Skip to content

Terms of Service

Conditions of use of the service.

Rules governing the relationship between JAAK and Mailack customers: the service, its classes of email, the evidence with evidentiary value, and each party's obligations.

Last updated: August 14, 2026

01

1. Purpose and Acceptance

These terms govern access to and use of Mailack (mailack.com), a certified email service with NOM-151 preservation evidence, operated by JAAK ('The Provider') from infrastructure located in Mexico. By creating an account, generating API credentials, or sending messages through the platform, the customer fully accepts these terms. Anyone acting on behalf of a legal entity represents that they have sufficient authority to bind it.

2. The Service and the Classes of Email

Mailack sends email from its own infrastructure in Mexico and preserves technical evidence for every message. The service offers four classes of sending:

  • Ordinary email: transactional delivery with a technical record of the transmission (SMTP transcript, DSN receipts), but without a sealed NOM-151 certificate and therefore without the evidentiary-value evidence that characterizes certified email.
  • Certified email: the message is canonicalized, its cryptographic fingerprint (hash) is computed, and it is added as a leaf to a Merkle tree whose root is sealed with a NOM-151 preservation certificate issued by PSC Codex, an accredited Certification Service Provider (PSC). The customer can export a proof bundle that is verifiable offline, without depending on the Provider.
  • Certified email with attachments: attached files travel inside the message itself and are covered by the same cryptographic fingerprint and the same certificate: what is attested is the complete message, with everything it carried.
  • Reliable notification and reading (notificación y lectura fehaciente): the document does not travel as an attachment; the Provider retains it and the message includes a link specific to each recipient, so that every access to the document is recorded and sealed with a NOM-151 certificate, on the terms of clause 4.

3. Scope of the Certificate

The NOM-151 certificate attests to the existence and integrity of the message content as of a given date, together with the technical transmission events archived as evidence. It does not attest that the recipient read the message, nor does it replace notices that the law reserves to specific means. The weight given to the evidence in any proceeding is determined by the authority hearing the matter.

  • What it does attest: that the content existed with that hash on that date, that the recipient's server accepted the transmission, and the literal technical dialogue of that delivery.
  • What it does not attest: that a person read the message. No email technology proves that on its own, and the Provider presents no technical signal as proof of reading.
  • In particular, the download of images or other remote resources contained in a message does not evidence reading: corporate security systems and mail providers' privacy services fetch those resources automatically, with no human involvement.

4. Reliable Notification and Reading: Certified Documents and Acknowledgement of Receipt

Where the customer sends a certified document, the document does not travel as an attachment: the Provider retains it and the message includes a link specific to each recipient. This allows the Provider to certify the exact bytes that were delivered and the moment of delivery, which an attachment does not allow once it leaves the Provider's custody. Articles 91 and 92 of the Mexican Commercial Code allow the parties to agree on the method by which receipt of a data message is acknowledged; where the customer enables this functionality, the parties agree that the acknowledgement method is the confirmation performed by the recipient on the Provider's platform, on the terms of this clause.

  • Access to the document is recorded at three distinct levels, which the Provider does not present as equivalent: "served" means the link was requested, and includes automated requests; "displayed" means the document was shown in a real browser and the window remained visible; "confirmed" means whoever held the link performed an explicit act of confirmation, without that evidencing their identity.
  • The Provider never asserts that a document has been read or understood. No technical means evidences this, and the Provider offers none that simulates it.
  • Confirmation requires an explicit act and can only occur through a write request. No automated visit, preview, or security scan can produce a confirmation.
  • Before confirming, the recipient is shown the document and its digital fingerprint, so that the confirmation refers to specific content rather than to a description of it.
  • Access, at any of its three levels, is evidenced against whoever holds the link delivered to a given email address, not against an identified person. The Provider does not verify the recipient's civil identity, and the record must not be construed as doing so.
  • Each access records the date and time, the address the link was delivered to, the level reached, and the fingerprint of the document served, and is sealed with a NOM-151 certificate in the same way as the message. The classification of whether an access originates from a person or an automated system is stored separately and does not form part of the sealed record, being a revisable interpretation rather than a fact.
  • The absence of access or confirmation does not evidence that the recipient failed to receive the message, and the Provider does not present it as such.

