Privacy Policy Notice

Download PDF Version Spanish PDF German PDF

RPost is a global cloud service provider for secure and certified electronic communications with its patented e-delivery proof, encryption, and e-signature technologies. Millions of users have enjoyed RPost services for more than a decade in more than 100 countries.

This is the Privacy Notice of RPost UK Limited and its related entities providing RPost service operations (RPost Holdings Inc., RPost Communications Limited, RPost Switzerland GmbH, and parent and subsidiary companies of these) (“RPost”) and RPost service providers but only for their customer data processed by RPost services. The registered office of RPost UK Limited is The Glades, Festival Way, Festival Park, Stoke on Trent ST1 5SQ. RPost UK Limited is the company that acts as the Data Processor for the purposes of the scope of the European General Data Privacy Regulation (EU) 2016/679 (GDPR).

RPost does business in California under entities RPost US Inc. and RPost Holdings Inc. The business that RPost conducts in California complies with the California Consumer Privacy Act of 2018 (CCPA) as stated herein, by giving California consumers privacy rights including (a) the right to know about the personal information a business collects about them and how it is used and shared; (b) the right to delete personal information collected from them (with some exceptions); (c) the right to opt-out of the sale or sharing of their personal information; (d) the right to non-discrimination for exercising their CCPA rights; (e) the right to correct inaccurate personal information that a business has about them; and (f) the right to limit the use and disclosure of sensitive personal information collected about them. RPost entities do not sell consumer information, as further stated herein. Consumers in California who have questions about the data that RPost may or may not have or have requests regarding exercising their rights, may refer to this Consumer Notice and may contact RPost for more information or for support (https://rpost.com/contact/questions) related to consumer data that RPost may hold.

RPost’s privacy policies were certified by the US, European and Swiss governments for compliance with the US-EU Safe Harbor and Privacy Shield programs when those programs were generally accepted.

This Privacy Notice is in three sections and describes RPost policies with regards to information privacy as it relates to the use of information for the purposes of providing RPost services (any service provided by RPost including RMail®, RSign®, and Registered Email™ services, or any the RPost® service operations of any service with RPost technology participation) and communications with RPost service users (senders, receivers, customer administrators, offerors, or parties related to them) and prospective users (senders, receivers, customer administrators, offerors, or parties related to them):

Privacy Policies

A. Personal Data We May Collect While Clients Use Our Service Operations

B. Personal Data We May Collect for Marketing Our Services

C. Additional Privacy Statement: RMail App for Gmail

The RMail app for Gmail routes outbound Gmail SMTP messages to RMail services by modifying the recipient addresses with a domain extension. The messages are routed using a wildcard MX record and the added recipient domain extensions are removed for processing when received by the RMail service. (For example: To: jack@example.com is modified to: jack@example.com.rpostextention.xyz en route from Gmail servers to RMail service servers; the DNS Lookup for one such extension is *.rpost.biz is MX 10 gate.r1.rpost.net).

In the RMail for Gmail app, the RMail software downloads the draft message to be sent, modifies the recipient addresses in the draft as noted above, sends the modified message to the modified destination as noted above, and deletes the original draft message. Additionally, the RMail software modifies the addresses in the sent item after sending and in the user contacts after sending, to reflect the original correct recipient addresses (without the RMail added domain extension).

Updating the sent item requires listing and downloading the sent item with modified addresses, creating a replacement sent item with the correct original addresses, deleting the sent item with modified addresses. To delete a message (sent item), the only Google provided scope available is https://mail.google.com/ https://developers.google.com/gmail/api/v1/reference/users/messages/delete).

That scope covers all the RMail software needs apart from the Gmail Contacts API used to update the contacts address to return it to its original unmodified address (without the RMail added extension). For contacts management, the RMail software uses: https://www.google.com/m8/feeds/

Therefore, the RMail app for Gmail applies for the above mentioned two scopes, the minimum that the RMail app for Gmail needs. A summary of Scopes and APIs used follow. Scopes: https://mail.google.com/ and https://www.google.com/m8/feeds/. APIs:

  1. https://www.googleapis.com/gmail/v1/users
  2. https://www.googleapis.com/gmail/v1/users/userId/drafts
  3. https://www.googleapis.com/gmail/v1/users/userId/labels
  4. https://www.googleapis.com/gmail/v1/users/userId/messages
  5. https://www.googleapis.com/gmail/v1/users/userId/messages/id/modify
  6. https://www.googleapis.com/gmail/v1/users/userId/profile
  7. https://www.googleapis.com/upload/gmail/v1/users
  8. https://www.googleapis.com/upload/gmail/v1/users/userId/messages/send
  9. https://accounts.google.com/o/oauth2
  10. https://accounts.google.com/o/oauth2/token
  11. https://www.google.com/m8/feeds/contacts/

PRIVACY PHILOSOPHY

RPost uses best efforts to abides by each respective country’s privacy rules and principles as service is taken up in the country. RPost abides by practices and procedures to meet the requirements of the European General Data Protection Regulation and Privacy Shield, the National Privacy Principles of Australia, and the U.S. Privacy Act 1988, as well as other privacy laws specific to other countries and territories.

RPost had been complying with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States while these agreements were generally accepted. It is understood that the provenance of the Privacy Shield Program is uncertain at this time due to geo-political differences and for this reason, RPost has not renewed its certification with the Department of Commerce but has continued to follow the principles that were set forth in the generally accepted EU-U.S. Privacy Shield Framework and SwissU.S. Privacy Shield Framework.

The U.S. based RPost entities are subject to the investigatory and enforcement powers of the Federal Trade Commission, while all RPost entities commit to cooperate with EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC), and comply with the advice given by such authorities with regard to unresolved Privacy Shield complaints concerning data transferred from the EU and Switzerland.

RPost will not share your information with third parties for a purpose that is materially different from original purpose(s) without your consent. In instances where RPost shares your information with third parties, RPost shall remain liable under the principles of Privacy Shield if such third parties process such personal information in a manner inconsistent with the Principles, to the extent that RPost’s actions were responsible for the event giving rise to the damage.

If you wish to object to the collection of personal data listed under “data collection and purpose“ RPost asks you to refrain from using the RPost Services, as data collection is directly linked to the provision of the services.

Please contact us if you have any questions about our privacy policies or information we hold about you, by electronic transmission to the forms mentioned herein, which are accessible globally (e.g. https://rpost.com/contact/questions/. Information submitted to these forms as it related to this privacy policy may be escalated to a data protection point of contact as RPost deems appropriate, or you may address a request specifically to “RPost Data Protection”. You may also write to: Privacy Team, RPost UK Ltd, The Glades, Festival Way, Festival Park, Stoke on Trent, ST1 5SQ. According to the EU General Data Protection Regulation Art 13 para. 2 (d) you have the right to lodge a complaint with the supervisory authority in your country and you may inform us of such a complaint using the abovementioned addresses. If you wish to object to the collection of personal data listed under “data collection and purpose“ RPost asks you to refrain from using RPost Services, as data collection is directly linked to the provision of the services.

This notice was last updated on October 10, 2024. We reserve the right to change this notice and our privacy policies at any time.

Download PDF Version Spanish PDF German PDF