GDPR Compliance
We are committed to protecting your privacy and complying with the European Union's General Data Protection Regulation (GDPR). Learn about your rights and how we protect your data.
Your Data Protection Rights Under GDPR
The General Data Protection Regulation (GDPR) gives EU residents comprehensive rights over their personal data. As a responsible data processor, we ensure full compliance with GDPR requirements and make it easy for you to exercise your rights.
Lawfulness
Legal basis for all data processing
Transparency
Clear information about data use
Purpose Limitation
Data used only for stated purposes
Data Minimization
Only necessary data collected
Accuracy
Data kept accurate and up-to-date
Storage Limitation
Data retained only when necessary
Your Data Protection Rights
Under GDPR, you have comprehensive rights regarding your personal data. We make it easy to exercise these rights.
Right to Information
You have the right to know what personal data we collect, how it's used, who we share it with, and how long we keep it.
What this means:
- Transparent privacy notices
- Clear purpose for data collection
- Information about data recipients
- Details about retention periods
Right of Access
You can request a copy of all personal data we hold about you, including how it's being processed.
What you'll receive:
- Copy of your personal data
- Processing purposes
- Categories of recipients
- Retention periods
- Your other GDPR rights
Right to Rectification
You can request correction of inaccurate personal data and completion of incomplete data.
When to use:
- Incorrect personal information
- Outdated contact details
- Incomplete account data
- Wrong billing information
Right to Erasure
Also known as the "right to be forgotten" - you can request deletion of your personal data in certain circumstances.
When applicable:
- Data no longer necessary for original purpose
- You withdraw consent
- Data processed unlawfully
- Compliance with legal obligation
Right to Restrict Processing
You can request that we limit how we use your personal data in certain situations.
Available when:
- Accuracy of data is contested
- Processing is unlawful
- Data no longer needed but you need it for legal claims
- Objection to processing is pending
Right to Data Portability
You can receive your personal data in a structured, commonly used format and transmit it to another controller.
Includes:
- Machine-readable format (JSON, CSV)
- Account information
- Verification history
- Usage statistics
Right to Object
You can object to processing of your personal data based on legitimate interests, direct marketing, or research.
Object to:
- Marketing communications
- Profiling for marketing
- Processing based on legitimate interests
- Research and statistical purposes
Rights Related to Automated Decision-Making
Protection against decisions based solely on automated processing, including profiling, that significantly affect you.
Our approach:
- No fully automated decisions affecting you
- Human review of significant decisions
- Transparent criteria for any profiling
- Right to explanation of automated decisions
How We Process Your Data
Understanding our data processing activities and legal bases
Account Data
What we collect:
Name, email address, company information, billing details
Legal basis:
Contract Performance - Necessary to provide our services
Retention period:
Until account deletion + 30 days for recovery
Recipients:
Payment processors, cloud infrastructure providers
Email Verification Data
What we collect:
Email addresses submitted for verification (processed temporarily)
Legal basis:
Contract Performance - Core service functionality
Retention period:
Immediately deleted after verification (no storage)
Recipients:
Email servers (for verification only), no third parties
Usage Analytics
What we collect:
API usage, feature usage, performance metrics (anonymized)
Legal basis:
Legitimate Interest - Service improvement and optimization
Retention period:
2 years (anonymized after 6 months)
Recipients:
Analytics providers (Google Analytics with anonymization)
Communication Data
What we collect:
Support requests, feedback, correspondence records
Legal basis:
Contract Performance - Customer support and service improvement
Retention period:
3 years for quality assurance and legal compliance
Recipients:
Customer support platforms, internal support team only
Billing Data
What we collect:
Payment information, billing history, invoice data
Legal basis:
Legal Obligation - Tax and accounting requirements
Retention period:
7 years for legal and tax compliance
Recipients:
Payment processors (Stripe, PayPal), accounting firms
Marketing Data
What we collect:
Email preferences, newsletter subscriptions, marketing interactions
Legal basis:
Consent - Explicit opt-in for marketing communications
Retention period:
Until consent is withdrawn or 3 years of inactivity
Recipients:
Email marketing platforms (with appropriate safeguards)
Exercise Your GDPR Rights
We make it easy to exercise your data protection rights. Choose the option that works best for you.
Request Process
Submit Request
Submit your request via email with identity verification
Verification & Review
We verify your identity and review your request within 3 business days
Processing & Response
We process your request and provide a complete response within 30 days
International Data Transfers
When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place to protect your data.
Standard Contractual Clauses (SCCs)
EU Commission approved contractual terms ensuring GDPR-level protection
Privacy Shield Certification
US service providers certified under EU-US Privacy Shield framework
Adequacy Decisions
Transfers to countries with EU adequacy decisions (Canada, Japan, etc.)
Technical & Organizational Measures
Additional security measures including encryption and access controls
Data Processing Locations
United States
Processing: Cloud infrastructure, support, data processing
Safeguards: Standard Contractual Clauses (SCCs), encryption, access controls
Data Protection Officer
Our appointed DPO is available to help with all data protection matters, GDPR compliance questions, and privacy concerns.
BulkEmailVerification.com
P.O. Box 12 Norwood, NJ 07648
United States of America