Draft — pending legal review.
When you send us phone numbers or e-mail addresses to check, we process personal data for you. Our Data Processing Agreement (DPA) sets out how we do that. It meets the requirements of Article 28 GDPR and the UK GDPR. It is available on request: mention it in the request-access form, or contact [email protected]. The processor is BroadNet Technologies Inc., 5th floor, Minkara Building, Clemenceau Street, Beirut, Lebanon.
What does the DPA cover?
In summary, the DPA commits us to:
- Process on your instructions only: checking the identifiers you submit for the services you request, and storing results for the retention period you set.
- Keep it confidential: everyone who can access customer data is bound by confidentiality.
- Secure the data: identifiers are sealed (encrypted) at rest and matched through keyed hashes, logs contain masked identifiers only, API keys are stored as keyed hashes, and all traffic is encrypted in transit. Details are on the Trust page.
- Follow your retention settings: real-time lookups are kept for 7 days and bulk jobs for 30 days by default. You can change the bulk period from 1 day to 24 months, or delete a job at any time.
- Help you: with data-subject requests, data-protection impact assessments and consultations with authorities, as far as our role allows.
- Report breaches: we notify you of a personal-data breach without undue delay ([notification period — pending]).
- Delete or return data at the end: unless the law requires us to keep it.
- Support audits: we provide the information needed to show compliance ([audit terms — pending]).
How are sub-processors handled?
We publish sub-processor categories: hosting and infrastructure, storage, e-mail delivery, payments, and data-verification partners that perform the checks you request.
Every customer who signs the DPA can get the named list of sub-processors under confidentiality. We give at least 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds. If we can't resolve the objection, you may end the affected service.
International transfers
Some sub-processors may process data outside the EEA or the UK. Where they do, the DPA relies on [transfer mechanism, e.g. Standard Contractual Clauses — pending], with supplementary measures where needed.
Where are we controller rather than processor?
For some processing, we may act as a controller in our own right:
- our spam-reputation data, which is compiled from report data;
- possibly parts of the account-presence checks (pending counsel review).
The DPA and our data-subject notice explain these cases. Suppression requests from individuals apply across all customers.

