← Back to home

Data Processing Agreement

Last updated: September 3, 2026

This agreement governs how we handle the personal data you upload to FullyVerify. It forms part of our Terms of Service and applies automatically when you use the service — you do not need to sign a separate copy, though we will sign one on request.

1. Roles

When you upload a list of email addresses, those addresses are personal data about people who are not you. In that relationship:

  • You are the controller. You decide whose addresses to submit, and why. You are responsible for having a lawful basis to do it.
  • We are the processor. We act only on your instructions, and uploading a job is your instruction to verify those addresses with the providers in the bundle you chose.
  • The verification providers are sub-processors. They are listed in section 7.

For your own account data — your name, email and billing history — we are the controller, and our Privacy Policy governs it instead. Under PIPEDA, which does not use the controller/processor split, we remain accountable for personal information transferred to a sub-processor for processing and use contractual means to give it comparable protection.

2. What we process

  • Categories of data: email addresses, and any additional column you choose to include in an uploaded file.
  • Categories of people: whoever the addresses belong to — typically your subscribers, leads, customers or contacts.
  • Purpose: checking deliverability with each provider in your bundle, and returning their verdicts to you.
  • Duration: as set out in section 6.

FullyVerify is not built for special category data, health data, financial account data or government identifiers. Do not upload them.

3. Our commitments

  • We process uploaded data only on your documented instructions, and only to provide the service.
  • We do not sell uploaded addresses, market to them, add them to any shared or cross-customer database, or use them to train models.
  • People with access to the data are bound by confidentiality obligations, and access is limited to those who need it.
  • We keep appropriate technical and organisational security measures, described in section 5.
  • We help you respond to requests from individuals exercising their rights, and we help you with impact assessments and breach notifications so far as is reasonable given what we know.
  • If we believe an instruction from you would breach data protection law, we will tell you rather than carry it out.

4. Your commitments

  • You have a lawful basis to collect each address and to have it verified, and you have given whatever notice your own privacy policy and applicable law require.
  • The addresses were not obtained by address-harvesting software or by any other means CASL, the GDPR or PIPEDA prohibit.
  • Your instructions to us will not put us in breach of applicable law.

5. Security

  • Data is encrypted in transit.
  • Provider API credentials are held only in server-side environment variables and are never exposed to the browser.
  • Authentication is delegated to Clerk; we never hold your password.
  • Every data-access path checks that the requesting account owns the row it is asking for.
  • Access to production data is limited to those who need it for operations and support.

6. Retention and deletion

  • The raw uploaded list is held only while the job needs it and is deleted automatically once the job finishes or fails.
  • Verification results remain available while your account is open, so you can revisit and export past jobs. Email us to have a specific job’s results erased sooner.
  • Deleting your account cascades through our database and removes your jobs, results, bundles, orders and feedback, including every uploaded address held in them.
  • Sub-processors retain data under their own policies. Deleting data here does not automatically delete it at a provider; tell us if you need us to request erasure from a specific provider.

7. Sub-processors

Verification necessarily discloses an address to the providers you selected. An address is only ever sent to the providers in the bundle you chose for that job — never to the others.

Verification providers

  • ZeroBounce — United States
  • NeverBounce — United States
  • Emailable — United States
  • MillionVerifier — European Union
  • Bouncer — Poland
  • Hunter — France
  • IcyPeas — France
  • EmailListVerify — European Union
  • Clearout — India

Infrastructure providers

  • Convex — application database and backend hosting
  • Vercel — web application hosting
  • Clerk — authentication and user management
  • Stripe — payment processing (billing data only)
  • Resend — transactional email (your address only)

Infrastructure sub-processors never receive uploaded addresses except Convex, which stores them as the application database.

Changes. We will give you at least 30 days notice before adding a new sub-processor that handles uploaded addresses. If you object on reasonable data protection grounds, tell us within that period and we will either exclude the provider from your bundles or let you stop using the affected bundles and refund the credits you cannot use.

8. International transfers

We are in Canada; our sub-processors are in Canada, the United States, the European Union and India. The European Commission recognises Canada as providing adequate protection for personal data handled by organisations subject to PIPEDA, so EEA and UK transfers to us need no separate safeguard. Onward transfers to sub-processors outside Canada are made under standard contractual clauses or an equivalent mechanism. Where Quebec’s Law 25 applies, we assess a transfer outside Quebec before making it.

9. Breaches

If we become aware of a personal data breach affecting data you uploaded, we will notify you without undue delay, with what we know about the nature and scope of the breach and the steps we are taking, so that you can meet your own notification duties. We also report to the Office of the Privacy Commissioner of Canada where PIPEDA requires it, and keep a record of every breach.

10. Audits

We will provide the information reasonably needed to demonstrate we are meeting this agreement, and will respond to a security questionnaire once a year. If you require an on-site audit, we will agree scope and timing in advance and you cover the reasonable cost.

11. Liability and term

This agreement is subject to the limitation of liability in our Terms of Service. It lasts as long as we process personal data on your behalf, and the obligations that by their nature should survive termination do so.

12. Contact

Our privacy officer: privacy@fullyverify.com. Ask us there for a countersigned copy of this agreement.