GDPR Compliance

We are committed to protecting your privacy and complying with the European Union's General Data Protection Regulation (GDPR). Learn about your rights and how we protect your data.

GDPR Compliant

Your Data Protection Rights Under GDPR

The General Data Protection Regulation (GDPR) gives EU residents comprehensive rights over their personal data. As a responsible data processor, we ensure full compliance with GDPR requirements and make it easy for you to exercise your rights.

We process data lawfully, fairly, and transparently
We collect data for specified, explicit purposes only
We implement appropriate technical and organizational measures
We respect your rights and respond to requests promptly

Lawfulness

Legal basis for all data processing

Transparency

Clear information about data use

Purpose Limitation

Data used only for stated purposes

Data Minimization

Only necessary data collected

Accuracy

Data kept accurate and up-to-date

Storage Limitation

Data retained only when necessary

Your Data Protection Rights

Under GDPR, you have comprehensive rights regarding your personal data. We make it easy to exercise these rights.

Right to Information

You have the right to know what personal data we collect, how it's used, who we share it with, and how long we keep it.

What this means:

  • Transparent privacy notices
  • Clear purpose for data collection
  • Information about data recipients
  • Details about retention periods
How to exercise: Review our Privacy Policy

Right of Access

You can request a copy of all personal data we hold about you, including how it's being processed.

What you'll receive:

  • Copy of your personal data
  • Processing purposes
  • Categories of recipients
  • Retention periods
  • Your other GDPR rights
Response time: Within 30 days

Right to Rectification

You can request correction of inaccurate personal data and completion of incomplete data.

When to use:

  • Incorrect personal information
  • Outdated contact details
  • Incomplete account data
  • Wrong billing information
How to exercise: Update account or contact us

Right to Erasure

Also known as the "right to be forgotten" - you can request deletion of your personal data in certain circumstances.

When applicable:

  • Data no longer necessary for original purpose
  • You withdraw consent
  • Data processed unlawfully
  • Compliance with legal obligation
Note: Some data may be retained for legal compliance

Right to Restrict Processing

You can request that we limit how we use your personal data in certain situations.

Available when:

  • Accuracy of data is contested
  • Processing is unlawful
  • Data no longer needed but you need it for legal claims
  • Objection to processing is pending
Effect: Data stored but not processed

Right to Data Portability

You can receive your personal data in a structured, commonly used format and transmit it to another controller.

Includes:

  • Machine-readable format (JSON, CSV)
  • Account information
  • Verification history
  • Usage statistics
Format: JSON or CSV export

Right to Object

You can object to processing of your personal data based on legitimate interests, direct marketing, or research.

Object to:

  • Marketing communications
  • Profiling for marketing
  • Processing based on legitimate interests
  • Research and statistical purposes
Result: Processing stops unless compelling grounds exist

Rights Related to Automated Decision-Making

Protection against decisions based solely on automated processing, including profiling, that significantly affect you.

Our approach:

  • No fully automated decisions affecting you
  • Human review of significant decisions
  • Transparent criteria for any profiling
  • Right to explanation of automated decisions
Protection: Human oversight required

How We Process Your Data

Understanding our data processing activities and legal bases

Account Data

What we collect:

Name, email address, company information, billing details

Retention period:

Until account deletion + 30 days for recovery

Recipients:

Payment processors, cloud infrastructure providers

Email Verification Data

What we collect:

Email addresses submitted for verification (processed temporarily)

Retention period:

Immediately deleted after verification (no storage)

Recipients:

Email servers (for verification only), no third parties

Usage Analytics

What we collect:

API usage, feature usage, performance metrics (anonymized)

Retention period:

2 years (anonymized after 6 months)

Recipients:

Analytics providers (Google Analytics with anonymization)

Communication Data

What we collect:

Support requests, feedback, correspondence records

Retention period:

3 years for quality assurance and legal compliance

Recipients:

Customer support platforms, internal support team only

Billing Data

What we collect:

Payment information, billing history, invoice data

Retention period:

7 years for legal and tax compliance

Recipients:

Payment processors (Stripe, PayPal), accounting firms

Marketing Data

What we collect:

Email preferences, newsletter subscriptions, marketing interactions

Retention period:

Until consent is withdrawn or 3 years of inactivity

Recipients:

Email marketing platforms (with appropriate safeguards)

Exercise Your GDPR Rights

We make it easy to exercise your data protection rights. Choose the option that works best for you.

Online Portal

Use our self-service data rights portal to submit requests and track their status.

✓ Instant request submission
✓ Real-time status tracking
✓ Secure identity verification
✓ Download your data
Access Portal

Email Request

Send your data rights request directly to our Data Protection Officer via email.

✓ Detailed request handling
✓ Personal assistance
✓ Complex requests supported
✓ Response within 30 days
Email DPO

Request Process

1

Submit Request

Submit your request via email with identity verification

2

Verification & Review

We verify your identity and review your request within 3 business days

3

Processing & Response

We process your request and provide a complete response within 30 days

International Data Transfers

When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place to protect your data.

Standard Contractual Clauses (SCCs)

EU Commission approved contractual terms ensuring GDPR-level protection

Privacy Shield Certification

US service providers certified under EU-US Privacy Shield framework

Adequacy Decisions

Transfers to countries with EU adequacy decisions (Canada, Japan, etc.)

Technical & Organizational Measures

Additional security measures including encryption and access controls

Data Processing Locations

🇺🇸

United States

Processing: Cloud infrastructure, support, data processing

Safeguards: Standard Contractual Clauses (SCCs), encryption, access controls

Data Security Measures

We implement comprehensive security measures for all data processing:

  • End-to-end encryption for data in transit and at rest
  • Secure cloud infrastructure with access controls
  • Regular security audits and compliance monitoring
  • Data minimization and retention policies
Learn About Security

Data Protection Officer

Our appointed DPO is available to help with all data protection matters, GDPR compliance questions, and privacy concerns.

Address: Data Protection Officer
BulkEmailVerification.com
P.O. Box 12 Norwood, NJ 07648
United States of America
Response Time: Within 48 hours for GDPR requests

DPO Qualifications

Certified Information Privacy Professional/Europe (CIPP/E)
Certified Information Privacy Manager (CIPM)
GDPR Practitioner Certificate
LLM in Data Protection Law