CobraLedger 365 Backup & Archive — Privacy Statement
Effective date: September 2, 2026
This Privacy Statement explains how Prevail-IT Solutions USA Inc, a Florida corporation located at 4491 S SR-7, Davie, FL 33314 ("Prevail-IT," "we," "us," or "our"), collects, uses, discloses, and protects personal data in connection with the CobraLedger 365 Backup & Archive service and the websites at cobraledger.com and mailarchiver.cobraledger.com (together, the "Service").
Because we serve customers worldwide, this Statement is designed to address the requirements of laws including the EU and UK General Data Protection Regulation ("GDPR") and U.S. state privacy laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where a specific law grants you rights, those rights apply to the extent that law applies to you.
1. Our two roles: controller and processor
Our role depends on the data:
- Account and website data — we are the controller. For the personal data of our customers, their administrators and contacts, and website visitors (for example, names, business email addresses, company information, billing metadata, and usage data), we determine the purposes and means of processing and act as the data controller (or "business" under U.S. law).
- Archived email content — we are the processor. The email content, attachments, and mailbox metadata that the Service copies from a customer's Microsoft 365 environment ("Customer Data") is processed on behalf of, and under the instructions of, our customer. For that data, the customer is the controller and we act as the processor (or "service provider" under U.S. law). If you are an individual whose email has been archived by an organization that uses the Service (for example, an employer), that organization is responsible for how the data is handled; please direct your privacy requests to them, and see Section 9.
This Statement primarily addresses data for which we are the controller. Our processing of Customer Data is governed by our agreement with the relevant customer, including our Terms and Conditions and, where applicable, a Data Processing Addendum ("DPA") available on request.
2. Personal data we collect
a. Account and contact data. When you register, subscribe, or communicate with us: your name, business email address, company name, role, and information you include in support requests.
b. Authentication data. Login is primarily through Microsoft sign-in (Microsoft Entra ID). We receive identity tokens and basic profile information from Microsoft to authenticate you. We do not receive or store your Microsoft password.
c. Billing data. Payments are processed by Square. We do not receive or store your full payment card number. We store only limited billing metadata and identifiers, such as card brand, the last four digits, expiration month/year, and Square customer, card, subscription, and invoice identifiers, together with subscription and payment status.
d. Customer Data (processed as processor). The email content, attachments, and mailbox metadata that the Service archives from your designated Microsoft 365 mailboxes, plus the searchable index and operational metadata we maintain to make it browsable. This may include personal data of senders, recipients, and individuals mentioned in email. We process this only to provide the Service, as described in Section 1.
e. Usage, device, and log data. Technical information generated when you use the Service, such as IP address, browser and device type, pages viewed, actions taken, timestamps, diagnostic and performance telemetry, and error logs. We use application performance monitoring within Microsoft Azure to collect this operational telemetry.
f. Cookies and analytics. The websites use cookies and similar technologies, including Google Analytics, to understand usage and improve the sites. See Section 11.
We do not intentionally collect special categories of personal data about our own account holders. Customer Data may, however, contain any information present in email; that content is controlled by our customer.
3. How we use personal data
We use personal data to:
- provide, operate, maintain, secure, and support the Service;
- create and administer accounts and authenticate users;
- process subscriptions, payments, renewals, and billing through Square;
- provide the archiving, search, and download functionality;
- monitor, diagnose, and improve performance, reliability, and security, and detect and prevent fraud and abuse;
- communicate with you about your account, transactions, security, changes to the Service, and support;
- send service-related and, where permitted, limited product communications (you may opt out of non-essential messages); and
- comply with legal obligations and enforce our agreements.
We process Customer Data only to provide and support the Service and per our customer's instructions, and not for our own independent purposes. We may create and use aggregated or de-identified data that does not identify any individual to operate and improve the Service.
4. Legal bases for processing (GDPR and similar laws)
Where the GDPR or similar law applies and we are the controller, we rely on:
- Contract — to provide the Service you or your organization requested and to administer the relationship;
- Legitimate interests — to secure, improve, and support the Service, prevent fraud and abuse, and run our business, balanced against your rights;
- Legal obligation — to comply with applicable laws, including tax and accounting; and
- Consent — where required, such as for certain analytics cookies or optional communications; you may withdraw consent at any time.
Where we act as processor for Customer Data, the customer (controller) is responsible for establishing the legal basis for the processing.
5. How we share personal data
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only as follows:
- Service providers / sub-processors who help us operate the Service under contractual confidentiality and data-protection obligations, including:
- Microsoft (Microsoft Azure for hosting, archive storage, and telemetry; Microsoft 365 / Microsoft Graph as the source of archived email; Microsoft Entra ID for authentication);
- Square for payment processing; and
- Google for website analytics (Google Analytics).
