1. Scope and roles
This policy covers Relaytera websites, accounts, support, and service operations. For account, billing, security, and business-contact information, the operator determines why and how information is used. For customer-submitted Relay message content, recipient details, lists, templates, customer-controlled event data, cPanel website/database/mail data, and Relay Mail mailbox data, the customer is generally the controller and Relaytera acts as processor or service provider.
2. Information handled
- Account and workspace details, authentication records, policy acceptance, roles, plan, and billing references.
- Sending domains, API and SMTP credential metadata, templates, audiences, suppression records, message envelopes and content.
- Where Relay Hosting is selected: cPanel account metadata, customer domain configuration, website and database content, mailbox data, and service-access audit records.
- Where Relay Mail is selected: mailbox/domain/alias configuration, individual mailbox content and metadata held by the mail host, access changes, DNS verification state, recipient-suppression state, and deletion-request records.
- Delivery events, bounces, complaints, webhook attempts, IP address, user agent, audit logs, security signals, and diagnostics.
- Support communications and information supplied during incident, abuse, privacy, or deliverability reviews.
3. Purposes and legal bases
Information is used to provide and secure the service, authenticate users, process messages, prevent abuse, bill customers, provide support, meet legal duties, and improve reliability. For operator-controlled processing, the relevant basis depends on the activity and may include performance of a contract, compliance with a legal obligation, consent, or legitimate interests such as security and abuse prevention. Customers remain responsible for identifying their own basis for customer-submitted data and message recipients.
4. Sharing and international processing
Information is shared only with authorised personnel, the customer’s configured integrations, receiving email networks, and the service providers actually named in the Subprocessor Register. It may also be disclosed to comply with law, protect rights and safety, or complete a corporate transaction with appropriate safeguards.
The Subprocessor Register must identify actual production providers, their purpose, location, and transfer safeguard before paid customer processing begins. If a restricted international transfer is initiated, Relaytera must use an applicable transfer mechanism before making it; the register records the mechanism relevant to each provider.
5. Retention and deletion
For Relay application records, workspace retention settings govern content, event metadata, webhook payload, and audit-record handling. A workspace JSON export covers Relay control-plane records but does not export cPanel website/database data, Relay Mail mailbox contents, or external delivery-provider records. Those services use their own export mechanisms and instructions.
Relay Hosting follows its service cancellation and retained-account lifecycle: after cancellation, the service is retained in a suspended state for up to 30 days by default before it is terminated and its content is removed. Relay Mail mailbox deletion is separate from subscription cancellation: the customer must use IMAP or JMAP to export required mail, submit a confirmed deletion request, and wait for its retention/review process, which retains the mailbox for up to 30 days by default before the mail host receives a deletion instruction. Backup data is not edited in place for an individual request. The published backup-retention schedule is: Relay Hosting — backups of a cancelled or terminated service are retained for up to 30 days by default, matching the cancellation-retention window; Relay Mail — backups of a deleted mailbox are retained for up to 30 days by default, matching the mailbox deletion-retention window. Backups then expire on the normal backup rotation.
6. Security and essential storage
Relay uses the security controls described in the Security Overview. Some controls and service features remain staged behind release gates, and no system is risk-free.
The website uses essential session and security storage needed to authenticate users and protect requests. The operator must update this policy and add consent controls before enabling non-essential analytics or advertising technologies.
7. Rights and contact
Depending on location, individuals may have rights to access, correct, delete, restrict, object, port, or complain about use of their information. Recipient requests should normally be directed to the customer that sent the message. Account and operator privacy requests may be sent to support@relaytera.com. Identity and authority may be verified before action is taken. UK individuals may also complain to the Information Commissioner’s Office.