Privacy Policy
Last updated: 2026-06-04
1. Introduction
1.1. Overview
This Privacy Policy describes how Demi Solutions OÜ ("we", "us", or the "Company"), located at Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia, collects, uses and discloses information about you when you use DemiSignal at demisignal.com and the services, features and content we offer (the "Services"). Demi Solutions OÜ is the data controller for the personal data described here.
1.2. Information Sources
We receive information about you: (i) when you register for an account; (ii) when you use the Services; and (iii) automatically from your device and browser as you interact with the Services.
1.3. Consent and Legal Bases
We process personal data only where we have a legal basis to do so (see Section 9.4). Where the law requires prior opt-in for non-essential cookies — for example in the EU/EEA — we ask for your consent through a cookie banner before setting them, and you may withdraw it at any time (see Sections 4 and 10). Where prior opt-in is not required — for example in the United States — we set the limited first-party functional cookie described in this policy on a disclosed basis, without a banner. Using the Services does not, by itself, constitute consent to non-essential tracking where consent is required.
1.4. International Processing and Transfers
We are based in Estonia (EU). Your information may be processed by us or by our service providers in countries outside the European Economic Area. Where that happens, we rely on an adequacy decision or on EU Standard Contractual Clauses to safeguard the transfer. See Section 5.5 for the categories of service providers involved.
2. Scope of This Privacy Policy
This Privacy Policy covers our treatment of information gathered when you use or access the Services. It does not apply to third-party websites or services we do not own or control, including any sites you reach through the Services. We encourage you to review the privacy policies of those third parties.
3. Information We Collect and How We Use It
3.1. Account Information
When you create an account we collect personal information such as your name and email address. If you register or sign in using a third-party login — Google or Microsoft — we receive your name and email address from that provider, according to your settings with them, so we can create and secure your account. We use your contact information to operate your account and to send you service-related messages. You can manage marketing messages from your account settings.
Children: Our Services are not directed to children. Under Estonian law the digital age of consent is 13; we do not knowingly collect personal data from children under that age, and we will delete such data if we learn we have collected it.
3.2. Domain Scans
A core feature of DemiSignal is scanning the email-authentication setup of domains you submit. When you run a scan we collect and store the domain name you submit and the public DNS records we retrieve for it — including your SPF, DKIM, DMARC and MX records and domain-blacklist status. For each record we store the raw value returned by DNS, our parsed interpretation of it, and any configuration issues we detect, together with an overall health score, an issue count, and the time each scan started and completed. When you are signed in, this information is associated with your account, workspace and the domain (project) it belongs to. The DNS records we collect are published by you (or your DNS provider) in the public Domain Name System; we retrieve them the same way any receiving mail server would.
3.3. Monitoring and Alerts
If you enable monitoring for a domain, we store your monitoring configuration — such as how often we re-scan the domain, whether alerts are enabled, and any additional recipient email addresses you choose to notify — and we re-run scans automatically on that schedule. When a scan detects a new or critical issue, a drop in your health score, or a failed scan, we generate an alert record (its type, a summary message, and related context) and may email it to the address associated with your account or workspace and to any additional recipients you have configured for that domain.
3.4. Free Domain Checker
You can use our free public domain checker without an account. When you do, we receive the domain name you submit and run the same email-authentication checks described above. Your report stays accessible through a verifiable shareable link that regenerates the report on demand rather than storing it. To unlock the full report we ask for your email address, which we use to deliver the report and may use to follow up with you about DemiSignal. When you provide your email to unlock a report, that email and the domain are recorded in our application logs; a failed scan may also record the domain.
3.8. First-Party Usage Analytics
To understand how the Services are used and to improve them, we record page views on our own servers. For each page view we may store the page URL and path, the referring page, any campaign (UTM) parameters in the URL, a coarse device type (desktop, mobile or tablet) inferred from your browser, your IP address, your browser user-agent, the time of the view, and — if you are signed in — your account identifier. We do not sell this data or share it with advertising networks. Legal basis: our legitimate interest in measuring and improving the Services (Section 9.4).
3.9. Affiliate / Referral Tracking
We operate an affiliate (referral) program. When you arrive through an affiliate link — a URL containing a
?ref= parameter (and optionally ?subid=) — we record a referral visit and set a single first-party cookie
(app_visitor) holding a randomly-generated, per-browser identifier. For each visit we store on our servers:
the affiliate referral code and sub-identifier; that visitor identifier; your IP address; the full URL you
landed on; the referring website, if any; and the date and time. The referral code itself is not stored in a
cookie — only the visitor identifier is. Where prior cookie consent is required (see Section 10), we record
nothing until you accept.
Referral visits start out tied only to that per-browser identifier, not to your name. If you later create an
account after arriving through an affiliate link, we link those earlier visits — including the IP addresses and
URLs captured at the time — to your account so we can attribute the referral and calculate affiliate
commissions. Because of this linkage we treat referral-visit data as personal data. We reconstruct the referring
affiliate on our own servers from the most recent affiliate visit tied to your app_visitor identifier (a
"last-touch" model); the referral source is not stored in the cookie. The app_visitor cookie lasts 30 days —
that is the window during which a later sign-up can be matched to an earlier affiliate visit — while the
underlying visit records are retained for the longer period described in Section 9.3 for commission calculation
and auditing. Legal basis: our legitimate interest in operating and auditing the affiliate program; where prior
cookie consent is required (see Section 10), we also rely on your consent for the app_visitor cookie (see
above).
