Data processing agreement
Version 1.0 · Effective 1 October 2026
This DPA is pre-signed and needs no signature from ProofTell. It applies automatically to every customer who accepts our terms of service. You do not need to contact us, and you do not need an enterprise agreement, to rely on it. Print this page or save it as a PDF to file it; countersign it if your process requires.
Parties
Processor: Epic Grove Ltd, trading as ProofTell, a company registered in England and Wales (company number 17285617), whose registered office is at 128 City Road, London, EC1V 2NX, United Kingdom (“ProofTell”, “we”).
Controller: the customer identified in the Agreement (“Customer”, “you”).
Each a “Party”, together the “Parties”.
1. Background and scope
1.1 This Data Processing Agreement (“DPA”) forms part of, and is subject to, the ProofTell terms of service or other written agreement between the Parties (the “Agreement”). Where this DPA conflicts with the Agreement on the subject of personal data processing, this DPA prevails.
1.2 This DPA applies where ProofTell processes Customer Personal Data on the Customer’s behalf in providing the Services.
1.3 Roles. For Customer Personal Data, the Customer is the controller and ProofTell is the processor. Where the Customer itself acts as a processor for a third party, ProofTell acts as its sub-processor and the Customer’s instructions are deemed to be those of that third party. Where ProofTell processes personal data of the Customer’s own account users for account management, billing, security and service communications, ProofTell acts as an independent controller for that limited purpose, governed by its privacy policy and not by this DPA.
1.4 Definitions. “Data Protection Law” means the UK GDPR and the Data Protection Act 2018, and Regulation (EU) 2016/679 (“EU GDPR”) together with its implementing laws, each to the extent applicable. “Customer Personal Data” means the personal data the Customer submits to the Services for processing on its behalf, and the results the Services return about it. “Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” carry the meanings given in Data Protection Law. “Sub-processor” means a third party engaged by ProofTell to process Customer Personal Data.
1.5 Services covered. This DPA applies to all Services under which ProofTell processes Customer Personal Data on the Customer’s behalf, namely:
- Phone intelligence: validation and enrichment of a telephone number;
- Email verification: verification that the mailbox of an email address exists;
- IP intelligence: location, network and anonymity attributes of an IP address;
- Risk assessment: the combination of the above into a score, a verdict and reasons; and
- File verification: the application of the above to the rows of a file uploaded by the Customer.
They are described in Annex I.
2. Processing on documented instructions
2.1 ProofTell shall process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do so by law to which ProofTell is subject. In that case ProofTell shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
2.2 The Agreement, this DPA (including Annex I), the settings the Customer chooses in the Services, and the Customer’s use of the Services through their documented interfaces constitute the Customer’s complete documented instructions.
2.3 ProofTell shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law. ProofTell may suspend performance of the affected instruction pending resolution.
2.4 ProofTell shall not sell Customer Personal Data, use it for its own marketing, combine it across customers to build profiles of data subjects, or use it to train machine-learning models. ProofTell may generate and use aggregated, non-identifying statistics about the use of the Services (for example request volumes, latency and the distribution of results), provided such statistics contain no personal data and cannot be attributed to any data subject.
2.5 The Customer is responsible for the lawfulness of its instructions, for having a legal basis to process Customer Personal Data, and for the decisions it takes on the basis of the results the Services return.
3. Confidentiality
3.1 ProofTell shall ensure that persons authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality, whether contractual or statutory.
3.2 ProofTell shall limit access to Customer Personal Data to personnel who require access to perform the Agreement.
4. Security
4.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, ProofTell shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II.
4.2 ProofTell may update the measures in Annex II provided the level of security is not materially reduced.
5. Sub-processors
5.1 The Customer grants ProofTell general authorization to engage Sub-processors for the processing of Customer Personal Data. The Sub-processors engaged at the date of this DPA are listed in Annex III.
5.2 ProofTell shall give the Customer at least thirty (30) days’ prior notice of the addition or replacement of any Sub-processor, by updating the sub-processor list at prooftell.com/security and notifying the Customer by email where the Customer has subscribed to such notifications.
