⚡ New Pricing Is Live
- Credits Never Expire -
Unknowns Not Charged

Data Processing Agreement

Last updated: 1 January 2025
This Data Processing Agreement (the “Agreement” or “DPA”) is entered into by and between:
EastOne LLC dba Proofy (“Data Processor”, “Processor”, “Provider”, “we” or “us”), a company incorporated in the United States and registered at 118 Paisley Promenade, Boiling Springs, SC 29316, USA, operating under the domain proofy.io, and
[Client Entity] (“Data Controller”, “Controller” or “you”), whose details are set forth in the applicable Order or Terms of Service.
The Data Controller and the Data Processor are hereinafter jointly referred to as the “Parties” and each separately as a “Party.”

This Agreement forms part of the Terms of Service between the Parties and governs the Processing of Personal Data in connection with the Services. The Parties intend to ensure that such Processing is performed in compliance with all applicable data protection laws, including the EU General Data Protection Regulation (GDPR), U.S. privacy laws, and other relevant global frameworks.

For this Agreement, the Controller is the controller of the Personal Data and the Provider is the processor, or sub-processor where applicable. This Agreement replaces any prior data processing agreements between the Parties. Each Party remains responsible for its own obligations under applicable data protection laws.

Definitions

Controller” - the entity that determines the purposes and means of Processing Personal Data.
Processor” - the entity that Processes Personal Data on behalf of the Controller.
Personal Data” - any information relating to an identified or identifiable natural person, including email addresses and related contact data.
Processing” - any operation performed on Personal Data, such as upload, import, storage, use, or deletion. “Proofy” — the email verification and data quality service operated by EastOne LLC under the domain proofy.io.
Service” or “Services” - the email verification and related services provided by Proofy.io under the Terms of Service.
Website” - proofy.io and its subdomains operated by the Processor.
Sub-processor” - a third party engaged by the Processor to Process Personal Data on behalf of the Controller.
Applicable Data Protection Laws” - all data protection and privacy laws and regulations applicable to the Processing of Personal Data under this Agreement, including but not limited to the GDPR, U.S. federal and state privacy laws, and other relevant global frameworks.

Overview and Scope of Processing

This Agreement applies exclusively to the Processing of Personal Data by Proofy in connection with the provision of its Services. Pursuant to Article 28(3) of the GDPR, the Controller engages the Processor to carry out such Processing, and the Processor accepts the engagement.

The purpose of this Agreement is to ensure that Processing is conducted in compliance with Applicable Data Protection Laws and to reflect each Party’s obligations and responsibilities. The Processor will perform Processing only as necessary to deliver the Services, including but not limited to uploading and importing files, API transmissions, batch verification, normalization, deduplication, syntax and deliverability checks, temporary storage, retention, and deletion.

The Processor may exercise reasonable discretion in carrying out Processing, provided that it stays consistent with this Agreement and the Terms of Service and acts only on the Controller’s documented instructions, unless required by law.

The Processor will provide the Controller with information and assistance necessary to help the Controller meet its own obligations under Applicable Data Protection Laws, including supporting Data Subjects in exercising their rights.

The Controller is responsible for determining the lawful basis for Processing and for obtaining and documenting any required consents. The Controller also represents and warrants that no special categories of Personal Data (such as financial, health, biometric, political, religious, or other sensitive information) or children’s data are uploaded to or Processed by the Services.

The Processor may request evidence of the Controller’s lawful basis for Processing, and the Controller must provide such documentation within a reasonable period upon request. If a Data Subject revokes consent, the Controller is responsible for notifying the Processor without undue delay, and the Processor will act according to the Controller’s instructions regarding that Personal Data.

This Agreement supersedes any previous data processing agreements between the Parties. Nothing in this Agreement relieves either Party from its direct responsibilities or liabilities under Applicable Data Protection Laws.

Purpose of Processing

The purpose of Processing Personal Data is to perform the Services under the Terms of Service. Processing includes uploading and importing files via the Website or API, temporary storage for verification, exporting results, and deletion under the retention policy.

Categories of Data and Data Subjects

The Controller engages the Processor to Process the following types of Personal Data:

  • Contacts: individuals whose Personal Data is contained in the Controller’s email lists.
  • Email List: email addresses uploaded by the Controller to the Website or API that are subject to the Services.
  • Google Cloud Platform (GCP) - supporting infrastructure and analytics if required.

Data Retention Period

The Processor will Process Personal Data only as long as necessary to provide the Services or as required by law. Processing continues for the duration of the Controller’s active use of the Services unless a longer retention period is legally required.
Personal Data and verification results are retained for up to sixty (60) days, after which they are permanently deleted. The Controller may delete data or its account at any time through the Service.

