Privacy Policy
How Postclic handles the documents you send, the addresses they carry and the account data behind every registered mailing.
1. Identity of the controller and reach of this policy
The site https://www.postclic.com is published and operated by Postclic technology Limited (C 114711), whose registered office is at . For each item of personal data described below, that company decides the purposes pursued and the means employed, and accordingly acts as controller within the meaning of Article 4(7) of the General Data Protection Regulation.
The policy sets out what Postclic does with the data of those who open an account, of those who pay for a mailing, and of the recipients whose addresses are carried on the mail despatched. It is drawn up under Regulation (EU) 2016/679 (GDPR) for persons situated in the European Union, under amended Law No. 78-17 (Data Protection Act) for France, and under the Personal Data Protection Law (PDPL) applicable in Malta.
Any question on its application may be addressed to [email protected].
2. Data gathered at each stage of a mailing
Collection is confined to what the supply, administration and invoicing of the service require. Five categories arise, at distinct points in the flow.
- Identity data
- Surname, first name, postal address, electronic address, telephone number and country, given at account opening and reproduced as the sender's particulars on the mail itself.
- Account data
- Login name, password held only in hashed form, the record of subscriptions taken out and the invoices issued against them.
- Payment data
- The card number and the associated banking particulars are collected and processed by the provider Stripe alone. Postclic at no point has sight of them.
- Content and addressing data
- The documents uploaded or drafted through the service, the templates created, the sender and recipient particulars, the history of despatches and the tracking of each item.
- Technical data
- IP address, type of device, browser, server logs, and the cookies used for measurement and for security.
3. Purposes pursued and legal bases relied upon
Data gathered under clause 2 above is processed in order to supply and execute the service, which is to say to draft, print and despatch the mail; to administer the account and issue invoices; to prevent fraud and secure payments; to answer requests for assistance and technical support; to improve the site and the performance of the service; to satisfy legal obligations bearing on invoicing, accounting records and the fight against money laundering; to transmit administrative or contractual information connected with the service; and to deal with requests made in exercise of GDPR or PDPL rights.
Each of those purposes rests on one of four bases. Performance of the contract carries the use of the service, the processing of orders and invoicing. Consent carries the creation of an account, cookies and marketing. A legal obligation carries the keeping of records and of invoices. Legitimate interest carries the prevention of fraud and the improvement of the service.
4. How long data is kept
Data is retained for the period strictly necessary to the purpose for which it was gathered, on the following scale.
| Category | Maximum period |
|---|---|
| Account data | for so long as the account is open, then three years from its deletion |
| Invoicing data | ten years, under accounting obligations |
| Data on mail despatched | the term of the subscription, then six months |
| Technical data and logs | twelve months |
| Analytics cookies | thirteen months at most |
Documents and files belonging to the customer are erased automatically when the subscription comes to an end or the account is closed.
5. Persons to whom the data is disclosed
Postclic neither sells nor lets personal data. Disclosure is made only to the technical providers charged with hosting, routing, printing and support; to the payment provider; to carriers and postal operators, so far as a despatch demands it; and to administrative or judicial authorities where the law compels it. Each is bound by strict duties of confidentiality and security.
The processors presently engaged are the following.
- Stripe Payments Europe Ltd., for the processing of payments.
- OVHcloud (OVH SAS)., for hosting.
- Google LLC, for audience measurement through Google Analytics 4.
- The postal service used for the printing and the despatch of mail.
- The OpenAI interface, and equivalent artificial intelligence interfaces, for automated generation of text, which keep no personal data once the text has been produced.
We use Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
6. Hosting and transfers beyond the European Union
Data resides on the secured servers of OVHcloud (OVH SAS)., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus (https://www.ovhcloud.com), situated within the European Union, in Lithuania and in the Netherlands. Backups and certain processing operations may be carried out in Malta in the course of the technical management of the service, and the same holds for the needs of support.
Every transfer beyond the Union is covered by the safeguards the Regulation demands, that is to say the Standard Contractual Clauses adopted by the European Commission under Article 46 GDPR, together with the equivalent guarantees of the Personal Data Protection Law referred to in clause 1 above, so that the protection secured is equivalent to the one obtaining within the Union.
7. Measures taken to secure the data
Postclic applies technical and organisational measures answering to recognised international standards: encryption of traffic by SSL/TLS, hashing of passwords, firewalling, logging of access, segregation of environments, strict control of authorisations, and internal security audits conducted periodically.
8. Cookies placed on the site
Three categories of cookie are used: technical cookies, without which the service cannot run; analytics cookies, placed through Google Analytics 4 in order to measure audience; and functional cookies, which retain the chosen language and the customer's display preferences.
The customer governs them through the consent banner or through the settings of the browser. Refusal of technical cookies may put the service beyond reach.
9. Rights of the data subject and complaints
Under GDPR and under PDPL alike, the customer holds a right of access to the data concerning him, a right to rectification, a right to erasure, known as the right to be forgotten, a right to restriction of the processing, a right to object, a right to portability by way of an export, and, in the European Union only, a right to lay down directives governing what becomes of the data after death.
A request is addressed to [email protected] and answered within thirty days at the outside. A document evidencing identity may be called for before it is executed.
A customer situated in the European Union may in addition lodge a complaint with the supervisory authority for data protection of his own country.
10. Amendment of this policy
Postclic reserves the power to amend this policy at any time. The version governing the relationship is the one published on the site on the day of consultation. Any substantial amendment is notified by electronic mail or through the customer account.
How Google uses your data
When you accept advertising and measurement cookies, Google processes your personal data as an independent controller for its own purposes. Google explains those uses, and the choices you have, here: How Google uses data from sites or apps that use its services