Last updated: June 25, 2026
EmailConsul LLC is a company registered under the laws of the State of New York, United States, with its registered address at 90 State Street, STE 700, Office 40, Albany, NY 12207, United States ("EmailConsul", "we", "us", "our").
We operate the EmailConsul platform, which provides email deliverability monitoring, DMARC monitoring, inbox placement testing, email list cleaning, IP and domain blocklist monitoring, lookalike domain detection, email threat intelligence, and related deliverability services ("Platform" or "Services").
For questions about this policy or our data practices, contact us at [email protected].
EmailConsul is not established in the European Union or European Economic Area. For data subjects located in the EU/EEA, we have appointed Admonto BV as our EU representative pursuant to Article 27 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"):
Admonto BV
2033PJ, Hannie Schaftstraat 62, Haarlem, Netherlands | [email protected]
EU/EEA data subjects and supervisory authorities may contact Admonto BV directly at [email protected]. When writing, please use the subject line format: [GDPR] [EmailConsul] – [your request type] and include your name, a description of your request, and your return email address. This contact point is for EU/EEA residents and supervisory authorities only.
This Privacy Policy describes how EmailConsul collects, uses, stores, and shares personal data when you:
visit our website at emailconsul.com;
use our free tools (inbox placement test, DMARC analyser, blocklist checker, etc.);
register for and use the EmailConsul Platform;
contact us for support or sales enquiries; or
enter into a contractual relationship with us.
This policy applies to all users. Additional rights specific to EU/EEA data subjects are described in Section 10. US residents may refer to Section 11.
Note on data we process on behalf of our customers. When our customers use the Platform to process email lists, DMARC data, or other data relating to their own end-users, EmailConsul acts as a data processor on behalf of those customers (who are the data controllers). That processing is governed by our Data Processing Agreement, available at emailconsul.com/legal/dpa, and not by this Privacy Policy.
When you create an account: full name, business email address, company name, job title, and password (stored in hashed form only — we do not have access to your password in plain text).
When you subscribe to a paid plan: billing contact name and email address, company billing address, VAT/tax identification number (where applicable), and subscription plan details. Payment card details are processed directly and securely by Stripe; we do not store card numbers on our systems.
When you use the Platform: IP addresses, browser type, operating system, pages and features accessed, timestamps, session identifiers, API credentials (stored in encrypted form), and feature interaction data.
Depending on the services you use, you may submit: domain names and IP addresses for monitoring, DMARC aggregate and forensic report data, email lists (email addresses for list cleaning and validation), seed test campaign parameters, and SMTP log data. Where this data contains personal data about third parties, you are the data controller for that data and are responsible for having a lawful basis to submit it to us for processing.
When you use our free online tools (inbox placement test, DMARC XML analyser, blocklist checkers, SPF/DKIM/DMARC checkers): the domain, IP, or email address you enter, together with your IP address and browser data.
When you contact us: the content of your messages, support ticket history, chat logs, and your contact details.
If you subscribe to our newsletter or download resources: your email address and, where provided, your name and company.
If you connect third-party accounts to the Platform (e.g. Google Postmaster Tools, Microsoft SNDS), we receive only the data necessary to provide the connected service. We do not store your Google or Microsoft credentials — authentication is handled via OAuth.
We collect personal data: directly from you when you register, use the Platform, submit data through our tools, or contact us; automatically through cookies and tracking technologies when you visit our website (see Section 14); and from third-party services where you connect those accounts to the Platform.
We process your personal data on the following legal bases under Article 6 GDPR:
Performance of a contract (Article 6(1)(b)): Processing necessary to provide the Services you have subscribed to, including creating and managing your account, operating the Platform, processing payments, and delivering customer support.
Legitimate interests (Article 6(1)(f)): Processing for our legitimate business interests, including: security monitoring and fraud prevention; detecting and preventing abuse of our free tools; improving and developing the Platform and Services; sending service-related operational communications; maintaining records of our business relationships; and resolving disputes. We have assessed that these interests are not overridden by your rights and interests.
Legal obligation (Article 6(1)(c)): Processing required to comply with applicable law, including financial record-keeping, tax compliance, and responding to lawful requests from public authorities.
Consent (Article 6(1)(a)): Where we send marketing emails or newsletters, we rely on your consent. You may withdraw consent at any time by clicking "unsubscribe" in any marketing email or by contacting [email protected].
