Privacy Policy
Published: 20 July 2026
This Privacy Policy explains how GBD Software as a Service Private Limited Company handles Personal Data when someone visits MillionVerifier, creates or uses an Account, buys or uses the Services, communicates with us or otherwise interacts with our business.
MillionVerifier is a business-only service, but data-protection rights still apply to natural persons, including sole traders, self-employed professionals, Authorized Users, administrators, billing contacts, support contacts, prospects and people whose data a Customer submits for verification.
For Account, billing, security and our own business activities, GBD normally acts as the controller. When a Customer submits email addresses or other Personal Data for verification, the Customer normally acts as controller and GBD acts as processor under the Data Processing Agreement (DPA) and the Customer’s documented instructions.
1. Who is responsible
GBD Software as a Service Private Limited CompanyRegistered office: 6065 Lakitelek, Szikra tanya 93., HungaryCompany registration number: 03-10-100682Hungarian tax number: 27325162-2-03EU VAT number: HU27325162General support: [email protected]
Our Data Protection Officer is Dr. Ham-Szabo Boglarka Barbara. You can contact her at [email protected] or by post at the address above, marked for the attention of the Data Protection Officer.
Capitalised words used but not defined here have the meaning given in the Terms of Service. Personal Data means information about an identified or identifiable natural person. Customer Personal Data means Personal Data submitted or otherwise processed for a Customer through the Services.
2. Personal Data we collect
Depending on how you interact with us, we may collect:
- Account and business information: name, email address, password hash, phone number, role, Account identifier, company or trading name, company-registration details, tax or VAT number, business or self-employment status, professional role, authority to act for a Customer and reasonable evidence of identity, business status or Account control.
- Integration and support information: API keys, tokens, connection details and integration settings used to provide and secure integrations, together with support requests, emails, chats, call records, meeting notes and related metadata.
- Contract and notification information: service and push-notification preferences, the applicable Terms or policy version and publication date, Account and Authorized User identifiers, a new Customer’s acceptance checkbox, in-app notices, emails, delivery or bounce status, dates, times, IP address, user agent, and Website, application, API or integration activity used to document continued use after publication.
- Billing, payment and Credit information: billing name and address, tax details, payment method type, limited card information supplied by a payment processor, purchases, invoices, refunds, chargebacks, Paid and Promotional Credit classifications, Credit Ledger and FIFO information, inactivity, Recovery Records and Credit restoration. We do not store full card credentials.
- Compliance evidence: information reasonably requested under the Terms to verify the lawful source and permitted use of email addresses, such as provider details, agreements, invoices, licence terms, warranties, privacy notices, controller instructions, lawful-basis records, suppression or objection records, audit records and limited representative samples.
- Usage, device and security information: IP address, approximate location, browser, operating system, device information, referral source, pages and navigation, dates and duration of use, Account and API activity, authentication events, security events, error logs and cookie or similar identifiers.
- Marketing and business-contact information: professional contact details, employer, role, source, engagement history, communication preferences, consent, opt-out, unsubscribe and suppression records.
We may receive this information from you, another Account administrator, a Customer, payment and fraud-prevention providers, authentication and integration providers, communications and analytics providers, public professional sources, B2B data providers, advisers, authorities or a previous provider in a Business Transfer. Where law requires us to notify a person about data obtained indirectly, we will do so unless an exception applies or the person has already been informed.
3. How and why we use Personal Data
We use Personal Data only where we have a legal basis. The main purposes and bases are:
When we rely on legitimate interests, we consider the business need, the impact on individuals and appropriate safeguards. When we rely on consent, it can be withdrawn at any time without affecting earlier lawful processing.
Providing information may be necessary to create or administer an Account, process a payment, verify business status or authority, restore Credits or respond to a rights request. If required information is not provided, we may be unable to complete the relevant action or continue providing the Services or Account access.
4. Customer Personal Data
When GBD acts as processor, we use Customer Personal Data only to provide, secure, support and maintain the Services, follow the Customer’s documented instructions, comply with the DPA and meet legal obligations. Access is limited to authorised personnel and service providers that need it. We do not use Customer lists for our own direct marketing or to build unrelated marketing lists.
