Last updated: July 2026
VerifyBuddy is built to help you meet your obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR. This page summarises how we handle personal data and how we support your compliance.
For the personal data in the email lists you verify, you are the data controller and VerifyBuddy is the data processor, acting on your documented instructions. For your own account data (name, email, billing), we are the controller.
We process the email addresses you submit solely to perform verification and return a result to you. We do not use your lists to build our own databases, we do not sell or share them, and we do not email the addresses you verify.
We store only what is needed to deliver the service. Verification results are retained per your plan and can be deleted on request. Free-plan results are automatically pruned after 90 days.
You can access, export, correct or delete your personal data at any time from your account settings, or by contacting us. We respond to data-subject access requests within statutory timeframes. Account deletion triggers a full erasure of your workspace after a short grace period.
A Data Processing Agreement (DPA) is available to all customers. See our DPA & Sub-processors page for the list of sub-processors and international-transfer safeguards (Standard Contractual Clauses where applicable).
All data is encrypted in transit (TLS) and at rest. Access is role-based and audited. See our Security page for details.
VerifyBuddy never sends email to the addresses you verify — our SMTP checks stop before the message body is ever transmitted. You are responsible for ensuring you have a lawful basis to contact the people on your lists.
For any GDPR or privacy request, contact privacy@verifybuddy.xyz.