We use the personal data we collect to:
create and manage your account and provide the Platform and Services;
process payments, issue invoices, and manage your subscription;
send transactional communications (account confirmation, billing notifications, password reset, service alerts);
provide customer support and respond to enquiries;
monitor the security, availability, and reliability of the Platform;
detect and prevent fraudulent, abusive, or unauthorised use;
improve and develop the Platform and our Services;
comply with legal and regulatory obligations;
send marketing communications where you have provided consent or where permitted under applicable law.
We do not use your personal data to make automated decisions that produce significant legal or similarly significant effects without human review.
To deliver the Platform, we engage carefully selected third-party service providers ("sub-processors") who process personal data on our behalf. All sub-processors are bound by written data processing agreements that impose data protection obligations at least as protective as those under the GDPR.
Our current authorised sub-processors are:
| Sub-processor | Country | Purpose |
|---|---|---|
| MongoDB, Inc. | United States | Cloud database — primary storage of platform data |
| Amazon Web Services, Inc. | United States | Cloud infrastructure, storage, logging, transactional email |
| DigitalOcean, LLC | United States | Application hosting (Kubernetes) |
| Cloudflare, Inc. | United States | CDN, DDoS protection, edge security |
| Stripe, Inc. | United States / Ireland | Payment processing and billing management |
| Twilio Inc. (SendGrid) | United States | Transactional email delivery |
| Slack Technologies, LLC | United States | Internal operational alerting |
| Functional Software, Inc. (Sentry) | United States | Application error and performance monitoring |
| OpenAI, L.L.C. | United States | AI-assisted platform features |
The complete sub-processor list — including registered addresses, data categories processed, and retention periods — is maintained and kept current at emailconsul.com/legal/sub-processors.
We will notify you by email at least 30 days before adding or replacing any sub-processor. You may object to any proposed change on documented, legitimate data protection grounds by notifying us at [email protected] within 14 days of the notification date.
We may also share personal data with: professional advisers (lawyers, accountants, auditors) acting under confidentiality obligations; regulatory or law enforcement authorities where we are required to do so by applicable law; and a successor entity in the event of a merger, acquisition, or sale of all or substantially all of our business assets, subject to equivalent data protection obligations.
We do not sell personal data. We do not share personal data with advertisers or any third party for their own independent marketing purposes.
EmailConsul is based in the United States. When we transfer personal data from the EU/EEA to the United States (whether directly or via our sub-processors), we rely on the following transfer mechanisms:
Standard Contractual Clauses (SCCs). Transfers of personal data from the EU/EEA to EmailConsul are governed by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: Controller to Processor), incorporated into our Data Processing Agreement available at emailconsul.com/legal/dpa.
For onward transfers from EmailConsul to sub-processors, we rely on SCCs (Module 3: Processor to Sub-Processor). Additionally, all nine of our current sub-processors are independently certified under the EU-US Data Privacy Framework, verifiable at dataprivacyframework.gov.
We retain personal data only for as long as necessary for the purposes described in this policy and in accordance with applicable law:
Account data: For the duration of your subscription, plus 30 days following account closure (to allow for recovery), after which it is deleted.
Billing and financial records: 7 years from the date of the transaction, as required by applicable financial and tax record-keeping law.
Platform usage logs: Up to 6 months, then automatically deleted.
Application error and performance data (Sentry): Up to 90 days.
Email list and DMARC data submitted for processing: For the duration of your service relationship, then deleted within 30 days of account closure or upon written request.
Support and communications records: Up to 3 years from the date of last contact.
Automated backup data: 7-day rolling window; backups are automatically purged outside this window.
Free tool submissions: Not retained beyond the session required to return the result.
After the applicable retention period, personal data is securely and permanently deleted or irreversibly anonymised.
We implement comprehensive technical and organisational measures to protect your personal data against unauthorised access, disclosure, loss, destruction, or alteration. Our security measures include:
Encryption. All data in transit is encrypted using TLS 1.2 or higher. All data at rest is encrypted using AES-256.
Access controls. Access to production systems is governed by role-based access control (RBAC) with least-privilege principles. Multi-factor authentication (MFA) is required for all personnel with access to production infrastructure.
Network security. DDoS mitigation and edge protection via Cloudflare; network segmentation between production, staging, and development environments.
Vulnerability management. Regular vulnerability scanning, scheduled penetration testing, automated dependency and secrets scanning in the development pipeline, and prompt security patching.
Audit logging. All access to personal data in production systems is logged, monitored, and retained for security audit purposes.
Incident response. A documented data breach response and notification procedure is in place. In the event of a personal data breach meeting the threshold under Articles 33–34 GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach and will notify affected data subjects without undue delay where there is a high risk to their rights and freedoms.
