This policy explains what VerifyPro Technologies Ltd. does with personal data. It covers two different roles we hold at the same time, and the difference between them decides who you should ask about what.
1. The two roles
We are a processor for the email addresses our customers submit for verification and for the results derived from them. We hold that data on a customer's documented instruction, we do not decide what it is for, and we do not use it for anything of our own.
We are a controller for account, user, billing, invoice, sign-in and telemetry data; for our own marketing and prospect data; and for the aggregate domain-level intelligence datasets our detection engine depends on.
2. What we hold, and under what basis
| Data | Our role | Basis | Kept for |
|---|---|---|---|
| Addresses submitted for verification | Processor | Our customer's basis, warranted by them | Their retention setting; deleted or returned at contract end |
| Verification results | Processor | Our customer's basis | As above; erasable on their instruction |
| Account, user, billing and invoice data | Controller | Contract, plus legal obligation for tax records | Contract term; tax records for the statutory period |
| Sign-in logs and security telemetry | Controller | Legitimate interest — account security | Rolling security-retention window |
| Domain reputation and provider-behaviour datasets | Controller | Legitimate interest — anti-abuse and network security | Indefinitely; they contain no address-level personal data |
| Suppression register (irreversible hash of an address) | Controller | Legal obligation, plus legitimate interest | Permanent by design — see section 5 |
3. What we never do with submitted addresses
- We do not market to them.
- We do not sell them, rent them or build an enrichment product from them.
- We do not train models on address-level data.
- We do not reuse one customer's addresses to answer another customer's question.
- We do not send them to a third-party verifier unless the customer has explicitly switched that on. The default is deny, and while it is denied nothing leaves — not in bulk, and not as a single spot check.
4. Who else processes data
Our sub-processors are published at https://server.canopusitsolutions.com/sub-processors, with the country each processes in and the transfer mechanism relied on. Adding one, or changing what it receives or where it processes, is notified at least 30 calendar days in advance, and customers may object during that window.
5. If you did not sign up and your address was verified
You can ask us directly, at privacy@verifypro.example, to stop processing your address and to have verification data about it deleted.
Because we are a processor for that data, the request runs on two tracks:
- Immediately: we add an irreversible keyed hash of your address to a global suppression register. From that moment the address is refused everywhere on the platform — by every customer, on every upload, permanently — and no verification is performed on it again. The register stores no plaintext and cannot be reversed into an address list. It is itself exempt from erasure, because deleting it would defeat the protection it provides.
- Then: we notify the customers holding data about you and delete it, unless one of them lodges a documented objection within 14 calendar days — a right their contract with us gives them as the controller of that data. If one does, we will tell you who they are so you can exercise your rights against them directly.
Where we are the controller — you have an account with us — we answer directly, with no second track.
6. Your rights
Access, rectification, erasure, restriction, portability and objection, under the data-protection law that applies to you. Write to privacy@verifypro.example. We answer within one month, and we will tell you if we need to extend that and why. You also have the right to complain to your supervisory authority.
7. Security
Encryption in transit and at rest, tenant isolation enforced at the query layer rather than by convention, least-privilege role-based access, enforced multi-factor authentication for staff, and an append-only audit log with a tamper-evident chain. Security reports: security@verifypro.example.
8. International transfers
Where data leaves its region of origin we rely on the mechanism named against each recipient in the sub-processor register — Standard Contractual Clauses with the UK Addendum where applicable, or an adequacy decision. The register is the authoritative list; this policy does not restate it, so the two cannot disagree.
9. Changes
This document is versioned and dated at the top of the page. Material changes are announced in-product. Because this policy describes what we do rather than binding you to an obligation, it is notice-only: it does not gate your use of the service.
10. Contact
Data protection enquiries: dpo@verifypro.example. Postal: Registered office address on file with the registrar.