Data Processing Addendum
Effective date: August 4, 2026 · Incorporated into our Terms of Service
This Data Processing Addendum ("DPA") applies whenever a customer ("you", the controller) submits personal data, in practice email addresses, to verifications.email ("EVA", the processor) for verification. It gives effect to Article 28 GDPR and equivalent requirements in other privacy laws, and it applies automatically to every customer as part of our Terms of Service. Customers who need a countersigned copy for their records can email [email protected] with their company details.
1. Our commitments as processor
- Documented instructions. We process submitted data only to provide the verification service you request through the API and dashboard, and for no other purpose.
- Confidentiality. Access to customer data is limited to personnel bound by confidentiality obligations.
- Security (Art. 32). TLS encryption in transit, bcrypt-hashed credentials and API keys, HttpOnly session cookies, network isolation of production systems, access controls, and continuous monitoring.
- Subprocessors. You provide general authorization for the infrastructure subprocessors that host and support the service. A current list is available on request at [email protected]. We will give at least 30 days notice by email before adding a subprocessor that processes customer-submitted data, and you may object on reasonable data-protection grounds.
- Assistance. We assist you, taking into account the nature of processing, with data subject requests and with your obligations regarding security, breach notification, and data protection impact assessments.
- Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your data.
- Deletion and return. At termination of service, or earlier on request, we delete submitted email addresses and verification results, unless retention is required by law. Deletion requests are completed within 30 days.
- Audit. We make available information reasonably necessary to demonstrate compliance with this DPA, and permit audits on reasonable written notice, no more than once per year absent a specific incident.
2. Details of processing
| Subject matter | Email address verification services |
| Duration | The term of your account, plus the deletion period above |
| Nature and purpose | Technical analysis of email addresses (syntax, DNS, SMTP-level checks) to assess validity and deliverability, at your request |
| Categories of data | Email addresses and derived verification metadata (verdicts, scores, provider information). No special categories are requested or intended to be processed |
| Data subjects | Your customers, leads, subscribers, and users whose addresses you submit |
3. International transfers
Where data protected by GDPR is transferred to a country without an adequacy decision (including our US infrastructure), the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two: controller to processor) are incorporated into this DPA by reference, with EVA as data importer and you as data exporter. The technical and organizational measures in section 1 form Annex II.
4. Your responsibilities
You warrant that you have a lawful basis for every address you submit and that your instructions to us comply with applicable law. You are responsible for responding to data subject requests concerning data you control; we will assist as described above.