GDPR Compliance — Email Validator — N-Software
Email Validator
Features Pricing Add-ons API Docs Blog Login Sign Up

GDPR Compliance

Last updated: July 26, 2026

Contents

  1. Our GDPR Commitment
  2. Data Controller & Data Processor Roles
  3. Data Processing Agreement (DPA)
  4. Sub-Processors
  5. Technical & Organizational Measures (TOMs)
  6. Data Residency & EU Hosting
  7. Data Breach Notification
  8. Data Protection Officer
  9. Request a DPA

1. Our GDPR Commitment

Email Validator, operated by N-Software, is fully committed to compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and applicable national data protection laws of EU member states. We have designed our Service, infrastructure, and data processing practices with privacy by design and privacy by default principles.

2. Data Controller & Data Processor Roles

Under GDPR, your relationship with us depends on the nature of the data:

  • You (our customer) are the Data Controller for the email lists you upload for verification. You determine the purposes and means of processing those email addresses.
  • We (N-Software / Email Validator) act as a Data Processor for your uploaded email lists. We process these email addresses solely on your instructions to provide the email verification service.
  • We act as an independent Data Controller for your account information (email, name, billing records) which we process for our own administrative and legal purposes under the legal bases described in our Privacy Policy.

3. Data Processing Agreement (DPA)

Per Article 28 of the GDPR, a Data Processing Agreement (DPA) is required between the Data Controller and the Data Processor. Our DPA is automatically incorporated into our Terms of Service and covers the following GDPR-required elements:

  • Subject-matter and duration of processing: Email verification for the duration of your subscription or credit consumption.
  • Nature and purpose of processing: SMTP-level verification, catch-all detection, disposable email identification, and typo correction.
  • Type of personal data: Email addresses only.
  • Categories of data subjects: Recipients on your email lists.
  • Your obligations as Controller: Ensure you have a lawful basis for processing the email addresses you provide to us.
  • Our obligations as Processor:
    • Process only on your documented instructions
    • Ensure confidentiality of personnel authorized to process
    • Implement appropriate technical and organizational security measures
    • Assist you with data subject requests
    • Notify you of data breaches without undue delay
    • Delete or return all personal data upon termination of service
    • Make available all information necessary to demonstrate compliance

DPA Included by Default

By using our Service, you are covered by our DPA. No additional paperwork or signed agreement is required for standard use. For enterprise customers requiring a separately executed DPA, please contact us (see section 9 below).

4. Sub-Processors

We use the following sub-processors to deliver the Service. All sub-processors are GDPR-compliant and contractually bound to equivalent data protection obligations:

Sub-Processor Purpose Data Accessed Location
Hetzner Online GmbH Cloud hosting (primary server) All stored data (database, files) Frankfurt, Germany 🇩🇪
Lemon Squeezy, LLC Payment processing (Merchant of Record) Order metadata, email United States 🇺🇸 (DPF certified)
Brevo (Sendinblue SAS) Transactional email delivery Email address, name France 🇫🇷 / EU
noez.de (Manuel Pfeiffer) SMTP relay / IP transit SMTP pass-through traffic only Germany 🇩🇪
Verifly Yahoo-specific email validation Email address (transient) United States 🇺🇸

We will notify customers of any changes to our sub-processor list via email or in-app notification. Customers may object to a new sub-processor within 14 days of notification.

5. Technical & Organizational Measures (TOMs)

Per Article 32 of the GDPR, we implement the following technical and organizational security measures:

  • Encryption: TLS 1.3 for all data in transit. Database and file storage at rest within Hetzner's encrypted infrastructure.
  • Access Control: Principle of least privilege. SSH key-based authentication only. No password-based server access.
  • Application Security: Bcrypt password hashing (12 rounds), CSRF protection on all forms, Content Security Policy (CSP) headers, X-Frame-Options DENY, XSS protection headers.
  • Backups: Automated database backups every 10 minutes, replicated to a secondary geographic location. Backup retention: 2 days.
  • Monitoring: Health watchdog service alerts on service degradation. SMTP rate limiting to prevent abuse. Automated sysadmin alerts via email.
  • Data Minimization: We collect only the minimum data necessary to provide the Service. Password resets use time-limited tokens. API keys can be revoked and regenerated at any time.
  • Incident Response: Defined procedures for detecting, reporting, and investigating data breaches. Customers notified without undue delay (within 72 hours of awareness).

6. Data Residency & EU Hosting

All customer data and verification processing is hosted in Frankfurt, Germany — fully within the European Union. We do not transfer personal data outside the EU/EEA in our core operations. The one exception is Verifly (used for Yahoo email validation), which is based in the US. Our agreement with Verifly incorporates the EU Standard Contractual Clauses (SCCs) as an appropriate safeguard per Article 46 GDPR.

7. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify affected customers without undue delay and no later than 72 hours after becoming aware of the breach.
  • Provide a description of the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
  • Cooperate fully with customers to meet their Article 33 and 34 notification obligations to supervisory authorities and data subjects.

8. Data Protection Officer

As a small organization, N-Software is not currently required to formally appoint a Data Protection Officer under Article 37 GDPR. However, we have designated a privacy contact who serves this function:

  • Email: privacy@email-validaton.com
  • Response time: Within 48 hours

EU residents may also lodge complaints with their local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.

9. Request a DPA

For enterprise customers requiring a separately signed Data Processing Agreement, or for any questions about our GDPR compliance program, contact us at privacy@email-validaton.com. We will respond within 2 business days.

© 2026 Email Validator. All rights reserved.

Pricing Features Add-ons Blog Terms Privacy Cookies GDPR Refunds Contact
🎁
One-Time Offer

Before you go…

200

Free Verifications

✅ No credit card required
✅ Instant bulk Excel uploads
✅ Catch-all & disposable detection
✅ API access included
Claim 200 Free Credits →