The short version
- We never store the full email addresses you check. We keep the domain and a keyed hash of the part before the
@. - For your account we keep your email, name, sign-in method, settings, consents and usage.
- Request analytics are kept for 90 days. The database is in the EU.
- We use a few service providers (Cloudflare, Hetzner, Brevo, Google, Microsoft, Slack) and never sell data.
- Google Analytics runs only if you consent.
- You can export or delete your data from your dashboard, or write to privacy@isbusinessemail.com.
1. Who is responsible
The controller is Tilfortis MB, a small partnership (mažoji bendrija) registered in Lithuania.
Privacy contact: privacy@isbusinessemail.com. We haven’t appointed a data protection officer, as we’re not required to; the privacy contact handles all data protection questions.
2. Who this policy covers
- Account holders: people who sign up for the Service and use the dashboard or API.
- Website visitors, including people who use the public checker.
- People whose email address or domain is checked through the API by our customers, or typed into the public checker.
- People whose address is on a blocklist we use.
- People who contact us.
3. What we process and why
3.1 Account holders
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address, name, sign-in provider and identifiers (Google or Microsoft account IDs, Microsoft tenant ID) | Create and run your account, sign you in | Contract, Art. 6(1)(b) |
| Our verdict on your own email (category, workspace detection) | Show you the Service in action; keep out disposable and relay signups; understand who uses the Service | Contract, Art. 6(1)(b); legitimate interests in preventing abuse and understanding our users, Art. 6(1)(f) |
| API keys (stored only as hashes), key names, allowed origins | Authenticate API requests | Contract, Art. 6(1)(b) |
| Usage: checks per day and category, latency, the last 1,000 requests (domain only) | Quotas, your dashboard, support | Contract, Art. 6(1)(b) |
| Consent records: document, version, time, hashed IP address, user agent | Prove you accepted the Terms and Privacy Policy, and record marketing consent | Legal obligation to demonstrate consent and legitimate interests, Art. 6(1)(c) and (f) |
| Session data: hashed session tokens, device and approximate location for sign-in alerts | Keep you signed in; alert you to new sign-ins | Contract, Art. 6(1)(b); security, Art. 6(1)(f) |
| Service emails (sign-in links, key notices, limit warnings, terms updates) and their delivery status | Run the Service and keep your account secure | Contract, Art. 6(1)(b) |
| Optional product updates and digests | Keep you informed | Consent, Art. 6(1)(a). Withdraw any time. |
| Internal notifications to our team about new sign-ups and limit hits (name, email, verdict on your email, country) | Spot abuse and support new users | Legitimate interests, Art. 6(1)(f) |
| Feedback reports you send (domain, expected category, comment) | Improve the Service | Legitimate interests, Art. 6(1)(f) |
3.2 Website visitors and the public checker
| Data | Purpose | Legal basis |
|---|---|---|
| IP address (processed transiently; stored only as a hash or as network/country), user agent, request metadata | Deliver the site, protect it from bots and abuse, rate-limit the public checker | Legitimate interests, Art. 6(1)(f) |
| Human-verification signals processed by Cloudflare Turnstile | Tell people from bots | Legitimate interests, Art. 6(1)(f) |
| Strictly necessary cookies (session, checker pass, consent choice) | Make the site work | Legitimate interests, Art. 6(1)(f); exempt from consent as strictly necessary |
| Google Analytics 4 data (pages viewed without query strings, device and approximate location, events) | Understand how the site is used | Consent, Art. 6(1)(a). See the Cookie Policy. |
3.3 People whose email is checked
When a customer checks an address through the API, or someone types one into the public checker:
- The full address is processed in memory only long enough to produce a verdict, and is not stored. Logs redact it.
- We keep the domain and its classification. Most domains belong to organizations; where a domain identifies an individual, it can be personal data.
- We keep a keyed hash (HMAC) of the local part (the part before
@) inside a probabilistic counter per domain. It lets us notice domains that behave like shared providers. It can’t be reversed and we can’t list the addresses behind it.
Our role. For checks made through the API, the customer decides why and how to check its users’ addresses; for producing the verdict we act as the customer’s processor under our DPA. For our own purposes (keeping domain-level data, the hashed counter, security and abuse prevention, improving the Service) we act as controller, on the basis of our legitimate interests (Art. 6(1)(f)) in providing an accurate, secure and abuse-resistant service. We’ve balanced these interests against yours: we keep no full addresses, use keyed hashes, and only aggregate.
Can we identify you? Generally not. We don’t store your address, so we usually can’t find data about you specifically (Art. 11 GDPR). If you want to exercise your rights regarding a check, contact the business that checked your address first; you’re also welcome to write to us.
3.4 Blocklists
To help customers stop spam and abuse, we keep blocklists of domains and of individual addresses. Our administrators add entries after reviewing spam and abuse reports and feedback on verdicts.
- Blocked addresses are stored only as SHA-256 hashes, never in clear text, and without the report text.
- A match is returned as
is_blocked. Exact-address matches are shown only to holders of secret API keys, and repeated lookups across one domain are flagged. - Legal basis: legitimate interests in preventing spam, fraud and abuse, for us and our customers (Art. 6(1)(f)).
