Overview
Mailmyra is an email signature platform that helps individuals and organisations create, manage, preview and export consistent email signatures. Security is treated as an ongoing product and operational responsibility rather than a one-time feature.
Our approach is based on limiting access, keeping workspaces clearly separated, collecting only information needed to provide the service and making ownership of each step understandable. These principles apply to the website, account area, signature builder and the workflows used to prepare signature output.
This page is a product-facing description of our current security approach. It does not claim certification against a particular security framework unless Mailmyra confirms that status separately in writing.
Shared responsibility
Mailmyra is responsible for operating the service and applying reasonable safeguards to the systems and workflows under its control. Customers are responsible for the accuracy of the information they enter, the people they invite, the permissions they grant and the way exported signatures are installed or distributed.
Mailmyra responsibilities
- Maintain access controls around accounts and workspaces.
- Reduce unnecessary collection and exposure of workspace information.
- Review product changes that affect authentication, permissions or export behaviour.
- Respond to credible reports of security issues affecting the service.
Customer responsibilities
- Use a unique, strong password and protect account credentials.
- Invite only authorised collaborators and review access when roles change.
- Confirm signature content, links and required legal text before deployment.
- Notify Mailmyra promptly if account misuse or unauthorised access is suspected.
Account and access controls
Access to a Mailmyra workspace is tied to an account. Authentication and recovery workflows are intended to keep workspace access connected to the correct user. Where team or agency features are available, access should be granted according to the work a collaborator needs to perform.
Users should not share credentials. If a person leaves an organisation or no longer needs access, the workspace owner should remove or update that access without delay. Mailmyra may temporarily restrict an account where there is a reasonable security concern, suspected abuse or a legal requirement to do so.
Administrative access used to operate and support the service is limited to authorised personnel with a legitimate operational need. Such access is expected to be used only for support, maintenance, security or legal purposes.
Data handling and minimisation
Mailmyra is designed to process the identity, contact, brand and workspace information needed to provide signature creation and management features. Depending on how the service is used, this may include names, roles, business contact details, company information, logos, profile images, links, campaign content and workspace settings.
We aim to avoid collecting information that is not necessary for the requested service. Customers should also avoid entering confidential, sensitive or unrelated personal information into signature fields or support messages.
Information may be processed by service providers that support hosting, delivery, monitoring, communication or customer support. These providers are selected for a defined operational purpose and should receive only the information required to perform that purpose. Further detail about personal information is provided in the Privacy Policy.
Workspace and client separation
Mailmyra structures team and agency activity around workspaces. A workspace provides a defined context for members, brand settings, signatures and related configuration. Agency users should create and manage client contexts separately instead of mixing unrelated client data.
Workspace owners are responsible for deciding who may access each workspace. Permissions and invitations should be reviewed periodically, particularly after staffing, supplier or client relationship changes.
No access model removes the need for careful administration. Users should verify the active workspace before editing brand assets, publishing campaign content or exporting signatures.
Signature generation and export
Mailmyra generates email signature output from the content and settings selected by the user. Preview and export workflows are designed to keep that output connected to an approved workspace configuration.
An exported signature may contain personal contact information, linked images, campaign links and legal text. The customer must review the final result before installation and confirm that it is appropriate for the intended recipients, organisation and email client.
Once HTML or an .htm file leaves Mailmyra and is installed, copied, modified or distributed through another system, the security and behaviour of that external environment are outside Mailmyra's direct control.
Service operations
Mailmyra uses operational practices intended to reduce avoidable service and security risk. These include reviewing relevant changes, maintaining service dependencies, limiting privileged access and monitoring the service for behaviour that may require investigation.
No internet service can guarantee uninterrupted operation or absolute security. We evaluate safeguards in proportion to the nature of the service, the information involved and credible risks. Controls may change as the platform, infrastructure and regulatory environment develop.
Customers with specific procurement, vendor review or deployment requirements should contact Mailmyra before relying on the service for a regulated or high-risk workflow.
Security reports and incident response
Reports of a suspected vulnerability, compromised account or unauthorised disclosure are assessed according to their credibility, severity and potential impact. Where a confirmed incident affects customer information, Mailmyra will take reasonable steps to contain the issue, investigate its cause and communicate as required by applicable law.
Security researchers should act in good faith, avoid accessing information that does not belong to them, avoid disruption and provide enough detail for the issue to be reproduced. Public disclosure should not occur before Mailmyra has had a reasonable opportunity to investigate and respond.
Reports can be sent to hello@mailmyra.com with the subject line “Security Report”.
Privacy and compliance requests
Mailmyra aims to support lawful use of the service and reasonable customer review requirements. The obligations that apply to a customer may depend on its location, industry, role, workforce and the information included in its signatures.
Customers remain responsible for determining whether their use of Mailmyra meets their own legal, regulatory and contractual obligations. This includes deciding what notices, disclaimers, consent language or retention practices are required for their organisation.
Questions relating to personal data, applicable rights or deletion requests should be submitted using the contact details in the Privacy Policy. Requests should include enough information to identify the relevant account or workspace without sending unnecessary sensitive information.
Contact Mailmyra
For security questionnaires, vulnerability reports, privacy enquiries or questions about this document, contact:
MailmyraKonya, Türkiye
hello@mailmyra.com
To help us respond efficiently, include your name, organisation, the relevant workspace and a clear description of the request. Do not include passwords, recovery codes or unrelated confidential information.