Privacy Policy
Last updated: 2026-07-21
Data controller
grimdmarc.com is operated by Grim & Strössel, based in Sweden. For any question about this policy or about personal data we hold, contact hello@grimdmarc.com.
What we collect
We only collect data tied to a specific action you take on the site — there is no visitor tracking beyond the analytics described below.
- Domain scans. When you run the Domain Scanner, SPF Analyzer, DMARC Analyzer or BIMI Analyzer, we log the domain you searched, the result shown to you, and the IP address the request came from. This is used to keep the tools reliable and to investigate abuse (for example, automated or excessive querying).
- Detailed reports. If you click "Send detailed report" on a scan result and enter your email address, we store that email together with the scan it relates to, in order to send you the report.
- Early access signups. If you sign up for early access to a hosted product, we store your email address and which page you signed up from.
- Contact form. If you submit the contact form, we store your name, email address and message, and use them to reply to you.
Cookies and analytics
We use Google Tag Manager to measure basic site usage, such as page views and which tools are used. This only runs after you accept it via the cookie banner shown on your first visit — no analytics cookies are set before that. You can change your choice at any time using "Cookie Settings" in the footer.
The site is hosted on Cloudflare, which sees the IP address of every request as part of normal web hosting and applies rate limiting to protect the site from abuse; this happens at the infrastructure level and isn't something we configure per visitor.
Legal basis and retention
We process scan logs and abuse-prevention data on the basis of our legitimate interest in keeping the tools available and free from abuse. We process report requests, early-access signups and contact submissions on the basis of your consent, given by submitting the relevant form.
We keep this data only as long as it serves the purpose it was collected for, and delete or anonymize it once it's no longer needed.
Who we share data with
We use a small number of processors to run the site and platform: Cloudflare (hosting, DNS and abuse protection), Amazon Web Services (DNS hosting, certificate issuance and content delivery for hosted MTA-STS/DMARC/TLS-RPT/BIMI records), SMTP2GO (sending report and contact-notification emails) and Google (Tag Manager / Analytics, only after consent). We don't sell personal data, and we don't share it with anyone beyond what's needed to operate these services.
Security
Security controls are designed in alignment with ISO/IEC 27001 principles.
Your rights
Under the GDPR, you can ask us to access, correct or delete personal data we hold about you, or object to how we process it. Send such a request to hello@grimdmarc.com and we'll respond as required by law. You also have the right to lodge a complaint with your local data protection authority — in Sweden, the Integritetsskyddsmyndigheten (IMY).