Data Processing Agreement
Published: 20 July 2026
This Data Processing Addendum (DPA) forms part of the MillionVerifier Terms of Service (Terms) between:
GBD Software as a Service Private Limited Company, a company incorporated under the laws of Hungary, with its registered office at 6065 Lakitelek, Szikra tanya 93., Hungary, company registration number 03-10-100682, Hungarian tax number 27325162-2-03 and EU VAT number HU27325162, represented by Tamás Hám-Szabó, CEO (GBD, Provider or Processor); and
the business Customer identified in the Account or billing details (Customer or Controller).
This DPA applies when GBD processes Customer Personal Data on the Customer’s behalf. It takes effect when the Customer accepts the Terms or otherwise becomes bound by the current Terms, including through continued use of the Services, API or an integration after publication.
Capitalised terms not defined here have the meaning given in the Terms. The terms controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in the GDPR.
1. Scope and order of documents
- This DPA governs GBD’s processing of Customer Personal Data as a processor under the GDPR and other data-protection laws applicable to that processing (Applicable Data Protection Law).
- GBD acts as an independent controller for Account administration, billing, fraud prevention, Account-level compliance and enforcement, legal claims, and security records used to protect its own systems and business, as described in the Privacy Policy. This DPA does not govern those controller activities, but it continues to govern security processing of Customer Personal Data performed to provide the Services.
- If this DPA conflicts with the Terms, this DPA prevails only in relation to the processing of Customer Personal Data. The Terms continue to govern all other matters.
2. Roles and instructions
- The Customer is the controller of Customer Personal Data and GBD is its processor. The Customer determines the purposes and essential means of the processing.
- The Customer instructs GBD to process Customer Personal Data as needed to provide, secure, maintain and support the Services described in the Terms and Annex 1. The Terms, this DPA, the Customer’s Account settings, uploads, API requests, integration settings and written support requests together form the Customer’s documented instructions.
- GBD will process Customer Personal Data only on documented instructions from the Customer, including instructions concerning international transfers, unless applicable law requires otherwise. Where legally permitted, GBD will inform the Customer before carrying out legally required processing outside those instructions.
- GBD will inform the Customer without undue delay if it reasonably believes an instruction infringes Applicable Data Protection Law. GBD may suspend the affected processing until the instruction is changed, confirmed to be lawful or otherwise resolved.
- Additional instructions that are not supported by the ordinary functionality of the Services require GBD’s written agreement and may be subject to reasonable fees agreed in advance.
- GBD will not use Customer Personal Data for its own direct marketing or to build unrelated marketing lists. Except for the separate controller activities described in the Privacy Policy, GBD will not use Customer Personal Data for its own purposes unless it has first been irreversibly anonymised so that no Customer, data subject or other person is reasonably identifiable.
3. Customer responsibilities
- The Customer is responsible for:
- the lawfulness, fairness and transparency of its processing;
- choosing and documenting an appropriate legal basis;
- providing required privacy notices;
- responding to data-subject requests and objections;
- the accuracy, relevance and permitted use of Customer Personal Data; and
- ensuring that its instructions comply with Applicable Data Protection Law.
- Customer Personal Data does not have to relate only to subscribers or individuals who opted in to the Customer’s communications. The Customer may submit data collected directly or obtained through a third party, including data that was purchased, rented or licensed, provided that the Customer lawfully acquired it, is authorised to disclose it to GBD and may lawfully use it for the Customer’s intended purpose.
- The Customer must not submit special-category personal data, personal data relating to criminal convictions or offences, government identifiers, full payment-card data, financial-account credentials or other highly sensitive information unless GBD has expressly agreed in writing and the parties have documented the required safeguards.
- The Customer must use reasonable security measures to protect its Account, API keys, integrations and access credentials, and must promptly notify GBD of suspected unauthorised access that may affect Customer Personal Data.
4. GBD’s processor obligations
GBD will:
- ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed for their duties;
- implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature, scope, context and purposes of processing and the relevant risks. The current categories of measures are described in Annex 2;
- assist the Customer, taking into account the nature of the processing and the information available to GBD, with:
- data-subject requests;
- security obligations;
- personal data breach assessment and notification;
- data-protection impact assessments; and
- prior consultation with supervisory authorities;
- maintain the records and information required of GBD as a processor and make information reasonably necessary to demonstrate compliance with this DPA available to the Customer; and
- cooperate with competent supervisory authorities where required by Applicable Data Protection Law.
Where assistance goes beyond the ordinary functionality and documentation of the Services, GBD may charge reasonable costs unless the assistance is required because GBD breached this DPA.
5. Personal Data Breaches
- GBD will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
- The notice will be sent to the Customer’s primary Account contact or another security or privacy contact designated by the Customer. The Customer is responsible for keeping those details current.
- To the extent available, GBD’s notice will describe:
- the nature of the breach;
- the categories and approximate number of affected data subjects and records;
- the likely consequences;
- the measures taken or proposed to contain, investigate and remediate the breach; and
- a contact point for further information.
- GBD may provide information in phases as the investigation develops. A breach notice does not amount to an admission of fault or liability.
- The Customer is responsible for deciding whether notification to a supervisory authority or data subjects is required. GBD will provide reasonable assistance as required by this DPA and Applicable Data Protection Law.
6. Subprocessors
- The Customer gives GBD general written authorisation to use subprocessors to provide the Services.
- GBD maintains a current list of subprocessors that process Customer Personal Data. The list is available by contacting [email protected].
