Privacy Policy
Last updated: September 24, 2026
This policy explains what personal information Duva collects, why, who has access to it, how long we keep it and how to exercise your rights. It is written to comply with the Québec Act respecting the protection of personal information in the private sector ("Law 25") and PIPEDA.
The French version is the authoritative one.
1. Who is responsible
Duva is operated by 9573-4562 Québec inc. (Québec business number NEQ 1182434036, 302 de l'Éboulis, Rimouski, QC G5L 7Z2) ("Duva", "we", "us").
The person in charge of the protection of personal information is the person with the highest authority in the company. For any question, request or complaint about your personal information, write to them at [email protected], with "Privacy" as the subject.
2. Two situations to tell apart
Our customers, their teams and the visitors of our sites. We decide why and how their information is used: we are responsible for it, and this policy applies directly.
The recipients of emails sent by our customers. Our customers choose the recipients, the content and the reasons for writing. We process this information on their behalf, only to provide the service; the customer is responsible for having collected it lawfully and for having obtained the necessary consents.
If you received an email sent by Duva on behalf of a customer and want to access your information, have it corrected or stop being contacted, first contact the sender, whose name appears in the email. You may also write to us: we will forward your request to the customer, and we will stop sending to your address at their request or yours.
3. The information we collect
Customers and their team members
- Account: email address, role, language, time zone, organization name, domains, webhook addresses. API keys are kept only as an irreversible fingerprint: we cannot read them back.
- Sign-in and security: password (kept as a fingerprint), second-factor secret (encrypted), recovery codes (as fingerprints), sign-in dates. For each session: IP address and browser type. The audit log records who performed which sensitive action, when and from which IP address.
- Billing: plan, subscription status, billing period and the customer and subscription identifiers at Stripe. We never receive your card number: it is entered at Stripe.
- Communications: the messages you write to us.
- Support tickets: the subject, category, domain concerned and messages you write to our team on the “Support” screen, with our replies and internal notes. Our staff read them in order to answer you. Never write an API key, a password or a private key in a ticket: we never ask you for them.
- Go-live request: what you declare on the “Go live” screen — how you will use Duva, the types of email you send, the expected monthly volume, where your recipients' addresses come from and, if you give it, your website address. Our staff read it to assess the request.
Sending (information about our customers' recipients)
- For each message: sender address, recipient addresses (and their name, if provided), subject, tags and metadata added by the customer, date, status of each recipient, events (delivered, bounced, complaint, deferred) and the technical response of the recipient's server.
- Content: text, HTML and attachments are kept for only 30 days, then deleted.
- Suppression lists: addresses that bounced permanently, complained or were suppressed by the customer.
- DMARC reports: only if the customer publishes Duva's report address in their DMARC record. We then receive the aggregate reports sent by email providers: counters only (number of messages per sending IP address and authentication result), with no content and no recipient address.
- Open and click tracking: only if the customer had it enabled for their domain. We then record the fact and the time of the open or click, and nothing else about the visitor.
Visitors of our sites
- The public site (duva.ca) sets no cookie. We measure its traffic with an anonymous, cookie-free analytics tool that we host ourselves: page viewed (without identifiers), referrer, language, type of device, browser and system, approximate country. The IP address is not kept and your browser's "Do Not Track" signal is respected.
- The dashboard sets a session cookie, needed to sign in, and a language cookie that lasts one hour. It uses the same anonymous statistics, scrubbed of any customer identifier or domain name before they are sent. If you tick “Remember this device” at the two-step verification, one more cookie (a random token, valid for 30 days) lets that browser skip the code; you can forget it at any time on the Account security page.
- Our servers record the IP address, the date and the requested page in technical logs, for security and diagnostics. For the SMTP gateway, they record the IP address, the sending domain and the outcome of each connection or message, never the content, the subject, the recipients' addresses or a password.
- Public forms (sign-up, forgotten password), when they are open, are protected by Cloudflare Turnstile, which may collect technical signals from your browser to tell a person from a bot.
4. Why we use it
- to provide the service: send emails, track their delivery, manage accounts and access;
- to keep the service secure, prevent and investigate abuse and protect the reputation of our sending addresses;
- to bill and manage subscriptions;
- to answer your requests and communicate with you about the service (for example about a change of terms or an incident);
- to meet our legal obligations;
- to understand how our sites are used, from anonymous statistics.
We do not sell any personal information, we show no advertising and we do no profiling. Some mechanisms are automatic (rate limits, suppression lists). If a suspension decision affects you, you may write to us to have it reviewed by a person.
