Version 1.0
Effective from 2026-01-01
Artefact type privacy_policy
Content hash (SHA-256) fbcfe20298beb40879814fc9d58a3ad6…

This policy explains what VerifyPro Technologies Ltd. does with personal data. It covers two different roles we hold at the same time, and the difference between them decides who you should ask about what.

1. The two roles

We are a processor for the email addresses our customers submit for verification and for the results derived from them. We hold that data on a customer's documented instruction, we do not decide what it is for, and we do not use it for anything of our own.

We are a controller for account, user, billing, invoice, sign-in and telemetry data; for our own marketing and prospect data; and for the aggregate domain-level intelligence datasets our detection engine depends on.

2. What we hold, and under what basis

Data Our role Basis Kept for
Addresses submitted for verification Processor Our customer's basis, warranted by them Their retention setting; deleted or returned at contract end
Verification results Processor Our customer's basis As above; erasable on their instruction
Account, user, billing and invoice data Controller Contract, plus legal obligation for tax records Contract term; tax records for the statutory period
Sign-in logs and security telemetry Controller Legitimate interest — account security Rolling security-retention window
Domain reputation and provider-behaviour datasets Controller Legitimate interest — anti-abuse and network security Indefinitely; they contain no address-level personal data
Suppression register (irreversible hash of an address) Controller Legal obligation, plus legitimate interest Permanent by design — see section 5

3. What we never do with submitted addresses

  • We do not market to them.
  • We do not sell them, rent them or build an enrichment product from them.
  • We do not train models on address-level data.
  • We do not reuse one customer's addresses to answer another customer's question.
  • We do not send them to a third-party verifier unless the customer has explicitly switched that on. The default is deny, and while it is denied nothing leaves — not in bulk, and not as a single spot check.

4. Who else processes data

Our sub-processors are published at https://server.canopusitsolutions.com/sub-processors, with the country each processes in and the transfer mechanism relied on. Adding one, or changing what it receives or where it processes, is notified at least 30 calendar days in advance, and customers may object during that window.

5. If you did not sign up and your address was verified

You can ask us directly, at privacy@verifypro.example, to stop processing your address and to have verification data about it deleted.

Because we are a processor for that data, the request runs on two tracks:

  • Immediately: we add an irreversible keyed hash of your address to a global suppression register. From that moment the address is refused everywhere on the platform — by every customer, on every upload, permanently — and no verification is performed on it again. The register stores no plaintext and cannot be reversed into an address list. It is itself exempt from erasure, because deleting it would defeat the protection it provides.
  • Then: we notify the customers holding data about you and delete it, unless one of them lodges a documented objection within 14 calendar days — a right their contract with us gives them as the controller of that data. If one does, we will tell you who they are so you can exercise your rights against them directly.

Where we are the controller — you have an account with us — we answer directly, with no second track.

6. Your rights

Access, rectification, erasure, restriction, portability and objection, under the data-protection law that applies to you. Write to privacy@verifypro.example. We answer within one month, and we will tell you if we need to extend that and why. You also have the right to complain to your supervisory authority.

7. Security

Encryption in transit and at rest, tenant isolation enforced at the query layer rather than by convention, least-privilege role-based access, enforced multi-factor authentication for staff, and an append-only audit log with a tamper-evident chain. Security reports: security@verifypro.example.

8. International transfers

Where data leaves its region of origin we rely on the mechanism named against each recipient in the sub-processor register — Standard Contractual Clauses with the UK Addendum where applicable, or an adequacy decision. The register is the authoritative list; this policy does not restate it, so the two cannot disagree.

9. Changes

This document is versioned and dated at the top of the page. Material changes are announced in-product. Because this policy describes what we do rather than binding you to an obligation, it is notice-only: it does not gate your use of the service.

10. Contact

Data protection enquiries: dpo@verifypro.example. Postal: Registered office address on file with the registrar.