Privacy Policy
Effective September 20, 2026 · Astra Innovations LLC, Sanford, Florida, USA
Version 2026-09-20. This Privacy Policy explains how Astra Innovations LLC, a Florida limited liability company based in Sanford, Florida, USA (“Astra”, “InBuzzed”, “we”, “us”) collects, uses, shares and protects personal information in connection with inbuzzed.com and the InBuzzed email operations platform (the “Service”).
Contents
- 1. Scope and our roles
- 2. Information we collect
- 3. Where the information comes from
- 4. Why we process it and on what legal basis
- 5. Anti-abuse and platform integrity processing
- 6. Email open and click tracking
- 7. How we share information; subprocessors
- 8. No sale and no cross-context behavioural advertising
- 9. International transfers
- 10. How long we keep information
- 11. Security
- 12. Your rights (EEA, UK and Switzerland)
- 13. Your rights (California and other US states)
- 14. How to exercise your rights
- 15. Children
- 16. Do Not Track and Global Privacy Control
- 17. Cookies and local storage
- 18. Data breach notification
- 19. Changes to this policy
- 20. How to contact us
1. Scope and our roles
1.1 This policy applies to our public website, marketing pages, documentation, the InBuzzed web application, the transactional email API and SMTP relay, hosted business mailboxes, and the emails we send to our own users.
1.2 Where we are the controller. We act as a controller (or, under US state laws, a business) for personal information about our own users, prospects and site visitors: account holders, team members, billing contacts, people who fill in our contact or signup forms, and people who write to our support address. Sections 2 to 20 of this policy describe that processing.
1.3 Where we are the processor.When a customer uses InBuzzed to manage contacts and send messages, the customer decides what data to upload, who to send to and why. For that data — contact records, list and segment membership, consent records, email content, engagement data and mailbox contents — the customer is the controller (or business) and we are the processor (or service provider), acting on the customer’s documented instructions. Our commitments in that role are set out in the Data Processing Addendum.
1.4 If you received an email sent through InBuzzed. We are not the sender and we did not choose to contact you. The organisation named in the message is the controller of your data. Use the unsubscribe link in the message, or contact that organisation directly, to opt out or to exercise your rights. If you cannot identify or reach the sender, write to support@inbuzzed.com and we will pass your request to the customer and, where we can, suppress further sending to your address.
2. Information we collect
2.1 Account and profile data. Name, business name, email address, hashed password, authentication factors, workspace name and identifiers, job role or use-case details you provide, team member invitations and role assignments, sending domains and DNS verification status, tracking domain configuration, and profile preferences.
2.2 Billing data. Plan, billing period, billing contact and address, tax identifiers, invoice and payment history, subscription and trial status, credits and complimentary grants, and payment-method metadata such as card brand, last four digits and expiry. Card numbers are collected and stored by Stripe, not by us; we receive tokens and status information from Stripe.
2.3 Consent and acceptance records. The version of the Terms, Privacy Policy, AUP and DPA you accepted, the date and time of acceptance, the account and user identifier, and the IP address from which acceptance was given; your marketing preferences for our own communications; and cookie or consent-banner choices.
2.4 Customer content. Templates, campaign and broadcast content, subject lines, funnel and automation definitions, form definitions and submissions, uploaded images and files, contact records and segments, suppression lists and message payloads submitted through the API or SMTP relay. Contact records typically include an email address and may include a name, company, location, tags and any custom fields the customer chooses to store.
2.5 Hosted mailbox contents. For workspaces with hosted business mailboxes, the messages, attachments, folders, contacts and settings stored in those mailboxes, and the connection and authentication logs of the mail host.
2.6 Delivery and engagement data. For each message: send time, sending domain and IP, recipient address, message identifiers, size, SMTP response codes, delivery, deferral, bounce, rejection, complaint and unsubscribe events, and open and click events. Open and click events may carry the recipient IP address, user-agent string, approximate location derived from IP (usually city or region level), device or client type, and the URL clicked.