5. Accounts, Credentials, and API Keys

The customer is responsible for the accuracy of their account information, the confidentiality of their credentials, and all activity performed with their API keys. Any message sent with the customer's valid credentials is deemed sent by the customer. Upon any compromise or suspected compromise of a credential, the customer must rotate it immediately and notify the Provider at hola@mailack.com. The Provider may revoke compromised credentials to protect the platform.

6. Acceptable Use

Mailack is built for transactional and certified email to legitimate recipients. Using the service for any of the following is prohibited:

  • Sending unsolicited email (spam) or mailing lists of recipients who have not consented to receive the customer's communications.
  • Impersonating third parties or falsifying senders, headers, or content.
  • Distributing malware, phishing, or content that is unlawful under applicable law.
  • Interfering with the operation of the platform or degrading the shared sending reputation.

7. Sending Domains and DNS Verification

The customer may only send from domains they own or are expressly authorized to use. Each sending domain must complete verification through DNS records (SPF, DKIM, DMARC, and the verification record indicated by the platform) and keep those records current. The Provider may pause sending from domains whose verification fails or whose authorization cannot be confirmed.

8. Availability

The Provider operates the service with commercially reasonable efforts and gives notice of scheduled maintenance. Unless a service level agreement (SLA) has been agreed in writing in an enterprise contract, uninterrupted availability is not guaranteed. Verification of certificates already issued does not depend on platform availability: the proof bundle is verifiable offline.

9. Pricing, Quotas, and Billing

Prices are denominated and billed in Mexican pesos (MXN), plus applicable taxes. Each plan includes monthly sending quotas; overages are billed at the current rate of the contracted plan. The Provider issues the corresponding Mexican tax invoice (CFDI). Non-payment entitles the Provider to suspend the service under clause 12.

10. Evidence Retention and Account Termination

The evidence for each certified message (canonicalized message, cryptographic fingerprint, Merkle inclusion proof, and NOM-151 certificate) is preserved for the duration of the contract in accordance with NOM-151-SCFI-2016. Upon termination of the relationship, for any reason:

  • The customer may export the proof bundles for their messages during the ninety (90) calendar days following the effective termination date.
  • Certificates already issued do not lose validity upon termination: the exported proof bundle is verifiable offline, with publicly available verification tools, without requiring any service from the Provider.
  • After the export period, the Provider may delete message content, retaining only the information whose preservation is required by NOM-151 or applicable law.

11. Intellectual Property

The platform, its software, documentation, trademarks, and distinctive signs are the property of JAAK or its licensors. The customer retains full ownership of the content of their messages and grants the Provider a limited, non-exclusive license to process them for the sole purpose of providing the service: transmitting them, archiving them, and generating the associated evidence.

12. Limitation of Liability

The Provider's total liability for direct damages arising from the service is limited to the amount actually paid by the customer in the twelve (12) months preceding the event giving rise to it. The Provider is not liable for indirect damages, lost profits, or data loss beyond its control, nor for the weight that authorities or third parties give to the evidence in any proceeding. Nothing herein limits liability that cannot be limited under applicable law.

13. Suspension and Termination

The Provider may immediately suspend sending upon breaches of acceptable use, security risks, or non-payment, notifying the customer of the cause. Either party may terminate the relationship with thirty (30) calendar days' notice. Upon termination, clause 9 applies to the evidence and its export.

14. Changes to These Terms

The Provider may update these terms by publishing the new version on this page with its update date. Substantial changes will be notified to the account's contact email at least fifteen (15) calendar days in advance. Continued use of the service after the changes take effect constitutes acceptance.

15. Governing Law and Jurisdiction

These terms are governed by the laws of the United Mexican States, including the Commercial Code provisions on the preservation of data messages and NOM-151-SCFI-2016. For any dispute, the parties submit to the jurisdiction of the competent courts of Monterrey, Nuevo León, Mexico, waiving any other forum to which they may be entitled.

Questions about these terms

Legal Contact

For questions about these terms of service or your contract:

hola@mailack.com