This document is incomplete, and here is exactly how.

JunkGate has not yet published the company you would be contracting with, or the law that governs this agreement. A contract that names no counterparty cannot be enforced at the moment somebody needs to enforce it, so please read this as a description of how the service behaves rather than as an agreement you could rely on in a dispute.

No paid plan is open and nothing is being charged. There is no payment processor connected to this service at all, so there is nothing here that could take money from you, and no paid plan opens until the details below are published.

Still to be published: Contracting entity, Registration number, Registered address, Governing law.

We would rather show you this notice than fill the gap with something that looks official.

Legal

Data processing addendum

What we do with the personal information you hand us, who is responsible for what, and what we commit to in writing. It applies on every plan, including the free one.

Version 1.0, in effect from 10 August 2026. Earlier versions are kept and we will send you any of them on request.

This applies on every plan, including the free one. It is not an upgrade and there is nothing to buy to get it. The service handles the personal information of people who never agreed to anything with us, and that does not become more true when somebody pays.

1. What this is, and who it is between

This addendum forms part of the terms of service between you and not yet published, registration number not yet published, of not yet published. Below, "we" and "us" mean that company and "you" means the customer who set up the account.

You accepted this when you accepted the terms. There is nothing to sign and nothing to send back. If your procurement process needs a countersigned copy, ask at support@junkgate.com and we will sign one.

This addendum is governed by not yet published. Where it disagrees with the terms of service about the handling of personal information, this addendum wins.

Formal notices to us go to not yet published, copied to support@junkgate.com. Notices to you go to the email address on your account, so please keep it current.

"Data protection law" below means the privacy and data protection law that applies to each of us. We have deliberately not written one country's statute into this document, because the obligations we are committing to are the same either way.

2. Who is responsible for what

This is the part that matters most and it is short.

You are the controller of the submissions. The messages people send through your contact form, or to a mailbox you have pointed at us, are yours. You decide what your form asks for, why you collect it, what you tell the people filling it in, and what you do with your own copy. We handle that content only to do the job you switched on.

We are the processor of that content. JunkGate reads it, decides whether it looks like a genuine enquiry, holds what it judges to be junk, delivers the rest, and shows you what happened. Nothing else, and no person reads it to make that decision.

We are the controller of your account information. Your name and sign-in details, your site settings, our records of your use of the service, our billing records when billing exists, and the anonymous counts behind your dashboard figures are ours to look after directly. Our privacy page describes them.

InformationWho decides what happens to itWhat we are
The messages your visitors and customers send You Processor, acting on your instructions
Your account, sign-in and site settings Us Controller
Billing records, once billing exists Us Controller
The anonymous counts behind your accuracy figures Us Controller, and they hold no personal information at all

3. What we process, and why

Subject matter
Reading each enquiry sent to you for its content and its intent, deciding whether it is genuine, holding what we judge to be junk, delivering the rest, and showing you every decision so you can overrule it.
Duration
For as long as your account is open, plus the retention window in section 10. Each individual submission is processed for far less than that: the decision itself takes seconds.
Nature of the processing
Receiving, automated classification, storage for your review, delivery, release on your instruction, notification, and automatic deletion on a timer.
Purpose
Separating genuine enquiries from spam and scams, so that a business does not lose a customer in a flooded inbox.
Categories of people
Anyone who contacts your business through a form or a mailbox connected to JunkGate. Mostly your prospective customers, and the people sending you junk.
Types of personal information
Whatever your form collects, which is typically a name, an email address, sometimes a phone number, and the text of the message. Plus the network address the submission arrived from and basic technical details of the request.
Sensitive information
We do not ask for any. If your form collects health, financial, biometric or similar information, that is your decision, and telling the people filling it in is your responsibility rather than ours.

4. We act on your instructions, and only on them

We process submission content only on your documented instructions. Your instructions are your settings, the actions you take in your dashboard, and this addendum. If we ever believe an instruction would break the law that applies to us, we will tell you and stop, rather than quietly comply or quietly refuse.

Some things we will not do with it, stated plainly because a promise you cannot check is worth very little:

One thing we ask of you in return: keep looking at what is held. The dashboard exists so mistakes are visible and reversible, and that only works if somebody reads it.

5. Confidentiality

Everyone with access to production data is bound to keep it confidential, and that obligation outlasts their involvement. Access is limited to the people who need it to operate and repair the service, which today is a very small number of people.