2.7 Usage and telemetry. Pages and features used in the application, actions taken, API endpoints and SMTP commands called, request volumes and rate-limit events, error and performance data, job and automation execution records, and webhook delivery attempts and responses.
2.8 Device, log and network data. IP address, browser type and version, operating system, device type, language, referring URL, timestamps, session identifiers, and server, proxy and firewall logs including security events such as failed logins, bot-detection outcomes and blocked requests.
2.9 Cookies and local storage. See Section 17. We use a small number of strictly necessary cookies and store your authentication session in browser local storage.
2.10 Support and communications. Emails and messages you send us, attachments and screenshots you provide, the contents of support tickets, and records of verification steps we take before acting on a request.
2.11 Abuse reports. Reports we receive about a customer or a message, including reporter contact details where provided, message headers and samples, feedback-loop complaints from mailbox providers, and blocklist notifications.
3. Where the information comes from
3.1 Directly from you, when you create an account, configure the Service, buy a plan, contact support or accept our terms.
3.2 Automatically, from your use of the website, application, API and SMTP relay, and from recipient interaction with messages sent through the Service.
3.3 From our customers, when they upload or sync contact data into their workspace. We do not control what a customer uploads and we do not buy, rent or append contact data.
3.4 From service providers and partners, such as Stripe (payment and subscription status), Cloudflare (security signals and bot-detection outcomes), mailbox providers and feedback loops (bounce and complaint reports), DNS lookups (domain authentication status) and blocklist operators.
4. Why we process it and on what legal basis
Where the GDPR or UK GDPR applies to our own controller processing, we rely on the following bases.
- Providing the Service— creating and administering accounts and workspaces, authenticating users, accepting and transmitting messages, storing contacts and templates, running automations, delivering webhooks, operating mailboxes, and giving you analytics. Basis: performance of a contract.
- Billing and payments— charging your payment method, handling renewals, trials, overage, credits, refunds, dunning and chargebacks, and issuing invoices. Basis: performance of a contract; legal obligation for tax and accounting records.
- Platform emails to you— verification, password reset, security alerts, quota and billing notices, incident notifications and material changes to terms. Basis: performance of a contract; legal obligation; legitimate interests in operating a safe service.
- Support— answering your questions, diagnosing delivery problems, and keeping a record of what was asked and done. Basis: performance of a contract; legitimate interests.
- Security, fraud and abuse prevention — the activities in Section 5. Basis: legitimate interests in protecting the platform, our customers, recipients and third parties; legal obligation where applicable.
- Service improvement and analytics— understanding how features are used, measuring reliability and deliverability, and prioritising development, using aggregated or pseudonymised data where practicable. Basis: legitimate interests.
- Marketing to our own prospects and customers— product announcements, onboarding tips and offers, always with an unsubscribe link. Basis: consent where required; otherwise legitimate interests in marketing to existing business customers.
- Non-essential cookies and analytics — where used. Basis: consent.
- Legal compliance and defence of claims— responding to lawful requests, retaining records required by law, enforcing our terms, and establishing, exercising or defending legal claims. Basis: legal obligation; legitimate interests.
- Corporate transactions— evaluating or completing a merger, financing, reorganisation or sale of assets. Basis: legitimate interests.
Where we rely on legitimate interests, we have assessed that our interests are not overridden by the rights and freedoms of the individuals concerned. You may object to that processing as described in Section 12.
5. Anti-abuse and platform integrity processing
InBuzzed is sending infrastructure, so preventing spam, phishing and fraud is a core operational duty. We process personal information to:
- Review new and free workspaces before sending is enabled, which may include reviewing the account details, business identity, website, sending domain and sample content, and requesting evidence of consent.
- Apply rate limits, quotas and throttling, and queue, defer or pause sending where volume or patterns present risk.
- Operate bot and automation protection on signup, login and public forms, including Cloudflare Turnstile and Cloudflare network protections, which process IP address, user-agent, request metadata and behavioural signals to distinguish humans from automated clients.
- Monitor bounce, complaint, spam-trap, unsubscribe and authentication-failure rates per workspace, domain and IP, and act on feedback-loop and blocklist reports.
