GDPR Compliance

Last updated: July 2026

VerifyBuddy is built to help you meet your obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR. This page summarises how we handle personal data and how we support your compliance.

1. Roles

For the personal data in the email lists you verify, you are the data controller and VerifyBuddy is the data processor, acting on your documented instructions. For your own account data (name, email, billing), we are the controller.

2. Lawful basis & purpose limitation

We process the email addresses you submit solely to perform verification and return a result to you. We do not use your lists to build our own databases, we do not sell or share them, and we do not email the addresses you verify.

3. Data minimisation & retention

We store only what is needed to deliver the service. Verification results are retained per your plan and can be deleted on request. Free-plan results are automatically pruned after 90 days.

4. Your rights (DSAR)

You can access, export, correct or delete your personal data at any time from your account settings, or by contacting us. We respond to data-subject access requests within statutory timeframes. Account deletion triggers a full erasure of your workspace after a short grace period.

5. Data Processing Agreement

A Data Processing Agreement (DPA) is available to all customers. See our DPA & Sub-processors page for the list of sub-processors and international-transfer safeguards (Standard Contractual Clauses where applicable).

6. Security

All data is encrypted in transit (TLS) and at rest. Access is role-based and audited. See our Security page for details.

7. No unsolicited email

VerifyBuddy never sends email to the addresses you verify — our SMTP checks stop before the message body is ever transmitted. You are responsible for ensuring you have a lawful basis to contact the people on your lists.

8. Contact

For any GDPR or privacy request, contact privacy@verifybuddy.xyz.