Privacy
Postnaro
Privacy policy for Postnaro
Information on the processing of personal data when using Postnaro.
Last updated: July 2026
1. Controller
This privacy policy explains how personal data is processed when you use postnaro.com, the Postnaro customer account, the digital mailbox, public profiles, contact forms, short links and the mail and location services offered. It applies exclusively to Postnaro.
The legal controller of the central Postnaro platform and of personal data processing in connection with postnaro.com and central Postnaro services is:
- Company
- MIOSMEDIA ONLINE S.L.U
- Address
- Diseminado Polígono 4, Parcela 91, 07530 Sant Llorenç des Cardassar, Illes Balears, Spanien
- support@postnaro.com
- Phone
- +49 (0) 5975 / 900 99 84 · +34 871 24 20 71
- VAT ID
- ESB72701436
2. Roles for own and partner locations
For processing linked to a booked Postnaro location, the location-specific privacy information also applies. The location operator named in the contract confirmation is controller for its local services. MIOSMEDIA ONLINE S.L.U. operates the central Postnaro platform and may act as processor for defined technical processes.
3. Visiting the website
When you visit postnaro.com, Cloudflare processes technical data such as IP address, timestamps, user agent and request metadata for secure delivery. Legal basis: Art. 6(1)(f) GDPR.
4. Customer account and authentication
We use Supabase for registration, login, authentication, database and private storage. Supabase project region: eu-west-1 (Ireland, EU). Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR for security.
5. Identity verification
Where required, identity checks run via Stripe Identity (documents and verification results). Legal basis: Art. 6(1)(b) and, where legally required, (c) GDPR; consent under (a) where needed for the specific check.
6. Booking, contract and payment
Contract, billing and payment data are processed via Stripe. We do not store full card numbers. Legal basis: Art. 6(1)(b) and (c) GDPR for statutory retention.
Digital Postnaro features
This section and the following sections on the digital mailbox, profiles, contact forms, short links, statistics, support and security describe personal data processing for Postnaro’s digital platform features. Controller of the central platform: MIOSMEDIA ONLINE S.L.U, Diseminado Polígono 4, Parcela 91, 07530 Sant Llorenç des Cardassar, Illes Balears, Spanien, email: support@postnaro.com.
7. Digital mailbox
The digital mailbox stores metadata and — depending on the booked service — digitised mail content. Access is role-based. Legal basis: Art. 6(1)(b) GDPR.
8. Mail acceptance and intake logging
For mail acceptance we process shipment data needed for intake, account assignment and status display. Local acceptance is performed by the location operator. Legal basis: Art. 6(1)(b) GDPR.
9. Opening and digitising letters
Opening and scanning occur only where you booked the service and provided the required authorisations or consent. Digitised letter contents are stored long-term in a European storage region. Legal basis: Art. 6(1)(b) and, where required, (a) GDPR.
10. Retention and forwarding
For storage, destruction and physical forwarding we process the address, order and shipment data needed to fulfil your instructions. Legal basis: Art. 6(1)(b) and, where applicable, (c) GDPR.
11. Public profiles and micro-sites
For public profiles and micro-sites we process the content and settings you provide. Legal basis: Art. 6(1)(b) GDPR; optional third-party embeds may require Art. 6(1)(a) GDPR.
12. Contact forms and messages
Contact-form messages (sender details and content) are usually stored for 180 days in the dashboard unless deleted or exported earlier. A contact request is not newsletter consent. Legal basis: Art. 6(1)(b) GDPR.
13. Short links, QR codes and domains
We process target URLs, configuration and technical security/access data to provide short links, QR codes and domains and to prevent abuse. Legal basis: Art. 6(1)(b) and (f) GDPR.
14. Click and usage statistics
Raw click/analytics events are kept for at most 90 days; aggregated statistics for the contract term plus 12 months. Legal basis: Art. 6(1)(b) and (f) GDPR; non-essential tracking only with Art. 6(1)(a) GDPR.
15. Support and contract communication
We process support requests, contact details and transactional messages. Contact: support@postnaro.com. Legal basis: Art. 6(1)(b) GDPR; optional marketing only with Art. 6(1)(a) GDPR.
16. Security and abuse prevention
We process technical logs and security events for IT security, fraud and abuse prevention. Security logs: typically 90 days; closed moderation records: up to 24 months. Legal basis: Art. 6(1)(f) and, where required, (c) GDPR.
18. Processors and recipients
Active service providers for central platform functions currently include:
- Supabase (Datenbank, Authentifizierung, Objektspeicher): Kundenkonto, Profildaten, Dateien, Authentifizierung. Datenkategorien: Kontodaten, Profildaten, Uploads, Authentifizierungsdaten. Regionen: EU (eu-west-1) und ggf. unterstützende Infrastruktur. Rolle: Auftragsverarbeiter.
- Cloudflare (DNS, CDN, Sicherheit, Workers): Auslieferung, Schutz und technische Verarbeitung der Website/App. Datenkategorien: IP-Adressen, technische Logs, Request-Metadaten. Regionen: global verteilte Edge-Infrastruktur. Rolle: Auftragsverarbeiter.
- Stripe (Zahlungen und Stripe Identity): Abrechnung, Mandatsverwaltung, Identitätsprüfung. Datenkategorien: Zahlungsdaten, Rechnungsdaten, Identitätsprüfergebnisse. Regionen: EU und ggf. weitere Stripe-Regionen. Rolle: eigenständiger Verantwortlicher / Auftragsverarbeiter je Verarbeitung.
Only providers that actively process personal data are listed. Where required, we conclude Art. 28 GDPR processing agreements.
19. Third-country transfers
Some providers may process data outside the EEA based on an adequacy decision, Standard Contractual Clauses or other GDPR-compliant safeguards. Long-term stored mail and contract documents are kept in the European storage region configured for Postnaro.
20. Retention
We retain personal data only as long as needed for the processing purposes or legal duties. In particular:
- Customer account and contract data: for the term of the contract
- Data export after contract end: 30 days
- Active profiles and uploaded content: deleted no later than 30 days after the export phase ends
- Contact-form messages in the dashboard: 180 days, unless deleted or exported earlier
- Technical security and access logs: 90 days
- Raw click and analytics events: at most 90 days
- Aggregated statistics: during the contract term and 12 months thereafter
- Closed moderation and abuse cases: 24 months
- Identity-verification status and required evidence: contract term plus 12 months, unless a longer legal duty applies
- Letter scans and original-mail information: according to the booked plan, customer instructions and Postnaro retention terms
- Backups of deleted data: removed within the backup cycle of at most 30 days
- Invoices and payment records: according to statutory retention duties
21. Data-subject rights
Subject to legal requirements, you have rights of access, rectification, erasure, restriction and data portability. Contact: support@postnaro.com.
22. Withdrawal of consent
Where processing is based on consent (Art. 6(1)(a) GDPR), you may withdraw it at any time with effect for the future. Contact: support@postnaro.com.
23. Right to object
You may object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation. Contact: support@postnaro.com.
24. Right to lodge a complaint
You may lodge a complaint with a supervisory authority, in Spain including the Agencia Española de Protección de Datos (AEPD), or with the authority at your habitual residence or place of work.
25. Changes to this privacy policy
We may update this privacy policy when services, law or technologies change. The current version is always available on this page.