- Scan message content, links, headers and attachments automatically, and manually where a signal or report warrants it, to detect phishing, malware, credential harvesting, fraud and AUP violations.
- Maintain suppression lists of addresses that hard-bounced, complained or unsubscribed, at workspace level and, where necessary, platform-wide.
- Investigate abuse reports and cooperate with mailbox providers, blocklist operators and lawful requests from authorities.
These activities may result in a message being blocked, a campaign being paused, a workspace being suspended, or an account being terminated. Decisions with a legal or similarly significant effect are not made by purely automated means without human review available on request.
6. Email open and click tracking
6.1 How it works.Where a customer enables tracking, we may insert a small transparent image (a tracking pixel) into an HTML message and rewrite links so that clicks pass through a tracking domain — either a shared InBuzzed domain such as track.inbuzzed.com or a tracking domain the customer owns. When the image loads, or a rewritten link is clicked, we record the event together with the time, the message and campaign identifier, the recipient identifier, the IP address, the user-agent string, an approximate location derived from the IP address, and the destination URL for clicks.
6.2 Accuracy. Open data is inherently approximate. Many clients block or proxy images, and some prefetch them, which can create opens that no human caused or hide opens that occurred. We filter obvious machine traffic where we can, but neither we nor the customer can guarantee accuracy.
6.3 Roles. Tracking is performed on behalf of the sending customer, who decides whether to enable it and is the controller of the resulting data. We are the processor.
6.4 How recipients can avoid tracking. Disable automatic image loading in your mail client; use a client or privacy proxy that blocks remote content; read messages in plain text; avoid clicking tracked links; unsubscribe using the link in the message; or contact the sender and ask them to stop tracking or to delete your data. Requests sent to support@inbuzzed.com will be forwarded to the sending customer.
7. How we share information; subprocessors
We do not share personal information except as described here. Each recipient is bound by contract to use the information only to provide services to us and to protect it appropriately.
- Stripe— payment processing, subscription billing, invoicing, tax calculation and fraud screening.
- Cloudflare— DNS, CDN, TLS, WAF, DDoS protection and bot detection (Turnstile) for our web properties and tracking endpoints.
- Amazon Web Servicesand other hosting and infrastructure providers — compute, storage, databases, queues, object storage and backups, located in the United States.
- Email delivery and mail-transfer infrastructure— the outbound MTA and relay infrastructure that accepts, queues and delivers messages, and processes bounce and feedback-loop responses.
- Hosted mailbox provider— the third-party mail host on which workspace inbox mailboxes are provisioned, which stores mailbox contents and processes connection logs.
- Operational tooling— error monitoring, logging, transactional email for our own platform notices, and support ticketing, where used.
- Product analytics— where we use an analytics provider on our website or in the application, it is limited to what is necessary and, for non-essential analytics, is subject to your consent.
- Professional advisers— lawyers, accountants, auditors and insurers, under duties of confidentiality.
- Authorities and legal process— where we are legally required to disclose, or where disclosure is necessary to protect rights, safety, property or to investigate fraud or abuse. We review requests for validity and, where legally permitted and practicable, notify the affected customer.
- Corporate transactions— a prospective or actual acquirer, investor or successor, in which case personal information remains subject to this policy or a successor policy no less protective, and we will notify affected customers.
A current list of subprocessors used for customer personal data, and how to be notified of changes and to object, is maintained with the Data Processing Addendum.
8. No sale and no cross-context behavioural advertising
8.1 We do not sell personal information, and we have not sold personal information in the preceding twelve months.
8.2 We do not share personal information for cross-context behavioural advertising, and we do not use customer contact data, recipient data, message content or mailbox contents for advertising, for building advertising profiles, or for training generally available machine-learning models.
8.3 We do not knowingly sell or share the personal information of anyone under 16.
9. International transfers
9.1 We are based in the United States and our infrastructure and subprocessors are primarily located there. If you use the Service from outside the United States, your information will be transferred to and processed in the United States and in other countries where our providers operate.
