phoneveriflo
Pricing
Sign in Start free preflight
Home›Legal & Trust›Data Processing Agreement (DPA)
Official Governance & Legal Agreements

Data Processing Agreement (DPA)

Standard Data Processing Addendum under Article 28 of the GDPR and UK GDPR governing the processing of customer personal data.

Effective: January 15, 2026 Last Revised: August 14, 2026Version v3.2English (UK / Global)
Legal Inquiry →
Privacy PolicyTerms of ServiceRefund & CancellationData Processing (DPA)Acceptable Use Policy
Table of Contents
1. Scope & Order of Precedence2. Controller & Processor Roles3. Technical & Organizational Measures4. Sub-processor Authorization5. Data Subject Rights Assistance6. Security Incident Notification7. Data Deletion & Return8. Standard Contractual Clauses (SCCs)9. Annex 1 & 2: Security & Processing Details
Need assistance?

Contact our legal compliance & DPO desk.

[email protected]

1. Scope & Order of Precedence

This Data Processing Agreement ("DPA") supplements the phoneveriflo Terms of Service and applies to the processing of Customer Personal Data by phoneveriflo Ltd. in connection with providing verification services.

In the event of any conflict between this DPA and the Terms of Service, the provisions of this DPA shall prevail with respect to data protection obligations.

2. Controller & Processor Roles

  • Customer as Controller: The Customer determines the purposes and means of processing Customer Personal Data and warrants that it has established a valid lawful basis (including necessary consents or notices) prior to submitting datasets.
  • phoneveriflo as Processor: phoneveriflo shall process Customer Personal Data strictly upon the documented instructions of the Customer and in accordance with applicable Data Protection Legislation (GDPR Art. 28(3)(a)).

3. Technical & Organizational Measures (TOMs)

phoneveriflo implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against unauthorized access, destruction, loss, or alteration (GDPR Art. 32):

  • Envelope Encryption: AES-256-GCM encryption for all stored files, cache records, and preflight outputs.
  • In-Transit Cryptography: TLS 1.3 encryption with strict cipher suites for all network ingress and egress.
  • Pseudonymized Indexing: Blind HMAC-SHA256 nonces for cache lookups, preventing plain PII indexing.
  • Role-Based Access: Multi-factor authentication, least-privilege RBAC, and immutable audit trails for administrative access.

4. Sub-processor Authorization

The Customer grants general written authorization to phoneveriflo to engage technical sub-processors (cloud hosting, database replication, email delivery) to provide the Service.

phoneveriflo imposes equivalent data protection obligations on all sub-processors under binding written contracts and remains fully liable for the performance of its sub-processors' obligations.

5. Data Subject Rights Assistance

Taking into account the nature of processing, phoneveriflo provides self-service tools and technical assistance to enable the Customer to fulfill its obligations to respond to data subject requests under GDPR Chapter III (access, rectification, erasure, restriction, and portability).

6. Security Incident Notification

In the event of a confirmed Personal Data Breach affecting Customer Personal Data, phoneveriflo shall notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of the breach, providing relevant details to assist the Customer in regulatory notifications.

7. Data Deletion & Return

Upon termination of services or upon customer request, phoneveriflo shall delete or return all Customer Personal Data in accordance with our rolling retention policies, except where retention is required by applicable statutory law.

8. Standard Contractual Clauses (SCCs)

For data transfers to third countries not recognized as providing an adequate level of data protection, the parties incorporate by reference the European Commission Standard Contractual Clauses (Module 2: Controller to Processor).

9. Annex 1 & 2: Details of Processing & TOMs

Annex 1: Processing Particulars
Categories of Data Subjects: Customer's end-users, prospective leads, and contact list subscribers.
Categories of Personal Data: Telephone numbers, email addresses, line type flags, carrier codes, and delivery timestamps.
Nature of Processing: Normalization, validation, carrier lookup, and cryptographic deduplication.
Duration of Processing: For the term of the customer agreement, subject to the 90-day maximum cache cap.
phoneveriflo

Verification workflows with transparent preflight pricing, provider-neutral results, and visible freshness metadata.

Platform status

Products

Phone validationEmail validationNumber generatorBulk verificationDeveloper API

Solutions

CRM cleaningSMS list cleaningSignup verificationFraud preventionData migrationCustomer engagement

Developers

API documentationQuickstartLibraries & SDKsWebhooksChangelog

Resources

Blog & guidesToolsGlossaryCoverageSupport

Company

AboutSecurityPrivacyTermsContact
© 2026 phoneveriflo. All rights reserved.PrivacyTermsSecurityStatus