Data Processing Addendum
This Data Processing Addendum ("DPA") describes how Verifence processes personal data on behalf of customers when providing the Verifence platform, and forms part of the agreement between Softway Solutions SRL, trading as Verifence ("Processor"), and the customer ("Controller") governing use of the Service. It supplements our Terms of Service and should be read alongside our Privacy Policy.
1. Introduction
Verifence is operated by Softway Solutions SRL, a company registered in Romania with its registered address at Calea Văcărești 340, bl. 16, ap. 22, Bucharest, Romania. Where a customer submits personal data to Verifence for scanning or verification — such as email addresses, or personal data contained in files or URLs submitted for analysis — Verifence acts as a processor on the customer's behalf and the customer acts as the controller of that data. As an entity established in Romania, Verifence is directly subject to the EU General Data Protection Regulation (GDPR), and this DPA is structured accordingly; it also reflects the requirements of the UK GDPR for customers in the UK.
2. Definitions
- Personal Data — any information relating to an identified or identifiable natural person submitted to the Service by or on behalf of the customer.
- Processing — any operation performed on Personal Data, including collection, storage, analysis, and deletion.
- Controller — the customer, who determines the purposes and means of processing Personal Data.
- Processor — Verifence, which processes Personal Data on the Controller's behalf and instructions.
- Sub-processor — a third party engaged by Verifence to process Personal Data in order to provide the Service.
3. Subject matter and duration
The subject matter of processing is the Personal Data submitted to Verifence through the web app, API, or WordPress plugin for the purpose of email validation, document scanning, URL scanning, and related risk-checking features. Processing continues for the duration of the customer's use of the Service, plus the applicable data retention period described in our Privacy Policy.
4. Nature and purpose of processing
Verifence processes Personal Data solely to provide the Service: to evaluate and return a risk verdict on submitted emails, files, and URLs, to store scan history for the customer's account, and to detect abuse of the Service. Categories of data subjects typically include the customer's own end users, leads, or contacts (for example, the individuals behind email addresses submitted for verification). Categories of Personal Data are generally limited to email addresses and, where present, personal data contained within submitted files or URLs.
5. Processor obligations
- Process Personal Data only on the Controller's documented instructions, including as set out in this DPA, unless required to do otherwise by law.
- Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
- Implement appropriate technical and organizational measures to protect Personal Data, as described in our Security page.
- Assist the Controller in responding to data subject requests and in meeting its own compliance obligations, taking into account the nature of processing.
- Notify the Controller of a Personal Data breach without undue delay after becoming aware of it.
- Delete or return Personal Data at the end of the engagement, except where retention is required by law.
6. Sub-processors
The Controller provides general authorization for Verifence to engage the following sub-processors, each bound by data protection terms consistent with this DPA:
- Hetzner Online GmbH (Germany) — server hosting for the web app, API, and stored Personal Data
- Cloudflare, Inc. (United States) — CDN and DDoS protection in front of our servers
- Stripe Payments Europe, Ltd. (Ireland) — payment processing and subscription billing
- Clicky (Roxr Software Ltd.) — web analytics
- Google LLC — Google Analytics (United States) — usage analytics
- Google WebRisk, VirusTotal, URLScan.io, Spamhaus, Barracuda — threat intelligence lookups performed as part of scanning
Verifence will update this list as sub-processors change and will provide notice of material changes to customers who have requested it by emailing hello@verifence.io.
7. International transfers
Verifence is established in Romania, and Personal Data is primarily stored and processed on servers hosted by Hetzner in Germany, with billing handled by Stripe's Irish entity — all within the European Economic Area. Some of our sub-processors — including Cloudflare and Google — are located in or transfer data to the United States for narrower purposes such as CDN/DDoS protection and analytics. Where Personal Data is transferred outside the EEA, Verifence relies on appropriate safeguards recognized under the GDPR, in particular the European Commission's Standard Contractual Clauses, and, where applicable, a sub-processor's certification under the EU-U.S. Data Privacy Framework, to ensure the data remains protected.
8. Security measures
Verifence maintains technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, and incident response procedures. Full detail is available on our Security page.
9. Assistance with data subject requests
If Verifence receives a request from a data subject relating to Personal Data processed on the Controller's behalf, we will promptly notify the Controller and, where the Controller cannot resolve the request through the Service directly, provide reasonable assistance to fulfill it.
10. Audit rights
Verifence will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for, and contribute to, audits and inspections conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice, confidentiality, and scheduling that avoids disruption to other customers.
11. Breach notification
Verifence will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data, and will provide information reasonably available to help the Controller meet its own notification obligations.
12. Return and deletion of data
Upon termination of the Service, or upon request, Verifence will delete Personal Data in accordance with the retention periods described in our Privacy Policy, except where continued retention is required by law.
13. Requesting a signed copy
This page summarizes the terms we apply to all customers by default. If your organization requires a fully executed DPA — including Standard Contractual Clauses for your specific transfer scenario — contact us and we'll get it signed.
Softway Solutions SRL (trading as Verifence)
Calea Văcărești 340, bl. 16, ap. 22
Bucharest, Romania
hello@verifence.io