Privacy, terms, GDPR and our data processing agreement, written to be read, not skimmed past. Last updated 18 August 2026.
What we collect. Your account details (name, email, billing), the lists you upload for verification, and standard service logs. Nothing else. No tracking pixels in your exports, no browsing profiles.
Why we collect it. To verify your addresses, bill you correctly, and keep the service secure. Uploaded lists are used for exactly one purpose: producing your verification report.
Retention. Uploaded lists auto-delete 30 days after processing; you can delete them instantly at any time. Account data is kept while your account is active and removed within 30 days of closure.
Your rights. Access, correction, export, deletion: email privacy@scrubbed.email and we'll action it within statutory timelines.
Acceptable use. Verify lists you own or have consent to process. No purchased lists, no harvested addresses, no using verification to enable spam. We terminate accounts that do.
Credits & billing. Credits are purchased upfront, never expire, and are consumed one per address processed. Duplicates are deduplicated free before counting. Prices are shown in your billing currency (USD, ZAR, AUD, GBP or EUR) and include VAT where it applies.
Service levels. We target 99.9% availability for the dashboard and 99.99% for the verification API. Verification accuracy is measured continuously against real delivery outcomes.
Liability. Verification is a statistical judgement, not a guarantee of delivery. Our liability is capped at the amount you paid in the preceding 12 months.
Roles. For uploaded lists, you are the data controller and Scrubbed is your processor under GDPR (and the operator under POPIA). We process addresses solely on your documented instruction: the clean itself.
Data processing agreement. Our standard DPA (with SCCs for international transfers) is published in full at scrubbed.email/legal/dpa and applies to every customer. Email privacy@scrubbed.email for a countersigned copy.
Data residency. EU customer data is processed in EU regions; South African customer data can be pinned to SA regions on request.
Subprocessors. Hosting and payment processing only, listed with regions on the Security page. We give 30 days' notice before adding any subprocessor.