Supplier assurance. All sub-processors are contractually required to maintain security standards equivalent to or exceeding our own. Key certifications held by our sub-processors include SOC 2 Type II (MongoDB, AWS, DigitalOcean, Cloudflare, Stripe, Twilio, Slack, Sentry), ISO 27001, and PCI DSS Level 1 (Stripe).
Training. All personnel with access to personal data receive regular data protection and security awareness training.
If you are located in the EU/EEA, you have the following rights under the GDPR. You may exercise any of these rights by contacting us at [email protected] or our EU representative at [email protected]. We will respond within 30 days. We may ask you to verify your identity before processing your request.
Right of access (Article 15). You may request confirmation of whether we process personal data about you, and if so, a copy of that data together with information about how it is used.
Right to rectification (Article 16). You may ask us to correct inaccurate or incomplete personal data.
Right to erasure (Article 17). You may ask us to delete your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw the consent on which processing is based, or where we have no other lawful basis for processing.
Right to restriction of processing (Article 18). You may ask us to restrict the processing of your personal data in certain circumstances — for example while the accuracy of the data is contested, or while an objection is assessed.
Right to data portability (Article 20). You may receive personal data you have provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller, where processing is based on consent or contract and is carried out by automated means.
Right to object (Article 21). You may object at any time to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary to establish, exercise, or defend legal claims.
Right to withdraw consent (Article 7(3)). Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right not to be subject to automated decision-making (Article 22). You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces significant legal or similarly significant effects on you.
Where requests are manifestly unfounded or excessive, we may charge a reasonable administrative fee or decline to act, and will explain our reasons.
Depending on the US state in which you reside, you may have rights under applicable state privacy law, including the right to know what personal information we collect, to request deletion or correction, to obtain a portable copy, and to opt out of the sale or sharing of personal information. EmailConsul does not sell personal information and does not share it for cross-context behavioural advertising.
To submit a request, contact [email protected]. We will respond within the timeframe required under your state's law (45 days for most states, with one extension where permitted). We will not discriminate against you for exercising your rights.
Our website uses cookies and similar technologies. Cookies are small text files placed on your device that help us provide essential functionality, understand how visitors use our site, and improve your experience.
We use the following categories of cookies:
Strictly necessary cookies — required for the website and Platform to function. These cannot be disabled.
Analytics cookies — we use Google Analytics to understand how visitors interact with our website (pages visited, session duration, referral sources). Analytics cookies are only set with your consent.
Marketing and advertising cookies — we may use third-party tools for remarketing. These are only set with your consent.
Our website also embeds YouTube videos (Google LLC). When you play an embedded video, YouTube may set cookies and collect viewing data; this is subject to Google's own privacy policy.
A full Cookie Policy is available at emailconsul.com/cookie-policy. You can manage your preferences at any time via the cookie settings link in the footer of our website or through your browser settings. Note that disabling certain cookies may affect the functionality of the Platform.
For browser-level cookie management, guidance is available from your browser provider.
If you subscribe to our newsletter, we will send you targeted information about our services and deliverability resources. We use Mailchimp (Intuit Inc.) to manage newsletter distribution. Your email address and any additional information you provide are transferred to and stored by Mailchimp in the United States, subject to its own data processing agreement.
We use a double opt-in process: you will receive a confirmation email before we add you to our list. You can unsubscribe at any time via the link in any newsletter, or by emailing [email protected]. Your email address will be removed from our distribution list promptly following your unsubscription request.
The Platform and website are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 18, please contact us immediately at [email protected] and we will delete it without delay.
Our website may contain links to third-party websites, tools, and resources. This Privacy Policy does not apply to those third-party sites. We are not responsible for the privacy practices of external sites and encourage you to review their privacy policies before providing any personal data.
We may update this Privacy Policy periodically to reflect changes in our practices, services, or applicable law. We will notify registered users of any material changes by email and will update the "Last updated" date and version number at the top of this page. We encourage you to review this policy periodically. Continued use of the Platform following notification of material changes constitutes acceptance of the updated policy.
For any questions, requests, or concerns about this policy or our data practices:
EmailConsul LLC
90 State Street, STE 700, Office 40
Albany, NY 12207, United States
[email protected]
EU/EEA Representative (Article 27 GDPR):
Admonto BV
2033PJ, Hannie Schaftstraat 62
Haarlem, Netherlands
[email protected]
Right to lodge a complaint. If you are located in the EU/EEA and are not satisfied with our response to a request or concern, you have the right to lodge a complaint with the supervisory authority in your country of residence or place of work. A list of EU supervisory authorities is available at edpb.europa.eu.