01

Email deliverability platform with GDPR compliant email verification

This page exists for the security review. It states what data we hold, on what basis, who can reach it, how long it stays and what happens when someone asks to be removed.

02

Business contact data, in a professional context

The scope is deliberately narrow, because a narrow scope is what makes this defensible.

We do not process special category data. We do not build profiles of private individuals, we do not hold home addresses or phone numbers, and we do not run reverse lookups from an address to a person's private life.

  • Work email addresses, the company domain they belong to and the naming pattern of that domain.
  • The name and professional role of the person the address belongs to, where that is published.
  • Technical data about the domain: MX records, the detected mail provider and the catch-all status.
  • The verification result and the time it was produced.
04

Who on your side can do what

Control Starter Growth Scale Enterprise
Seats210UnlimitedUnlimited
Role based access controlNot includedNot includedIncludedIncluded
Team workspaces with per client separationNot includedNot includedIncludedIncluded
Audit log of searches, exports and API callsNot includedNot includedIncludedIncluded
SSO with SAMLNot includedNot includedNot includedIncluded
SCIM user provisioningNot includedNot includedNot includedIncluded
Configurable retention windowStandardStandardConfigurableCustom
Regional data residencyNot includedNot includedNot includedIncluded
05

How long data stays and where it lives

  • Search results and exports are held for the standard retention window on Starter and Growth, and for a window you configure on Scale.
  • Enterprise sets a custom retention window and a region for data residency.
  • Suppression entries are kept indefinitely on purpose, because their whole function is to stop an address returning.
  • Deleting your account removes your searches, your lists and your exports. It does not remove suppression entries, for the reason above.

The data processing agreement

Enterprise includes a data processing agreement covering us as processor for the data you bring, the subprocessors we use, the security measures in place and the breach notification timeline. It is signed before the first invoice, alongside the security questionnaire.

06

What Enterprise commits to in writing

  • A 99.9 percent uptime commitment with a named response window for incidents.
  • A named technical contact and an onboarding process.
  • Invoicing against a purchase order with net terms.
  • Support for your security questionnaire, answered by us rather than pointed at a portal.
07

Verification is a deliverability control, not just a data control

The security review usually asks about data. The marketing operations review asks about the sending domain, and this is the same purchase.

Mailbox providers score how often your domain sends to addresses that do not exist. Verification before the send keeps that number down, which keeps your mail in inboxes, which is the whole reason the campaign exists. That is why bulk email verification and scheduled re-verification are usually the first things an operations team turns on.