Privacy Notice — Website & Customer Admin Users (postal.ID as Controller)
Effective date: [DATE] This notice explains how [POSTAL.ID LEGAL NAME] ("postal.ID") processes personal data when we act as a Controller (i.e., we decide the purposes and means of processing). This includes:
- visitors to our website postal.id;
- prospective customers and leads;
- customer administrators and authorized users (accounts, authentication, billing contacts);
- suppliers/partners.
Verification subjects: If you are an end customer receiving a postal.ID verification request, see "Subject Terms & Privacy Notice" (separate document). In most cases, postal.ID acts as a Processor for verification subject data on behalf of the business customer initiating the verification.
1. Data we collect
- Contact and identity: name, business email, phone, job title, company.
- Account/security: login identifiers, MFA details, IP address, device/browser metadata, access logs.
- Billing: invoicing details, plan, usage metrics, payment metadata (handled by payment providers).
- Website analytics/cookies: cookie identifiers, page views, referral data (subject to cookie preferences).
2. Purposes
- Provide and secure customer accounts (auth, RBAC, audit logs).
- Provide support and respond to inquiries.
- Billing, invoicing, tax and accounting.
- Improve the Site and platform (analytics).
- Marketing (where permitted and in line with preferences).
3. Legal bases (typical)
- Contract necessity (account provisioning, billing).
- Legitimate interests (security, fraud prevention, service improvement).
- Consent (certain cookies/marketing, where required).
4. Sharing
We share data with subprocessors/service providers (hosting, email delivery, CRM, billing) under contract and access controls. See our Subprocessor List.
5. International transfers
We may transfer personal data internationally. Where required, we use appropriate safeguards such as:
- EU Standard Contractual Clauses (SCCs) for EU/EEA data exports,
- UK IDTA or UK Addendum for UK restricted transfers,
- DIFC transfer mechanisms (adequacy/safeguards) for DIFC data exports.
6. Retention
We retain controller data only as long as necessary for the purposes above, then delete or anonymize it. Billing/tax records may be retained longer as required by law.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, object, or restrict processing. Contact [PRIVACY@POSTAL.ID].
8. Security
We maintain technical and organizational measures (TOMs) appropriate to risk.
9. Contact
Privacy: [PRIVACY@POSTAL.ID] DPO/Privacy lead: [DPO@POSTAL.ID] Legal: [LEGAL@POSTAL.ID]