5.3 The Customer may object to a change on reasonable data-protection grounds within the notice period. Where the Parties cannot resolve the objection, the Customer may terminate the affected Services on written notice, with a refund of its paid, unused balance.
5.4 ProofTell shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of that Sub-processor’s obligations.
5.5 Mail servers are not Sub-processors. Verifying an email address consists of asking the mail server responsible for that address whether it would accept mail for it. That server is operated by, or for, the holder of the address’s domain, and is the system already designated to receive mail for that address. It does not process Customer Personal Data on ProofTell’s instructions and is not a Sub-processor; clauses 5.1 to 5.4 do not apply to it. The request made to it carries the email address and nothing else: no Customer identity, account identifier, file or other Customer data.
6. Data subject rights
6.1 Taking into account the nature of the processing, ProofTell shall assist the Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
6.2 Where ProofTell receives a request directly from a data subject relating to Customer Personal Data, ProofTell shall not respond to the substance of the request, and shall promptly forward it to the Customer where the Customer can be identified.
6.3 Because ProofTell holds Customer Personal Data only as described in Annex I and does not maintain an index of data subjects across customers, the Customer acknowledges that assistance under this clause is provided through the review, retention and deletion functions of the Services, and by reasonable cooperation on request.
7. Personal data breach, DPIA and prior consultation
7.1 ProofTell shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.
7.2 The notification shall describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where information is not available at the time of notification, it shall be provided in phases without undue delay.
7.3 ProofTell shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultation with a supervisory authority under Articles 35 and 36 GDPR, taking into account the nature of processing and the information available to ProofTell.
8. Deletion and return
8.1 Deletion by the Customer. The Customer may delete an uploaded file and its outputs at any time through the Services; deletion removes the underlying stored objects at once. The Customer may set the period for which assessments are stored, including to zero, in which case assessments are not stored.
8.2 Automatic deletion. ProofTell deletes uploaded files, their working data and their result files thirty (30) days after upload, and deletes each stored assessment at the end of the retention period the Customer has set. The Customer is responsible for downloading result files within that period.
8.3 Deletion on termination. On expiry or termination of the Agreement, or on closure of the Customer’s account, ProofTell shall, at the Customer’s election, delete or return all Customer Personal Data and delete existing copies, within thirty (30) days, unless storage is required by law to which ProofTell is subject.
8.4 The retention periods applicable during the term of the Agreement are set out in Annex I, section 6.
9. Audit and information
9.1 ProofTell shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR.
9.2 ProofTell shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The Customer shall give at least thirty (30) days’ written notice; audits shall occur no more than once in any twelve-month period (except following a personal data breach or where required by a supervisory authority), shall be conducted during business hours, shall not unreasonably disrupt ProofTell’s operations, and shall be subject to confidentiality obligations.
9.3 ProofTell may satisfy an audit request by providing its then-current security documentation and responding to a reasonable security questionnaire, where this addresses the Customer’s requirements.
9.4 ProofTell does not currently hold SOC 2, ISO 27001 or equivalent third-party certification.
10. International transfers
10.1 Customer Personal Data is stored and processed in the European Economic Area, as set out in Annex I, section 5, save that, in providing Email verification, the email address being verified is transmitted through verification servers located in several countries inside and outside the European Economic Area and the United Kingdom, as described in Annex I, section 5 and Annex III.
10.2 ProofTell is established in the United Kingdom. Where processing under this DPA involves a transfer of Customer Personal Data outside the European Economic Area or the United Kingdom, the Parties agree that the transfer is made:
- (a) in reliance on any adequacy decision or adequacy regulations then in force in respect of the destination; or
- (b) failing that, subject to the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), Module Two (controller to processor), and/or the UK International Data Transfer Addendum, as applicable, incorporated by reference and completed as set out in Annex IV.
10.3 ProofTell shall not transfer Customer Personal Data outside the European Economic Area or the United Kingdom other than as described in Annex I and Annex III.
11. Liability and term
11.1 Each Party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
11.2 This DPA takes effect on the date the Customer accepts the Agreement and continues for as long as ProofTell processes Customer Personal Data. Clauses 3, 8, 9, 10 and 11 survive termination.
11.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where Data Protection Law requires otherwise.
