Privacy notice
Template — requires legal review before launch
Two kinds of data
VerifyInbox processes two categories that are worth keeping separate, because the lawful basis and your rights differ between them.
Account data — the name, email address and billing details of people who sign up. Processed to provide the service under contract.
Business contact data — email addresses published by companies on their own websites, together with the name and job title shown alongside. This is the index the product searches.
Business contact data
Source. Public web pages a company publishes about itself: team pages, contact pages, staff directories, and legally-required imprint pages. Every record stores the URL it came from and the dates it was first and last seen.
What is not collected. Personal addresses at free consumer providers. Anything behind a login. Anything submitted through a form. Special category data of any kind.
Lawful basis (GDPR). Legitimate interests, under Article 6(1)(f) — providing business contact information to other businesses. That basis requires a balancing test the operator must document, and it is subject to your right to object.
Retention. Records are retained while the source page continues to publish them, and are removed on request immediately.
Your rights
Erasure is available immediately and without an account through the data request form. It deletes the record and adds the address to a permanent suppression list, so it is not collected again on the next crawl.
For access, rectification, restriction, portability or objection, use the same form and describe what you need.
Customer data
Addresses that customers upload for verification are processed on their instructions, as a processor. They are retained only as long as needed to return and store the result, and are not added to the public index.
What we log
Request logs carry a request id, an organization id and a user id. Email addresses are masked before they reach a log line, and authorization headers, cookies, API keys and payment webhook signatures are redacted.
Sharing
Data is shared only with the subprocessors listed on the subprocessors page. It is not sold.
Security
See the security page for how credentials are stored and how access is controlled.
Contact
Use the data request form. The operator must add a named data controller, a postal address, and an EU representative where Article 27 applies, before this notice is fit to publish.