Controls
- Identity verification with Stripe Identity
- Role-based access (customer, partner, admin)
- Encrypted transport (TLS/SSL)
- Private storage buckets, access via short-lived signed URLs
- Retention and deletion rules centrally configurable
- Processors including Supabase, Stripe, Cloudflare

Region
Supabase project region (documents/DB): eu-west-1 (Ireland, EU), as of 2026-07. Other processors (e.g. Stripe, Cloudflare) may involve processing outside the EU.
Trust center
Central orientation on MIOSMEDIA ONLINE S.L.U, privacy, location standards and availability — without duplicating legal texts.
MIOSMEDIA ONLINE S.L.U · Diseminado Polígono 4, Parcela 91, 07530 Sant Llorenç des Cardassar, Illes Balears, Spanien
Now available in Mallorca. More European locations are being developed.
How we protect your mail and data
Concrete answers instead of vague promises — complementary to the privacy policy.
Who gets access?
You as account holder, authorised location staff for physical handling, and Postnaro admins for support and operations — role-based, not public.
How is mail stored?
Physically on site in a supervised operating area — not a public letterbox. Digitised content sits in private storage buckets.
When is mail opened?
Opening and scanning only happen after the relevant instruction and within the contractual scope — not automatically for every arrival.
How are scans transmitted?
Over encrypted connections (TLS). Inbox access uses short-lived signed URLs — not a permanently public link.
When are originals destroyed or forwarded?
Per your instruction and applicable retention rules. Forwarding uses external carriers with handling fee and postage.
How is access logged?
Technical security and access logs are typically retained for 90 days. Details are in the privacy policy.