Legal · DPA

Data Processing Agreement

Last updated: 1 July 2026Effective: 1 July 2026Processor: EmailLabs

The short version

  • You're the controller, we're the processor — we only process data on your instructions.
  • We process verification requests transiently and don't store the addresses you submit or the results.
  • Sub-processors are bound by the same obligations; the current list is available on request.
  • Need a signed DPA? We have a standard agreement ready — just reach out.

1. Overview

This page summarises how EmailLabs, operated by EmailLabs, processes personal data on behalf of its customers. It forms the basis of our Data Processing Agreement ("DPA"), which supplements our Terms of Service and applies whenever we process personal data on your behalf as a processor under the GDPR and similar laws.

2. Roles of the parties

When you use EmailLabs to verify addresses, you are the data controller — you decide which addresses to submit and why. EmailLabs is the data processor, acting only on your documented instructions as expressed through your use of the service.

3. Scope of processing

  • Subject matter — verification of email addresses you submit via our API or dashboard.
  • Duration — for the length of your subscription, plus any short window required by law.
  • Nature & purpose — real-time deliverability checks and returning the result to you.
  • Types of data — email addresses and the technical signals derived during verification.
  • Data subjects — the individuals whose addresses you choose to verify.

4. Zero retention by design

The addresses you submit for verification are processed in memory and are not stored. Once we return a result, the input is discarded — we keep no verification history and no copies of the addresses or results on your behalf.

This data-minimising design substantially reduces your processing risk: there is no verification dataset for us to expose, breach, or be compelled to disclose. The only personal data we retain is the account information of your team members who log in.

5. Our commitments as processor

  • Process personal data only on your documented instructions.
  • Ensure people authorised to process data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Assist you, where relevant, with data subject requests and security obligations.
  • Notify you without undue delay after becoming aware of a personal data breach.
  • Delete or return account data on termination, as described in our Privacy Policy.

6. Sub-processors

We use a small number of vetted sub-processors — for example, cloud hosting and payment processing — each bound by data-protection terms no less protective than this DPA. A current list is available on request, and we'll give notice of material changes so you can object.

7. International transfers

Where personal data is transferred outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses. EU data residency is available on request.

8. Security

We maintain encryption in transit and at rest for account data, scoped API keys, and least-privilege access controls. See our Security page for details.

9. Data subject requests

Because we don't retain the addresses you verify, most requests about verified individuals are handled on your side. For account data we hold, we'll assist you as required by law. Contact privacy@emaillabs.io.

10. Signing a DPA

If your organisation requires a countersigned DPA, email legal@emaillabs.ioand we'll share our standard agreement.