Legal
JoltMx Privacy Policy
This Privacy Policy explains how JoltMx collects, uses, stores, shares, and protects information across the website, dashboard, APIs, support channels, and email routing platform.
Controller / Processor Split
For customer email data processed through customer-configured domains, the JoltMx customer is the data controller and JoltMx acts as the data processor.
- Last updated
- May 10, 2026
- Privacy contact
- privacy@joltmx.com
- Related legal page
- Terms of Service
This Privacy Policy explains how Ninvoice Limited trading as JoltMx (“JoltMx”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you use our websites, applications, APIs, email routing services, support channels, and related services.
JoltMx provides email forwarding, routing, storage, filtering, diagnostics, automation, and related email infrastructure services. Because of the nature of the service, we may process both account information about our customers and technical or email data passing through the JoltMx platform.
For customer email traffic, the key distinction is this: the JoltMx customer is the data controller for customer email data processed through their connected domains. JoltMx acts as the data processor for that customer email data.
By using JoltMx, you agree that we may process information as described in this policy.
1. Who we are and our role
JoltMx is operated by:
Company details
Ninvoice Limited trading as JoltMx3rd Floor, 86-90 Paul Street
London
EC2A 4NE
United Kingdom
Company number: 08186678
Contact: privacy@joltmx.com
JoltMx provides email routing, forwarding, filtering, storage, diagnostics, and automation infrastructure for customers who connect their own domains to the service.
For customer email data processed through customer-configured domains, the JoltMx customer is the data controller and JoltMx acts as the data processor.
Customer email data includes email messages, attachments, headers, envelope data, sender and recipient data, message metadata, routing records, delivery events, spam and authentication results, and related diagnostic information generated as part of processing that customer’s email.
The customer decides:
- which domains to connect
- what email to route through JoltMx
- which aliases, recipients, and forwarding rules to configure
- where messages are forwarded
- whether messages are stored, quarantined, rejected, or deleted
- how long messages are retained
- which integrations are enabled
- what automation, filtering, and routing rules apply
JoltMx processes customer email data on behalf of the customer and in accordance with the customer’s configuration, our agreement with the customer, this Privacy Policy, our Terms, and applicable law.
JoltMx acts as a data controller only for data we process for our own business and platform purposes, including:
Controller activities
- account registration
- billing
- authentication
- fraud prevention
- platform security
- abuse prevention
Operational and business activities
- service analytics
- product improvement
- customer support
- legal compliance
- operational records
- business administration
2. Information we collect
We may collect and process the following categories of information.
Account information
- name
- email address
- login details
- company or organisation name
- billing details
- VAT or tax information
- account preferences
- domain names added to your account
- plan, subscription, and usage information
- support requests and communication history
Domain and configuration data
- domains connected to JoltMx
- DNS and MX configuration state
- forwarding rules
- aliases and catch-all settings
- routing rules
- webhooks and integration settings
- destination addresses
- authentication settings
- retention settings
- spam, security, and filtering preferences
- API keys, tokens, or credentials you provide for integrations
Customer email data
Depending on customer configuration, we may process:
- sender addresses
- recipient addresses
- envelope data
- message headers
- subject lines
- message bodies
- attachments
- authentication results such as SPF, DKIM, DMARC, ARC, TLS, PTR, and HELO information
- spam and abuse scores
- delivery status
- routing decisions
- forwarding attempts
- bounce, deferral, and rejection information
- message IDs and internal trace IDs
- diagnostic timelines
- message metadata
- raw message content where required for storage, forwarding, resend, search, quarantine, debugging, or related features
JoltMx is an email routing and processing service. We do not treat customer email content as public information, and we do not sell customer email content.
Technical and usage data
- IP addresses
- device and browser information
- operating system
- approximate location derived from IP address
- log-in times
- API usage
- request and response metadata
- error logs
- diagnostic events
- system telemetry
- performance data
- security events
- rate-limit events
- SMTP connection data
- traffic patterns
- feature usage
- pages viewed within the JoltMx dashboard
Payment information
Payments may be processed by third-party payment providers such as Stripe. We do not intentionally store full payment card numbers on our own systems.
