Version 1.0
Effective from 2026-01-01
Artefact type aup
Content hash (SHA-256) 7408f55b123553dcab46988d831e317d…
This artefact is re-acceptance gated.

When we publish a material change to it, existing customers are asked to accept the new version. Until they do — after a 30-day grace period — bulk upload, API bulk submit and connector sync are blocked. Reading data, downloading existing exports and downloading invoices are never blocked.

This policy is part of the Terms of Service. It exists because verification runs over shared infrastructure: your uploads travel through the same IP reputation every other customer's verifications depend on. A rule below that looks strict is usually protecting the accuracy of somebody else's results.

1. You must not submit

  • Addresses you have no lawful basis to process, or no right to submit for verification.
  • Lists purchased, scraped or otherwise acquired without the data subjects' knowledge, where the applicable law required it.
  • Addresses you know or suspect to be spam traps, submitted in order to test whether we detect them. This is the single fastest way to damage the network, and it is grounds for immediate suspension.
  • Deliberately malformed, adversarial or generated data intended to probe, benchmark or degrade the service rather than to verify a real list.
  • Files containing malware, or archives crafted to exhaust processing resources.
  • Addresses belonging to a person who has told us to leave them alone. Our suppression register enforces this automatically; attempting to work around it is a breach.

2. You must not

  • Use the service to build, enrich, validate or clean a list you intend to use for unsolicited bulk email in breach of the law that applies to the recipient.
  • Resell raw verification capacity outside a partner agreement with us.
  • Circumvent, or attempt to circumvent, rate limits, credit accounting, plan ceilings or tenant isolation.
  • Share API credentials across organisations, or use another organisation's credentials.
  • Probe our infrastructure for vulnerabilities without a written authorisation from us. Responsible disclosure is welcome at security@verifypro.example and we will not pursue anyone who reports in good faith and does not exfiltrate data.
  • Misrepresent our results — for example, publishing a "guaranteed deliverable" claim on the basis of a verification we returned as catch-all or unknown.

3. Volume and fairness

Plan ceilings on rows per job, requests per minute and concurrent jobs are enforced technically. You may ask for a higher ceiling; you may not engineer around the one you have. Sustained traffic that degrades service for other customers may be throttled, and we will tell you when we do it and why.

4. How we enforce this

  1. Automated protection. Uploads are screened before processing. A list whose risk profile suggests trap density or non-consensual acquisition is paused, not silently processed, and you are told what triggered it.
  2. Warning. For a first, non-urgent breach we contact your organisation's owner with what we saw and what needs to change.
  3. Suspension. For a breach causing or likely to cause harm to third parties or to the verification network, we suspend immediately and tell you why. Suspension stops ingest; it does not delete your data, and export remains available.
  4. Termination. For a repeated or deliberate breach. Unused paid credits are refunded under the Refund Policy unless the breach was fraudulent.

5. Appeals

Any enforcement action can be appealed by writing to support@verifypro.example. We log the reason for every suspension, so an appeal is answered against a recorded reason rather than against somebody's recollection.

6. Reporting abuse

If you believe an account is using the service in breach of this policy, tell us at security@verifypro.example. If your address was verified through us and you want it left alone permanently, write to privacy@verifypro.example — see the Privacy Policy, section 5.