Last updated: 1 August 2026
JustPost applies technical and organisational measures designed to protect the confidentiality, integrity and availability of customer data. Our security controls are reviewed regularly and are proportionate to the nature of the services we provide.
JustPost is a platform operated by FairSay Ltd that enables organisations to create and manage campaigns involving the distribution of printed communications, including postcards and other supporter engagement activities.
We recognise that campaigns supported through the JustPost platform may involve information relating to individuals' political opinions, affiliations, activism, or engagement with campaigns. Such information may constitute sensitive or special category personal data under applicable data protection laws.
FairSay Ltd is registered with the UK Information Commissioner's Office (ICO) as an organisation that processes politically sensitive personal data. We apply appropriate technical and organisational measures designed to protect the confidentiality, integrity and availability of information processed through the JustPost platform.
This Security Policy describes the measures implemented to protect customer data and support the secure operation of the JustPost platform.
Security is integrated into the design, development and operation of the JustPost platform.
Our approach is based on the following principles:
We apply security measures appropriate to the nature of the information processed, including supporter engagement data and campaign-related information.
Security responsibilities are managed within FairSay Ltd, with access to systems limited to authorised personnel and approved developers or subcontractors who require access to perform their duties.
JustPost is hosted using managed cloud infrastructure designed to provide secure, reliable and scalable services.
Our infrastructure includes:
Infrastructure providers are selected based on their reliability, security practices and ability to support appropriate data protection requirements.
JustPost is designed to operate using managed services where appropriate, reducing operational risk and allowing security updates and infrastructure maintenance to be handled by specialist providers.
Access to JustPost systems is restricted to authorised users based on their role and operational requirements.
Our access control practices include:
Customer dashboard access is controlled by customer administrators, who are responsible for managing users within their organisation.
Sensitive application configuration, including credentials, API keys and other secret values required by the JustPost platform, is managed using controlled secret-management facilities provided by the platform infrastructure. Secrets are not intentionally stored in application source code or publicly accessible configuration. Access to sensitive configuration is restricted to authorised personnel and systems according to operational requirements.
Encryption is used to help protect information during storage and transmission.
Measures include:
JustPost is designed to support customers in meeting their data protection obligations.
Customers generally act as data controllers for information submitted to the JustPost platform, while FairSay Ltd acts as a data processor providing the platform services.
Measures include:
Customers are responsible for ensuring that they have an appropriate lawful basis for processing personal data through JustPost, including where campaigns involve special category personal data such as political opinions.
Customer administrators are also responsible for ensuring that exported or downloaded data is handled securely and in accordance with applicable data protection requirements.
Further information about privacy and personal data processing is available in the JustPost Privacy Policy.
Security is considered throughout the development lifecycle of JustPost.
Our development practices include:
Development and production environments are separated to reduce the risk of unintended changes affecting customer data.
JustPost uses logging and monitoring capabilities to support operational reliability, troubleshooting and security investigations.
Relevant logs are maintained by:
Activities such as moderation, campaign setup, reporting and authorised supporter data access are performed through controlled systems that maintain relevant operational records.
If a security incident occurs, we will investigate the issue, take appropriate corrective action, and notify affected customers where required by applicable data protection laws.
Where required by applicable data protection laws, customers will be notified of personal data breaches without undue delay.
Access to JustPost systems is limited to authorised individuals who require access to perform their responsibilities.
Personnel and contractors with access to systems are expected to:
Physical security of data centres and core infrastructure is managed by our cloud infrastructure providers.
JustPost relies on providers that implement physical security measures designed to protect hosted systems and customer data.
JustPost uses selected third-party service providers to deliver parts of the platform infrastructure and related services.
Third-party providers are selected based on factors including security practices, reliability, contractual commitments and data protection requirements.
Current subprocessors include (Provider -> Purpose -> Data location):
Subprocessors are subject to appropriate contractual arrangements, including data processing agreements where required.
FairSay relies on carefully selected third-party providers for infrastructure, hosting, communications, storage and other operational services that support the JustPost platform.
As part of supplier assessment and ongoing review, FairSay considers factors including security practices, data protection commitments, operational resilience, contractual protections, independent assurance reports and recognised security certifications where relevant.
Where suppliers maintain recognised security certifications or assurance frameworks, these may include standards such as ISO/IEC 27001, SOC 2 or equivalent industry frameworks.
Supplier certifications and assurance measures are considered alongside the nature of the service provided, the type of data processed and the overall risk associated with the service.
The following suppliers used by JustPost maintain publicly available security information and certifications where applicable:
For suppliers that process customer personal data on behalf of FairSay, see the JustPost Subprocessor List.
JustPost is designed for resilience and continuity.
Measures include:
We design our services for resilience and continuity while recognising that no online service can guarantee uninterrupted availability.
Security vulnerabilities are taken seriously.
Our approach includes:
If you believe you have identified a security vulnerability affecting JustPost, please report it responsibly by contacting: support@justpost.pro
Please include sufficient information to help us understand and investigate the issue.
We request that security researchers avoid accessing, modifying or deleting customer data and provide reasonable time for investigation and remediation before publicly disclosing vulnerabilities.
JustPost is designed to support customers in meeting applicable data protection obligations.
Our approach includes:
FairSay Ltd maintains registration with the UK Information Commissioner's Office (ICO) for relevant data processing activities.
Our infrastructure providers maintain their own security certifications and compliance programmes where applicable. These certifications apply to their services and do not represent certification of JustPost itself unless explicitly stated.
Security is a shared responsibility between JustPost and its customers.
Customers are responsible for:
Customers should promptly report suspected security issues or unauthorised access.
FairSay maintains documented processes to support service reliability, operational resilience and recovery following disruption.
Further information on service availability, continuity planning and recovery arrangements is provided in the Service Reliability Statement and Business Continuity & Disaster Recovery Procedure.
For questions about this Security Policy or to report security concerns email: support@justpost.pro
This Security Policy is reviewed periodically and may be updated to reflect changes to the JustPost platform, security practices or applicable requirements.
This overview should be read alongside our full policies, statements and commitments.
Together, these documents explain how JustPost operates, how we protect information and the standards expected of organisations using the platform.