Data Processing Agreement

Published: 26 August 2026

This Data Processing Addendum (DPA) forms part of the MillionVerifier Terms of Service (Terms) between:

GBD Software as a Service Private Limited Company, a company incorporated under the laws of Hungary, with its registered office at 6065 Lakitelek, Szikra tanya 93., Hungary, company registration number 03-10-100682, Hungarian tax number 27325162-2-03 and EU VAT number HU27325162, represented by Tamás Hám-Szabó, CEO (GBD, Provider or Processor); and

the business Customer identified in the Account or billing details (Customer).

This DPA applies when GBD processes Customer Personal Data on the Customer's behalf as a processor or subprocessor. It takes effect when the Customer accepts the Terms or otherwise becomes bound by the current Terms, including through continued use of the Services, API or an integration after publication.

Capitalised terms not defined here have the meaning given in the Terms. The terms controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in the GDPR.

1. Scope and order of documents

  1. This DPA governs GBD's processing of Customer Personal Data as a processor under the GDPR and any other data-protection law that directly applies to GBD in respect of that processing (Applicable Data Protection Law). A data-protection law that applies only to the Customer does not impose additional contractual obligations on GBD under this DPA unless that law also directly applies to GBD or GBD agrees otherwise in writing.
  2. GBD acts as an independent controller for Account administration, billing, fraud prevention, Account-level compliance and enforcement, legal claims, and security records used to protect its own systems and business, as described in the Privacy Policy. This DPA does not govern those independent-controller activities, but continues to govern processing of Customer Personal Data carried out by GBD on the Customer's behalf to provide, secure, maintain and support the Services.
  3. If this DPA conflicts with the Terms, this DPA prevails only to the extent necessary to govern GBD's processing of Customer Personal Data as a processor or subprocessor. The Terms continue to govern all other matters, including commercial terms, suspension, termination, Credits, refunds, warranties, indemnities and liability, except where Applicable Data Protection Law mandatorily requires otherwise.

2. Roles and instructions

  1. Where the Customer determines the purposes and essential means of processing Customer Personal Data, the Customer is the controller and GBD is its processor. Where the Customer processes Customer Personal Data on behalf of another controller, the Customer acts as a processor and engages GBD as its subprocessor. In either case, the Customer represents and warrants that it has all authority and authorisations required to engage GBD, issue the instructions under this DPA and authorise GBD's use of subprocessors.
  2. The Customer instructs GBD to process Customer Personal Data as reasonably necessary to provide, secure, maintain and support the Services described in the Terms and Annex 1. The Terms, this DPA, the Customer's use and configuration of the Services, Account settings, uploads, API requests and integration settings constitute the Customer's documented instructions. A written request from an authorised representative of the Customer is an additional documented instruction only to the extent that it is consistent with the Terms and this DPA and falls within the agreed scope or is accepted by GBD under Section 2.5.
  3. GBD will process Customer Personal Data only on the Customer's documented instructions, including instructions concerning transfers of personal data to a third country or international organisation, unless Union or Member State law to which GBD is subject requires otherwise. Where legally permitted, GBD will inform the Customer before carrying out processing required by such law.
  4. GBD will immediately inform the Customer if, in GBD's opinion, an instruction infringes the GDPR or another applicable Union or Member State data-protection provision. GBD is not responsible for determining the overall lawfulness of the Customer's processing, legal basis, source of data or intended use. GBD may decline or suspend affected processing until the instruction is withdrawn, changed, confirmed to be lawful or otherwise resolved, and may exercise any related suspension or termination right available under the Terms.
  5. GBD is not required to comply with an instruction that is outside the ordinary functionality or agreed scope of the Services unless compliance is expressly required by this DPA or Applicable Data Protection Law or GBD accepts the instruction in writing. GBD may condition acceptance of an additional instruction on reasonable technical, operational or commercial requirements and reasonable fees agreed in advance.
  6. GBD will not use Customer Personal Data for its own direct marketing or retain Customer Personal Data in, contribute it to, or use it to build or enrich a persistent reputation database, marketing list or other data product made available to another customer for that other customer's independent use.
    GBD may retain submitted addresses and verification results in a temporary operational cache for up to seven (7) days where reasonably necessary to provide, secure, optimise or support the Services. Cached data is automatically expired or deleted at the end of the applicable cache period and is not used for model training.
    This restriction does not prevent processing performed on the Customer's documented instructions, including independently processing information separately submitted by another customer, engaging authorised subprocessors, processing reasonably necessary for a Business Transfer, or using information that has been anonymised so that it no longer constitutes Personal Data under Applicable Data Protection Law.

