Privacy policy
Last updated: 23 September 2026
dmarc.com is a DMARC analysis and monitoring service operated by HUCENCY. This policy describes the personal data we process, the purposes and legal bases for that processing, its recipients, retention periods, and the rights available to you under the General Data Protection Regulation (GDPR).
Data controller
The data controller is HUCENCY, a limited liability company (SARL) with share capital of €50,000, registered with the Rouen Trade and Companies Register under number 832 080 055, whose registered office is at 313, rue Edouard Delamare Deboutteville, 76160 Saint-Martin-du-Vivier, France. Its full details appear in the legal notice.
Data processed, purposes and legal bases
We process your data only for the purposes described below, each resting on a legal basis within the meaning of Article 6 of the GDPR.
- Account management and authentication: account creation, sign-in and security (email address, hashed password, two-factor authentication, third-party sign-in identity where applicable).
- Performance of the contract (Art. 6(1)(b))
- DMARC monitoring: collection and analysis of the aggregate reports (RUA) for the domains you monitor (source IP addresses, volumes, SPF/DKIM alignment, identification of sending sources). For third-party data contained in those reports, the customer is the controller and HUCENCY acts as a processor.
- Performance of the contract (Art. 6(1)(b))
- AI assistant “Thomas”: processing of the content of your exchanges with the assistant to help you with DMARC remediation. The anonymous public chat is covered in a dedicated section below.
- Performance of the contract (Art. 6(1)(b)) for authenticated users; legitimate interest in providing and improving the assistant (Art. 6(1)(f)) for the anonymous public chat
- Transactional emails: sending messages related to the service (verification, notifications, alerts).
- Performance of the contract (Art. 6(1)(b))
- Billing and payment: management of subscriptions, invoices and VAT.
- Legal accounting and tax obligation (Art. 6(1)(c)) and performance of the contract (Art. 6(1)(b))
- Prospecting: processing of email addresses left during a public analysis or a contact request.
- Legitimate interest in developing our business (Art. 6(1)(f)); consent (Art. 6(1)(a)) where you voluntarily sign up to our communications
- Audience measurement: site traffic statistics (page views, derived country, device type), without cookies and without retaining your IP address. With your consent, additional audience measurement is carried out by Google Analytics 4 (cookies, see the “Cookies” section).
- Legitimate interest in measuring and improving our audience (Art. 6(1)(f)); consent (Art. 6(1)(a)) for Google Analytics
- Advertising and campaign measurement: with your consent, the LinkedIn Insight Tag measures the effectiveness of our LinkedIn campaigns and allows advertising audiences to be built on LinkedIn (see the “Cookies” section).
- Consent (Art. 6(1)(a))
- Audit log and security: traceability of actions and prevention of abuse (IP address, actor's email, action performed, timestamp).
- Legal security obligation (Art. 6(1)(c)) and legitimate interest in securing the service (Art. 6(1)(f))
- Forensic reports (RUF): their collection is disabled by default; when enabled, it covers message excerpts that may contain sensitive data.
- Performance of the contract (Art. 6(1)(b))
- Account deactivation: measures taken in the event of proven abuse or fraud.
- Legitimate interest in preventing fraud and abuse (Art. 6(1)(f))
- Free security-testing tools: when a test (for example “WP2SHELL”) is requested on a domain you monitor, verification of domain ownership (DNS TXT token), collection of your explicit consent (timestamp and IP address kept as proof) and a non-intrusive diagnostic of the domain (no vulnerability is exploited).
