Privacy policy

What MessageReach Communications Ltd does with personal data: the people who use this site, and the recipient records an operator puts in front of a handset.

14 August 2026
Updated
Cyprus
Jurisdiction
A shield module on a dark plinth with a glowing check mark on its face

Controller and processor

MessageReach Communications Ltd, registered in Cyprus under company number HE 418206 with its registered office at Griva Digeni 81, Office 4, 3101 Limassol, Cyprus, operates the messagereach.net website and the messaging platform described on it.

We act in two capacities and the distinction matters for your rights. For data relating to this website, to prospective customers and to the people who administer an account, we are the controller. For the recipient data a customer submits when it sends a message, we are a processoracting on that customer's documented instructions. If you received a message and want to know why, the operator whose sender identity appears on it is the controller and is the right party to ask.

What we collect

As controller:

  • Contact details submitted through the contact form or by email: name, work email, the operator you represent, and whatever you put in the message.
  • Account and key metadata: the administrators on an account, the keys issued, their scopes, and an audit trail of who changed what.
  • Technical logs from the website and the API: IP address, user agent, timestamps, requested paths and response codes, kept for security and debugging rather than profiling.
  • Billing records where a commercial relationship exists: volume, segments, markets, channels and the invoices generated from them.

We do not run advertising trackers on this site, and we do not sell, rent or share personal data with anyone for their own marketing purposes.

Lawful basis

  • Legitimate interests for answering enquiries, operating and securing the platform, and preventing abuse of the gateway.
  • Contract for everything needed to provide the service to a customer and to invoice for it.
  • Legal obligation for records we are required to keep, including tax records and the traffic records regulated markets require.
  • Consent for non-essential cookies, which are only set if you accept them.

Message traffic

When a customer sends a message we process the destination number, the message body or template reference, the metadata needed to route it, and the delivery result. We do that to deliver the message, to report on it, and to keep the records the destination network or regulator requires.

We do not build audiences from customer traffic, we do not use one customer's data to inform another's, and we do not use message content to train anything. Consent records are held so the gateway can enforce them, including refusing a send where the most recent record is an opt-out. Inbound replies are stored against the conversation so the customer can answer them.

Sharing and subprocessors

Message data necessarily reaches the mobile networks and, where a direct bind is unavailable, the interconnect partner needed to reach them. Beyond that we use a small set of subprocessors for infrastructure, error monitoring, email and invoicing, each bound by a written agreement carrying the same obligations we owe our customers. The current list is available to customers on request and updated with thirty days notice before anything is added.

We disclose data to a public authority only where legally compelled, and where we are lawfully able to tell the customer that we have been compelled, we do.

International transfers

Primary infrastructure sits in the European Economic Area. Delivering a message to a network outside the EEA necessarily transfers the destination number and the body to that network. Where a subprocessor sits outside the EEA, transfers rely on the European Commission's standard contractual clauses together with a transfer risk assessment. Dedicated plans can contract for data residency in a named region.

Retention

  • Enquiry correspondence: twenty four months from the last exchange.
  • Message content: thirty days by default, configurable down to seven on request.
  • Message metadata and delivery results: twenty four months, for reporting and dispute resolution.
  • Inbound conversation history: twelve months, or as agreed in an order form.
  • Consent records: the life of the customer relationship plus six years.
  • Billing and tax records: as required by Cyprus law.

Your rights

Where we are the controller you can ask for access, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests. Where we are a processor we will pass your request to the relevant customer and support them in answering it, but we cannot act on their data without instruction.

Write to api@messagereach.net to exercise any of these. You also have the right to complain to the data protection authority in Cyprus or in the country where you live.

Security

The platform is certified to ISO 27001 and audited annually. In practice that means encryption in transit and at rest, keys scoped per environment and per route class, production access limited to named engineers with hardware-backed authentication, and an audit log of privileged actions that we cannot edit. We notify affected customers of a personal data breach without undue delay and within the window applicable law requires.

Contacting us

Privacy questions go to api@messagereach.net, or by post to MessageReach Communications Ltd, Griva Digeni 81, Office 4, 3101 Limassol, Cyprus. Please say whether your question is about this website or about a message you received, as they reach different people.