3. Customer responsibilities

  1. The Customer is responsible for:
    • the lawfulness, fairness and transparency of its processing;
    • complying with data-protection laws applicable to the Customer and its use of the Services;
    • choosing and documenting an appropriate legal basis;
    • obtaining any required consent, permission or authorisation;
    • providing required privacy notices;
    • responding to data-subject requests and objections;
    • the accuracy, relevance, minimisation and permitted use of Customer Personal Data;
    • ensuring that it is authorised to disclose Customer Personal Data to GBD;
    • where the Customer acts as a processor, ensuring that its instructions to GBD are authorised by the relevant controller; and
    • ensuring that its instructions comply with applicable law.
  2. Customer Personal Data does not have to relate only to subscribers or individuals who opted in to the Customer's communications. The Customer may submit data collected directly or obtained through a third party, including data that was purchased, rented or licensed, provided that the Customer lawfully acquired it, is authorised to disclose it to GBD and may lawfully use it for the Customer's intended purpose.
  3. The Customer must not submit special-category personal data, personal data relating to criminal convictions or offences, government identifiers, full payment-card data, financial-account credentials or other highly sensitive information unless GBD has expressly agreed in writing and the parties have documented any required lawful basis, instructions and safeguards. GBD has no obligation to inspect Customer Personal Data to determine whether prohibited information has been submitted and may reject, suspend processing of or delete prohibited information where reasonably necessary.
  4. The Customer must use reasonable security measures to protect its Account, API keys, integrations and access credentials and must promptly notify GBD of suspected unauthorised access that may affect Customer Personal Data. The Customer is responsible for activity performed through its Account, Authorized Users and credentials except to the extent directly caused by GBD's breach of an applicable obligation.
  5. The Customer will provide information and cooperation reasonably necessary for GBD to verify the authority, scope or lawfulness of a material instruction where GBD has reasonable grounds to request it. GBD may suspend the affected processing while reasonably required information remains outstanding.

4. GBD's processor obligations

GBD will:

  1. ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and process the data only as required for their duties;
  2. implement and maintain appropriate technical and organisational measures in accordance with Article 32 of the GDPR, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing and the risks to the rights and freedoms of natural persons. The current categories of measures are described in Annex 2;
  3. taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, with fulfilment of the Customer's obligations to respond to requests for exercising data-subject rights;
  4. taking into account the nature of the processing and the information available to GBD, reasonably assist the Customer with its obligations under Articles 32 to 36 of the GDPR, including:
    • security obligations;
    • Personal Data Breach assessment and notification;
    • data-protection impact assessments; and
    • prior consultation with competent supervisory authorities;
  5. maintain records and information required of GBD in its capacity as a processor and, subject to Section 9, make available information necessary to demonstrate GBD's compliance with the obligations applicable to it under Article 28 of the GDPR; and
  6. cooperate with competent supervisory authorities to the extent required of GBD by Applicable Data Protection Law.

The Customer will first use the functionality, documentation, reports and compliance materials ordinarily made available through the Services where they reasonably address the relevant request.

Where assistance requires bespoke work beyond the ordinary functionality, documentation and compliance materials of the Services, GBD may charge reasonable costs, including for customer-specific questionnaires, technical work, legal review or repeated assistance, unless and to the extent that the assistance is required because of GBD's material breach of this DPA or mandatory law requires otherwise.

5. Personal Data Breaches

  1. GBD will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
  2. The notice will be sent to the primary email address associated with the Customer's Account. The Customer designates that address as its contractual contact address for notices under this Section 5 and is responsible for keeping the address current and appropriately monitored. GBD may use additional notification channels at its discretion but is not required to send a notice to any additional security, privacy, legal or other contact designated by the Customer.
  3. To the extent the information is available to GBD, the notice will describe:
    • the nature of the Personal Data Breach;
    • the categories and approximate number of affected data subjects and records, where available;
    • the likely consequences;
    • the measures taken or proposed to contain, investigate and remediate the breach; and
    • a contact point for further information.
  4. GBD may provide information in phases as its investigation develops. A notification or provision of assistance under this Section does not constitute an admission of fault, negligence, breach or liability.
  5. The Customer remains responsible for determining whether notification to a supervisory authority, data subjects or another person is required and for making any notification for which the Customer is responsible. GBD will provide the assistance required of it under Section 4 and Applicable Data Protection Law. Nothing in this DPA transfers the Customer's controller notification obligations to GBD.

