Legal & Compliance

Privacy Policy

Last updated: August 2026 • Solidrix Technologies

1. Information We Collect

Solidrix Technologies ("Solidrix Send", "we", "our") collects the following types of information:

  • Account Information: Name, email address, company name, and password (hashed) when you register for a Solidrix Send account.
  • Email Routing Telemetry: Gateway response codes, delivery timestamps, bounce metrics, open and click events — necessary to provide our email routing and failover services.
  • Contact Form Submissions: When you use our contact page, we collect your first name, last name, email address, phone number (optional), company name (optional), subject, and message content. We also record your IP address and browser user-agent for spam prevention purposes.
  • Newsletter Opt-in: If you subscribe to our newsletter via the contact form or footer, we store your email address for that purpose only.
  • Technical Metadata: Log data including IP addresses, HTTP headers, and request timestamps when you interact with our API, SMTP proxy, or dashboard.

2. How We Use Your Data

  • To operate and deliver our email gateway routing, multi-gateway failover, and Virtual SMTP Proxy services.
  • To calculate and enforce plan quotas (e.g., 500 emails/day on Free plans) using atomic Redis counters.
  • To respond to contact form inquiries submitted via send.solidrix.com/contact.
  • To detect and prevent abuse, spam, and fraudulent submissions (see Section 4).
  • To send transactional alerts (quota warnings, gateway failure notifications) to registered users.
  • To send newsletters to users who have explicitly opted in. You may unsubscribe at any time.
  • To generate anonymised, aggregated analytics about platform usage and delivery performance.

We never sell, rent, or share your personal data or email payload contents with third parties for marketing purposes.

3. Data Security & Encryption

  • At Rest: All API keys, gateway SMTP credentials, and sensitive configuration values are stored in encrypted format using AES-256.
  • In Transit: All traffic between your application and our Virtual SMTP Proxy (:587) and REST API endpoints is protected via TLS 1.3.
  • API Key Security: API keys are hashed and support IP whitelisting and per-key rate limits. Keys can be revoked at any time from the dashboard.
  • Password Security: User passwords are hashed using bcrypt with a salt factor of 12 and are never stored in plaintext.
  • Infrastructure: Our servers are hosted on secured VPS infrastructure with firewall rules, SSH key-only access, and regular security patches.

4. Spam Protection & Abuse Prevention

To protect our platform and users from abuse, we apply the following automated security measures on public-facing forms:

  • Honeypot Fields: A hidden invisible form field is present on our contact form. Automated bots that fill this field are silently blocked.
  • Rate Limiting: We limit contact form submissions to 3 per IP address per 10-minute window. Submissions exceeding this threshold are rejected.
  • DNS Email Validation: Submitted email addresses are validated against DNS records to reject fake or non-existent domains.
  • Duplicate Submission Guard: Repeated submissions from the same email address within a 5-minute window are rejected to prevent flooding.
  • Spam Keyword Filtering: Messages containing known spam keywords, affiliate links, or third-party URLs are automatically flagged and blocked.
  • Hot Leads Log: All blocked submissions (regardless of block reason) are written to a secure internal log file (hot_leads.log) for audit and false-positive review. This log is not publicly accessible and is rotated every 30 days.

IP addresses collected for spam prevention are stored only in internal logs and are not associated with valid submissions in our main database, unless mandated by applicable law.

5. Data Retention

  • Contact form submissions are retained for 2 years from the date of submission, after which they are permanently deleted.
  • Email delivery logs (telemetry) are retained for 90 days rolling, after which individual records are purged.
  • Spam / hot-lead logs are retained for 30 days and automatically rotated.
  • Account data is retained while your account is active. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.

6. Cookies

We use session cookies required for authentication and CSRF protection. We do not use third-party advertising or tracking cookies. For full details, see our Cookie Policy.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Ask us to correct inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten").
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to certain processing activities, including newsletter communications.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

8. Third-Party Services

Solidrix Send integrates with third-party email delivery providers (AWS SES, Mailgun, Postmark, Resend, Brevo, SendGrid) to route your emails. Your email content is passed to these providers solely for delivery purposes, subject to their own privacy policies. We do not grant these providers rights to use your data for their own marketing.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Significant changes will be communicated to registered users via email. Continued use of Solidrix Send after changes constitutes acceptance of the updated policy.

10. Contact Us

For questions regarding our privacy practices, data compliance, or to exercise your rights, please contact:

Solidrix Technologies

Lakhimpur, Uttar Pradesh, 262701

Email: [email protected]

Phone: +91 98116 55457

→ Use our contact form