Privacy Policy (GDPR)
Version: 1.1 · Effective date: 2026-09-10 · Operator: TriStiX S.L. (VAT ESB26925016), Avenida Maisonnave 41, 3º H, 03003 Alicante/Alacant, España
1. Who we are
TraXmark® is operated by TriStiX S.L. (VAT ESB26925016), Avenida Maisonnave 41, 3º H, 03003 Alicante/Alacant, España. TriStiX S.L. is the data controller for account data and a data processor for contact data uploaded by customers. Contact: privacy@traxmark.com.
2. What we process
- Account data: name, email, billing references, security data (MFA, consents).
- Engagement data: open signals, clicks, replies — classified with confidence scores. IP addresses and user agents are pseudonymized at ingestion (hashed), never stored raw.
- Document analytics: page views and time-on-page for shared documents.
3. Legal bases (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)) — providing the Service.
- Legitimate interest (Art. 6(1)(f)) — service security, abuse prevention.
- Consent (Art. 6(1)(a)) — where required for tracking recipients; our customers obtain and record it.
4. Tracking honesty and ePrivacy
Per EDPB Guidelines 2/2023, tracking pixels and tracked URLs fall under ePrivacy. We provide: consent records, opt-out via the recipient privacy portal, pseudonymization, retention limits and transparency. We never claim an open signal proves reading.
5. Recipients' rights
Recipients of tracked messages can: opt out of tracking, request access (Art. 15), request erasure (Art. 17) via the privacy portal linked in every message.
6. Your rights as a customer
Access, rectification, erasure, portability, restriction, objection — via Settings → Privacy or privacy@traxmark.com. We respond within 30 days.
7. Retention
Raw engagement events: 12 months, then aggregated or erased. Documents: per your retention settings. Invoices: statutory retention (5 years).
8. Sub-processors
We use infrastructure sub-processors (cloud hosting, database, payments). The current list is available on request. EU data residency; transfers outside the EEA only with SCCs.
9. Security
Encryption in transit and at rest, envelope encryption for credentials, RLS tenant isolation, MFA, immutable audit logs. Details in the Security Whitepaper.
10. Changes and complaints
Material changes require re-acceptance. You may lodge a complaint with your supervisory authority.
11. Google API Services (OAuth) data
This section covers the data TraXmark receives through Google APIs when you connect a mailbox with your Google account (OAuth). It supplements sections 1 to 10 and is to be read together with them.
- (a) Access. When you connect a mailbox we access the email address of the Google account you sign in with (scopes openid and email) and, under the read-only scope https://www.googleapis.com/auth/gmail.readonly, the message list, headers and metadata of incoming messages in that mailbox. Message bodies are not copied out of the customer workspace beyond what is needed to classify the open signal. We request no write, send, draft, modify, label or delete access to the mailbox: the connection is strictly read-only.
- (b) Use. We use this data solely to classify opens of messages sent to the connected mailbox as human, as privacy-proxy (for example Apple Mail Privacy Protection) or as bot pre-fetch, and to provide engagement analytics inside the customer's own workspace (tenant). This processing follows the Limited Use requirements of the Google API Services User Data Policy: the data is used only to provide the features you requested, only inside your own workspace, and for no other purpose.
- (c) Sharing. We do not transfer or disclose Google user data to third parties. We do not sell it and we do not use it for advertising. The infrastructure sub-processors named in section 8 act only as processors on our behalf under a written contract (GDPR Art. 28) and within our EU data residency; they obtain no rights of their own in the data.
- (d) Protection. We use encryption (AES-256-GCM at-rest, TLS in transit) to protect your information. OAuth access and refresh tokens and IMAP credentials are stored only as envelope-encrypted ciphertext (a per-record data key sealed with a master key held in the server environment, plus a random IV and a key version for rotation); plaintext never reaches the database, the browser, the logs or the audit trail. Access is confined by row-level tenant isolation and recorded in immutable audit logs (section 9).
- (e) Retention and deletion. Mailbox connection credentials are deleted as soon as you disconnect the mailbox. Data derived from the connection follows the retention periods in section 7: raw engagement events are kept for 12 months and then aggregated or erased. You may request deletion by disconnecting the mailbox, via DSAR export/anonymize, or by revoking access in Google My Account. In the product: disconnect under Settings → Mailbox connections; DSAR export and anonymization under Settings → Data requests (DSAR); revocation on the Google side under Google My Account → Security → Third-party apps with account access. Requests sent by email are answered within 30 days (section 6).
- (f) AI/ML. TraXmark does not use Google Workspace APIs to develop, improve, or train non-personalized AI/ML models; machine-learning features run per customer workspace on that customer's own data solely to provide user-facing analytics.
- Tracking pixel and cookies. The open signal itself comes from a tracking pixel in the message; it is governed by section 4 (ePrivacy: consent records, opt-out, pseudonymization, retention limits) and by the Cookie Policy at /legal/cookie-policy. TraXmark's own web application uses strictly necessary session cookies (HttpOnly, Secure, SameSite=Lax) for authentication and for the OAuth connection flow (PKCE: the code verifier lives in a short-lived HttpOnly cookie and is exchanged server-side only). We use no third-party advertising cookies and place no cookies on your recipients' devices.
- Contact. Send requests about Google user data (access, deletion, revocation, questions) to support@traxmark.com; the data protection officer contact point is privacy@traxmark.com.
Document integrity (SHA-256): 635a972d121a886f