6. Subprocessors

  1. The Customer gives GBD general written authorisation to engage subprocessors to process Customer Personal Data in connection with the Services.
  2. GBD maintains a current list of subprocessors that process Customer Personal Data on the Service Providers, Recipients and Subprocessors page. Providers identified with the scope DPA or Both constitute GBD's subprocessor list for purposes of this DPA.
  3. GBD will give reasonable advance written notice of an intended addition or replacement of a subprocessor that will process Customer Personal Data through a prominent notification in the Customer's Account. The notice will identify the intended subprocessor and give the Customer an opportunity to object before the subprocessor is engaged.
    The Customer agrees that the Account is the designated notification channel for notices under this Section 6. GBD is not required to provide a separate email or notice to another contact. The Customer is responsible for monitoring Account notices, including where the Customer principally accesses the Services through the API, an integration or an automated process.
  4. An objection must:If the Customer does not object within the notice period, GBD may engage the proposed subprocessor after the stated effective date.GBD will consider a timely objection in good faith and will not engage the proposed subprocessor to process that Customer's Personal Data while the timely objection remains unresolved.If the objection cannot reasonably be resolved, GBD may, at its option:The Customer may stop using the affected part of the Services. Any Account closure, suspension, Credit, payment or refund consequence is governed exclusively by the Terms and mandatory law.
    • be submitted within the notice period stated in the notification;
    • follow any reasonable response method stated in the notification; and
    • identify specific, reasonable and documented data-protection grounds relating to the proposed subprocessor's processing of that Customer's Personal Data.
    • not use the proposed subprocessor for that Customer;
    • provide a commercially reasonable alternative;
    • modify the affected processing;
    • postpone the proposed change;
    • suspend the affected part of the Services; or
    • terminate the affected Services or, where the affected processing cannot reasonably be separated, the Account.
  5. GBD will impose on each subprocessor, by written contract or other legally binding arrangement, the data-protection obligations required by Article 28(4) of the GDPR to the extent applicable to that subprocessor's processing. GBD remains responsible for the subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.

7. International transfers

  1. Processing under this DPA is not automatically an international transfer. GBD's current subprocessors are identified on the Service Providers, Recipients and Subprocessors page.
  2. Where GBD initiates a transfer of Customer Personal Data that is subject to Chapter V of the GDPR, GBD will use a lawful transfer mechanism required for that transfer under Applicable Data Protection Law and will implement supplementary contractual, technical or organisational measures to the extent legally required having regard to the circumstances of the transfer.
  3. Where a transfer between the Customer and GBD legally requires a separate transfer mechanism under Applicable Data Protection Law directly applicable to GBD or to GBD's receipt or processing of Customer Personal Data, the parties will reasonably cooperate to implement the legally required mechanism. GBD is not required to enter into a country-specific or customer-specific transfer agreement, addendum or other instrument solely because a data-protection law applies to the Customer, unless the instrument is also legally required for the relevant processing by GBD or GBD separately agrees to it in writing.
  4. On reasonable request, GBD will provide information reasonably necessary to demonstrate compliance with transfer obligations directly applicable to GBD. GBD may satisfy such requests using standard documentation or compliance materials and may withhold or redact information where reasonably necessary to protect legal privilege, security, trade secrets, another customer's information or confidential third-party information, provided that this does not prevent GBD from meeting a mandatory disclosure obligation.

8. Return and deletion

  1. Customer-uploaded files and result files are normally deleted automatically within 30 days unless a different period is agreed or clearly stated for a particular Service. GBD may apply a shorter retention period where reasonably appropriate for the relevant Service or processing. The Customer is responsible for exporting or retaining any results it requires before deletion.
  2. During the term, the Customer should use available Service functionality to access, export or delete Customer Personal Data. Where such functionality is not reasonably sufficient, the Customer may request reasonable assistance from GBD subject to Section 4.
  3. When GBD stops providing the relevant processing Services, the Customer may choose to have the remaining Customer Personal Data then held by GBD returned or deleted, unless Union or Member State law requires retention.Return may be completed using the export functionality ordinarily available through the Services or another format agreed by GBD. GBD is not required to create a bespoke export format, reconstruct data already deleted in accordance with the Services or this DPA, or retain data beyond the applicable retention period solely to facilitate a later export.
  4. The Customer may communicate a contrary return or deletion instruction within 30 days after termination of the relevant processing Services. If the Customer gives no contrary instruction during that period, the Customer instructs GBD to delete the remaining Customer Personal Data in accordance with GBD's normal deletion processes.
  5. Copies contained in backups or disaster-recovery systems may remain until removed through GBD's ordinary backup lifecycle. While retained, those copies remain subject to the protections of this DPA and will not be used for ordinary business purposes. GBD is not required to alter an ordinary backup cycle or restore a backup solely for the purpose of separately deleting data from that backup, except where Applicable Data Protection Law requires otherwise. If a backup containing previously deleted Customer Personal Data is restored, GBD will continue to apply the applicable deletion instruction.
  6. This Section does not require deletion or return of information that GBD lawfully processes as an independent controller under the Privacy Policy, including limited security, audit, billing, compliance, legal or Recovery Record information.

