1. Who we are
MB Tafe, registration code 308026391, Laisvės al. 85E-5, Kaunas, Lithuania, operates Agent Herald at agentherald.dev.
For privacy questions, write to [email protected].
2. Two roles
This distinction runs through everything below, so it is worth stating first.
We are a controller for data about the people who hold accounts with us — your name, your email address, your billing details, how you use the service. We decide what to collect and why, and this policy governs it.
We are a processor for the contents of the mail you send and receive. The recipients of your mail are your contacts, not ours. We hold that data because you instructed us to send or receive it, we act on your instructions, and we do not use it for our own purposes. Your obligations to those people are yours; ours are to you, and are set out in our Terms.
We do not sell personal data. We do not use message content to train machine learning models, our own or anyone else's. We do not build advertising profiles.
3. Account data
| What | Why | Legal basis |
|---|---|---|
| Email address | Identifying your account, sending sign-in codes, service notices | Performance of a contract |
| Name, where given | Addressing you | Performance of a contract |
| Domains you add and their DNS records | Verifying you control the domain you send from | Performance of a contract |
| API keys, hashed | Authenticating your requests | Performance of a contract |
| Provider credentials you supply | Sending through your own provider account, where you choose that | Performance of a contract |
| Audit log of account actions | Security, abuse investigation, answering "who changed this" | Legitimate interests |
| Sending statistics | Showing you your numbers, enforcing deliverability thresholds | Legitimate interests |
Our legitimate interests above are keeping the platform secure and keeping its sending reputation intact. We think these are interests you share, since the alternative is a platform that does not deliver mail.
4. Message data
When you send a message we process its sender, recipients, subject, body, attachments and headers, together with delivery events returned by the sending provider — accepted, delivered, bounced, complained, deferred.
When you receive a message on a domain you have configured for inbound mail, we process the raw message and the parsed version of it.
We hold this because you instructed us to. The legal basis for your own processing of it — your relationship with your recipients — is yours to establish, and our Acceptable Use Policy requires you to be able to.
We access message content only to operate and debug the service, to respond to a support request you have made, or where we are investigating a specific abuse report or legal obligation. Access is logged.
5. Technical data
Our servers keep operational logs — IP address, timestamp, endpoint, response status, user agent — for security, debugging and abuse investigation, on the basis of our legitimate interests. Application logs record events, not message bodies.
6. Cookies and the website
The site sets a session cookie and a CSRF token cookie. Both are strictly necessary to keep you signed in and to prevent request forgery, so neither requires consent and there is no cookie banner to click.
We run no analytics, no advertising pixels and no third-party trackers. Nobody is measuring your scroll depth.
Webfonts are served by fonts.bunny.net, a privacy-focused font host that does not log requests or set cookies. If it is unreachable, the pages fall back to your system fonts and nothing else changes.
7. How long we keep things
| What | Kept for |
|---|---|
| Message content — bodies, attachments, raw inbound mail | 30 days, then deleted |
| Message metadata — recipients, subject, delivery events | 365 days, then deleted |
| Suppression entries | For the life of the account — deleting them would mean mailing people who asked you to stop |
| Audit logs | For the life of the account |
| Account data | Until you close the account, then deleted within 30 days except where we must keep records to meet a legal obligation |
Content retention is short by design. The less message content we hold, the less there is to lose.
8. Who else sees it
A short list of vendors, each named with what they do and where they are, is maintained at Subprocessors. We self-host our database, queues, authentication and webhook delivery rather than buying them, which is why that list is shorter than you might expect.
We otherwise disclose personal data only where we are legally compelled to, and where we may lawfully tell you about it, we will.
9. International transfers
Message content, message metadata and application data are stored in the European Union — our infrastructure runs in Ireland and our host is Lithuanian.
Some vendors on the subprocessor list have parent companies outside the EU. Where a transfer outside the EEA occurs, it is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, as noted against each entry.
10. If you received mail sent through us
If a message reached you via Agent Herald and you want it stopped, corrected or deleted, the person to ask is the sender — they decided to write to you, and under the GDPR they are the controller of that decision. Their identity is in the message.
If you cannot reach them, or the mail should not have been sent at all, write to [email protected] with the message headers. We will suppress your address so nothing further reaches you from that account, and act under the Acceptable Use Policy if the mail broke it.
11. Your rights
Under the GDPR you may request access to your personal data, correction of it, erasure, restriction of processing, portability of data you gave us, and you may object to processing we base on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting what came before.
Write to [email protected]. We respond within one month, and will say so if a request is complex enough to need the extension the GDPR allows. We do not charge for this.
If you are unhappy with how we handled it, you may complain to the Lithuanian supervisory authority, the Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), or to the authority where you live.
12. Security
The controls we run are described in detail on the Security page, including what we have not yet done.
Where a personal data breach is likely to result in a risk to people's rights, we notify the supervisory authority within 72 hours of becoming aware of it, and affected customers without undue delay.
13. Changes
When this policy changes materially we update the effective date at the top and notify account holders by email before it takes effect. Minor corrections happen without notice.
14. Contact
MB Tafe
Laisvės al. 85E-5, Kaunas, Lithuania
[email protected]