Legal

GDPR

· BounceIntel · Bulevardul Republicii 363, Vaslui 730121, Romania

An email address is personal data. Verifying one is therefore processing, and it needs a lawful basis, a defined purpose and a retention period like any other processing.

This page sets out how we meet our side of that, and (because it is the part customers most often get wrong) what you need in place on yours.

01Who is what

For the addresses you submit, you are the controller: you decided to collect them, you decided they should be verified, and you decide what happens to the result. We are your processor.

For your own account and billing data we are the controller in our own right, and that processing is described in the Privacy Policy.

Our establishment is BounceIntel, Bulevardul Republicii 363, Vaslui 730121, Romania, which makes the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) our lead supervisory authority.

02Your lawful basis for verifying

We cannot supply your lawful basis; only you can. In practice most customers rely on legitimate interests (keeping a contact database accurate and protecting sender reputation are well-recognised examples), but that requires a balancing assessment you can produce if asked.

Verification must also be compatible with the purpose for which the address was collected. Checking whether a mailbox you already hold is still live is normally compatible. Verifying a list you bought, scraped, or received without a lawful basis is not, and no amount of care on our side fixes it.

You should reference verification in your own privacy notice, and name us (or the category of provider) among your recipients.

03Data minimisation, in practice

The API needs an address. It does not need a name, a company, a phone number or a customer identifier, and our uploader deliberately extracts only addresses from whatever file you drop on it, ignoring every other column.

For bulk lists we do not store the addresses in our database at all: they live only in the generated report, which expires. That is a design decision made so that deleting a report genuinely deletes the personal data rather than leaving a second copy behind.

04The processing we carry out

  • Subject matter: verification of email addresses supplied by the controller.
  • Duration: for as long as the account is active, plus the retention windows set out in the Data Processing Agreement.
  • Nature and purpose: syntax parsing, DNS and MX resolution, SMTP interrogation of the receiving mail server, risk scoring, and the production of results and reports.
  • Type of personal data: email addresses, and any personal data a controller chooses to include in an address's local part or domain.
  • Categories of data subject: the controller's contacts, subscribers, customers, applicants or users.
  • No special category data is required, expected or requested.

05Our obligations as processor

We process only on your documented instructions (your API calls and uploads are those instructions), and we tell you if an instruction appears to breach data protection law rather than carrying it out silently.

Everyone with access is bound by confidentiality. We keep appropriate technical and organisational measures, engage sub-processors only under equivalent written terms, and maintain the public register of who they are.

We assist you with data subject requests, with breach notification, and with a data protection impact assessment where you need one. On termination we delete or return the personal data, subject to any retention the law requires of us.

06Data subject requests reaching us

If someone whose address one of our customers verified contacts us directly, we will not act on the request ourselves: we are not the controller and we do not hold the context. We will identify the customer concerned, pass the request on, and help them answer it.

Requests about your own account data, where we are the controller, are handled by us directly and answered within one month.

07International transfers

Verification is performed in the European Union. Where a sub-processor listed in our register operates outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses together with supplementary technical measures, and is assessed before it begins.

08Records and accountability

We maintain a record of processing activities carried out on behalf of controllers, as Article 30(2) requires, and can make the relevant extract available to a customer who needs it for their own compliance file.

We have not appointed a statutory Data Protection Officer, because our processing does not meet the Article 37 thresholds that require one. Privacy questions go to [email protected] and are answered there.

09Getting a signed DPA

Our Data Processing Agreement is incorporated into the Terms of Service and applies automatically when you use the Service; you do not need to sign anything for it to bind us.

If your procurement process requires a countersigned copy, or you need the Standard Contractual Clauses executed as a separate instrument, write to [email protected] and we will arrange it.