5. Consent
For the purposes necessary to the service — opening and managing your account, billing, security and legal obligations — we process your information on that basis of necessity, without requiring separate consent. For any other purpose, we ask for your consent when we collect the information. You may withdraw a consent you gave at any time by writing to us; withdrawing consent necessary to the service may prevent us from providing it.
6. Who has access to the information
- Our staff, as far as their duties require. The internal console is separate from the dashboard, its access is limited and logged, and it shows neither the content of emails nor private signing keys.
- Our suppliers, who process information for us:
- OVHcloud: hosting of the servers in Beauharnois (Québec) and storage of encrypted backups in a Canadian data centre;
- Cloudflare: DNS, web traffic protection and delivery, anti-bot check (Turnstile);
- Stripe: payment and subscription management.
The detail of this processing, for your recipients' information, is set out in the data processing addendum.
- Recipients' mail servers, to which we hand the messages: this is inherent to sending an email.
- Mailbox providers, complaint-handling services or authorities, where the law allows or requires it, to investigate an abuse or comply with an order.
7. Information disclosed outside Québec
Our servers and backups are in Canada. Web traffic to our applications (site, dashboard, API) passes through Cloudflare's network, which protects the service against attacks and terminates TLS encryption before it reaches our servers: the content of your requests, including emails submitted through the API, therefore transits through Cloudflare's global network before arriving at our servers in Canada. Messages sent by SMTP (smtp.duva.ca) do not pass through Cloudflare: they reach us directly, encrypted with TLS. Some suppliers, including Stripe and Cloudflare, may also process information elsewhere, notably in the United States, and emails are delivered to recipients all over the world. We disclose only what is necessary, we choose suppliers that commit to protecting the information, and we carry out a privacy impact assessment when the law requires one.
8. How long we keep it
| Information | Retention |
|---|---|
| Email content and attachments | 30 days after sending |
| DMARC aggregate reports (counters) | 100 days |
| Information about sends (sender, recipients, subject, statuses and events) | 12 months after sending, or shortly after the 30-day grace period following account closure, whichever comes first |
| Account, team and settings | As long as the account exists; destroyed shortly after the 30-day grace period following closure, except what the law requires us to keep |
| Sign-in sessions | Until they expire or you sign out |
| Audit log | As long as needed for its purpose (security, evidence in a dispute, legal obligations), at most 5 years |
| Billing records | 6 years, as tax laws require |
| Backups | Up to 6 months; information that has been destroyed disappears from backups as they are renewed |
| Server technical logs | The time needed for security and diagnostics |
| Messages you write to us | The time needed to handle your request |
| Support tickets (messages, replies and internal notes) | 12 months after they are resolved; an unresolved ticket is kept until it is resolved; destroyed with the account shortly after the 30-day grace period following closure |
| Go-live request declaration | As long as the account exists; destroyed with the account shortly after the 30-day grace period following closure |
When we no longer need information, we destroy or anonymize it, unless the law requires us to keep it.
The owner of an account can close it from the account settings, or ask us to close it by writing to [email protected]: closure is final, and the account's data is then destroyed, except what the law requires us to keep.
9. How we protect it
- Connections to the service are encrypted (TLS).
- The second authentication factor is mandatory; passwords and API keys are kept only as fingerprints; sensitive secrets (signing keys, second-factor secrets) are encrypted.
- Each customer sees only their own data, which our tests verify.
- Off-site backups are encrypted.
- Our staff's access is limited to what is necessary and logged.
No system is infallible. We keep a register of confidentiality incidents and, when an incident presents a risk of serious injury, we notify the Commission d'accès à l'information du Québec, the people affected and, for their recipients' information, the customer concerned.
10. Your rights
You may, by writing to us at [email protected]:
- find out whether we hold information about you and access it;
- have inaccurate, incomplete or equivocal information corrected;
- withdraw your consent;
- obtain your information in a structured, commonly used technological format;
- ask that a decision affecting you be reviewed by a person.
We may ask you to prove your identity. We reply within 30 days; a refusal is reasoned and states your remedies. For the information of an email recipient, we refer you to the customer concerned when they are the one who controls it.
If you believe we are not respecting your rights, you may file a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca).
11. Minors
Duva is for businesses and professionals. We do not knowingly collect information about minors under 14; if you believe this has happened, write to us and we will delete it.
12. Changes to this policy
We may update this policy. The date of the last update appears at the top of the page; for a material change, we notify customers by email or in the dashboard.
13. Contact us
9573-4562 Québec inc. — 302 de l'Éboulis, Rimouski, QC G5L 7Z2 — [email protected]