Document version: 2026-08-24-draft
Status: Draft for legal review. This page does not create a processing engagement without a signed order or statement of work.
Roles and instructions
The signed order identifies the controller and processor roles for each engagement. MailAuthOps processes customer data only to provide the agreed DMARC ingestion, source review, remediation, reporting, support, security, and deletion services, or as required by applicable law.
Data and people
Processing may include business contacts, domains, DMARC aggregate reports, sender identifiers, source classifications, evidence, remediation notes, audit events, and support records. Data subjects may include customer personnel, MSP personnel, and business contacts represented in authentication data.
Security
MailAuthOps uses encrypted transport and storage, role-based access, MFA, tenant isolation, restricted support access, audit events, backups, vulnerability management, and documented incident and recovery procedures. Security controls are risk-managed and do not constitute a guarantee that an incident cannot occur.
Subprocessors and transfers
Current subprocessors and processing locations are listed on the subprocessor page. MailAuthOps will provide notice of a material subprocessor change through the agreed contact route and will use applicable contractual safeguards for restricted transfers.
Assistance and incidents
MailAuthOps will provide reasonable assistance with data-subject requests, security assessments, breach obligations, and deletion requests in proportion to the agreed service. Confirmed incidents affecting customer data are communicated without undue delay through the designated security contact.
Return and deletion
Data is returned or deleted according to the signed order and published retention schedule, subject to backup cycles and records that must be retained for security, suppression, tax, dispute, or legal purposes.
Contact
Questions about this addendum can be sent to privacy@mailauthops.com.