No person reads your enquiries as part of a filtering decision. The product reads them. A person only ever sees one when you ask us to look at a specific problem, or when repairing a fault requires it, and we would rather tell you that than claim an absolute nobody could verify.

6. Security

What we actually do:

What we will not claim: we hold no security certification and we are not going to imply one with a badge. If your procurement needs a security questionnaire answered, send it to support@junkgate.com and it will be answered honestly by the person who wrote the code.

7. Sub-processors

You give us general authorisation to use sub-processors. The current list, by category and purpose, is at sub-processors and forms part of this addendum.

Before a new sub-processor starts handling anything covered by this addendum, we will publish it on that page and email the address on your account, at least 30 days in advance. If you object within those 30 days and we cannot resolve it, you may end your subscription and we will refund the unused part of anything you have paid for.

We remain responsible to you for what our sub-processors do with your data, to the same extent as if we had done it ourselves, and we place obligations on them no weaker than the ones in this addendum.

8. Requests from the people whose information it is

If one of your visitors asks you to give them a copy of their submission, correct it, or delete it, we help you answer. Deletion you can do yourself from the dashboard in one click; for anything else, ask us and we will help at no charge for any reasonable number of requests.

If one of them contacts us instead, we do not tell them it is not our problem. We acknowledge within 3 business days, identify which site the message went to, route the request to you as the controller, and tell them we have done it. Where their information exists only inside our own retention window, we also delete our copy and confirm that to them. The whole procedure is published at making a data request so that anyone can hold us to it.

We will also give you the information you reasonably need for a data protection impact assessment or a consultation with a regulator, which in practice means answering your questions about what we do, in writing.

9. Telling you when something goes wrong

If we discover a personal data breach affecting information we process for you, we will tell you without undue delay, and in every case within 72 hours of becoming aware of it.

We will not wait until we have a complete picture, because a complete picture takes longer than your own reporting deadlines allow. The first message will say what we know, what we do not yet know, what we are doing about it, and when we will next update you. Then we will keep updating you.

10. How long anything is kept, and what deleting means here

Submissions are deleted 30 days after they arrive. That happens automatically and it applies to everything equally, genuine and junk alike. You can shorten the window in your settings. Nothing is ever deleted because of a filtering decision: the decision affects where a message goes, never whether it survives.

Backups are purged within 35 days. Backups are encrypted and are held slightly longer than the messages themselves so that a restore stays possible. A deleted message is fully purged from them within 35 days. We would rather tell you about that short tail than claim a deletion is instant everywhere when it is not.

What survives deletion: anonymous counts, so your accuracy figures still work after the messages behind them are gone. They contain no names, no addresses, no message content, and nothing that could be traced back to a person.

When you leave: export whatever you want from the dashboard first, because closing your account deletes the submissions we hold for you. Tell us within 30 days of closing if you want them back instead and we will return them if the retention clock has not already taken them. Account and billing records are kept only for as long as we need them for tax and legal reasons, and then deleted.

11. Where it is processed

Submission content is processed and stored in a region we will name on request. Our sub-processor page describes suppliers by category rather than by name, and explains why, so if you need the specific supplier, region and purpose for a procurement review, ask and we will put it in writing.

Where a transfer of personal information across borders is restricted by the data protection law that applies to you, we will put appropriate safeguards in place before it happens, including standard contractual clauses where those are the right instrument.

12. Showing our working

You may audit our compliance with this addendum by written questionnaire. Send it to support@junkgate.com and we will answer within 30 days, once in any twelve month period, and more often if a regulator requires it or if there has been a breach affecting your data. We will also give you the information you reasonably need to demonstrate your own compliance.

We do not offer on-site inspection, and the honest reason is that it would be theatre. There is no data centre of ours to visit. The questionnaire is answered by the people who built and run the system, which is where the real answers are.

13. Changes to this addendum

When we change this document we change the version number and the date at the top of the page, and we tell account owners before a material change takes effect. Earlier versions are kept, and we will send you any of them on request, so you can always tell what you agreed to and when.

We record which version of this addendum each account accepted. That is not bookkeeping for its own sake: it is the only way either of us can later say with confidence what the agreement was on a given day.

Who you would be dealing with

Contracting entity
not yet published
Registration number
not yet published
Registered address
not yet published
Governing law
not yet published

All legal documents, with the version and date of each. Questions about any of this go to support@junkgate.com.