How Orangeburg Secure collects, processes, and protects data in our email security gateway service.
Last updated: July 1, 2026
Orangeburg Secure ("we", "us") operates an email security gateway at orangeburgradiology.com. This policy describes how we handle data when you use our inbound filtering, outbound relay, quarantine, and API services.
As an email security gateway, we process email message content, headers, metadata, and attachments solely for threat detection, quarantine management, and delivery. We also process account information (name, email, company, billing details) and API usage logs.
Messages scanned by the gateway are analyzed in memory and in isolated sandbox environments. Quarantined messages are stored encrypted at rest for the retention period defined by your plan (30–365 days). Released messages are delivered to your mail server and removed from quarantine storage within 24 hours.
We do not sell, rent, or share email content with third parties for marketing purposes. Threat intelligence derived from blocked messages is anonymized and aggregated — no recipient content is included in shared intel feeds.
We use infrastructure providers for hosting (Vultr), monitoring, and payment processing. All sub-processors are bound by data processing agreements and SOC 2 compliance requirements.
All data in transit uses TLS 1.2+. Data at rest is encrypted with AES-256. API keys (px_live_/px_test_) are hashed and never stored in plaintext. Access to production systems requires MFA and is logged.
You may request access, correction, or deletion of your account data by contacting contact@orangeburgradiology.com. Quarantined message deletion is available via the admin console or API. EU/UK customers may exercise GDPR rights including data portability.
Account data is retained for the duration of your subscription plus 90 days. Audit logs are retained per your plan tier. Anonymized threat statistics may be retained indefinitely.
Privacy inquiries: contact@orangeburgradiology.com