Data processing agreement
Template — requires legal review before launch
This is a description of the processing, not an executed agreement. The operator must have a DPA drafted and reviewed before offering one to customers.
Which data this covers
Addresses a customer uploads or submits for verification. For those, the customer is the controller and VerifyInbox is the processor, acting on their instructions.
It does not cover the public business contact index. For that data VerifyInbox is the controller, and the privacy notice governs.
Processing
- Subject matter. Verification of email addresses supplied by the customer.
- Duration. For the term of the customer agreement.
- Nature. Storage, SMTP verification, and return of results.
- Data subjects. The people whose addresses the customer submits.
- Data types. Email addresses and any columns the customer chooses to include in an upload.
Our commitments
- Process only on the customer's documented instructions.
- Keep uploaded addresses out of the public index. They are never added to it.
- Maintain the technical measures described on the security page.
- Use only the subprocessors listed, with notice of changes.
- Delete or return data on termination.
- Assist with data-subject requests and, where required, breach notification.
Requesting one
Once the reviewed agreement exists, customers on Growth and above will be able to request it. Use the contact form in the meantime.