Policy
Privacy and data processing
Effective 4 August 2026. Oizzy is an email marketing service operated by Klementine Ventures LLC. Questions, requests and complaints: ronald@oizzy.co.
1. Two different roles
For our customers' data, Klementine Ventures LLC, trading as Oizzy, is the controller (GDPR) / responsible party (POPIA): account names, email addresses, password hashes, sessions and billing details are ours to answer for.
For subscriber data, the customer who owns the audience is the controller / responsible party and Oizzy is the processor / operator. We store and send on their instructions. If you are a subscriber, the sender named in the email you received holds the relationship — but you can always reach us directly at the address above and we will act, including suppressing your address.
2. What we hold
- Account data: name, email address, hashed password, session records with IP and user agent, and the establishment country set at setup.
- Subscriber data, on behalf of customers: email address, optional name, tags, membership status per audience, and the consent ledger — timestamp, source, IP address captured at signup or confirmation, consent-text version and recipient jurisdiction.
- Delivery data: one record per recipient per campaign with status (queued, sent, delivered, bounced, complained), the SES message id, and open and click events where tracking is enabled for that campaign.
- Suppression data: addresses suppressed after a hard bounce, a spam complaint, or a "never contact" request.
This website is a static site. It sets no cookies, runs no third-party analytics, and loads nothing from an external host.
3. Why we hold it
- To run the service our customers asked for — delivering their campaigns.
- To prove consent. Under 정보통신망법, GDPR and POPIA the burden of proof sits with the sender, so the ledger is the point of the product.
- To protect recipients and deliverability: suppression, complaint handling and abuse investigation.
- To keep the account secure and to meet legal obligations.
4. Where it lives, and who else touches it
Application data is stored on Oizzy-operated infrastructure. Mail is delivered by
Amazon SES in the ap-northeast-2 (Seoul) region,
which receives the recipient address and the message itself, and returns delivery,
bounce and complaint events over SNS. Amazon Web Services is our only mail
subprocessor. Transfers out of the EU rely on the Standard Contractual Clauses in
the AWS Data Processing Addendum.
We do not sell personal data, do not share it with advertising networks, and never use one customer's subscribers to mail on behalf of another.
5. Tracking in email
Campaigns may record opens and clicks, attributed to the delivery record for that recipient. This is per-campaign and disclosed to the subscriber in the sender's footer. Aggregated rates are what the dashboard reports.
6. How long we keep it
- Consent records: for as long as the membership exists, and afterwards for the period we may need to evidence lawful sending.
- Delivery and event records: for the reporting life of the campaign.
- Suppression records: indefinitely — a suppressed address is kept precisely so it never receives mail again. This is the one record that survives an erasure request, reduced to the minimum needed to keep the promise.
- Account data: until the account is closed, plus any statutory retention.
7. Your rights
Subscribers may ask for access, correction, a copy of their data, erasure, or to never be contacted again. Oizzy stores one record per person per account, so those requests resolve against a single record rather than scattered list copies. Erasure removes the person; suppression keeps the address unmailable. Both can apply at once.
Every marketing message carries a one-click unsubscribe and a footer link. Opt-outs take effect immediately. Under GDPR you may also complain to your supervisory authority; under POPIA, to the Information Regulator (South Africa); in Korea, to the KCC or PIPC.
8. Security
Traffic is encrypted in transit, mail is sent over TLS-required connections, passwords are hashed, and the credentials used to reach Amazon SES are scoped to sending on our own verified identities.
9. Changes
Material changes to this policy are announced to customers by email before they take effect, and the effective date at the top of this page is updated.
Related: anti-spam and acceptable use, and what Oizzy stores as consent proof.