GDPR & Data Processing Addendum
Last updated: June 10, 2026
This page describes how Email List Validation complies with the EU/UK General Data Protection Regulation (GDPR) and forms a Data Processing Addendum ("DPA") between you (the "Controller") and Email List Validation (the "Processor") for the personal data you submit for verification. A countersigned DPA is available on request.
1. Roles
For the email addresses you upload or send via the API, you are the Controller and we are the Processor: we process those addresses only on your documented instructions, to verify them and return results. For your own account and billing data, we are the Controller (see our Privacy Policy).
2. Subject matter & purpose
- Subject matter: verification of email addresses you provide.
- Duration: for the term of your use of the Service, until you delete the data or your account.
- Nature & purpose: syntax, domain, MX and SMTP checks and risk scoring to determine deliverability.
- Categories of data: email addresses and any associated fields you choose to upload.
- Data subjects: the individuals whose email addresses you submit.
3. Your responsibilities as Controller
You confirm that you have a lawful basis (e.g. consent or legitimate interest) to process the email addresses you submit, that you have provided any required notices to data subjects, and that your instructions to us comply with applicable law.
4. Our commitments as Processor
- Process personal data only on your instructions and to provide the Service;
- Ensure personnel are bound by confidentiality;
- Apply appropriate technical and organisational security measures (encryption in transit/at rest, access controls, monitoring);
- Not sell or use your uploaded data for our own purposes;
- Assist you, where reasonably possible, with data‑subject requests, security, breach notification and impact assessments;
- Delete or return personal data on termination, subject to backup expiry and legal retention.
5. Sub‑processors
You authorise us to engage sub‑processors to deliver the Service (payment processing, transactional email, hosting, and our verification infrastructure — listed in our Privacy Policy). We impose data‑protection obligations on them no less protective than those here, and remain responsible for their performance. We will give notice of new sub‑processors so you can object.
6. International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Data‑subject rights
We will assist you, taking into account the nature of the processing, in fulfilling your obligations to respond to data‑subject requests (access, rectification, erasure, restriction, portability, objection). Submit requests to [email protected].
8. Breach notification
We will notify you without undue delay after becoming aware of a personal‑data breach affecting your data, with the information you need to meet your own notification obligations.
9. Contact
For DPA requests, sub‑processor lists, or any data‑protection matter, contact [email protected].