Data Processing Agreement
Version 2026.09
What This Agreement Is
This agreement covers how we handle personal data—mainly, the email addresses you submit for verification—on your behalf. It applies whenever European data protection law (the GDPR and similar laws) covers that data.
It sits alongside your Terms of Service. GDPR Article 28 requires this kind of contract whenever one company processes personal data for another, so this document exists to satisfy that requirement.
You stay in control of the data and decide why it's collected. We only do what you and this agreement say, keep the data secure, and help you meet your own GDPR obligations.
You agree to this document automatically when you accept our Terms of Service at signup, or by continuing to use our services after we post it. That's enough under Article 28—you don't need to sign anything separately, which keeps signup self-serve.
A Few Terms, Explained
GDPR uses some specific words. Here's what they mean in plain terms, and how we use them in this document:
Personal data. Any information that identifies a person, like an email address.
Processing. Anything we do with that data: collecting it, checking it, storing it, deleting it.
Controller. Whomever decides why data is collected and what it's used for. In this agreement, that's you.
Processor. Whomever processes data on the controller's instructions. In this agreement, that's us.
Sub-processor. Another company we bring in to help us process the data (for example, our cloud hosting provider).
Security incident. What GDPR calls a "personal data breach": an event where data is lost, stolen, or accessed without permission.
Standard Contractual Clauses (SCCs). A standard contract, written by the European Commission, that legally protects data sent outside Europe.
Your Role and Ours
You're the controller and we're the processor for the data covered by this agreement—the email addresses (and any details submitted alongside them) you send us for verification. You decide what to submit and why; we process it only to give you a verification result.
We're an independent controller for the account, billing, and marketing data we collect directly from your team to run the business relationship—things like signup contact details, payment information, and support tickets. Our Privacy Policy covers that data, not this agreement.
What We Process
GDPR Article 28 requires us to spell out exactly what we do with your data. Here's the summary:
What we're doing: Automatically checking whether an email address is valid and likely to receive mail
How long: For as long as this agreement is in effect, plus the retention period described under How Long We Keep Data
How we do it: Automated checks on format, domain, and mailbox status, run by our verification engine
What data: Email addresses, and any name, company, or other identifying details you submit alongside them
Whose data: Whomever's email addresses you submit
What We Promise as Your Data Processor
Here's what we commit to, so you can meet your own GDPR obligations:
We follow your instructions. We only process your data the way you and this agreement say—through your ordinary use of our service, or through written instructions. If the law ever requires us to do something different, we'll tell you first, unless the law says we can't.
We keep it confidential. Everyone on our team who touches your data is bound by confidentiality obligations.
We keep it secure. We use the security measures listed in Attachment A, in line with GDPR's security requirements.
We're careful about who else touches it. See Companies That Help Us below for how we handle sub-processors.
We help you respond to your users' requests. If someone asks you to access, correct, or delete their data, we'll give you reasonable help—through product features or support—to make that happen.
We help you handle security incidents. If we discover a security incident affecting your data, we'll tell you without unreasonable delay. We'll also reasonably cooperate if you need to assess the risk to your users or notify a regulator.
We delete or return your data when we're done. When this agreement ends, we'll delete or return your data—whichever you prefer—unless the law requires us to keep it (see How Long We Keep Data).
We can show you we're doing all of this. We'll give you the information you reasonably need to confirm we're meeting these commitments, and we'll allow audits as described below.
Audits
If you have questions about whether we're meeting our commitments, ask—we'll respond to reasonable written requests for information. If that's not enough, you (or an independent auditor who agrees to keep things confidential) can audit our relevant records and security controls. We ask for at least 30 days' notice, and we limit this to once a year unless we've had a confirmed security incident. You cover the cost of the audit unless it turns up a real compliance problem, in which case we do.
Companies That Help Us
We use a small number of other companies—sub-processors—to help deliver the service, mainly cloud hosting and email infrastructure. You're giving us permission to use them, as long as we:
Keep an up-to-date list of who they are
Hold each of them to data-protection terms at least as strong as this agreement
Give you at least 30 days' notice before adding a new one, so you can raise concerns—and if we can't resolve them together, you can cancel the affected part of the service
Stay responsible to you for anything a sub-processor gets wrong
How Long We Keep Data
We keep your data for as long as your account is active, and for up to 18 months after you stop using our services—matching the retention period in our Privacy Policy. If you'd like it deleted sooner, just ask and we will, unless we're required by law to hold onto it longer.
Sending Data Outside Europe
[⚑ NEEDS DECISION BEFORE PUBLISHING: Pending the decision in PRD-267. The text below assumes the recommended approach—Data Privacy Framework certification as the main safeguard, with Standard Contractual Clauses as a documented backup—replace with the final call before publishing.]
When we send your data outside the EEA, UK, or Switzerland—including to the United States, where we're based—we protect it using [our certification under the EU-U.S. Data Privacy Framework, backed up by Standard Contractual Clauses, included as Attachment C]. If that protection ever becomes invalid, we'll tell you and work with you in good faith to put a replacement in place.
Who's Responsible If Something Goes Wrong
The liability limits in your Terms of Service apply here too, to the extent the law allows. Nothing here limits either of our responsibilities to individuals or regulators under GDPR.
How Long This Agreement Lasts
This agreement takes effect when you accept our Terms of Service, and it lasts for as long as we process your data under those terms.
Our EU Contact
GDPR requires companies like us, based outside the EU, to name a contact person located in the EU. Ours is: [REPRESENTATIVE NAME], [EU ADDRESS], [CONTACT EMAIL].
Which Laws Apply
This agreement follows the same governing law as your Terms of Service. That doesn't take away any rights you have under GDPR or similar laws.
How You Accept This Agreement
By accepting our Terms of Service—checking the box at signup, or continuing to use our services after we post this agreement—you're agreeing to this document too, on behalf of your company.
Attachment A: How We Keep Your Data Secure
Matching the security commitments in our Privacy Policy, we:
Encrypt your data in transit and control who can access it
Limit access to team members who need it to do their jobs
Monitor our systems and regularly review who has access
Follow the security-incident response process described above
[LEGAL/SECURITY REVIEW: add specifics — encryption standards, hosting certifications, employee training, incident-response timelines — before publishing.]
Attachment B: More on the Data We Process
As described under What We Process above. We don't knowingly process any GDPR "special category" data—things like health or biometric information—so please don't submit that kind of data to our service.