Annex I: Details of processing
1. Subject matter. Provision of phone, email and IP risk signals and of a risk assessment combining them, through an API, a dashboard and file verification.
2. Duration. The term of the Agreement, plus the retention periods in section 6.
3. Nature and purpose.
Phone intelligence. Receiving a telephone number; validating its format and structure; enriching it with country, region, carrier and line-type attributes derived from reference datasets; and returning the result to the Customer. The number is processed within ProofTell’s own systems.
Email verification. Receiving an email address; checking its syntax and its domain; asking the mail server responsible for the address whether the mailbox exists, without transmitting a message; and returning the result to the Customer. The address is processed by ProofTell and by its Sub-processor Verimail Ltd, and is presented to the mail server responsible for it (clause 5.5).
IP intelligence. Receiving an IP address; looking it up in location, network and anonymity datasets held in memory on ProofTell’s own systems; and returning the result to the Customer. The address is not disclosed to any third party.
Risk assessment. Applying the three checks above to the inputs supplied, weighing their results with a fixed, versioned set of rules, and returning a score, a verdict and the reasons to the Customer. The assessment is stored for the retention period the Customer has set, so that the Customer can review and explain it.
File verification. Reading a file uploaded by the Customer, applying the checks the Customer selects to each row, and producing a result file for the Customer to download.
4. Categories of personal data.
| Source | Data |
|---|---|
| API requests | Telephone numbers, email addresses and IP addresses submitted by the Customer, and any reference identifier the Customer attaches to a request |
| Uploaded files | The above, plus any other columns the Customer chooses to include in the uploaded file, which may include names or other identifiers |
| Results | The above, plus the attributes, score, verdict and reasons returned |
ProofTell does not require, and does not ask for, any category of data beyond a telephone number, an email address and an IP address. Additional columns present in an uploaded file are passed through unmodified and are processed only incidentally.
Categories of data subjects: the individuals to whom the submitted telephone numbers, email addresses and IP addresses relate, as determined by the Customer; typically the Customer’s own customers, users, applicants, leads or contacts.
Special categories of data: none. The Customer shall not submit special category data under Article 9 GDPR or criminal offence data under Article 10 GDPR.
5. Processing locations. Customer Personal Data is stored and processed in the European Economic Area: compute, database and file storage are located in Belgium. Operational logs contain no Customer Personal Data (section 6).
In providing Email verification, the email address being verified, and nothing else, is transmitted through verification servers operated by the Sub-processor Verimail Ltd in several countries inside and outside the European Economic Area and the United Kingdom, because mail providers answer differently depending on where a request comes from. Those servers relay the request to the mail server responsible for the address.
6. Retention.
| Data | Retention |
|---|---|
| Inputs and results of single lookups (a telephone number, an email address or an IP address submitted on its own) | Not persisted to any database. Processed and returned in the response. |
| Assessments (inputs, score, verdict, reasons and the result of each check) | Stored for the retention period the Customer sets for its organization: 90 days by default, configurable from 0 (not stored) to 365 days. Deleted automatically after the period ends, normally within 24 hours. |
| Uploaded files, working data and result files | Deleted automatically 30 days after upload. Deleted at once when the Customer deletes the file. |
| File records (file name, format, column names, row counts, status, timestamps) | Retained until the Customer deletes the file or the account is closed. |
| Operational request logs | Contain the time, path, status and duration of a request and the address of the calling system. The values submitted travel in the request body and are not written to logs or error messages. Retained for 30 days. |
| Usage and billing records | Counts and amounts per signal and per organization. Contain no Customer Personal Data. Retained for the term of the Agreement and thereafter as the law requires. |
On termination or account closure, Customer Personal Data is deleted in accordance with clause 8.3.
Annex II: Technical and organizational measures
Encryption. All data in transit is protected by TLS. All data at rest is encrypted using Google-managed encryption keys (AES-256).
Authentication. Access to the API requires an organization-specific API key. Keys are displayed once, when created; only a SHA-256 hash is stored; a key can be revoked at any time. Access to the dashboard requires a verified email address and sign-in through an identity provider.