- GBD will give reasonable advance notice of an intended addition or replacement of a subprocessor. Notice may be given by email, through the Account or through a designated Help Centre or policy page. If urgent legal, security or operational reasons make advance notice impracticable, GBD will give notice as soon as reasonably possible.
- The Customer may object during the notice period on reasonable, documented data-protection grounds. GBD will consider the objection in good faith and may provide further information, use a reasonable alternative or take other reasonable steps. If the parties cannot resolve the objection and no commercially reasonable alternative is available, the Customer may stop using the affected part of the Services. Any Account closure, payment or refund consequence is governed by the Terms.
- GBD will impose data-protection obligations on each subprocessor that are no less protective, in substance, than the obligations applicable to GBD under this DPA for the relevant processing. GBD remains responsible for the subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law.
7. International transfers
- Processing under this DPA is not automatically an international transfer. Where GBD transfers Customer Personal Data to a country outside the European Economic Area and the GDPR requires a transfer mechanism, GBD will use an applicable safeguard, such as:
- a European Commission adequacy decision;
- the European Commission’s standard contractual clauses;
- binding corporate rules; or
- another lawful transfer mechanism.
- Where a transfer between the Customer and GBD requires separate transfer terms under Applicable Data Protection Law, the parties will cooperate in good faith to put the relevant standard clauses or addendum in place.
- On request, GBD will provide reasonable information about the applicable transfer safeguard, subject to confidentiality and security restrictions.
8. Return and deletion
- Customer-uploaded files and result files are normally deleted automatically within 30 days unless a different period is agreed or clearly stated for a particular Service. The Customer is responsible for exporting or retaining any results it needs before deletion.
- During the term, the Customer may delete Customer Personal Data using available Service functionality or request reasonable deletion assistance from GBD.
- When GBD stops providing the processing Services, GBD will, at the Customer’s choice, return or delete the remaining Customer Personal Data, unless applicable law requires retention. Return may be completed through the export tools ordinarily available in the Services or another reasonable format agreed by the parties. After returning the data, GBD will delete its remaining copies unless applicable law requires retention.
- If the Customer does not provide a contrary instruction within 30 days after termination, GBD may delete the remaining Customer Personal Data in accordance with its normal deletion process.
- Copies in backups may remain until removed through the normal backup cycle. While retained, they will be isolated from ordinary use and processed only for backup recovery, security or legal compliance.
- This section does not require deletion of information that GBD processes as an independent controller under the Privacy Policy, including limited security, audit, billing, compliance, legal or Recovery Record information.
9. Information and audits
- GBD will provide information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, which may include relevant policies, summaries of security measures, questionnaires, audit reports or certifications where available.
- If that information is not reasonably sufficient, the Customer may audit GBD’s relevant processing, subject to the following safeguards:
- the Customer gives at least 30 days’ written notice;
- ordinary audits are limited to once in any 12-month period;
- the audit takes place during normal business hours and avoids unreasonable disruption;
- the auditor is independent, appropriately qualified, bound by confidentiality and not a direct competitor of GBD;
- the audit does not expose another customer’s data, GBD’s confidential security information or systems unrelated to the Customer’s processing; and
- the Customer bears its audit costs and GBD’s reasonable assistance costs, unless the audit identifies a material breach of this DPA by GBD.
- The notice and frequency limits do not apply where a competent supervisory authority requires an audit, a confirmed Personal Data Breach reasonably justifies an earlier audit, or Applicable Data Protection Law requires otherwise.
10. Term, updates and Business Transfers
- This DPA remains in effect while GBD processes Customer Personal Data on the Customer’s behalf. It cannot be terminated separately from the Terms. Provisions that by their nature must continue—including confidentiality, deletion, audit, liability and international-transfer obligations—survive for as long as relevant.
- Updates to this DPA take effect under the publication, notice and acceptance mechanism in the Terms. An update will not materially reduce the protection applying to Customer Personal Data already entrusted to GBD, unless required by law or separately agreed with the Customer.
- In a Business Transfer described in the Terms, this DPA may transfer to the Successor Provider only if the Successor Provider assumes the applicable processor obligations in writing. Customer Personal Data will not be made available to the Successor Provider for operational use until that assumption and any required international-transfer safeguards are in place.
11. General terms and contact
- The liability, governing-law, jurisdiction, notice, assignment, severability and other general provisions of the Terms apply to this DPA. Nothing in the Terms or this DPA limits a responsibility that cannot lawfully be limited under Applicable Data Protection Law.
- This DPA is concluded electronically and does not require a handwritten signature.
- Data-protection questions concerning this DPA may be sent to:
- Data Protection Officer: Dr. Ham-Szabo Boglarka Barbara
- Email: [email protected]
- General support: [email protected]
- Post: GBD Software as a Service Private Limited Company, 6065 Lakitelek, Szikra tanya 93., Hungary
Annex 1 — Processing details
Annex 2 — Security measures
GBD maintains technical and organisational measures appropriate to the risks of the processing. Depending on the relevant system and risk, these measures may include:
- role-based and least-privilege access controls;
- authentication controls and additional protection for privileged access;
- encryption in transit and, where appropriate, at rest;
- logical separation of customer data;
- secure configuration, patching, vulnerability management and malware protection;
- logging, monitoring and controls designed to detect unauthorised access or misuse;
- backups, restoration procedures and business-continuity measures;
- incident-response and breach-management procedures;
- confidentiality obligations and appropriate security awareness for authorised personnel;
- subprocessor due diligence and contractual security requirements; and
- periodic testing, assessment and review of relevant security measures.
GBD may update these measures to reflect changes in technology, risk and the Services, provided that the overall level of protection is not materially reduced.
Previous versions
