This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Tilfortis MB, Lithuania (“Processor”, “we”) and the customer that accepted the Terms (“Controller”, “you”). It applies when we process personal data on your behalf as described below. A countersigned copy is available on request from privacy@isbusinessemail.com.
Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in Regulation (EU) 2016/679 (the “GDPR”).
1. Scope and roles
1.1. When you submit email addresses or domains to the API, we process them on your behalf to return a verdict. For that processing you are the controller and we are your processor.
1.2. We act as an independent controller for processing we do for our own purposes, as described in our Privacy Policy: account administration, security and abuse prevention, keeping domain-level records and keyed-hash counters that improve the Service, and the blocklists. This DPA doesn’t cover that processing.
1.3. Details of the processing are in Annex I.
2. Your instructions
2.1. We process personal data only on your documented instructions. The Terms, this DPA and your use of the API’s documented features (including the options you choose, such as policy and deep) are your instructions.
2.2. If we believe an instruction infringes data protection law, we’ll tell you. If EU or Member State law requires us to process personal data otherwise, we’ll inform you first unless the law forbids it.
2.3. You’re responsible for having a lawful basis for the checks you submit, for informing data subjects, and for decisions you make based on verdicts.
3. Confidentiality
Everyone we authorize to process personal data is bound by confidentiality obligations.
4. Security
We implement the technical and organizational measures in Annex II, appropriate to the risk, in line with Art. 32 GDPR. We may update them as long as the overall level of protection doesn’t decrease.
5. Sub-processors
5.1. You give us general authorization to use sub-processors. The current list is on our Subprocessors page (Annex III).
5.2. We’ll give at least 14 days’ notice of a new or replacement sub-processor, by updating the Subprocessors page and emailing account owners who’ve asked to be notified. You may object on reasonable data protection grounds within that period; if we can’t address the objection, you may stop using the Service and close your account.
5.3. We impose data protection obligations on each sub-processor that are at least as protective as this DPA, and remain responsible for their performance.
6. International transfers
Where personal data is transferred outside the EEA, we ensure an adequate level of protection, through an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), with supplementary measures where needed.
7. Assistance
7.1. Data subject requests. Taking into account the nature of the processing, we’ll help you respond to data subject requests. Because we don’t store full email addresses submitted for checks, there is usually no stored personal data to access, correct or delete for a given address. If we receive a request directly that relates to your processing, we’ll refer the person to you where we can identify you.
7.2. Other obligations. We’ll provide reasonable assistance with your obligations under Arts. 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to us.
8. Personal data breaches
We’ll notify you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notice will include what we know about the nature of the breach, likely consequences and measures taken or proposed, and we’ll update you as we learn more.
9. Deletion and return
Personal data submitted for a check is processed in memory and not stored in clear text, so there is nothing to return at the end of the Service. On termination we delete remaining personal data processed on your behalf (for example request logs) within the retention periods in Annex I, unless the law requires us to keep it.
10. Audits and information
We’ll make available the information reasonably necessary to demonstrate compliance with this DPA, such as this DPA, our security description and answers to reasonable questionnaires. If that’s not sufficient, you may audit our compliance, at your cost, with at least 30 days’ notice, during business hours, no more than once a year (unless a supervisory authority requires otherwise or after a breach), under confidentiality, and without access to other customers’ data or to our sub-processors’ facilities (for which we’ll provide their available reports or certifications).
11. Liability and term
11.1. Liability under this DPA is subject to the limitations in the Terms, to the extent permitted by law.
11.2. This DPA lasts as long as we process personal data on your behalf.
11.3. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Clauses prevail.
12. Governing law
This DPA is governed by the laws of the Republic of Lithuania; the courts of Vilnius have jurisdiction, as set out in the Terms.
Annex I: Details of processing
| Item | Description |
|---|---|
| Subject matter | Classifying email addresses and domains submitted by the Controller through the API |
| Nature and purpose | Normalizing the address, matching lists, querying public DNS and related public sources about the domain, and returning a verdict (category, recommendation, reasons, workspace detection) to the Controller |
| Duration | For the term of the Terms; each check is processed in real time |
| Categories of data subjects | The Controller’s users, prospects, leads or contacts whose email addresses the Controller submits |
| Categories of personal data | Email addresses (local part and domain); where a domain identifies an individual, the domain |
| Special categories | None. The Controller must not submit special categories of data. |
| Retention of data processed for the Controller | Full email addresses: not stored (processed in memory; logs redacted). Request analytics without email addresses: 90 days. Recent requests shown in the Controller’s dashboard: domain only, last 1,000. Encrypted backups: 30 days. |
| Location | Processing on Cloudflare’s global edge network; database in the EU (Hetzner, Germany/Finland) |
Annex II: Technical and organizational measures
- Data minimization: full email addresses are never stored; local parts only as keyed hashes (HMAC with a secret pepper); logs redact email addresses, API keys and cookies.
- Encryption: TLS for all traffic; encrypted database connections through a Cloudflare Tunnel; encrypted backups.
- Network isolation: the database has no public ports and is reachable only through an outbound tunnel protected by an access token.
- Access control: least-privilege database credentials; admin access limited to authorized staff, checked server-side and audited.
- Authentication: API keys stored only as SHA-256 hashes with checksums; revocation within 60 seconds; automatic revocation of keys leaked publicly on GitHub; passwordless sign-in; hashed sessions in secure, HTTP-only cookies.
- Application security: input validation on every request, strict Content Security Policy, HSTS, same-origin checks on state-changing requests, dependency monitoring.
- Availability: globally distributed edge infrastructure, DDoS protection, rate limiting, graceful degradation, nightly backups with tested restores.
- Separation: every account’s data is scoped by account; tests cover cross-account access.
- Incident response: monitoring and alerting, an incident and breach runbook including the 72-hour notification process.
- Personnel: confidentiality obligations for everyone with access.
Annex III: Sub-processors
See Subprocessors.
Changes
| Version | Changes |
|---|---|
| 2026-10-04 | First version. |