This document is published in English only. It is the authoritative version and applies regardless of the language you are browsing the rest of the site in.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and BounceIntel, Bulevardul Republicii 363, Vaslui 730121, Romania ("Processor"), and applies wherever we process personal data on your behalf.
It takes effect automatically when you use the Service. No signature is required for it to bind us; if your procurement process needs a countersigned copy, write to [email protected].
Where this DPA conflicts with the Terms of Service on the subject of personal data, this DPA prevails.
01Definitions
"Data Protection Law" means Regulation (EU) 2016/679 (GDPR) and any national law implementing or supplementing it, including Romanian Law 190/2018, and (where the Controller is established in the United Kingdom) the UK GDPR and the Data Protection Act 2018.
"Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR.
"Customer Personal Data" means personal data contained in the addresses and accompanying material the Controller submits to the Service.
02Subject matter and details of processing
- Subject matter: verification of email addresses submitted by the Controller through the dashboard, an upload or the API.
- Duration: the term of the Terms of Service, plus the retention periods in the "Retention and deletion" section below.
- Nature and purpose: syntax validation, DNS and MX lookup, SMTP interrogation, risk scoring, production of results, reports and aggregate statistics.
- Types of personal data: email addresses, and any personal data the Controller elects to include in them.
- Categories of data subject: the Controller's subscribers, customers, contacts, applicants or users.
- Special category data: not required and not expected. The Controller must not submit it.
03Roles and instructions
The Controller determines the purposes and means of processing Customer Personal Data. The Processor processes it only on the Controller's documented instructions, which comprise this DPA, the Terms of Service, and the Controller's use of the Service.
The Processor will inform the Controller if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until the matter is resolved.
The Controller warrants that it has a lawful basis for the processing, has given any notice required to data subjects, and is entitled to transfer the personal data to the Processor for this purpose.
04Confidentiality
The Processor ensures that every person authorised to process Customer Personal Data is bound by a duty of confidentiality that survives the end of their engagement, and grants access only where it is necessary for operating the Service.
05Security measures
The Processor implements appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation and the risk to data subjects. Current measures include:
- Encryption of all traffic in transit, and encryption at rest of the API credentials the platform holds on a customer's behalf.
- Passwords stored only as scrypt hashes; user-generated API keys shown once and retained only as a non-secret prefix.
- Access to production data restricted to personnel who require it, with security-relevant actions written to a dedicated audit log held separately from application logging.
- Report files containing submitted addresses stored outside the web root and served only through a route that authenticates the session and verifies row ownership.
- Network-level rate limiting, bot mitigation on public endpoints, and IP addresses recorded only as keyed hashes.
- Segregation of the website's database schema from the verification platform's, so a fault in one cannot alter the other's data.
06Sub-processors
The Controller gives general written authorisation for the Processor to engage sub-processors. The current list is published at bounceintel.com/sub-processors and forms part of this DPA.
The Processor imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for its sub-processors' performance.
The Processor will give at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected part of the Service without penalty and receive a refund of any prepaid, unused balance.
07International transfers
Verification is performed within the European Union. Where a sub-processor is located outside the EEA, the transfer is made under the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated into this DPA by reference, with Module Two (controller to processor) or Module Three (processor to processor) applying as appropriate.
Where the UK GDPR applies, the UK International Data Transfer Addendum to those Clauses applies in addition.
The Processor carries out a transfer impact assessment before any such transfer begins, and applies supplementary technical measures (including minimising what is transmitted and encrypting it in transit) as a matter of course.
08Assistance to the Controller
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in responding to data subject requests, and in meeting its obligations under Articles 32 to 36: security, breach notification, data protection impact assessment and prior consultation.
The Service's own controls do most of this work: the Controller can delete a report, and with it the addresses inside it, at any time from the dashboard.
09Personal data breach
The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the full picture is not yet available it is provided in phases, without delaying the initial notice.
10Audit
The Processor makes available the information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits conducted by the Controller or an auditor it mandates.
Audits are on reasonable notice, no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise, during business hours, and subject to confidentiality. The Controller bears its own costs and the Processor's reasonable costs of assistance.
11Retention and deletion
The Processor retains Customer Personal Data only as long as needed for the purposes above:
- Bulk list addresses: held only inside the generated report files, deleted when the retention window expires (30 days by default) or immediately on the Controller's instruction.
- Single-check records, including the address checked: deleted after 30 days.
- Aggregate verification statistics: retained for the life of the account. These contain counts, not addresses.
- On termination: all Customer Personal Data is deleted within 30 days, save where Union or Member State law requires the Processor to retain it, in which case it is isolated and protected until the obligation lapses.
12Liability and precedence
The limitations and exclusions of liability in the Terms of Service apply to this DPA, save that nothing limits either party's liability to a data subject or a supervisory authority under Data Protection Law.
If any provision of this DPA is held invalid, the remainder continues in force and the parties will replace the invalid provision with one that achieves its intent as closely as the law permits.