9. Information and audits

  1. GBD will make available to the Customer information necessary to demonstrate GBD's compliance with its obligations under Article 28 of the GDPR. GBD may satisfy this obligation through relevant policies, descriptions or summaries of technical and organisational measures, compliance questionnaires, independent audit reports, certifications or other reasonably appropriate documentation.
  2. The Customer will review information reasonably made available by GBD before requesting an audit. If that information is not reasonably sufficient to demonstrate compliance with the relevant Article 28 obligation, the Customer may conduct or mandate an audit of GBD's relevant processing, subject to the following reasonable safeguards:GBD may charge its reasonable internal and external costs of supporting an audit. If the audit establishes a material breach by GBD of an obligation under Article 28 relating to the audited processing, GBD will not charge assistance costs reasonably attributable to verifying that established breach.
    • the Customer will identify the specific compliance matter to be audited and provide a reasonable audit plan;
    • the Customer will give at least 30 days' written notice;
    • ordinary Customer-requested audits are limited to once in any 12-month period;
    • documentary or remote review will be used first where it can reasonably satisfy the audit purpose;
    • any inspection will take place at a mutually reasonable time during normal business hours and will minimise disruption to GBD's operations;
    • the auditor must be independent, appropriately qualified, bound by written confidentiality obligations and not a direct competitor of GBD;
    • the audit will be limited to systems, records and processing relevant to the Customer's Customer Personal Data and the applicable Article 28 obligations;
    • the audit must not expose another customer's data or confidential information;
    • the audit must not require disclosure of source code, credentials, cryptographic secrets, vulnerability details, privileged material, trade secrets or information that GBD is legally or contractually prohibited from disclosing, except to the minimum extent a mandatory legal obligation requires otherwise;
    • penetration testing, vulnerability scanning, destructive testing, social engineering, physical-security testing or direct testing of production systems requires GBD's prior written agreement and may be subject to separate security conditions;
    • the Customer and auditor must follow GBD's reasonable security, confidentiality, access and safety requirements; and
    • the Customer bears all costs of its auditor and its own audit activities.
  3. The ordinary notice and frequency restrictions in Section 9.2 do not apply to the extent:Even in those circumstances, the parties will use reasonable efforts to minimise unnecessary disruption and protect the confidentiality and security of GBD, its systems and other customers.
    • a competent supervisory authority requires an audit or inspection;
    • Applicable Data Protection Law requires an earlier audit; or
    • the Customer provides reasonable documented grounds indicating a material breach by GBD of its Article 28 obligations and an earlier audit is reasonably necessary to investigate that suspected breach.

Nothing in this Section limits the lawful powers of a competent supervisory authority.

10. Term, updates and Business Transfers

  1. This DPA remains in effect for as long as GBD processes Customer Personal Data on the Customer's behalf. It cannot be terminated separately from the Terms.Obligations that by their nature must continue after termination survive only to the extent and for the period necessary to govern Customer Personal Data that GBD is required or permitted to retain, to complete return or deletion, to comply with applicable law, or to determine or enforce rights and liabilities arising before termination.
  2. Updates to this DPA take effect in accordance with the publication, notice and acceptance mechanism set out in the Terms. The updated DPA will continue to satisfy the mandatory processor-contract requirements of Applicable Data Protection Law applicable to GBD's processing.No separate handwritten signature, separately negotiated amendment or customer-specific acceptance process is required unless mandatory law or a separately signed agreement expressly requires otherwise.
  3. In connection with a Business Transfer described in the Terms, the Customer confirms its documented instruction and authorisation for GBD to transfer the DPA, Customer Personal Data and related content as reasonably necessary to complete and implement the Business Transfer and enable continued provision of MillionVerifier by the Successor Provider in accordance with the Terms.This DPA and GBD's processor position may be assigned, novated or otherwise transferred to the Successor Provider together with the Terms without separate Customer consent, subject to the Business Transfer provisions of the Terms and mandatory law.Before the Successor Provider processes Customer Personal Data for operational purposes as the successor processor, it must be bound in writing or electronic form by this DPA or other processor obligations satisfying the mandatory requirements applicable to that processing. Any international-transfer safeguard legally required for that processing must also be in place.Except where mandatory law requires otherwise, no additional Customer consent or separate processor agreement is required solely because the identity, registration details, address or jurisdiction of the Provider changes as part of a Business Transfer carried out in accordance with the Terms.