- Performance of a requested service (Art. 6(1)(b)), explicit consent to the test (Art. 6(1)(a)) and legitimate interest in security (Art. 6(1)(f))
- Outbound prospecting, through two distinct channels. (1) LINKEDIN MESSAGE (InMail): identifying IT or security leads whose organisation has a publicly observable DMARC weakness. The contact data (name, role, LinkedIn profile, organisation) comes from LinkedIn and public professional sources, not from the individual. (2) EMAIL: where a domain has been analysed on this site's public analyser without an account being created afterwards, a contact address is sought among those the domain itself publishes — the "security.txt" file provided for that purpose, the address declared in its DNS zone to receive DMARC reports, or a standardised role address such as security@ or postmaster@. These addresses are never requested from the individual, and are most often functional mailboxes rather than personal ones; the address retained is stored on the prospect's file together with where it was found, so that the message can state its origin. A message is only ever sent to an address on the analysed domain itself, and every send carries an unsubscribe link that takes effect in a single click. In both channels, the link in the message is personalised: it identifies its recipient. Loading it, then a signal sent by the browser after a reading delay, measure whether the message was opened and then read; the first measurement is also triggered by automated mailbox security checks, so on its own it does not prove that a person read the message. The read signal also picks up the session token used for site audience measurement and records it on the prospect's file. From that moment on, the pages viewed during the session are linked to the identified person: the path of each page is recorded — never the content of the pages, nor URL parameters, nor the IP address — and internal use derives from it the number of pages viewed, the last page visited and, where applicable, whether a sign-up took place. If an email address is left elsewhere on the site (analysis, quote request, sign-up), it is matched to that same session and displayed next to the name. The prospect's file is erased at the term stated below, or earlier on request; the pages viewed, however, are not erased at the same time: they follow the period specific to audience measurement (180 days), and any email address left follows its own.
- Legitimate interest in offering a security service to exposed organisations (art. 6.1.f): the person is approached in their professional capacity, about a weakness observed on the public DNS records of their organisation's domain. The LinkedIn channel collects no email address: the message is sent from LinkedIn. The email channel, however, does store the address published by the domain along with where it was found — that address is what makes the send possible, and recording its origin is what allows the message to state where it came from. An address left elsewhere on the site (analysis, quote request, sign-up) falls under the lead-generation processing described above; it is not stored here, but it is matched to the file for display, as stated above. Objection is possible at any time and without justification: by replying to the message, by writing to the address below, or — for email — through the unsubscribe link carried by every send, which opens a confirmation page where a second click records the objection. The contact data (name, role, LinkedIn profile, email address) is then erased and no further message is sent. Two traces remain, for the sole purpose of keeping the objection effective: the domain row, which prevents the organisation from being selected again in a later draw, and a fingerprint of the address (a SHA-256 hash) recorded in an objection list. That fingerprint is kept with no time limit, deliberately: since the prospect's file is erased at the term stated below, an objection that disappeared with it would make the person contactable again — erasing their data would then produce the opposite of what they asked for. That fingerprint remains personal data — pseudonymised, not anonymous: the address is never stored in clear and the list cannot be read as a contact file, but someone holding the database could check whether a specific address, notably a common role address, is on it.
- Customer reviews: publication, on the pricing page, of a review written by an administrator of a customer organisation (rating, text, display name chosen by the author, optional role, language), after moderation. The review can be withdrawn at any time from the customer area.
- Consent (art. 6.1.a), collected through a checkbox at submission; withdrawable at any time
Recipients and transfers outside the European Union
Your data is never sold. It is accessible to our technical providers — processors within the meaning of Article 28 of the GDPR, acting solely on our instructions and bound by a data protection agreement — and, for the services subject to your consent only, to joint controllers within the meaning of Article 26:
- Hosting
- Scaleway (France, fr-par region): hosting of the application and backups. No data is transferred outside the European Union on this basis.
- Payment
- Stripe (Stripe Payments Europe, Ireland): payment collection and VAT calculation. We store no card data.
- Transactional emails
- Microsoft: delivery of the service's emails.
- Third-party sign-in (SSO)
- Microsoft and Google: only if you choose to sign in with one of these accounts.
- AI assistant
- Anthropic: processing of the requests sent to the assistant “Thomas”. The data transmitted is minimized (no email address, no message content, no raw report) and is not used to train the models.
- Audience measurement (with consent)
- Google Ireland Limited: Google Tag Manager and Google Analytics 4, only if you accept audience measurement. Processor (Google Ads Data Processing Terms).
- Advertising (with consent)
- LinkedIn Ireland Unlimited Company: LinkedIn Insight Tag, only if you accept advertising. LinkedIn is a joint controller (Article 26) for the data collected by this tag.
Some processing may involve a transfer outside the European Union: requests to the AI assistant (Anthropic, United States) and, depending on your email configuration, transactional emails (Microsoft), governed by the European Commission’s standard contractual clauses; and, if you have consented to them, audience measurement and advertising (Google and LinkedIn, United States), governed by the EU–US Data Privacy Framework and the standard contractual clauses. All other processing takes place within the European Union.
Retention periods
We keep your data only for as long as is strictly necessary for each purpose:
- Customer account
- Until the account is deleted, which is possible at any time from your settings.
