Privacy policy
How TextReach Technologies Ltd handles personal data, both for this website and for the message traffic customers route through the gateway.
- Last updated
- 12 August 2026
- Entity
- TextReach Technologies Ltd
- Jurisdiction
- Malta
Controller and processor
TextReach Technologies Ltd, registered in Malta under company number C 94708 with its registered office at Level 3, Quantum House, 75 Abate Rigord Street, Ta' Xbiex XBX 1120, Malta, operates the textreach.online website and the messaging API described on it.
We act in two distinct capacities, and the distinction matters for your rights. For personal data relating to this website, to prospective customers and to the people who administer a customer account, we are the controller. For the recipient data a customer submits when it sends a message, we are a processoracting on that customer's documented instructions. If you received a message and want to know why, the operator whose sender identity appears on it is the controller and is the right party to ask.
What we collect
As controller, we collect:
- Contact details you give us through the support form or by email: name, work email, the operator or brand you represent, and whatever you put in the message body.
- Account and key metadata for customers: the administrators on the account, the keys issued, their scopes, and the audit trail of who changed what.
- Technical logs from the website and the API: IP address, user agent, timestamps, requested paths and response codes. These exist for security and for debugging, not for profiling.
- Billing records where a commercial relationship exists: volume, segments, markets and the invoices generated from them.
We do not run advertising trackers on this site and we do not sell, rent or share personal data with anyone for their own marketing purposes.
Lawful basis
- Legitimate interests for answering enquiries, operating and securing the platform, and preventing abuse of the gateway.
- Contract for everything necessary to provide the service to a customer and to invoice for it.
- Legal obligation for the records we are required to keep, including tax records and the traffic records that regulated markets require us to retain.
- Consent for non-essential cookies, which are only set if you accept them.
Message traffic
When a customer sends a message, we process the destination number, the message body or template reference, the metadata needed to route it, and the delivery result. We do this only to deliver the message, to report on it, and to keep the records the destination network or regulator requires.
We do not build audiences from customer traffic, we do not use one customer's data to inform another's, and we do not use message content to train anything. Consent records submitted by a customer are held so that the gateway can enforce them, including refusing a send where the most recent record is an opt-out.
Sharing and subprocessors
Message data necessarily reaches the mobile networks and, where a direct bind is not available, the interconnect partner required to reach them. Beyond that we use a small set of subprocessors for infrastructure, error monitoring, email and invoicing. Each is bound by a written agreement with the same obligations we owe our customers, and the current list is provided to customers on request and updated with thirty days notice before anything is added.
We disclose data to a public authority only where we are legally compelled to, and where we are lawfully able to tell the customer that we have been compelled, we do.
International transfers
Our primary infrastructure sits in the European Economic Area. Delivering a message to a network outside the EEA necessarily transfers the destination number and the message body to that network. Where a subprocessor is outside the EEA, transfers rely on the European Commission's standard contractual clauses together with a transfer risk assessment. Operator plans can contract for data residency in a named region.
Retention
- Enquiry correspondence: twenty four months from the last exchange.
- Message content: thirty days by default, configurable down to seven on request.
- Message metadata and delivery results: twenty four months, for reporting and dispute resolution.
- Consent records: for the life of the customer relationship plus six years.
- Billing and tax records: as required by Malta law, currently ten years.
Your rights
Where we are the controller, you can ask for access to your data, correction of it, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where we are a processor, we will pass your request to the relevant customer and support them in answering it, but we cannot act on their data without instruction.
Write to developers@textreach.online to exercise any of these. You also have the right to complain to the data protection authority in Malta or in the country where you live.
Security
The platform is certified to ISO 27001 and audited annually to SOC 2 Type II. In practice that means encryption in transit and at rest, keys scoped per environment and per route class, access to production limited to named engineers with hardware-backed authentication, and an audit log of privileged actions that we do not have the ability to edit. We will notify affected customers of a personal data breach without undue delay and in any event within the window the applicable law requires.
Contacting us
Privacy questions go to developers@textreach.online, or by post to TextReach Technologies Ltd, Level 3, Quantum House, 75 Abate Rigord Street, Ta' Xbiex XBX 1120, Malta. Please say whether your question is about this website or about a message you received, as they reach different people.