Authorization. Access within an organization is governed by roles (owner, admin, developer, analyst), each a fixed set of capabilities, checked on every request against the verified identity of the caller. Membership is by invitation, bound to the invitee’s verified email address.
Segregation. Each organization’s data is stored under its own path in the database and in file storage, and is reached only through an organization-scoped handle. Uploaded files are accessible only through short-lived signed links issued to authorized members. Client applications have no direct access to the database.
Minimization. Single lookups are not written to any database. IP addresses are looked up in memory and are not disclosed to any third party. Submitted values are not written to logs. Usage records contain no personal data.
Administrative access. Access to production infrastructure is restricted through the cloud provider’s identity and access management to the personnel who operate the Services. Secrets are held in a managed secret store, not in source code or in the database.
Resilience. The Services run on Google Cloud managed infrastructure, with the database and file storage replicated across several zones of the region.
Change management. Changes are released to production only as a build that has passed automated tests and a post-deployment check, and can be rolled back to the previous release.
Deletion. Stored assessments and uploaded files are deleted automatically at the end of the periods in Annex I, section 6, by the storage systems themselves.
Vulnerability management. Dependencies are updated as part of the regular release process.
Certification. ProofTell does not currently hold SOC 2, ISO 27001 or equivalent third-party certification.
Annex III: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud EMEA Limited (Ireland) | Compute, database and file storage infrastructure for all Services | European Economic Area (Belgium) |
| Verimail Ltd (United Kingdom) | Email verification: receives the email address being verified, and nothing else | European Economic Area (Belgium) for the verification service; verification servers rented from hosting providers in several countries inside and outside the European Economic Area and the United Kingdom |
Phone intelligence is performed by the Veriphone service, which is operated by Epic Grove Ltd itself, on the infrastructure listed above; it involves no further Sub-processor.
Not Sub-processors. The mail server responsible for an email address being verified is not a Sub-processor (clause 5.5). Other third parties engaged by ProofTell in connection with the Customer’s own account, for payment processing, sign-in and the delivery of service emails, receive no Customer Personal Data and are not Sub-processors for the purposes of this Annex. ProofTell is controller for that data, and those recipients are disclosed in its privacy policy.
Changes to this list. ProofTell gives at least thirty (30) days’ prior notice of the addition or replacement of any Sub-processor, by updating its security page and by email where the Customer has subscribed to such notifications. The Customer may object on reasonable data-protection grounds within that period; where the objection cannot be resolved, the Customer may terminate the affected Services with a refund of its paid, unused balance. See clauses 5.2 and 5.3. To subscribe, email privacy@prooftell.com.
Annex IV: Standard Contractual Clauses
Where clause 10.2(b) applies, the Standard Contractual Clauses are incorporated by reference and completed as follows: the data exporter is the Customer; the data importer is Epic Grove Ltd; Module Two (controller to processor) applies; the optional docking clause is included; the governing law and forum are those stated in clause 11.3 to the extent the Clauses permit, and otherwise those of the EU Member State in which the Customer is established; Annex I to the Clauses is populated by Annex I above; Annex II to the Clauses is populated by Annex II above; and the list of sub-processors is Annex III above. Where the UK International Data Transfer Addendum applies, it is incorporated with the same annexes.
Signature
This DPA is incorporated into the ProofTell terms of service and applies automatically to every account. It is signed in advance by Epic Grove Ltd, so nothing is required from ProofTell, and no countersignature is required from the Customer for it to take effect (clause 11.2). The Customer may countersign where its own procedures require a signed copy on file; nothing needs to come back to us.
| Processor | Controller | |
|---|---|---|
| Signed | Adil Ben El Khattab | |
| Name | Adil BEN EL KHATTAB | |
| Title | Director | |
| For and on behalf of | Epic Grove Ltd, company no. 17285617 | |
| Date | 1 October 2026 |
Questions
For questions about this DPA, or to subscribe to sub-processor change notifications, email privacy@prooftell.com.
If your organization requires a negotiated DPA rather than this published one, see the enterprise agreement.
Data processing agreement · Version 1.0 · Effective 1 October 2026 · Epic Grove Ltd · Registered in England and Wales, company no. 17285617 · 128 City Road, London EC1V 2NX, United Kingdom