Version 1.0
Effective from 2026-01-01
Artefact type dpa
Governing jurisdiction EU
Content hash (SHA-256) 0587ab12eaaefc9e41b601d53d68ca7b…
This artefact is re-acceptance gated.

When we publish a material change to it, existing customers are asked to accept the new version. Until they do — after a 30-day grace period — bulk upload, API bulk submit and connector sync are blocked. Reading data, downloading existing exports and downloading invoices are never blocked.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer", acting as controller) and VerifyPro Technologies Ltd. (the "Processor"). It is accepted by clickwrap on every plan. Enterprise customers may counter-sign a negotiated paper version; this one remains in force until that is executed.

1. Subject matter, duration, nature and purpose

Subject matter Email address verification and list hygiene.
Duration The term of the subscription, plus the retention windows in section 8.
Nature and purpose Syntax, DNS, MX, SMTP and risk-signal evaluation of Customer-supplied addresses.
Type of personal data Email addresses; and any optional columns the Customer chooses to include in an upload (name, company, custom fields).
Categories of data subject The Customer's contacts, subscribers, leads and employees.

2. Documented instructions

We process personal data only on the Customer's documented instructions, which are: this DPA, the Terms, and the configuration of each job the Customer submits. We will tell the Customer if an instruction appears to us to infringe applicable data-protection law, and we may suspend the processing concerned until it is resolved.

2.1 Standing instruction on data-subject requests

The Customer instructs us to suppress platform-wide, and — absent a documented objection lodged within 14 calendar days of notice — to delete, verification data for any individual who exercises a right of erasure or objection directly with us. Without this standing instruction we could not answer such a person at all without breaching the documented-instructions duty above.

3. Confidentiality

Every member of our staff with access to personal data is under a written confidentiality obligation, and access is granted on a least-privilege basis and logged.

4. Security

We implement the measures required by Article 32, including: encryption in transit and at rest; tenant isolation enforced at the data-access layer; enforced multi-factor authentication for staff; an append-only, tamper-evident audit log; and separation of the verification network from the application estate.

5. Sub-processors

The Customer gives general written authorisation for us to engage sub-processors. The current list is published at https://server.canopusitsolutions.com/sub-processors.

  • Adding a sub-processor, or changing the data categories it receives or the country it processes in, is notified to the Customer's billing and security contacts at least 30 calendar days before it may receive any data.
  • The Customer may object in writing during that window. We will exclude the Customer from that sub-processor where technically possible — always possible for backup verification providers and for quality sampling.
  • Where exclusion is not possible, the Customer may terminate with a pro-rata refund of unused paid credits and prepaid subscription, and no early-termination charge.
  • A sub-processor in a proposed or notice-period state is technically unreachable in our systems, not merely unused.

6. Third-party verification is opt-in

Some sub-processors are direct competitors used only as emergency failover. The Customer's setting for this defaults to deny and can be changed only by an organisation owner. While it is denied, no address of the Customer is dispatched to any third-party verifier in any volume, including single-address checks. A verification that could only have been completed that way returns unknown and is not billed.

7. Assistance

  • Articles 12–22: we assist with data-subject requests through the in-product erasure tooling and the privacy API, and by executing the standing instruction in section 2.1.
  • Articles 32–36: we notify the Customer without undue delay after becoming aware of a personal-data breach affecting their data, with the information available to us at the time and updates as we learn more. We support the Customer's data-protection impact assessments with the documentation in our audit pack.

8. Deletion or return

At the end of the contract the Customer chooses deletion or return. The default is deletion after a 30-day return window, during which export and download remain fully available.

Deletion removes all data we hold as processor. It does not remove the aggregate domain-level intelligence datasets described in the Privacy Policy: those are ours as controller, contain no address-level personal data, and survive a tenant's exit. It also does not remove the suppression register, which stores an irreversible hash and exists so that a person who asked to be left alone stays left alone after the Customer has gone.

9. Audit

We provide an annual evidence pack on request. In addition the Customer may conduct one audit per year, on-site or remote, at the Customer's cost, on 30 days' written notice.

10. International transfers

Where a transfer requires them, the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Modules Two and Three as applicable, together with the UK International Data Transfer Addendum, are incorporated into this DPA and executed between the parties. The mechanism relied on for each recipient is named in the sub-processor register.

11. Liability

The liability provisions of the Terms of Service apply to this DPA and are not increased by it.

12. Contact

Data-protection contact: dpo@verifypro.example. Breach and security contact: security@verifypro.example.