In one sentence: you are the controller of the lists you upload, Scrubbed is your processor, and this agreement is the paperwork that binds us to treat your data exactly the way the Security page promises.
This Data Processing Agreement ("DPA") forms part of the Scrubbed Terms of Service and applies automatically to every customer whose use of the service involves personal data. It is written to satisfy Article 28 of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and section 21 of South Africa's Protection of Personal Information Act ("POPIA"). No signature is required for it to bind us; if your compliance team needs a countersigned copy, email privacy@scrubbed.email and we will return one.
1. Parties and roles
"Scrubbed", "we" and "us" means Scrubbed, a trading name of Mail Blaze (Pty) Ltd, a company registered in South Africa. "Customer", "you" means the person or entity holding the Scrubbed account.
- For the email lists you upload, paste, import through an integration, or submit through the API, you are the controller (GDPR) / responsible party (POPIA) and Scrubbed is the processor (GDPR) / operator (POPIA).
- For your account data (name, email, billing details, usage records), Scrubbed is itself the controller; that processing is governed by our Privacy Policy, not this DPA.
2. Subject matter and purpose
We process the personal data in your lists for exactly one purpose: verifying the deliverability and risk of the email addresses you submit and returning the results to you. We never use list data for our own purposes. In particular, list data is never used to train models, never sold, never used for advertising or enrichment, and never disclosed to anyone except the subprocessors in section 7.
| Item | Detail |
|---|---|
| Categories of data subjects | The individuals whose addresses appear in your lists (typically your subscribers, customers or leads) |
| Categories of personal data | Email addresses; any incidental columns present in an uploaded file (for example names). Only the email column is processed; other columns are stored with the source file and returned untouched |
| Special categories | None are sought or knowingly processed. Do not upload special-category data |
| Nature of processing | Ingestion, deduplication, syntax and DNS analysis, protocol-level mailbox verification, risk screening, report generation, storage, deletion |
| Duration | Your chosen retention window (7, 30 or 90 days per list), or until you delete the list, whichever comes first |
3. Your instructions
We process list data only on your documented instructions. Submitting a list for evaluation or cleaning, connecting an integration, calling the API, downloading results, pushing suppressions back to a connected platform, and deleting data each constitute a documented instruction. We will tell you promptly if, in our view, an instruction would breach data protection law.
You warrant that you have a lawful basis to have the addresses you submit processed for verification, and that your lists are your own. Purchased and harvested lists breach our Terms and this DPA.
4. Confidentiality
Every person we authorise to process list data is bound by a written confidentiality obligation. Human access to customer data requires a reason, is logged, and is reviewed; access rights follow least privilege.
5. Security measures
We maintain the technical and organisational measures below (Article 32 GDPR; POPIA section 19), and we will not reduce them during the life of your account:
- Encryption in transit: TLS on every connection, including internal service calls that leave a host.
- Encryption at rest for uploaded files, results and backups.
- Pseudonymised verification cache: repeat-verification results are stored against a salted, keyed hash of the address, never the plaintext address.
- Protocol-level checks only: verification is an SMTP conversation. No message is ever delivered to a data subject.
- Scheduled deletion: every list carries an automatic deletion date you control (7, 30 or 90 days); deletion removes the source file and every derived row.
- Instant deletion on demand: deleting a list, or your account, takes effect immediately. Backups expire on a rolling 14-day window, after which deleted data exists nowhere.
- Access control and audit: role-based access, unique accounts, audit logging of administrative access.
- Resilience: nightly verified backups, monitored queues, and documented recovery procedures.
6. Assisting you
Taking the nature of the processing into account, we will assist you in meeting your own obligations:
- Data subject requests. If a data subject approaches us directly we will refer them to you. On your instruction we will locate, export or erase a specific address from your stored lists without undue delay.
- Security, DPIAs and consultations. We will provide the information reasonably needed for your impact assessments and supervisory-authority consultations, drawing on the documentation on our Security page.
7. Subprocessors
You authorise the following categories of subprocessor, used strictly to deliver the service:
| Subprocessor | Purpose | Region |
|---|---|---|
| Akamai / Linode | Infrastructure hosting for the application, database and files | United Kingdom / EU |
| Specialist mailbox-verification infrastructure | Transient protocol-level verification of addresses that pass our local screens | EU / US (SCCs in place) |
| Mail Blaze | Delivery of transactional email about your account (never to your list) | South Africa / EU |
| Stripe; Peach Payments | Payment processing for your purchases (billing data only, never list data) | US / EU; South Africa |
We remain fully liable for our subprocessors' performance. We will give you at least 30 days' notice by email before adding or replacing a subprocessor that touches list data; if you object on reasonable data-protection grounds and we cannot resolve it, you may terminate and we will refund unused credits.
8. International transfers
Where list data moves outside the EEA, the UK or South Africa, the transfer is protected by the European Commission's Standard Contractual Clauses (module two, controller to processor), which are incorporated into this DPA by reference, or by another lawful transfer mechanism. Transfers out of South Africa comply with POPIA section 72.
9. Personal data breaches
If we become aware of a personal data breach affecting your list data we will notify you without undue delay, and in any event within 48 hours, with the information Article 33(3) GDPR requires: what happened, whose data, likely consequences, and what we are doing about it. We will not notify authorities or data subjects on your behalf unless you ask us to or the law requires it.
10. Deletion and return
You can export your results at any time while a list is stored. On expiry of a list's retention window, on your deletion of a list, or on account closure, we delete the personal data concerned; account closure removes all customer data within 30 days. After deletion we retain nothing except what the law obliges us to keep (for example invoices) and the pseudonymised verification cache described in section 5, which contains no readable addresses.
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA: our security documentation, subprocessor list, and answers to written security questionnaires. Where that is genuinely insufficient, you (or an independent auditor you appoint who is not our competitor) may audit on 30 days' written notice, at most once per year, during business hours, without disrupting the service, each party bearing its own costs.
12. Liability, term and law
This DPA starts when you first submit personal data to the service and lasts as long as we hold any of it. Liability under this DPA is subject to the limitations in the Terms of Service, except where data protection law does not permit them to apply. This DPA is governed by the law that governs your Terms of Service; the SCCs are governed as their own clauses provide. If this DPA conflicts with the Terms, this DPA wins on data protection matters; if the SCCs conflict with this DPA, the SCCs win.
Need it countersigned? Email privacy@scrubbed.email from your account address and we will return an executed copy, usually within two business days.