Who we are
Notideus is an email platform — transactional email, marketing broadcasts, templates, sending domains, and delivery analytics — operated by DUKIFY INC, a company registered in Delaware, USA.
Our registered address is:
DUKIFY INC
1111B S Governors Ave STE 29561
Dover, DE 19904, US
This policy covers the data we handle when you visit notideus.io (the landing site) and when you use the Notideus application and API (the service). The rules for using the service itself are in our Terms of Service.
For anything in this policy, write to privacy@notideus.io.
Data we process
We process five categories of data:
- Account data. When you register, we store your name, email address, and a hash of your password. We never store your password in plain text.
- Email content and metadata. When you send through the API, we process what you submit: recipient addresses, subjects, bodies (or the template and variables you send), and any tags you attach.
- Contact and audience lists. When you upload contacts for marketing broadcasts, we store those lists — email addresses and any attributes you include — so we can send on your behalf.
- Billing data. Payments are handled by Stripe. We see your billing name, email, and the last four digits of your card; we never store full card numbers.
- Technical logs. IP addresses, timestamps, API requests, and delivery events (sent, delivered, bounced, complained) that the platform records to operate and to show you analytics.
Controller and processor roles
For your account and billing data, DUKIFY INC is the data controller — we decide why and how that data is processed.
For contact lists and email content, the roles flip: you are the data controller and DUKIFY INC is the data processor, in the sense of Article 28 of the GDPR. You decide whose addresses go into your lists and what your emails say; we process that data only on your instructions — to send, deliver, track, and display it back to you. If you need a signed Data Processing Agreement on top of this policy, contact privacy@notideus.io.
Purposes and legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account | Account data | Contract |
| Send and deliver your emails | Email content and metadata, contact lists | Contract |
| Bill you | Billing data | Contract |
| Show delivery analytics in your dashboard | Delivery events | Contract |
| Keep the platform secure and prevent abuse | Technical logs | Legitimate interest |
| Answer your questions and support requests | Account data, message content | Legitimate interest |
| Meet tax, accounting, and legal duties | Billing data, logs | Legal obligation |
We do not sell your data, and we do not use your email content or contact lists to advertise to you or anyone else.
Subprocessors
We use two subprocessors to run the service:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (Amazon SES) | Email sending and delivery infrastructure. The AWS region is selected per sending domain. | Email content and metadata, contact lists, delivery events |
| Stripe | Payment processing and invoicing | Billing data |
Each subprocessor is bound by a data-processing agreement and may process data only to provide its service to us.
International transfers
DUKIFY INC is established in the United States, and your data is processed there. If you are in the EEA or the UK, your data is transferred to the US under Standard Contractual Clauses (SCCs) with our subprocessors, so it keeps GDPR-level protection while in transit and at rest.
Data retention
We keep your account data for as long as your account is open. Delivery analytics are kept for the retention window of your plan (3 days on Free, 30 days on Pro, 90 days on Scale), and technical logs for a limited period after that, to investigate incidents and abuse.
When you close your account, we delete your account data, templates, and contact lists within 30 days, except billing records we must keep by law. You can also ask us to delete specific data at any time — see the next section.
Your rights
Depending on where you live, you have some or all of these rights over your personal data:
- Access — get a copy of the data we hold about you.
- Rectification — fix data that is wrong or incomplete.
- Erasure — have your data deleted.
- Portability — get your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests.
To exercise any of these, email privacy@notideus.io from the address on your account. We answer within one month. If your data sits inside a customer's contact list, we will point you to that customer, who is the controller of that data.
Security
We protect your data with TLS encryption in transit, scoped API keys you can create and revoke per use case, and access controls that limit internal access to the people who need it to run the service. No system is perfectly secure, but these are the controls we hold ourselves to, and we will tell you promptly if a breach affects your data.
Cookies and tracking
The Notideus landing site sets no tracking cookies — no analytics cookies, no advertising pixels, nothing that follows you around. The Notideus application and API authenticate you with tokens, not tracking cookies.
EU representative
DUKIFY INC is established in the United States and has no establishment in the EU or UK. If you are in the EEA or the UK, you can direct any data-protection request — including requests you would otherwise send to a representative — to privacy@notideus.io, and we will handle it under the GDPR. A formal representative under Article 27 may be required as our European user base grows; we are assessing this and will update this section when one is appointed.
Changes and contact
If we change this policy, we will update the date at the top of the page and, for material changes, notify you by email or in the dashboard before they take effect.
Questions, requests, or complaints about this policy: privacy@notideus.io, or write to DUKIFY INC, 1111B S Governors Ave STE 29561, Dover, DE 19904, US.