Support and communication data
When you contact us, we may collect:
- your name and contact details
- the content of your messages
- support tickets
- screenshots or logs you provide
- information needed to investigate issues
- any other information you choose to send us
3. How we collect information
We may collect information:
- directly from you when you create an account, configure domains, use the dashboard, contact support, or pay for the service
- automatically when you use our website, API, SMTP endpoints, dashboard, or integrations
- from DNS, mail servers, receiving systems, sending systems, blocklists, security services, and email authentication systems
- from third-party services you connect to JoltMx
- from payment processors, analytics providers, infrastructure providers, and support tools
- from logs, monitoring systems, and security systems
- from publicly available sources where relevant to DNS, domain ownership, abuse prevention, deliverability, or security
4. How we use information
Service delivery and operations
- provide, operate, maintain, and improve JoltMx
- route, forward, store, inspect, quarantine, reject, or deliver email
- apply customer-configured rules
- authenticate users
- manage domains and DNS-related checks
- provide diagnostics, logs, and message timelines
- troubleshoot delivery issues
- process payments and manage subscriptions
- provide customer support
Security, communications, and improvement
- detect spam, malware, phishing, fraud, abuse, and unauthorised use
- enforce rate limits and usage limits
- send service announcements, security notices, invoices, and transactional emails
- send product updates or marketing communications where permitted
- develop new features, products, and services
- monitor service performance and reliability
- train, test, and improve internal systems, classifiers, rules, heuristics, and operational tooling
- generate aggregated or anonymised analytics
- comply with legal obligations
- enforce our terms and acceptable use policies
- protect JoltMx, our users, recipients, third parties, and the wider email ecosystem
5. Email scanning, filtering, and automation
As part of providing the service, JoltMx may inspect email metadata, headers, authentication results, content, and attachments for purposes including routing, forwarding, spam detection, malware detection, phishing detection, abuse prevention, policy enforcement, classification, summarisation, user-configured automation, webhooks and integrations, diagnostics, deliverability analysis, customer support, and service reliability and maintenance.
Where we provide AI-assisted or automated features, we may process customer email data through internal systems or trusted third-party providers. We will use reasonable safeguards when doing so.
Customers should not use JoltMx to process highly sensitive information unless they are satisfied that their configuration, retention settings, security controls, onward destinations, and legal basis are appropriate.
6. Legal bases for processing
Where UK GDPR, EU GDPR, or similar laws apply, we rely on one or more of the following legal bases:
- Contract: to provide the services you request.
- Legitimate interests: to operate, secure, improve, and promote JoltMx, prevent abuse, debug issues, and protect our business.
- Consent: where required, such as for certain marketing or optional features.
- Legal obligation: where we must comply with law, regulation, court orders, tax rules, accounting duties, or lawful requests.
- Vital or public interest: where relevant to preventing serious harm, fraud, abuse, or security incidents.
Where JoltMx acts as a processor for customer email data, the customer is responsible for identifying and maintaining the lawful basis for processing that data.
7. Customer responsibilities
If you use JoltMx to process email for your domain, you are the data controller for the personal data contained in that customer email traffic.
You are responsible for ensuring that you have a lawful basis to route, process, inspect, store, forward, reject, quarantine, automate, and otherwise handle email through JoltMx.
You are also responsible for:
- telling your users, employees, customers, correspondents, and other relevant people how their data is processed
- choosing appropriate retention settings
- configuring forwarding, routing, filtering, storage, and integration rules lawfully
- deciding whether email content, metadata, attachments, or logs should be retained
- responding to data subject requests where you are the controller
- ensuring that connected mailboxes, webhooks, queues, CRMs, helpdesks, automation platforms, and other destination services are suitable for the data you send to them
- protecting account credentials, API keys, destination mailboxes, and integration endpoints
- ensuring that your use of JoltMx complies with applicable laws, contracts, policies, and industry rules
If we receive a privacy request relating to customer email data, we may direct the requester to the relevant customer, domain owner, account holder, or other appropriate controller.
8. Customer email data and data subject requests
JoltMx does not decide who sends email to a customer domain, who receives email, what the email says, which recipients are configured, which forwarding rules are created, or which integrations a customer enables. Those decisions are made by the customer.
Requests relating to personal data contained in customer email traffic should be directed to the relevant JoltMx customer, domain owner, organisation, or account holder.
Where JoltMx acts as a processor, we may not be able to respond directly to requests for access, deletion, correction, restriction, objection, or portability relating to customer email data. In those cases, we may refer the requester to the relevant controller or ask for further information.
10. Integrations and onward delivery
If you configure JoltMx to forward email to another mailbox, webhook, queue, CRM, automation platform, or third-party system, you instruct us to send relevant email data to that destination.
Those third-party systems may process the data under their own terms and privacy policies. JoltMx is not responsible for how a destination service handles data after we deliver it according to your configuration.
You are responsible for making sure your chosen destination services are appropriate for the email data you send to them.
11. Sub-processors and service providers
We may use third-party service providers to operate JoltMx, including providers for cloud hosting, object storage, databases, DNS services, email delivery, spam and abuse detection, payment processing, analytics, monitoring and logging, customer support, error tracking, communications, identity and authentication, project management, security tooling, and AI-assisted classification, summarisation, or automation features.
