1. Overview
EmailVerifyerAPI is built and run by a small independent team in Montréal, Québec, Canada. We treat compliance as something we earn over time, not a badge we claim early. This page reflects where we genuinely are today.
The free verification tool on our homepage processes the addresses you check entirely in your browser. Those addresses are never sent to our servers, never logged, and never stored. That architecture removes most data-protection risk by default, as there is no database of your verification data to breach.
As we add optional accounts, billing and a hosted API, we will collect some personal data (such as your account email). The sections below describe how we handle it and how our posture will evolve. When our certification status changes, we will update this page rather than announce it in advance.
2. Privacy by design
- Browser-only verification. Single-address and bulk-CSV checks run client-side. The addresses you verify do not leave your device.
- Data minimisation. For account features we collect only what we need to operate the service, primarily your email address and authentication data.
- No sale of data. We do not sell or rent personal data, and we do not use addresses submitted for verification for any purpose other than returning your result.
- Encryption in transit. All traffic to EmailVerifyerAPI is served over HTTPS (TLS 1.2 minimum).
3. General Data Protection Regulation (GDPR)
We design our data handling to align with the EU GDPR (Regulation 2016/679):
- For account and billing data we are the data controller. Where customers use EmailVerifyerAPI to process personal data on their behalf, we act as a data processor.
- We honour data-subject requests (including access, correction, deletion, and portability) within the 30-day window set by Article 12. Email [email protected].
- We keep the amount of personal data we hold to a minimum and delete it when it is no longer needed (see our Privacy Policy for retention details).
We are not currently certified to any GDPR-related certification scheme. The points above describe our practices, not an audited attestation.
4. California Consumer Privacy Act (CCPA / CPRA)
EmailVerifyerAPI does not sell or share personal information as those terms are defined under the CCPA/CPRA. California residents may request access to, or deletion of, the limited personal data we hold by emailing [email protected]. We will not discriminate against you for exercising these rights.
5. Certification status
We want to be straightforward here, because trust pages are often where companies overstate things:
- SOC 2: Not currently certified. A SOC 2 examination is on our roadmap as we build out hosted infrastructure.
- ISO 27001: Not currently certified.
- HIPAA: EmailVerifyerAPI is not intended for Protected Health Information, and we do not offer a Business Associate Agreement. Please do not submit PHI.
We would rather tell you exactly where we stand than imply audits we haven't completed. If your procurement process requires a specific certification today, talk to us so we can discuss timelines and our current controls.
6. Data Processing Agreement (DPA)
If you use EmailVerifyerAPI to process personal data on behalf of your own users and need a Data Processing Agreement, we can provide one incorporating the EU Standard Contractual Clauses (controller-to-processor). DPAs are handled by email request while we build a self-serve flow.
Request a DPA
Email us and we'll send our current DPA template. We aim to respond within 2 business days.
7. Sub-processors
The browser-only verification tool does not transmit your verification data to any third party. For account, hosting and email features we rely on a small number of infrastructure providers. We will maintain a current sub-processor list here as those services go live, and notify account holders of material changes with at least 14 days' notice.
Before launch: publish the finalised sub-processor list (provider · purpose · data location · privacy-policy link).
8. Contact
Compliance enquiries
Questions about our data handling, a DPA, or our roadmap? Email us and a real person on the team will reply, usually within 2 business days.