This document is published in English only. It is the authoritative version and applies regardless of the language you are browsing the rest of the site in.
This policy explains how BounceIntel, Bulevardul Republicii 363, Vaslui 730121, Romania handles personal data. We are the controller for the data described in "Data about you", and a processor acting on our customers' instructions for the data described in "Data you send us to verify".
It is written to be read, not to be survived. If anything here is unclear, or you want to exercise a right, write to [email protected] and a person will answer.
01Two very different kinds of data
Almost every question about our privacy practices resolves once this distinction is clear.
The first kind is data about you as a visitor or customer: your name, your email address, your billing details, the fact that you signed in. We decide what to do with it, which makes us the controller.
The second kind is the email addresses you upload or send to the API. Those belong to your contacts, not to you and not to us. You decide why they are being verified; we only carry out the check. That makes you the controller and us the processor, and it is governed by the Data Processing Agreement rather than by this policy.
02Data about you, and why we hold it
- Account data: name, email address, password hash, and whether the address has been confirmed. Held to give you an account at all. Legal basis: performance of a contract.
- Billing data: company name, VAT number, billing address, and the payment records our payment processor returns to us. We never see or store your full card number. Legal basis: contract and our legal obligation to keep accounting records.
- Usage data: credits granted and consumed, the lists you have uploaded and their summary outcomes, API keys and when they were last used. Legal basis: contract, and our legitimate interest in operating and metering the Service.
- Security data: a keyed hash of your IP address, your user agent, sign-in events, rate-limit counters and an audit log of security-relevant actions. We hash rather than store raw IP addresses so the record is useful for abuse analysis without being a location history. Legal basis: legitimate interest in keeping the Service secure.
- Support data: what you write to us, and our replies. Legal basis: legitimate interest in answering you.
- Marketing data: if you opt in, your email address and whether you have opened or clicked. Legal basis: consent, withdrawable at any time.
03Data you send us to verify
When you verify an address, it passes through our pipeline and is used to produce a result. For a single check made in the dashboard, we keep the address alongside its verdict so your billing history can show what a credit was spent on; that record is deleted after 30 days.
For a bulk list, the addresses are not stored in our application database at all. They exist in the generated report files, which sit outside the web root, are reachable only through an authenticated route that checks ownership, and are deleted when the report's retention window expires, which is 30 days by default.
What we do keep beyond that is aggregate: how many addresses came back safe, risky, invalid or unknown on a given day, and which domains you check most often. These are counts, not addresses.
We do not use addresses you submit to build a directory, to enrich a dataset we sell, or for any purpose other than returning your result and the aggregate statistics described above.
04The free check on our home page
You can verify an address without an account. To keep that offer from being turned into a free bulk service, we set a signed, HttpOnly cookie identifying the browser and record a keyed hash of your IP address.
We log the check itself as a salted hash of the address plus its domain: enough to notice someone enumerating a single domain, and not enough to reconstruct who was checked. Legal basis: legitimate interest in preventing abuse of a free service.
05Cookies
We use a small number of first-party cookies. The strictly necessary ones (your session, cross-site request forgery protection, the guest identifier described above, and the record of your cookie choice) are set without consent because the Service cannot function without them.
Your language preference is stored in a cookie so the site opens in the language you last chose. Cloudflare Turnstile, which protects the free checker from automation, may set its own cookies when it challenges a request.
If you accept the optional category in the cookie notice, Google Analytics is loaded and sets its own cookies to measure which pages are used. Nothing is requested from Google until you accept, and refusing leaves the site fully usable. We run no advertising or retargeting pixels. The Cookie Policy sets out each cookie, its purpose and its lifetime.
06Who else sees your data
We share personal data only with the service providers we need in order to run the Service, and only to the extent each one needs. Every one of them is under a written contract that limits them to processing on our instructions.
The current register (who they are, what they handle and where) is published on our Sub-processors page and kept up to date.
We do not sell personal data, and we do not share it for anyone else's marketing. We disclose data to a public authority only where we are legally obliged to, and where the law permits we will tell you first.
07Where your data is processed
Our infrastructure is in the European Union and personal data is processed there by default.
A small number of the providers listed in our sub-processor register operate outside the EEA. Where data reaches them, the transfer is made under the European Commission's Standard Contractual Clauses together with the technical measures (encryption in transit, minimisation of what is sent) described in the register, and we assess each such transfer before it begins.
08How long we keep things
- Account and billing records: for the life of the account, then for as long as Romanian accounting law requires us to retain invoices.
- Single-check history, including the address checked: 30 days.
- Generated bulk reports and the addresses inside them: 30 days by default, or a shorter window if you configure one.
- Aggregate verification statistics: for the life of the account. These contain no addresses.
- Guest free-check logs: pruned once the abuse-prevention window has passed.
- Security audit logs: up to 12 months.
- Support correspondence: up to 24 months.
09How we protect it
Traffic is encrypted in transit. Passwords are stored as scrypt hashes, never in a recoverable form. The API key our platform holds on your behalf is encrypted at rest; the keys you generate for yourself are shown once and stored only as a prefix, which is why we cannot re-reveal one and can only replace it.
Access to production data is limited to the people who need it to operate the Service, and security-relevant actions are recorded in an audit log that is separate from application logging.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the Romanian supervisory authority within 72 hours of becoming aware of it, and tell you directly where the risk is high.
10Your rights
Under the GDPR you may ask for a copy of your personal data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing we base on legitimate interests, and receive your data in a portable format. Where we rely on consent, you may withdraw it at any time without affecting what was done beforehand.
Write to [email protected] and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm your identity first, not as an obstacle, but because handing someone else's data to the wrong person is itself a breach.
If you are unhappy with how we have handled a request you may complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), or to the supervisory authority where you live or work.
If it is our customer, rather than us, who decides why your address was verified, we will pass your request to them and support them in answering it; that is the right route, because they hold the context that makes an answer meaningful.
11Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
12Automated decisions
The verdict a verification returns is produced automatically. It is a statement about a mailbox, not a decision about a person, and it produces no legal or similarly significant effect on the person whose address was checked.
How our customers act on that verdict is their decision, taken in their own systems. We do not carry out profiling of visitors or customers for the purpose of automated decision-making.
13Changes to this policy
We update this policy when our practices change. The revision date at the top always reflects the current version, and material changes are announced by email to account holders before they take effect.
14Contact
Write to [email protected], or by post to BounceIntel, Bulevardul Republicii 363, Vaslui 730121, Romania. Privacy questions are handled by the same address; they are not routed to a queue that never answers.