Current or likely providers may include: Cloudflare, IONOS, Stripe, Grafana, Sentry, OpenAI, and other infrastructure, monitoring, payment, security, AI, or support providers.
12. International transfers
We may process and store information in the United Kingdom, European Economic Area, United States, and other countries where we or our providers operate.
Where required, we use appropriate safeguards for international transfers, such as adequacy regulations, standard contractual clauses, contractual commitments, technical controls, or other lawful transfer mechanisms.
13. Retention
We keep information for as long as reasonably necessary for the purposes described in this policy.
Retention periods may vary depending on:
- your account settings
- your subscription plan
- message retention configuration
- diagnostic requirements
- security and abuse-prevention needs
- backup cycles
- legal, accounting, or tax obligations
- disputes, investigations, or enforcement
- product and operational requirements
Customer email content and message metadata may be retained according to the retention settings available in your account, unless we need to retain it for longer to provide, secure, support, troubleshoot, maintain, or comply with applicable law.
Deletion from active systems may not immediately remove information from backups, logs, caches, analytics systems, or disaster recovery systems, although such data will usually age out over time.
14. Security
We use technical and organisational measures intended to protect information against unauthorised access, loss, misuse, alteration, or disclosure, including:
- encryption in transit
- encryption at rest where appropriate
- access controls
- authentication
- logging and monitoring
- network segmentation
- rate limiting
- abuse detection
- operational security controls
- backup and recovery processes
- least-privilege access where practical
No internet-connected service can be guaranteed to be completely secure. You are responsible for keeping your own credentials, domains, DNS settings, destination mailboxes, API keys, and integration endpoints secure.
16. Marketing communications
We may send you service emails, security notices, billing notices, product updates, onboarding messages, and other communications related to your use of JoltMx.
We may also send marketing communications where permitted by law. You can opt out of marketing emails using the unsubscribe link or by contacting us.
Even if you opt out of marketing, we may still send you important service, security, billing, legal, or account-related messages.
17. Your rights
Depending on where you live, you may have rights to:
- access your personal data
- correct inaccurate data
- delete data
- restrict processing
- object to processing
- receive a copy of your data
- withdraw consent
- object to direct marketing
- complain to a data protection authority
These rights may be limited by law, security requirements, our role as processor, the rights of others, or our need to retain information for legitimate purposes.
How to make a rights request
To exercise rights relating to your JoltMx account, contact us at privacy@joltmx.com.
For requests relating to email content, attachments, message metadata, routing records, or other customer email data, you should contact the relevant domain owner, organisation, account holder, or other controller.
Where we act as a processor, we may refer your request to the relevant controller or ask you to contact them directly.
We may need to verify your identity before responding to a request.
18. Data exports
Where technically reasonable, we may provide account holders with tools to export data relating to their own account, domains, configuration, message metadata, stored messages, logs, and other information.
Exports may be subject to security checks, plan limits, retention settings, technical constraints, and legal restrictions.
Account holders are responsible for handling exported data securely and lawfully.
19. Children
JoltMx is not intended for children. You must be at least 18 years old, or the age of majority in your jurisdiction, to use the service.
We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will take appropriate steps.
20. Abuse, security, and legal disclosure
We may access, preserve, use, or disclose information where we reasonably believe it is necessary to:
- comply with law
- respond to lawful requests
- protect JoltMx
- protect customers, recipients, or third parties
- investigate spam, phishing, malware, fraud, harassment, or abuse
- enforce our terms
- debug serious technical issues
- prevent harm
- maintain the security and reliability of the service
This may include reviewing account data, customer email data, message metadata, logs, routing behaviour, email content, attachments, IP addresses, and related technical data where necessary.
21. Business transfers
If JoltMx, Ninvoice Limited, or any part of our business is involved in a merger, acquisition, financing, restructuring, sale, insolvency process, or transfer of assets, information may be disclosed or transferred as part of that transaction.
Any successor may continue to process information according to this policy unless you are notified otherwise.
22. Changes to this policy
We may update this Privacy Policy from time to time.
If we make material changes, we may notify you by email, through the dashboard, or by posting an updated version on our website.
Your continued use of JoltMx after changes take effect means you accept the updated policy.
23. Contact
For privacy questions, requests, or complaints, contact:
Contact details
Ninvoice Limited trading as JoltMxEmail: privacy@joltmx.com
3rd Floor, 86-90 Paul Street
London
EC2A 4NE
United Kingdom
You may also have the right to complain to your local data protection authority. In the UK, this is the Information Commissioner’s Office.