- Professional advisors (such as lawyers, auditors, and accountants) under confidentiality obligations.
- Legal and safety — when we believe disclosure is necessary to comply with law, legal process, or governmental request; to enforce our agreements; or to protect the rights, property, or safety of Prevail-IT, our customers, or others.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Statement.
A current list of sub-processors is available to customers on request.
6. International data transfers
We are based in the United States, and our sub-processors may process data in the United States and other countries. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing adequate protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary measures where appropriate. You may request more information using the contact details below.
7. Data retention
We retain personal data for as long as needed to provide the Service and for the purposes described in this Statement, and thereafter as required to comply with legal, tax, accounting, and audit obligations, resolve disputes, and enforce our agreements. Specifically:
- Customer Data (archived email files, searchable index, and operational metadata): the archived
.emlfiles reside in archive storage that we provision and operate as part of the Service, for the duration of the customer's subscription. Following the effective date of cancellation or termination of a customer's subscription, we delete or de-provision the archived files, the searchable index, and operational metadata from our systems within seven (7) days, except for records we are permitted or required to retain and residual copies that are overwritten in the ordinary course of our routine storage-management processes. Customers are responsible for exporting any archived email they wish to keep before their subscription ends. - Account, billing, and audit records: retained for the period necessary to meet legal and financial-recordkeeping obligations.
8. Security
We implement technical and organizational measures designed to protect personal data, including per-customer database isolation, encryption in transit and at rest where supported, certificate-based application authentication to Microsoft services, read-only mail access, managed secret storage in a key vault, and access controls. No system can be guaranteed to be completely secure, and we cannot guarantee the absolute security of personal data. You are responsible for securing your own environment and credentials, including your Microsoft 365 tenant.
9. Your privacy rights
Depending on where you are and the applicable law, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your data;
- restrict or object to certain processing;
- data portability (receive your data in a portable format);
- withdraw consent where processing is based on consent; and
- lodge a complaint with a supervisory authority or regulator.
To exercise these rights with respect to data for which we are the controller, contact us at sales@prevail-it.com. We will respond within the time required by applicable law and may need to verify your identity. We will not discriminate against you for exercising your rights.
If your email was archived by an organization that uses the Service (for example, your employer), we process that Customer Data as a processor on that organization's behalf. Please direct requests regarding that data to the organization; if you contact us, we will refer your request to them and support their response as required.
10. U.S. state privacy rights (including California)
Where U.S. state privacy laws apply, you may have the rights described in Section 9, including the rights to know, access, correct, and delete personal information, and to be free from discrimination for exercising them. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not knowingly process sensitive personal information about our account holders for purposes requiring an opt-out. To exercise your rights, contact us at sales@prevail-it.com. You may use an authorized agent where permitted, subject to verification.
11. Cookies and analytics
The websites use cookies and similar technologies that are strictly necessary for the sites to function, and, where permitted, analytics cookies through Google Analytics to help us understand how the sites are used and to improve them. Google Analytics may set cookies and collect information such as your IP address and usage activity; Google processes this data in accordance with its own policies. You can control cookies through your browser settings, and you can opt out of Google Analytics using Google's opt-out browser add-on. Where required by law, we request consent before setting non-essential cookies. We honor recognized browser-based opt-out preference signals where applicable law requires.
12. Children's privacy
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data directly from children under the age of 16. If you believe a child has provided us personal data in a controller capacity, contact us and we will take appropriate steps to delete it. Email archived on behalf of a customer is Customer Data controlled by that customer.
13. Data breach notification
If we become aware of a personal-data breach affecting data for which we are the controller, we will notify affected individuals and regulators where and as required by applicable law and without undue delay. Where we act as processor, we will notify the affected customer (controller) without undue delay as required by our agreement so that the customer can meet its notification obligations.
14. Third-party links and services
The Service integrates with and may link to third-party services, including Microsoft and Square. Their processing of personal data is governed by their own privacy policies, and we are not responsible for their practices. We encourage you to review their policies.
15. Changes to this Privacy Statement
We may update this Privacy Statement from time to time. If we make material changes, we will post the updated Statement with a new effective date and, where appropriate, provide additional notice. Your continued use of the Service after the effective date constitutes acceptance of the updated Statement.
16. Contact us
For questions about this Privacy Statement or to exercise your rights, contact:
Prevail-IT Solutions USA Inc 4491 S SR-7, Davie, FL 33314, United States Email: sales@prevail-it.com
© 2026 Prevail-IT Solutions USA Inc. All rights reserved.