The Customer is responsible for the lawful source, lawful basis, authority, notices and permitted use of the data it submits. Data may have been collected directly or lawfully obtained from a data provider, list owner, broker or licensor. The individuals do not have to be the Customer’s subscribers and do not have to have opted in unless applicable law requires that for the Customer’s intended use.
Uploaded files and result files are normally deleted automatically within 30 days unless another period is agreed or limited information must be kept for security, audit, backup, dispute or legal reasons.
If we request compliance evidence under the Terms, we use it only as reasonably needed to assess compliance, protect the Services, apply restrictions or enforcement, prevent fraud and establish or defend claims. GBD acts as controller for the resulting Account-level review and enforcement records where it independently determines those purposes. The underlying verification processing remains governed by the DPA.
If a Customer submitted your Personal Data, you should normally direct your request to that Customer. We will assist the Customer as required by the DPA and applicable law.
5. Sharing Personal Data
We share Personal Data only as reasonably needed for the purposes above. Recipients may include:
- hosting, cloud, network, backup, security and content-delivery providers;
- customer-support, communications, scheduling and transactional-email providers;
- payment, billing, accounting and fraud-prevention providers, including Stripe or PayPal where used;
- analytics, consent-management, advertising and conversion-measurement providers, subject to applicable consent requirements;
- software-development, monitoring, automation, document-storage and business-operations providers;
- GBD affiliates, authorised personnel and contractors;
- lawyers, accountants, auditors, insurers, banks, financiers and other professional advisers;
- authorities, courts and other legal recipients where disclosure is required or reasonably needed to comply with law, enforce agreements, protect the Services, prevent unlawful conduct or establish or defend claims; and
- a third party chosen or authorised by the Customer, including through an integration.
Service providers that process Personal Data for us must follow appropriate confidentiality, security and data-protection obligations. A list of material subprocessors for Customer Personal Data is maintained under the DPA or is available on request.
We do not sell Personal Data as an unrelated data-broker product.
6. Business Transfers and international transfers
In a Business Transfer, we may share and transfer Personal Data, Accounts, service history, Credits, Credit Ledger information, Recovery Records, billing and support records as reasonably needed to assess or complete the transaction, continue MillionVerifier, preserve contractual entitlements, maintain security and comply with law.
Before completion, we will use aggregated, anonymised or otherwise minimised information where reasonably practical. Identifiable Personal Data will be disclosed before completion only where needed, permitted by law and protected by appropriate confidentiality and data-protection terms. Customer Personal Data will not be made available to a Successor Provider for operational use until the transfer is permitted by the Terms and DPA, the Successor Provider has assumed the relevant processor obligations in writing and appropriate transfer safeguards are in place.
We will notify affected Account contacts by email and, where reasonably available, through the Account or dashboard. Notice will normally be given in advance and no later than the transfer date. It will identify the Successor Provider, its registration details and address, the transfer date, the main categories and purposes of the transferred data, intended recipients, relevant country and transfer safeguard, billing and support details, privacy contact, applicable rights and the policies applying after the transfer. Where relevant, it will also identify the law authorising or requiring the collection. If the Successor Provider is subject to the New Zealand Privacy Act 2020, the notice will include the information reasonably required by Information Privacy Principle 3A.
GBD remains responsible for its processing before the transfer date. The Successor Provider is responsible for its own processing and the processor duties it assumes after that date, and its privacy policy applies from that date.
Personal Data may be processed outside Hungary or the European Economic Area. Where the GDPR applies, we use a lawful transfer mechanism, such as a European Commission adequacy decision, the European Commission’s standard contractual clauses, another recognised safeguard or a lawful derogation. New Zealand is currently covered by an EU adequacy decision, and we may rely on it while it remains in force. Information about the applicable safeguard can be requested from our Data Protection Officer.
7. Security and retention
We use technical and organisational measures designed to protect Personal Data against loss, misuse, alteration, unauthorised access and unlawful disclosure. Measures may include encryption, firewalls, secure configurations, role-based access, authentication, logging, monitoring, vulnerability management, backups, recovery controls, testing and confidentiality duties.