9.2For transfers of personal data from the EEA, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, and Module Three where applicable), supplemented by the UK International Data Transfer Addendum for UK transfers and by the relevant adaptations for Switzerland. These clauses are incorporated into the DPA.
9.3 We do not currently claim certification under the EU-US, UK or Swiss-US Data Privacy Framework. We apply supplementary technical and organisational measures, including encryption in transit and at rest, access controls and a policy of challenging overbroad government requests.
10. How long we keep information
We keep personal information only as long as needed for the purposes described, on the following schedule.
- Account and workspace data — for the life of the account and ninety (90) days after closure.
- Delivery, bounce and engagement logs — thirteen (13) months from the event.
- Consent and terms-acceptance records — six (6) years, to evidence compliance.
- Billing, invoice and tax records — seven (7) years, or longer where tax law requires.
- Security and access logs — twelve (12) months.
- Backups — up to thirty-five (35) days, after which deleted data ages out of the backup cycle.
- Hosted mailbox contents — until deleted by a user, removed under the dormancy rule, or the account is closed.
- Suppression records (unsubscribes, complaints, hard bounces) — retained indefinitely, as deleting them would allow the address to be mailed again.
- Support correspondence — twenty-four (24) months from the last message in the thread.
- Abuse investigation records — twenty-four (24) months, or longer where a dispute or legal claim is pending.
Retention may be extended where required by law, by a legal hold, or to establish, exercise or defend legal claims. Data held as a processor on behalf of a customer is retained and deleted according to the customer instructions and the DPA.
11. Security
11.1 We maintain administrative, technical and physical safeguards appropriate to the risk, including: TLS encryption for data in transit; encryption at rest for databases, object storage and backups; password hashing with a modern algorithm; role-based access control and least-privilege administrative access; separate environments for production and development; network protection and DDoS mitigation; centralised logging, alerting and monitoring; vulnerability scanning and timely patching; secure software-development practices and code review; background-appropriate personnel vetting, onboarding and confidentiality obligations; vendor security review; and an incident-response process with defined roles.
11.2 No system is perfectly secure. You are responsible for choosing a strong unique password, enabling available additional authentication factors, protecting API keys and SMTP credentials, and managing team member access and offboarding.
12. Your rights (EEA, UK and Switzerland)
Where the GDPR or UK GDPR applies to processing for which we are the controller, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase data where one of the grounds in Article 17 applies;
- restrict processing in the circumstances set out in Article 18;
- data portability for data you provided, in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests, and at any time and absolutely to processing for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting processing already carried out; and
- lodge a complaintwith your local supervisory authority, or with the UK Information Commissioner’s Office. We would appreciate the chance to address your concern first.
We have not appointed an EU or UK representative under Article 27 because our processing does not meet the threshold requiring one; if that changes, we will update this policy. Where we act as a processor for a customer, direct your request to that customer, and we will support them in responding.
13. Your rights (California and other US states)
13.1 California. Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to: know what personal information we collect, use, disclose and retain, and the categories of sources and recipients; access a copy of that information; delete it, subject to exceptions; correct inaccurate information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information; and not be discriminated against or receive different service for exercising these rights.
13.2 We do not sell personal information and we do not share it for cross-context behavioural advertising, so no opt-out mechanism is required, but you may still submit a request and we will confirm this in writing. We use sensitive personal information (such as account credentials) only to provide and secure the Service, which falls within the permitted purposes, so no right to limit arises; we do not use it to infer characteristics.
13.3 Categories. The categories of personal information we collect map to Section 2 above and correspond to the CCPA categories: identifiers; customer records and commercial information; internet or network activity; approximate geolocation derived from IP address; professional or employment information; and inferences limited to product usage. We disclose these categories for business purposes to the recipients listed in Section 7.
13.4 Authorised agents. An authorised agent may submit a request on your behalf with written permission signed by you or a valid power of attorney; we may contact you to confirm.
13.5 Metrics. California residents may request the metrics on requests received, complied with and denied for the prior calendar year by emailing us.
13.6 Other US states. Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware and others as they take effect, have comparable rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling. We honour these rights on the same basis, and offer an appeal: if we decline a request, you may reply to our decision within thirty (30) days and we will review the appeal and respond in writing with our reasoning and information about contacting your state attorney general.
