;
- to determine your regional location for the purposes of recommending a billing currency;
- to carry out targeted advertising (see the 'Advertising and targeting' section below).

Advertising and targeting
We use third-party providers to display adverts for our services on other websites. We, alongside these third-party providers, may use cookies and other similar tracking technologies, such as web beacons, to show you targeted adverts for MailMatic based on your browsing activity. We may also share your email address with Facebook or Google in a protected (hashed) form for similar targeting purposes. See our list of processors and sub-processors for further information on the data we share with our third-party providers.

Your contact lists
Your contact lists are stored in Singapore, on the secure servers of Digital Ocean (‘DO’). Unless you are using our 'SMTP' service, they will also be available to our email service providers (‘ESPs’). ESPs will only have access to your lists when you are sending an email. Once the email is sent, the ESPs no longer have access to your contact list. Our ESPs are Mailgun, SendGrid, Sparkpost, Elastic Email and SES. We don't, under any circumstances, sell or share your contact lists with anyone else. If someone on your contact list complains or contacts us, only then will we respond to that person. Only you, our authorised employees, and our ESPs have access to view your contact lists.

We may also monitor those events for the purposes of administering our service (including checking for any abuse of our service) and research on patterns and trends in the use of our service. We will never use any Contact data for the purposes of that administration or generating that research. It will always be conducted on an aggregated and anonymised dataset, which does not identify any individual Contact.

You may export (download) your contact lists from MailMatic at any point in time. We'll only ever use and disclose the information in your contact lists for the reasons listed in this section or in the section entitled 'How we use your personal information' above.

We will never use or disclose the information in your contact lists to send our own informational and promotional content. If we detect abusive or illegal behaviour related to your contact list, we may share your contact list or portions of it with affected internet service providers (“ISPs") or anti-spam organisations. We may also be required to disclose it to law enforcement or regulatory bodies. We will only do so if legally required.

We may conduct analysis on your use of the service and the results generated by your emails sent by means of the service. This analysis is conducted solely on an aggregated and anonymised basis.

Cookies and tracking technologies
Our website uses cookies to distinguish you from other users of our website. The majority of these cookies are required to provide our service, ensuring you remain signed in to MailMatic and that we can personalise the service offered. We may also use cookies and other similar tracking technologies, such as web beacons, for advertising and targeting purposes. See our Advertising and targeting section for further details.

Where we store your personal data
The account details and IP address that we collect from you are stored on our DO servers in Singapore. All the personal data we collect from you may be processed by our staff, or those of our ESPs and other service providers (see our list of processors and sub-processors) operating outside Singapore. Such staff may be engaged in, among other things, the fulfilment of your services, and the provision of support services. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy. Please contact us if you would like more details on the appropriate safeguards we employ to require that these providers process your data with due respect for its privacy.

All information you provide to us is stored on our secure servers. Any payment transactions will be carried out by Stripe over encrypted connections using SSL technology (see the 'Payment Information' section above). Where we have given you (or where you have chosen) a password or API key which enables you to access certain parts of our site, or you have invited team members to access parts of our site, you are responsible for keeping this password or API key confidential.

We take security very seriously, and 'privacy by design' is baked into our engineering and product development principles but, as with any online service, despite our use of leading security tools and techniques, the personal data we hold about you can never be 100% immune from unauthorised access.

Disclosure of your information
We may disclose your personal information to any company under the same ownership as us.
We may disclose your personal information to selected third parties, including:

 - in the event that we sell or buy any business or assets, the prospective seller or buyer of such business or asset; 
 - if MailMatic or substantially all of its assets are acquired by a third party, to the relevant third party; 
 - business parties and subcontractors for the purposes of providing the MailMatic services;
 - when you verify your domain for the purposes of receiving the services, our ESPs will see your email address, phone number, street address, domain, and account ID. When an email is sent using an ESPs service, the ESP will see the 'from' name and address, the subject, the body of the email, and the destination email addresses. When an email recipient opens an email you have sent or clicks a link in the email, the ESP will see the IP address of the recipient (from which may be inferred a notional latitude and longitude associated with that IP address). For a detailed list of which ESPs have access to which information, please contact us.
 - analytics providers that assist us in the improvement and optimisation of our website; and
 - law enforcement agencies or regulatory bodies; or other third parties for fraud detection and prevention. We will only do this is if we are legally required to do so.
 - We may also disclose your personal information to third parties if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our Terms of Use and Anti-Spam Policy and other agreements, or to protect the rights, property, or safety of MailMatic, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud detection and protection and credit risk reduction. 

