Legal / Privacy

Privacy Policy

Last updated: 5 July 2026

1. Who we are

Senthop is operated by Skyie Global InfoTech Ltd, a company registered in England and Wales (company number 17294509), with its registered office at 1 Surjit Court, 259 High Street, Rochester, United Kingdom, ME1 1HZ.

We are registered with the UK Information Commissioner's Office (ICO) under registration reference ZC180480.

For data protection queries, contact us at [email protected].

2. What data we collect

We collect the following categories of personal data:

  • Account data: name, email address, company name, and password hash when you create an account.
  • Billing data: payment information processed by Stripe (we do not store card numbers).
  • Email data: email addresses, message metadata (subject lines, timestamps, delivery status), and message content that you send through our platform. We process this data on your behalf as a data processor.
  • Usage data: API call logs, IP addresses, browser type, and pages visited for security and analytics.
  • Contact list data: recipient email addresses and associated metadata that you upload or manage through our platform.

3. How we use your data

We use your data for the following purposes:

  • Providing and operating our email infrastructure services
  • Processing and delivering emails on your behalf
  • Managing your account and billing
  • Sending service-related communications (not marketing)
  • Detecting and preventing fraud, abuse, and security threats
  • Improving our services through aggregated, anonymised analytics
  • Complying with legal obligations

4. Legal basis for processing

We process your data under the following legal bases (UK GDPR):

  • Contract performance: to provide the services you have signed up for.
  • Legitimate interest: for security, fraud prevention, and service improvement.
  • Legal obligation: to comply with applicable laws and regulations.
  • Consent: where required, such as for optional marketing communications.

5. Data residency and transfers

All customer data is stored on servers physically located in the United Kingdom (Portsmouth, England). Your data is subject to UK law and UK GDPR.

AI-powered features: optional deliverability features (such as inbox-placement prediction, content and bounce analysis, and send-time optimisation) run on Google Cloud Vertex AI, region-pinned to the United Kingdom (europe-west2, London), under the Google Cloud Data Processing Addendum. Content processed for these features stays in the UK region and is not used to train Google's models.

We do not transfer your data outside the UK except in the following cases:

  • Stripe (payment processing): billing data is processed by Stripe, Inc. under their EU/UK data processing agreement and Standard Contractual Clauses.
  • Email delivery: when you send emails through our platform, those emails are delivered to recipient mail servers worldwide. This is inherent to the nature of email delivery.

6. Data retention

  • Account data: retained while your account is active and for 30 days after deletion.
  • Email message logs: delivery metadata retained for 90 days. Message content is not stored beyond delivery.
  • API logs: retained for 30 days.
  • Billing records: retained for 7 years as required by UK tax law (HMRC).
  • Suppression list entries: retained indefinitely to prevent re-sending to addresses that have opted out or bounced.

7. Your rights

Under UK GDPR, you have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data (subject to legal retention requirements).
  • Restriction: limit how we process your data in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interest.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Security

We implement appropriate technical and organisational measures including:

  • Encryption in transit (TLS 1.2+) and at rest
  • DKIM, SPF, and DMARC authentication on all outbound email
  • Passwords stored as bcrypt hashes (never in plain text)
  • API keys stored as SHA-256 hashes (shown once, never retrievable)
  • Row-level security policies in the database
  • CSRF protection, rate limiting, and IP allowlisting
  • Cyber Essentials certification currently in progress (not yet certified)

For more details, see our Trust Center.

9. Cookies

We use the following cookies:

  • maielr_auth: authentication session (httpOnly, sameSite=strict). Essential.
  • maielr_csrf: CSRF protection token. Essential.

We do not use third-party tracking cookies or advertising cookies.

10. Subprocessors

  • Contabo GmbH (Germany) — infrastructure hosting, UK datacenter
  • Stripe, Inc. (US) — payment processing, with EU/UK SCCs
  • Google Cloud (UK region — europe-west2, London) — Vertex AI for optional deliverability features, under the Google Cloud Data Processing Addendum, processed in-region with no model training

11. Changes to this policy

Material changes will be communicated via email at least 14 days before taking effect.

12. Contact

Skyie Global InfoTech Ltd
1 Surjit Court, 259 High Street, Rochester, United Kingdom, ME1 1HZ

Email: [email protected]

ICO Registration: ZC180480 | Company Number: 17294509