13.7 Shine the Light. We do not disclose personal information to third parties for their own direct-marketing purposes.
14. How to exercise your rights
14.1 Email support@inbuzzed.com with the subject line Privacy Request, telling us what you want and, if you are not writing from the email address on the account, enough information to identify you.
14.2 Verification. We will verify your identity in proportion to the sensitivity of the request, usually by confirming control of the account email address and, for sensitive requests, by asking for additional information already in our records. We will not ask for more information than necessary and will use it only for verification.
14.3 Timing. We acknowledge requests promptly and respond within thirty (30) days for requests under US state laws (extendable once by a further forty-five (45) days where reasonably necessary, with notice), and within one month under the GDPR and UK GDPR (extendable by two further months for complex requests, with notice). Requests are free unless manifestly unfounded or excessive.
14.4 Requests about customer data.If your request concerns data held by a customer — for example, you want to be removed from a mailing list — we will forward it to the customer and tell you we have done so, and where appropriate we will add your address to a suppression list.
15. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18 as a user of the Service. If we learn that we have collected such information, we will delete it. Customers must not use the Service to send marketing to children where doing so is prohibited, and must not upload data about children without the required consent.
16. Do Not Track and Global Privacy Control
16.1 There is no industry consensus on how to respond to Do Not Track browser signals, and we do not currently respond to them.
16.2 We do treat a Global Privacy Control (GPC) signal received from your browser as a valid opt-out of sale and of sharing for cross-context behavioural advertising, and as a withdrawal of consent to non-essential cookies on our website, for that browser and device. Because we do not sell or share personal information, the practical effect is limited to non-essential cookies.
17. Cookies and local storage
17.1 Authentication. The application stores your authentication session in browser local storage so you stay signed in. Clearing site data signs you out. This storage is strictly necessary to provide the Service you requested.
17.2 Security cookies. Our network and bot-protection layer, including Cloudflare and Turnstile, may set strictly necessary cookies to distinguish humans from automated clients, to mitigate attacks and to maintain request integrity. These cannot be disabled without breaking sign-in and form submission.
17.3 Preference storage. We may store non-identifying interface preferences, such as theme or a dismissed notice, locally in your browser.
17.4 Analytics and non-essential cookies. Where we use analytics or any non-essential cookie or similar technology, we will obtain consent first where the law requires it, through a cookie banner that lets you accept or reject non-essential categories and change your choice later. Rejecting them does not affect your access to the Service.
17.5 Recipient-side technologies. Tracking pixels and rewritten links in customer messages are described in Section 6 and are controlled by the sending customer, not by our cookie banner.
18. Data breach notification
18.1 We maintain an incident-response process covering detection, triage, containment, eradication, recovery and post-incident review.
18.2 If we confirm a personal data breach affecting personal information for which we are the controller, we will notify affected individuals and the relevant supervisory authorities without undue delay and within the deadlines set by applicable law, including within seventy-two (72) hours of becoming aware where the GDPR or UK GDPR requires it.
18.3 Where we are a processor, we will notify the affected customer without undue delay and in any event within seventy-two (72) hours of confirming the breach, with the information described in the DPA, so that the customer can meet its own obligations.
18.4 Our notification will describe, as far as known, the nature of the incident, the categories and approximate volume of data affected, the likely consequences, the measures taken or proposed, and a contact point for further information.
19. Changes to this policy
We may update this policy. The version label and effective date at the top of this page identify the current version. For material changes we will give at least fourteen (14) days notice by email to your account address or by a prominent notice in the application before they take effect, and where the law requires consent for a new use, we will ask for it. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
20. How to contact us
Astra Innovations LLC, Sanford, Florida, USA. Privacy enquiries, rights requests and complaints: support@inbuzzed.com. Related documents: Terms of Service, Acceptable Use and Anti-Spam Policy, and the Data Processing Addendum.
Questions: support@inbuzzed.com · Terms · Privacy · Acceptable Use · DPA · Cookie Policy