Legal
Data Processing Agreement
Where verification is carried out on your behalf, you are the controller and this service is the processor. This page sets out the shape of that agreement.
Whether a standard DPA is offered self-serve or executed as part of an enterprise agreement is confirmed by Legal before launch. Until then, request it through contact sales.
Subject matter and duration
Verification of email addresses supplied by the controller, for the term of the agreement.
Nature and purpose of processing
Determining whether an address can receive mail, by evaluating syntax, domain configuration, mail routing and the response of the receiving mail server, together with risk signals such as disposable providers and role accounts. No message is delivered to any address processed.
Categories of data and data subjects
Email addresses, and the technical evidence derived from them. Data subjects are the individuals to whom those addresses belong — typically the controller’s customers, users or prospects.
Security measures
Technical measures that follow from the architecture and can be evidenced today are listed on the security page. The formal annex, including encryption statements and organisational measures, is [ANNEX].
Sub-processors
[REGISTER, NOTIFICATION AND OBJECTION PROCESS]
International transfers
[REGIONS AND TRANSFER MECHANISM]
Assistance, audit and deletion
[DATA-SUBJECT REQUEST ASSISTANCE, AUDIT RIGHTS, RETURN AND DELETION ON TERMINATION]
Breach notification
[TIMEFRAME AND PROCESS]
Marked sections are owned by Legal and block launch, not design review.