Integrations: MailMatic and other third party integrations
Our service integrates with your own account held with an email service provider, such as AWS (Amazon Web Services). Please see your provider's Privacy Policy and Terms and Conditions of Service to review their practices and processes regarding the usage, storage and disclosure of any data used in relation to their service.

You can additionally integrate your MailMatic account with third party apps websites or other services with whom you have your own account independent of MailMatic using our API or any integration utility we might provide. If you do decide to connect your account with that third party to MailMatic, the third party you integrate will as a result receive your contact lists, information about your use of our services, and access to any other personal data you make available to them. All third parties you integrate in this way are your own data processors – they are not sub-contractors or sub-processors of MailMatic.

Information collected by these third parties is subject to their own terms and privacy policies. An example of such a third party is Integromat or Zapier. 

Retention of your personal information
The periods for which we keep your information depend on why your information was collected and what we use it for. We will not keep your personal information for longer than necessary for our business purposes or for legal requirements.

For your convenience we will keep your account open (and therefore retain your data so that it is available to you) for up to 13 months after your last sign in or use of our service. Prior to closing your account and deleting your data, we will attempt to send warning emails to your account email address so that you have an opportunity to keep your account open or back up any data that you need. We may contact you about our services during this time, unless you have asked us not to contact you.

At any point you may delete your account and the data you have provided via the Dashboard. Copies of your data may remain for up to 90 days in backup storage, which we use to recover from an unexpected event that results in data loss. We may also keep limited information for up to 6 years for compliance and accounting purposes and to enforce or defend any legal claims in respect of our terms of service.

Legal basis for processing
We are required to state the legal basis on which we undertake processing of your personal information. We will only use your information where:

 - we have your consent to do so; or
 - we need to process the personal information to perform services for you under our terms and conditions of service.
 - We have a legitimate interest in engaging in the provision of our MailMatic service and in offering products and services of value to you. Please contact us if you would like to learn more about our assessment of our legitimate interests in processing data.
 - We are processing the data to meet a legal requirement.
 - Any consent you provide may be withdrawn at any time by emailing us.

Your rights
You have the right to request access to personal data that we may process about you.

You have the right to require us to correct any inaccuracies in your data, free of charge. If you wish to exercise this right, you should:
 - put your request in an email to us;
 - provide us with enough information to identify you (e.g. username or email address); and
 - specify the information that is incorrect and what it should be replaced with.

You can access, correct, update or request deletion of your personal information at any time, either through your online account or by contacting us

Deletion of data will be carried out on the understanding that removal of some information (e.g. email address) during an active membership term may negatively affect your ability to use the MailMatic service.

We cannot delete any invoices, as these are kept for tax purposes.

You can request that we restrict processing of your personal information, object to processing of your information or request portability of your personal information. For these requests please contact us. We will comply with your request where your rights have been exercised in accordance with applicable laws.

If we have collected and processed your personal information with your consent, then you can withdraw that consent at any time. To be clear, we may still continue to process your data if we have a different legal basis for doing so (for example, if we are required by law to do so, or we need to do so for the purposes of fulfilling our obligations to you under our terms and conditions of service).

You also have the right to ask us to stop processing your personal data for direct marketing purposes. You can do this through your MailMatic dashboard or via email. If you wish to exercise this right via email, you should:

 - put your request in writing (an email with a header that says 'Unsubscribe' is acceptable);
 - provide us with enough information to identify you (e.g. email address); and
 - if your objection is not to direct marketing in general, but to direct marketing by a particular channel (e.g. email or telephone), please specify the channel you are objecting to. 

Changes to privacy policy
We keep our privacy policy under regular review. If we change our privacy policy we will post the changes on this page, notify you, and place notices on other areas of the site, so that you may be aware of the information we collect and how we use it at all times. 

If you have any questions or comments regarding our use of your data, please contact us by email. If you make a complaint to us and think we have not dealt with it to your satisfaction, you may send your complaint to the Personal Data Protection Commission for investigation. For more information on the Personal Data Protection Commission, and how to make a complaint, please visit their website.

Our contact details
We welcome your feedback and questions. If you wish to contact us, please send an email to support@mailmatic.co