GDPR
Last updated 1 October 2026
What ProofTell does with personal data, in the terms your data protection officer will ask about. Short, because the detail lives in the documents this page links to.
ProofTell is a service of Epic Grove Ltd, a company registered in England and Wales (company no. 17285617). We apply the UK GDPR and, for customers and data subjects in the European Economic Area, the EU GDPR.
Two roles
For the data you submit, we are your processor. When you send a phone number, an email address or an IP address to be checked, you decide why it is processed; we process it only to return the result to you. That makes you the controller and Epic Grove Ltd your processor, under the data processing agreement.
For your account, we are the controller. For the data that describes you as our customer (your account, your billing, your messages to us) we are the controller, and the privacy policy says what we do with it.
What we give you as your processor
- A data processing agreement that meets Article 28. It is pre-signed and applies to every account: file it, no call needed.
- A published list of sub-processors, with 30 days’ notice before any change and a right to object.
- Processing and storage in the European Union, in Belgium. The one exception is described plainly: verifying an email address means asking its mail server, through verification servers in several countries.
- Retention you control. Single lookups are not stored. Assessments are kept 90 days by default, and you can set that from zero to 365 days. Files are deleted 30 days after upload, or when you delete them.
- No secondary use. We do not sell the data you submit, use it for marketing, build profiles across customers, or train models on it.
- Breach notification without undue delay, and within 72 hours.
- The security measures we apply, and an honest list of what we do not have.
Your side of it
We cannot decide these for you, but we can make them easier.
Legal basis. You need one for checking a phone number, an email address or an IP address. The GDPR recognizes the prevention of fraud as a legitimate interest (Recital 47); whether that, a contract or another basis fits your case is your assessment as controller.
Transparency. Tell the people you check, in your own privacy notice, that you verify contact details and assess fraud risk, and that a service provider does it for you.
Automated decisions. A verdict from ProofTell is information for your decision. If you let it decide alone something with a legal or similarly significant effect on a person, Article 22 applies to you. Every assessment lists the reasons behind its score precisely so that a person can review a decision and explain it.
Minimization. Send only what the check needs: the phone number, the email address, the IP address. In files, extra columns pass through untouched, so leave out what you do not need back.
Rights
If you are our customer, you can ask us for access to your personal data, its correction or deletion, the restriction of its processing, or a copy in a machine-readable form, and you can object to its processing. Write to privacy@prooftell.com; we answer within one month.
If a business checked your phone number, email address or IP address with ProofTell, that business is the controller and the one to ask. If you write to us, we will pass your request on to it where we can identify it.
You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or to the data protection authority of your country.
Documents
- Data processing agreement
- Security and sub-processors
- Privacy policy
- Terms of service
- Enterprise agreement, if your policies require a negotiated DPA or signed paper
GDPR · Last updated 1 October 2026 · Epic Grove Ltd · Registered in England and Wales, company no. 17285617 · 128 City Road, London EC1V 2NX, United Kingdom