4. Cookies
Cookies are small pieces of text stored by your browser. We keep our cookie use minimal:
| Cookie | Purpose | Essential? | Lifetime |
|---|---|---|---|
| Session cookie | Keeps you signed in and protects against request forgery. | Yes (always set) | 7 days |
app_visitor |
Per-browser identifier that links your affiliate referral visits and, if you register, ties them to your account for referral attribution. Set only when you arrive via an affiliate (?ref=) link. |
Functional | 30 days |
app_cookie_consent |
Remembers your cookie choice. Only used where we show a consent banner (see Section 10). | Functional | 1 year |
We do not use advertising or third-party tracking cookies. Strictly-necessary cookies are always set. The
app_visitor cookie is a first-party functional cookie; where the law requires prior consent (Section 10) it
is set only after you accept. You can delete cookies at any time through your browser; blocking strictly-necessary
cookies will break core features.
5. Information Sharing
5.1. What Is Not Public
Your account, the data you create in the Services, and your usage and referral information are private to your account by default and are not published or made publicly browsable by us.
5.2. IP Addresses
We store IP addresses (for example on referral visits and request logs) for security, fraud prevention and affiliate attribution. We retain them in raw form on our own servers; we do not currently hash them and we do not share raw IP addresses with third parties for their own purposes.
5.3. Service Providers
We share information with service providers who perform tasks on our behalf and under our instructions, only as needed to provide the Services. They may not use it for any other purpose.
5.4. Business Transfers
If we are involved in a merger, acquisition or sale of assets, your information may be transferred as part of that transaction; the recipient will remain bound by this Privacy Policy or provide equivalent protection.
5.5. Categories of Service Providers (Sub-Processors)
We use service providers in categories including: cloud hosting and infrastructure; authentication (Google, Microsoft); transactional email delivery; backup storage; and payment processing. We can provide the current list of named sub-processors on request.
5.6. Legal and Protection
We may access, preserve and disclose information where we reasonably believe it is necessary to comply with law or legal process, to enforce our terms, to detect or prevent fraud or security issues, or to protect the rights, property or safety of the Company, our users and the public.
5.7. With Your Consent
We share information as you direct, such as when you choose to share content through a third-party service.
6. Information Protection
Your account is protected by a password; keep it confidential. We use industry-standard security measures to protect personal data, but no method of transmission or storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you as required by applicable law.
7. Your Choices
You can use parts of the Services without an account, which limits the information collected about you. If you have an account, you can access and update your information from your account settings, and you can delete your account at any time. When you delete your account we anonymize the email address on your account, disconnect any linked sign-in providers, and erase the referral-visit data (IP addresses and URLs) linked to you. We may retain limited records where we have a legal obligation or a legitimate need to do so (for example, commission and billing records), as described in Section 9.3.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes to how we collect or use personal data, we will notify you by posting a notice in the Services or by email, and we will indicate when the changes take effect.
9. Your Rights and Data Retention
9.1. Your Rights
Depending on your location, you have rights over your personal data, which may include:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your personal data
- Restriction — request that we limit how we process your data
- Portability — receive your data in a machine-readable format
- Objection — object to certain processing
- Withdraw consent — withdraw consent at any time, without affecting prior processing
9.2. Exercising Your Rights and Complaints
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or with your local EU supervisory authority.
9.3. Data Retention
We keep personal data only as long as necessary for the purposes described here:
- Account data — while your account is active; your sign-in email is anonymized on deletion
- Affiliate referral-visit logs (IP, URL, referrer, visitor id) — up to 13 months from the visit, then deleted
- Affiliate referral and commission records — for the life of the referral relationship plus the period required for commission and financial-record obligations
- First-party usage analytics — retained for a limited period and then deleted or aggregated
- Marketing communications — until you unsubscribe
9.4. Legal Basis for Processing (GDPR)
- Contract — processing necessary to provide the Services to you
- Consent — where you have given specific consent, such as for non-essential cookies
- Legitimate interests — for security, fraud prevention, affiliate attribution and product improvement, balanced against your rights
- Legal obligation — where the law requires it
10. Cookie Consent
Strictly-necessary cookies are always active. Where the law requires prior opt-in for non-essential cookies
(for example, in the EU/EEA), we show a cookie banner and set the affiliate app_visitor cookie — and record
the referral visit in Section 3.9 — only after you choose "Accept all"; if you choose "Essential only" or ignore
the banner, neither is set. Where prior opt-in is not required (for example, in the United States), the
app_visitor cookie is a first-party functional cookie set with the disclosure in this policy. In all cases you
can delete the cookie through your browser at any time.
11. Questions or Concerns
If you have any questions or concerns about privacy, contact us at [email protected].
Company Details: Demi Solutions OÜ Sepapaja tn 6 15551 Tallinn Harju maakond Estonia