Sub-Processors and Third-Party Access

The Controller authorizes the Processor to engage Sub-processors as reasonably necessary to provide, secure, and support the Services.
Current Sub-processors (United States):

  • Amazon Web Services (AWS) - hosting and storage.
  • Cloudflare - security and content delivery.
  • Google Cloud Platform (GCP) - supporting infrastructure and analytics if required.

All Sub-processors are bound by written agreements imposing data-protection, confidentiality, and security obligations that are no less protective than those in this Agreement. The Processor remains fully responsible for the acts and omissions of its Sub-processors.

Personal Data is stored and processed in the United States unless otherwise agreed in writing. Personal Data is not sold, disclosed, or otherwise made available to unrelated third parties.

Cross-Border Data Transfers

Where the Controller is subject to EU or UK data-protection law and Personal Data is transferred to the United States or another country lacking an adequacy decision, the Parties incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (Controller-to-Processor), including the Docking Clause, and, where applicable, the UK International Data Transfer Addendum (ICO).

Data Return and Deletion Procedures

When this Agreement ends or upon the Controller’s written request, the Processor will delete, destroy, or return all Personal Data and ensure that any existing copies are also deleted or returned, unless longer retention is required by law.

The Processor will notify any engaged Sub-processors of termination and ensure they also delete or return all Personal Data.

All Personal Data is treated as strictly confidential and protected under continuing non-disclosure obligations beyond termination of this Agreement.

Data Security and Confidentiality

The Processor implements appropriate technical and organizational measures to ensure the security and confidentiality of Personal Data. To prevent unauthorized access, misuse, or loss of data, Proofy.io uses comprehensive safeguards, which are regularly reviewed and updated in line with technological and industry standards, including Article 32 of the GDPR.

Data is transmitted via secure encrypted connections (HTTPS/TLS) and processed automatically on secure servers without human interaction. In exceptional cases, such as investigating complaints or resolving service issues, authorized staff may access uploaded files or verification results strictly for support purposes.

All personnel with access to Personal Data are bound by confidentiality agreements or statutory duties of confidentiality. Sub-processors are required to uphold equivalent standards of security and confidentiality.

Assistance and Cooperation

The Processor will assist the Controller by implementing appropriate technical and organizational measures to support the Controller in fulfilling its obligations to respond to Data Subject requests under applicable laws, including GDPR and U.S. privacy laws.

If the Processor receives a complaint, inquiry, or request directly from a Data Subject, it will notify the Controller without undue delay and within fifteen (15) days, and in any event within one (1) month where required by law.

Data Breach Notification

The Processor will notify the Controller of any Personal Data breach — including accidental or unlawful access, destruction, loss, alteration, or disclosure — without undue delay and within forty-eight (48) hours of becoming aware of the breach.

The Processor will fully cooperate with the Controller to investigate and mitigate the incident and comply with applicable notification obligations.

No Sale, No Share, and Restricted Use

The Processor does not and will not sell, rent, lease, trade, share, sublicense, or otherwise disclose Personal Data to any third party for monetary or other valuable consideration, in accordance with applicable U.S. privacy laws, including the California Consumer Privacy Act (CCPA/CPRA).

Personal Data is disclosed only as needed to authorized Sub-processors for legitimate business purposes directly related to the Services and never for advertising, profiling, marketing, or cross-context behavioral targeting
Use Restrictions
The Processor will retain, use, or disclose Personal Data only to perform the Services, maintain system security and integrity, and comply with legal or regulatory requirements. The Processor will not use Personal Data for its own commercial benefit, analytics unrelated to the Services, or any purpose not authorized by the Controller.

Automatic and Client-Initiated Deletion

  • Automatic deletion: Personal Data uploaded to the Service is automatically deleted after a maximum of sixty (60) days under the retention policy.
  • Client deletion: The Controller may delete data or its entire account at any time through the Service interface or by written request. Upon such request, the Processor will promptly erase the corresponding data from active systems and backups. After final deletion, Personal Data becomes irreversibly removed and cannot be recovered or accessed by any party.

Responsibilities and Liability

The Controller represents and warrants that all data provided to the Processor complies with applicable laws and remains the Controller’s sole responsibility. The Processor is not liable for any losses or damages resulting from the Controller’s misuse of data or failure to comply with obligations.

The Controller agrees to indemnify and hold the Processor harmless from any claims, damages, or penalties arising from improper Processing of Personal Data by the Controller.

General Terms and Notices

This Agreement takes effect on the date accepted or signed by the Parties. Either Party may terminate it with one (1) week’s written notice.

The Agreement may be amended as reasonably necessary to comply with evolving data-protection requirements.

Any disputes arising under this Agreement will first be addressed through good-faith negotiations between the Parties. If unresolved, disputes will be submitted to binding arbitration under the laws of the United States.

All notices under this Agreement must be sent via email to support@proofy.io