- If you think your address or domain is listed wrongly, write to privacy@isbusinessemail.com. You can object to this processing (section 8).
3.5 People who contact us
We use what you send (name, email, message) to reply and keep a record of the conversation, based on our legitimate interests (Art. 6(1)(f)), or on the contract if you’re a customer.
3.6 Where the data comes from
From you; from your use of the Service; from our customers’ API requests; from Google or Microsoft when you sign in with them (name, email, account identifiers, and for Microsoft the tenant ID); from Noium’s abuse reports (hashes only); and from public sources (DNS, RDAP, Microsoft’s public discovery endpoints, websites) about domains.
4. Do you have to give us data?
You need an email address to create an account; without it we can’t provide the API. Marketing consent and analytics cookies are optional.
5. Automated decisions
The Service produces automated verdicts about email domains and addresses for our customers. These verdicts are informational. We don’t make decisions about individuals that have legal or similarly significant effects on them; our customers decide how to use the verdicts and are responsible for those decisions. If a customer’s use of our verdict affects you, contact that customer.
For our own sign-up, we use our engine to reject disposable and relay addresses. If that blocks you wrongly, write to privacy@isbusinessemail.com and a person will review it.
6. Who receives data
We don’t sell personal data. We share it only with:
| Recipient | What for | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting of website and API, CDN, security (WAF, DDoS protection, Turnstile), key-value storage, analytics storage, DNS-over-HTTPS resolution of domains, email routing | Global edge network; USA-based company |
| Hetzner Online GmbH | Database servers and encrypted backups | Germany / Finland (EU) |
| Brevo | Sending service emails | EU (France) |
| Sign-in with Google; Google Analytics 4 (only with consent); fallback DNS-over-HTTPS resolution of domains | USA / EU | |
| Microsoft | Sign-in with Microsoft; public tenant discovery for domains (no personal data sent) | USA / EU |
| Slack | Internal team notifications (new sign-ups, limit hits) | USA |
| Authorities and advisers | When required by law, or to establish or defend legal claims | As required |
| A successor | If the Service is transferred, under this policy | As applicable |
The current list of processors is on our Subprocessors page.
7. International transfers
Our database is in the EU. Some providers are based in, or may access data from, countries outside the EEA, notably the USA. Where that happens, transfers rely on an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or on the European Commission’s Standard Contractual Clauses, with additional safeguards where needed. Ask us for a copy of the relevant safeguards.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account exists; deleted within 30 days of account deletion |
| API request analytics (no email addresses) | 90 days |
| Recent-requests list in your dashboard (domain only) | Rolling: the last 1,000 requests |
| Daily usage counters | While your account exists |
| Consent records | While your account exists, then up to 3 years to demonstrate compliance |
| Sessions | Until they expire or you sign out; expired records are purged regularly |
| Sign-in links and codes | 15 minutes validity; purged shortly after |
| Service email log (template, status, provider message ID) | 12 months |
| Public checker abuse data (hashed IPs, counters, bans) | Counters: hours to days; temporary bans up to 7 days; permanent bans until lifted |
| Domain records and hashed local-part counters | As long as useful for the Service; domain-level |
| Blocklist hashes | Until removed by the source or our review |
| Feedback reports | Up to 24 months |
| Support emails | Up to 24 months after the conversation ends |
| Backups | 30 days, encrypted |
| Google Analytics data | 14 months (Google Analytics setting) |
| Server logs (redacted) | A few days |
9. Your rights
Under the GDPR you have the right to:
- access your personal data and get a copy;
- rectify inaccurate data;
- erase your data;
- restrict processing;
- data portability, for data you gave us under contract or consent;
- object to processing based on legitimate interests, including the blocklist, at any time, on grounds relating to your situation;
- withdraw consent at any time (marketing emails, analytics), without affecting earlier processing.
Account holders can export and delete their data from the dashboard (Profile). For anything else, write to privacy@isbusinessemail.com. We’ll answer within one month (extendable by two months for complex requests, in which case we’ll tell you). We may ask you to confirm your identity.
10. Complaints
You can complain to the Lithuanian supervisory authority, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), vdai.lrv.lt, or to the authority in your EU country of residence or work. We’d appreciate the chance to fix things first: privacy@isbusinessemail.com.
11. Security
We protect data with encryption in transit, hashed keys and sessions, no clear-text storage of checked addresses, a database without public network access, least-privilege access, audited admin actions and encrypted backups. Details: Security. If a personal data breach is likely to put your rights at risk, we’ll notify the VDAI within 72 hours and inform you where required.
12. Children
The Service is not for children. You must be 16 or older to create an account. If you believe a child has given us personal data, contact us and we’ll delete it.
13. Cookies
See the Cookie Policy.
14. Changes
Each version has a version date. For material changes we email account holders at least 30 days before they take effect and ask them to accept the new version at their next sign-in. Earlier versions are available on request.
| Version | Changes |
|---|---|
| 2026-10-04 | First version. |