11. General terms and contact

  1. The liability, exclusions, remedies, governing law, jurisdiction, notice, assignment, severability and other general provisions of the Terms apply to this DPA.To the maximum extent permitted by law, contractual claims arising out of or relating to this DPA are subject to the same exclusions, limitations, remedies and allocation of risk that apply under the Terms. This DPA does not create a separate or additional category of uncapped contractual liability.Nothing in the Terms or this DPA limits a responsibility, statutory liability or right that cannot lawfully be limited or excluded under Applicable Data Protection Law.
  2. This DPA is concluded electronically and does not require a handwritten signature.
  3. Data-protection questions concerning this DPA may be sent to:
    • General support: [email protected]
    • Post: GBD Software as a Service Private Limited Company, 6065 Lakitelek, Szikra tanya 93., Hungary
  4. Except for statutory rights that cannot lawfully be excluded, this DPA does not confer contractual rights on data subjects, supervisory authorities or other third parties.
  5. The Customer may exercise contractual rights under this DPA only through an authorised representative. GBD may reasonably rely on authenticated Account activity and communications from persons reasonably appearing to be authorised and may request reasonable evidence of authority where appropriate.

Annex 1 — Processing details

ItemDescription
Subject matterEmail verification, cleaning and related processing through the MillionVerifier Website, application, API and supported integrations.
DurationFor the period during which the Customer uses the relevant Services, followed by the deletion and backup periods described in this DPA.
Nature of processingReceiving, transmitting, temporarily storing, organising, validating, comparing, querying relevant technical systems, classifying, returning results, troubleshooting, securing, backing up and deleting Customer Personal Data.
PurposeTo provide, secure, maintain and support the Services according to the Customer's documented instructions.
FrequencyOn demand or continuously, as initiated or configured by the Customer through the Website, application, API or integrations.
Categories of data subjectsIndividuals whose contact information the Customer lawfully submits, which may include business contacts, prospects, customers, subscribers, employees, contractors or other contacts.
Types of Personal DataEmail addresses; names, company or professional details and other non-sensitive fields supported by the relevant Service and lawfully submitted by the Customer; verification status and result data; and list, file, API and processing metadata needed to provide the Services.
Special categories and criminal dataNot intended or authorised unless GBD expressly agrees in writing and the parties document the lawful basis, instructions and additional safeguards required for the processing.
Customer's rights and obligationsWhere the Customer is the controller, it retains control over the purposes of processing, its lawful instructions, legal basis, data-subject communications and requests and use of the results. Where the Customer acts as a processor, those matters remain subject to the instructions and authority of the relevant upstream controller. The Customer may use available Service controls to submit, access, export and delete Customer Personal Data and may issue lawful instructions within the scope of this DPA.

Annex 2 — Security measures

GBD maintains a security programme containing technical and organisational measures appropriate to the risks of the relevant processing in accordance with Article 32 of the GDPR.

The specific measures applicable to a system, component or processing activity may vary according to its purpose, architecture and risk. As appropriate, GBD's measures include controls in the following categories:

  • role-based and least-privilege access controls;
  • authentication controls and additional protection for privileged access;
  • encryption in transit and, where appropriate having regard to risk and architecture, at rest;
  • logical separation of customer data;
  • secure configuration, patching, vulnerability management and malware protection;
  • logging, monitoring and controls designed to detect unauthorised access or misuse;
  • backup, restoration and business-continuity measures;
  • incident-response and breach-management procedures;
  • confidentiality obligations and appropriate security awareness for authorised personnel;
  • subprocessor due diligence and contractual security requirements; and
  • periodic testing, assessment and review of relevant security measures.

GBD may modify, replace or update individual security measures, technologies, suppliers, controls and implementation methods as the Services, technology and risks evolve, provided that the resulting measures remain appropriate as required by Article 32 of the GDPR and Applicable Data Protection Law.

Nothing in this Annex requires GBD to use or retain a particular technology, product, supplier, certification, standard, hosting architecture or implementation method unless expressly agreed by GBD in writing.


Previous versions

Data Processing Agreement - archived - v. 20 July 2026
Published: 20 July 2026 This Data Processing Addendum (DPA) forms part of the MillionVerifier Terms of Service (Terms) between: GBD Software as a Service Private Limited Company, a company incorporated under the laws of Hungary, with its registered office at 6065 Lakitelek, Szikra tanya 93., Hungary, company registration number 03-
Data Processing Agreement - Archived - 2025-12-04
Thoughts, stories and ideas.