← back to legal
legal

DATA PROCESSING AGREEMENT

In one sentence: you are the controller of the lists you upload, Scrubbed is your processor, and this agreement is the paperwork that binds us to treat your data exactly the way the Security page promises.

This Data Processing Agreement ("DPA") forms part of the Scrubbed Terms of Service and applies automatically to every customer whose use of the service involves personal data. It is written to satisfy Article 28 of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and section 21 of South Africa's Protection of Personal Information Act ("POPIA"). No signature is required for it to bind us; if your compliance team needs a countersigned copy, email privacy@scrubbed.email and we will return one.

1. Parties and roles

"Scrubbed", "we" and "us" means Scrubbed, a trading name of Mail Blaze (Pty) Ltd, a company registered in South Africa. "Customer", "you" means the person or entity holding the Scrubbed account.

2. Subject matter and purpose

We process the personal data in your lists for exactly one purpose: verifying the deliverability and risk of the email addresses you submit and returning the results to you. We never use list data for our own purposes. In particular, list data is never used to train models, never sold, never used for advertising or enrichment, and never disclosed to anyone except the subprocessors in section 7.

ItemDetail
Categories of data subjectsThe individuals whose addresses appear in your lists (typically your subscribers, customers or leads)
Categories of personal dataEmail addresses; any incidental columns present in an uploaded file (for example names). Only the email column is processed; other columns are stored with the source file and returned untouched
Special categoriesNone are sought or knowingly processed. Do not upload special-category data
Nature of processingIngestion, deduplication, syntax and DNS analysis, protocol-level mailbox verification, risk screening, report generation, storage, deletion
DurationYour chosen retention window (7, 30 or 90 days per list), or until you delete the list, whichever comes first

3. Your instructions

We process list data only on your documented instructions. Submitting a list for evaluation or cleaning, connecting an integration, calling the API, downloading results, pushing suppressions back to a connected platform, and deleting data each constitute a documented instruction. We will tell you promptly if, in our view, an instruction would breach data protection law.

You warrant that you have a lawful basis to have the addresses you submit processed for verification, and that your lists are your own. Purchased and harvested lists breach our Terms and this DPA.

4. Confidentiality

Every person we authorise to process list data is bound by a written confidentiality obligation. Human access to customer data requires a reason, is logged, and is reviewed; access rights follow least privilege.

5. Security measures

We maintain the technical and organisational measures below (Article 32 GDPR; POPIA section 19), and we will not reduce them during the life of your account:

6. Assisting you

Taking the nature of the processing into account, we will assist you in meeting your own obligations:

7. Subprocessors

You authorise the following categories of subprocessor, used strictly to deliver the service:

SubprocessorPurposeRegion
Akamai / LinodeInfrastructure hosting for the application, database and filesUnited Kingdom / EU
Specialist mailbox-verification infrastructureTransient protocol-level verification of addresses that pass our local screensEU / US (SCCs in place)
Mail BlazeDelivery of transactional email about your account (never to your list)South Africa / EU
Stripe; Peach PaymentsPayment processing for your purchases (billing data only, never list data)US / EU; South Africa

We remain fully liable for our subprocessors' performance. We will give you at least 30 days' notice by email before adding or replacing a subprocessor that touches list data; if you object on reasonable data-protection grounds and we cannot resolve it, you may terminate and we will refund unused credits.

8. International transfers

Where list data moves outside the EEA, the UK or South Africa, the transfer is protected by the European Commission's Standard Contractual Clauses (module two, controller to processor), which are incorporated into this DPA by reference, or by another lawful transfer mechanism. Transfers out of South Africa comply with POPIA section 72.

9. Personal data breaches

If we become aware of a personal data breach affecting your list data we will notify you without undue delay, and in any event within 48 hours, with the information Article 33(3) GDPR requires: what happened, whose data, likely consequences, and what we are doing about it. We will not notify authorities or data subjects on your behalf unless you ask us to or the law requires it.

10. Deletion and return

You can export your results at any time while a list is stored. On expiry of a list's retention window, on your deletion of a list, or on account closure, we delete the personal data concerned; account closure removes all customer data within 30 days. After deletion we retain nothing except what the law obliges us to keep (for example invoices) and the pseudonymised verification cache described in section 5, which contains no readable addresses.

11. Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA: our security documentation, subprocessor list, and answers to written security questionnaires. Where that is genuinely insufficient, you (or an independent auditor you appoint who is not our competitor) may audit on 30 days' written notice, at most once per year, during business hours, without disrupting the service, each party bearing its own costs.

12. Liability, term and law

This DPA starts when you first submit personal data to the service and lasts as long as we hold any of it. Liability under this DPA is subject to the limitations in the Terms of Service, except where data protection law does not permit them to apply. This DPA is governed by the law that governs your Terms of Service; the SCCs are governed as their own clauses provide. If this DPA conflicts with the Terms, this DPA wins on data protection matters; if the SCCs conflict with this DPA, the SCCs win.

Need it countersigned? Email privacy@scrubbed.email from your account address and we will return an executed copy, usually within two business days.