Skip to content

Privacy notice

Template — requires legal review before launch

This document has not been reviewed by a lawyer. The operator of this service must have it reviewed for every jurisdiction it sells into before relying on it. The factual descriptions of what the system does are accurate; the legal characterisations are not a substitute for advice.

Two kinds of data

VerifyInbox processes two categories that are worth keeping separate, because the lawful basis and your rights differ between them.

Account data — the name, email address and billing details of people who sign up. Processed to provide the service under contract.

Business contact data — email addresses published by companies on their own websites, together with the name and job title shown alongside. This is the index the product searches.

Business contact data

Source. Public web pages a company publishes about itself: team pages, contact pages, staff directories, and legally-required imprint pages. Every record stores the URL it came from and the dates it was first and last seen.

What is not collected. Personal addresses at free consumer providers. Anything behind a login. Anything submitted through a form. Special category data of any kind.

Lawful basis (GDPR). Legitimate interests, under Article 6(1)(f) — providing business contact information to other businesses. That basis requires a balancing test the operator must document, and it is subject to your right to object.

Retention. Records are retained while the source page continues to publish them, and are removed on request immediately.

Your rights

Erasure is available immediately and without an account through the data request form. It deletes the record and adds the address to a permanent suppression list, so it is not collected again on the next crawl.

For access, rectification, restriction, portability or objection, use the same form and describe what you need.

Customer data

Addresses that customers upload for verification are processed on their instructions, as a processor. They are retained only as long as needed to return and store the result, and are not added to the public index.

What we log

Request logs carry a request id, an organization id and a user id. Email addresses are masked before they reach a log line, and authorization headers, cookies, API keys and payment webhook signatures are redacted.

Sharing

Data is shared only with the subprocessors listed on the subprocessors page. It is not sold.

Security

See the security page for how credentials are stored and how access is controlled.

Contact

Use the data request form. The operator must add a named data controller, a postal address, and an EU representative where Article 27 applies, before this notice is fit to publish.