Privacy & data protection
Privacy Policy
This policy explains which personal data Oveyon processes, why, on what legal basis and for how long — and how you exercise your rights. It is written to meet the European GDPR, the U.S. CAN-SPAM Act and applicable state law, and — for Brazilian data subjects — Brazil's General Data Protection Law (LGPD, Law No. 13.709/2018).
01Who we are
Oveyon is a customer-portfolio operations platform with built-in transactional email infrastructure, provided by Akamind Inc., a Delaware C-corporation ("Oveyon", "we"). Akamind Inc. is the controller for the personal data described in this policy. Registered office: contact legal@oveyon.com for the current registered address. We serve customers in the United States, Europe and Brazil, in accordance with the GDPR, CAN-SPAM and the LGPD as each applies.
02Controller and processor
Data-protection law — the GDPR and the LGPD alike — distinguishes who decides on the processing (the controller) from who carries it out on behalf of another (the processor). At Oveyon both roles exist:
- We are the controller of our customers' account data — registration, billing, authentication, platform security;
- We are the processor when a customer uses the platform to send messages to their own audience: the recipient data belongs to the customer, who is the controller. We process that data according to the customer's instructions and this policy.
If you are the recipient of a message sent by one of our customers and wish to exercise rights over your data, the primary point of contact is the sender (the controller). We can still help route your request — see Your rights.
03Data we process
| Category | Examples | Source |
|---|---|---|
| Registration and identification | name, email, tax ID (CPF/CNPJ/EIN), company | provided by the customer |
| Credentials | password (stored with bcrypt), API keys (stored as SHA-256 hashes), passkeys (passkey/WebAuthn) | generated at signup |
| Sending metadata | envelope, headers, timestamps, delivery result, bounce and complaint events, IPs | generated by use |
| Recipient data | addresses and attributes the customer submits for sending | provided by the customer (who is the controller) |
| Reputation | signals from Google Postmaster Tools and Microsoft SNDS, blocklist listings | third parties / providers |
| Technical records | access logs, audit trail of actions | generated by use |
The tax ID is validated by format and check digit and stored in normalized form. This is a format/PII validation, not verification against an official third-party registry.
04Legal bases
We process personal data on the following grounds (GDPR art. 6; LGPD art. 7):
- Performance of a contract — providing the service you signed up for;
- Compliance with a legal or regulatory obligation — including responding to authorities;
- Legitimate interest — information security, fraud and abuse prevention, and deliverability (authentication, reputation, suppression), always with an impact assessment and respect for your rights;
- Consent — where applicable, for example in non-essential communications.
05How we use the data
- Operate sending: authenticate (SPF, DKIM, DMARC), sign, deliver and correlate bounces and complaints;
- Protect the platform: compromised-account detection, rate limiting, content/URL scanning, sandbox and suppression;
- Maintain and demonstrate sending reputation with mailbox providers;
- Bill, provide support and meet legal obligations;
- Maintain an audit trail of actions performed on the platform.
We do not sell personal data and do not use it for third-party advertising.
06Message content
The body of messages (HTML and text) is not written to the application logs — the logger redacts those fields. The signed message may be archived encrypted at rest, with restricted access and only a pointer in the database, subject to the retention policy, for auditing, delivery-dispute resolution and legal obligations. We treat content as customer data, under the customer's instructions.
07Sharing and sub-processors
We share data only with providers necessary to operate the service, under confidentiality and security obligations:
| Sub-processor / service | Purpose |
|---|---|
| Cloudflare | DNS, edge and network protection |
| Google (Postmaster Tools, Web Risk, Safe Browsing) | sending reputation and malicious-URL checking |
| Microsoft (SNDS) | IP reputation with Outlook/Hotmail |
| AbuseIPDB | IP reputation checking |
| Relay providers (e.g., MailChannels, SMTP2GO) | overflow valve / alternative delivery routes |
The full list of sub-processors — with the data each one reaches and where it operates — is published at oveyon.com/sub-processors and kept current.
We may also disclose data to comply with the law, a court order or a valid request from an authority — in those cases, the contact is legal@oveyon.com.
08International transfers
Akamind Inc. is U.S.-based. The platform runs on infrastructure in the United States and Brazil, and some sub-processors operate in other jurisdictions (see sub-processors). Where personal data crosses borders, transfers follow the GDPR (standard contractual clauses and equivalent safeguards) and, for the data of Brazilian data subjects, the LGPD (art. 33), so that an adequate level of protection is maintained.
09Retention
- Account data — while the account is active and for the applicable legal period after closure;
- Sending metadata and audit trail — for a defined retention period, for security, deliverability and legal obligations;
- Archived message object — for the configured retention period, then deleted;
- Suppression list — kept for as long as needed to avoid re-sending to those who unsubscribed or complained (protecting the data subject).
10Security
Technical and organizational measures we apply:
No system is completely secure. We adopt measures appropriate to the state of the art and the risk involved, but absolute security cannot be guaranteed.
11Your rights
As a data subject, under the GDPR (arts. 15–22) and the LGPD (art. 18) you may: confirm the existence of processing; access your data; correct incomplete or outdated data; request anonymization, blocking or deletion of unnecessary data or data processed in breach of the law; request portability; obtain information about sharing; and withdraw consent.
To exercise these rights, write to privacy@oveyon.com. We will respond within the legal deadlines. If you are the recipient of a message sent by one of our customers, direct your request to the sender (the controller); we can help route it. You may also lodge a complaint with your supervisory authority — your EU data protection authority, or the ANPD in Brazil.
12Cookies
In the portal and dashboard we use a strictly necessary session cookie (oveyon_sid), with the HttpOnly, Secure and SameSite attributes, to keep you authenticated. It is not used for advertising or cross-site tracking. The marketing site does not depend on cookies to function.
On the public website (oveyon.com and oveyon.com.br) we use Google Analytics 4 (Google LLC) to measure visits, pages viewed and clicks. We do not enable advertising features or Google Signals; the data is pseudonymous usage data (pages, clicks, device and browser, truncated IP address) and may be processed in the United States under Google's standard contractual clauses. The measurement script is not loaded when your browser sends the Do-Not-Track signal, and you can block it with a content blocker or by disabling JavaScript. The portal and dashboard are not measured.
13Changes
We may update this policy. The version in force is the one published on this page, with the date at the top. Material changes will be communicated to active customers.
Change history — 27 August 2026: audience measurement on the public website (Google Analytics 4) was added to §12. August 26, 2026: the controller for oveyon.com became Akamind Inc.; the international-transfers and supervisory-authority sections were updated accordingly. July 31, 2026: first publication.
Privacy: privacy@oveyon.com · Legal: legal@oveyon.com · Abuse: abuse@oveyon.com
Akamind Inc. has not appointed a statutory Data Protection Officer, because its core activities do not involve large-scale processing within the meaning of GDPR art. 37. The privacy mailbox is read by the company's leadership.