GDPR-ready, processor by design.
How we comply with the GDPR as your data processor: our roles, the DPA, sub-processors, international-transfer safeguards, security measures, and how we help you honor data-subject rights.
01Controller and processor
Under the EU General Data Protection Regulation (GDPR) and UK GDPR, when you upload contacts to be verified, found, or cleaned, you are the data controller and EmailListChecker is your data processor. We process that personal data only on your documented instructions — namely, to return verification verdicts — and for no independent purpose of our own.
For your own account and our website, we act as controller for that limited set of data, as described in our Privacy Policy.
02Data Processing Agreement
Our Data Processing Agreement (DPA) is incorporated into your contract with us and sets out the subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects, and the obligations and rights of the controller — as required by Article 28 GDPR.
A pre-signed DPA (including the EU Standard Contractual Clauses) is available to every customer. Request it at [email protected] — Enterprise plans can countersign a negotiated version.
03Sub-processors
We use a small set of vetted sub-processors to run the platform, each bound by a DPA and confidentiality obligations consistent with Article 28:
- Cloud hosting & infrastructure — compute, storage, and networking in EU and US regions.
- Payment processing — billing and invoicing (we never store full card numbers).
- Transactional email — account and service notifications.
- Product analytics & monitoring — privacy-respecting, with no third-party ad trackers.
We maintain a current sub-processor list and notify customers of material changes with a window to object before a new sub-processor begins processing your data.
04International transfers
Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards — primarily the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — together with supplementary technical measures such as encryption. We offer EU data-residency options so eligible customers can keep verification processing within the EU.
05Security measures
We implement the technical and organizational measures required by Article 32, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- A SOC 2 Type II control program, least-privilege access, and audited administrative actions.
- Network isolation, continuous monitoring, and penetration testing.
- Configurable retention with auto-deletion, and a zero-retention API mode for eligible plans.
06Breach notification
We maintain a documented incident-response plan. In the event of a personal-data breach affecting your data, we will notify you without undue delay and provide the information you need to meet your own notification obligations under Articles 33–34.
07Assisting with data-subject rights
Because you control the lists you upload, you can fulfil data-subject requests (access, rectification, erasure, restriction, portability, objection) directly from your dashboard — export or delete any list or record at will. Where you need our help to respond to a request, we assist as your processor, and we delete or return personal data at the end of the engagement per your instructions.
08Data Protection Officer & contact
For any GDPR or data-processing matter — including DPA requests, sub-processor questions, or transfer mechanisms — contact our Data Protection Officer at [email protected]. EU/UK customers may also contact their local supervisory authority.
EmailListChecker, Inc. · Data Protection Officer: [email protected]