- DMARC reports (RUA)
- The raw report is erased as soon as it is processed; the aggregated detail is kept according to your plan: 30 days (Free), 90 days (Starter), 180 days (Pro), 365 days (Business), 730 days (Enterprise). Monthly aggregates are kept in anonymized form.
- Forensic reports (RUF)
- 30 days, when collection is enabled.
- Audit and security log
- 365 days for security events, 90 days for read access, 180 days for other actions.
- Prospects
- 730 days; lifetime of the account if the prospect becomes a customer.
- Anonymous public analyses
- 90 days.
- Anonymous public chat conversations
- 30 days.
- Audience statistics
- 180 days.
- Unverified sign-ups
- 7 days.
- Encrypted backups
- 30 days.
- Free-tool test results (WP2SHELL)
- 365 days (point-in-time security snapshot); deleted with the account.
- Proof of consent to a security test
- Lifetime of the contractual relationship (evidential value); deleted when the account is deleted.
- Invoices
- 10 years (legal accounting obligation).
- Prospects of outbound prospecting (LinkedIn or email): name, role, LinkedIn profile, contact address published by the domain and where it was found, link open measurement and the session token linked to the file
- 1095 days (3 years) from the last contact, then automatic erasure. The pages viewed that are linked to that token fall under audience measurement and follow its own period (180 days).
- Prospecting objection list: a fingerprint (SHA-256 hash) of the address and its domain — never the address itself; pseudonymised personal data
- Kept with no time limit, and deliberately so: since the prospect's file is erased after 1095 days, an objection that disappeared at the same time would make the person contactable again. This fingerprint is what guarantees the opposite. It never contains the address in clear, but remains pseudonymised personal data: someone holding the database could check whether a specific address is on it.
- Customer review (rating, text, display name, role, language)
- As long as the review is published or awaiting moderation; a withdrawn or rejected review stops being displayed immediately and is deleted with the organisation’s account.
Your rights
In accordance with the GDPR, you have the right of access, rectification, erasure, restriction, objection and portability regarding your personal data. Where processing is based on your consent, you may withdraw it at any time, without affecting processing already carried out.
If you have an account, you can exercise most of these rights directly from your settings (viewing, exporting your data, deleting the account). For any other request, use the contact address given below; we respond within one month.
You may also lodge a complaint with the CNIL (the French data protection authority), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.
We do not make any automated decisions producing legal effects concerning you. The assistant “Thomas” makes recommendations, but the decisions remain yours.
Cookies
The site uses cookies strictly necessary for its operation (session, authentication, two-factor authentication, third-party sign-in, remembering a trusted device for 24 hours at your request, language preference, remembering your cookie choice). These require no consent. The site’s in-house audience measurement (page views, derived country, device type) works without any cookie.
With your consent — and only with it — the site loads the Google Tag Manager tag manager, which can enable two third-party services, each subject to a separate choice: Google Analytics 4 (audience measurement; “_ga” and “_ga_*” cookies, kept for 13 months at most) and the LinkedIn Insight Tag (advertising and campaign measurement; LinkedIn cookies such as “li_fat_id”, “lidc” or “bcookie”). As long as you have accepted nothing, no request is sent to Google or LinkedIn. As soon as one purpose is accepted, the tag manager is loaded from Google’s servers, which then receive your IP address, the address of the page visited and the technical characteristics of your browser. Your choice (acceptance or refusal) is remembered for 6 months in a “dmarc_consent” cookie; you can change it at any time via “Manage cookies” in the footer. These services are never enabled in the customer area.
Conversations with Thomas (public analysis)
If you chat with Thomas without an account, from the public analysis, we keep the analyzed domain, your answers to Thomas's two opening questions (the tone you prefer and, if you tell us, how you heard about us) and the conversation for 30 days, then delete them automatically. A team member may review them to improve Thomas. We record neither your email address nor your IP address with these exchanges: they are tied to no account and cannot be linked back to a person (non-identifiable data within the meaning of Article 11 of the GDPR). For any question about them, write to us with the domain and the date.
Changes to this policy
This policy may change, in particular to reflect technical or regulatory developments. The date of the last update appears at the top of the page.
Contact
For any question about your personal data or to exercise your rights, contact our data officer at: dpo@hucency.com
In the event of any discrepancy between the language versions of this policy, the French version prevails.