No security measure eliminates all risk. We investigate Personal Data breaches and take reasonable containment and remediation steps. We notify individuals and authorities where required by law. We may ask for reasonable evidence of identity and authority before disclosing data or changing an Account.
We keep Personal Data only for as long as reasonably needed for the purpose for which it was collected and for contractual, security, accounting, tax, legal and dispute requirements. Unless a different period is required or justified:
- Account Data is kept while the Account is active. After an inactive Account is removed, ordinary Account Data is deleted or de-identified except for Recovery Records and information needed for legal, security, accounting, tax or dispute purposes. In other cases, Account Data may be kept for up to one year after the Services end.
- A Recovery Record contains a hashed email identifier, remaining Paid and Promotional Credit balances and the minimum ledger information needed to preserve classification and FIFO order and prevent duplicate or fraudulent restoration. It may remain Personal Data and is kept while reasonably needed to honour recoverable Credits and comply with law, subject to periodic review.
- Uploaded files and result files are normally deleted within 30 days.
- Business-eligibility, authority, compliance and policy-notice records are kept as long as reasonably needed to administer the relationship, verify compliance, enforce the Terms and handle claims.
- Support and correspondence records may be kept for up to 10 years where reasonably needed for records or claims.
- Usage and device information may be kept for up to 50 months after the relationship ends.
- Billing, invoice, transaction and tax records are kept for the period required by applicable law.
- Marketing preference and suppression records are kept as long as needed to respect choices and demonstrate compliance.
- Business Transfer records are kept as long as reasonably needed to document the transaction, maintain continuity, comply with law and resolve claims.
When a retention period ends, we delete, anonymise or securely isolate the data unless continued retention is legally required. Deleted data may remain temporarily in restricted backups until the normal backup cycle removes it. Withdrawing consent does not require deletion where another legal basis or retention duty applies.
8. Cookies, sensitive data and minors
We use cookies and similar technologies for essential operation, security, preferences, analytics and, where enabled, advertising or conversion measurement. Where required, we ask for consent before using non-essential technologies. Choices can be managed through our cookie controls and Cookie Policy.
Do not submit special-category or other highly sensitive Personal Data unless GBD has expressly agreed in writing and the processing is lawful. This includes government identifiers, full card details, financial-account credentials, health, genetic or biometric data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership and information about sex life or sexual orientation.
The Services are not directed to people under 18, and we do not knowingly ask minors to provide Personal Data through the Services.
9. Your rights
Depending on the applicable law and circumstances, you may have the right to:
- access your Personal Data;
- correct inaccurate or incomplete data;
- request deletion or restriction in certain cases;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain data in a structured, commonly used and machine-readable form and request portability where applicable;
- withdraw consent where processing is based on consent; and
- complain to a supervisory authority.
To stop marketing emails, use the unsubscribe link or contact [email protected]. We may keep enough suppression information to respect the request.
Rights requests are normally free. We may charge a reasonable fee or refuse a request only where law permits, including where it is manifestly unfounded or excessive. We may request information needed to verify identity and authority.
For Personal Data for which GBD acts as controller, contact [email protected]. Where we act only as processor, direct the request to the Customer that submitted the data; we will assist that Customer as required.
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address: 1363 Budapest, Pf. 9., Hungary
- Email: [email protected]
- Telephone: +36 (1) 391 1400; +36 (30) 683-5969; +36 (30) 549-6838
- Website: https://www.naih.hu/
After a Business Transfer, you may also contact the Successor Provider or the authority identified in its privacy policy or transfer notice.
10. Changes and contact
We may update this Privacy Policy for legal, regulatory, security, technical, operational or business reasons. A new version takes effect when published with its publication date, unless applicable law requires otherwise. Customer notices are provided through the Account or by email as described in the Terms of Service.
This Privacy Policy is a transparency notice. Publication, login, receipt of a notice or continued use does not by itself amount to consent where consent is legally required. If a new purpose requires consent or another legal step, we will complete it before that processing begins.
Questions about this Policy or GBD’s use of Personal Data can be sent to:
- General support: [email protected]
- Data Protection Officer: [email protected]
- Post: GBD Software as a Service Private Limited Company, 6065 Lakitelek, Szikra tanya 93., Hungary
Previous versions:
