Privacy policy
Two roles, and they have to be told apart
This service processes two categories of data that do not fall under the same regime, and treating them as one would be misleading.
For your account data (identity of the account holder, sign-in email address, billing, technical logs), Amelys Ltd is the controller.
For the addresses you submit to us for verification, Amelys Ltd is a processor within the meaning of article 28 of the GDPR: you are the controller, we act only on your instructions, and we use them for no other purpose.
⚠️ It is up to you to have a legal basis for entrusting these addresses to us, and to inform the data subjects where the law requires it.
What we do not do
We never write to the addresses you entrust to us. Verifying an address sends no message, no test, no receipt: no connection is opened to the mail server of the domain being verified. An address never becomes a recipient because it passed through us.
Your addresses appear in none of our logs — no technical trace, no error queue, no incident message.
We do not sell, rent, or transfer any data. Your addresses are not used for our own marketing, nor for that of third parties.
Data processed
Account: company name, name and email address of the account holder, password (hashed, never readable), API keys (only their fingerprint is kept).
Billing: credit movements, purchases, amounts.
Usage: technical logs and IP address, for security and fraud prevention.
Submitted addresses: the lists you upload, and the verdicts returned.
Chosen processing region
When you open your account, you choose the region where your data must be stored and processed: European Union, United Kingdom, United States and rest of world, or Asia. This choice is saved with your account and is final. Technical implementation of this separation is under way: until it is complete, this page cannot state where your data is actually located.
Purposes and legal bases
Providing the service and performing the contract; billing and accounting obligations (legal obligation); security and fraud prevention (legitimate interest).
Retention — what we keep, and what we do not
We keep only what called for an actual verification. An address set aside on its form alone — a typo, a missing separator — is recorded nowhere: working it out again costs nothing, keeping it would be exposure with nothing in return.
An address found undeliverable is kept only as a cryptographic fingerprint — we can recognize it if it is submitted to us again, we cannot read it back.
The list you upload is erased, for real, once its retention period has passed (30 days by default). The erasure is scheduled and verified.
Every payment produces an accounting record: the date, the amount, the currency, the provider's reference, and the company name and the name of the account holder as they stood at the time of purchase.
These records are kept six years after the end of the financial year, as the law requires of us — and they remain even if you delete your account. They are then the only thing about you that we keep: neither your lists, nor your find requests, nor your API keys survive it. After that period, they are erased.
Processors and recipients
Part of the verification — confirming that the mailbox exists — is carried out by a specialized provider, acting on instructions and bound by confidentiality. The named list of our processors is given to you on request, and you are notified before any change, in accordance with article 28 of the GDPR.
To these are added the hosting provider and the payment provider, which do not access the addresses you submit.
International transfers
Where data is transferred outside the United Kingdom or the European Economic Area, those transfers are covered by appropriate safeguards (standard contractual clauses, UK International Data Transfer Agreement, or an equivalent mechanism).
Security
The lists you upload are encrypted at rest. API keys are never stored in the clear. Access is controlled and logged — without your addresses appearing there.
Our "find" feature
When a customer asks us to find an address, Amelys Ltd acts as controller for the result it produces, and as a channel of distribution where the address comes from an external source queried on demand.
We query those sources, we do not copy them: each keeps its own holding, with its own opt-out. What we deliver, we hold as well, subject to our erasure form.
An address erased through our form is never produced again by this feature — neither by composition, nor from an external source.
Your rights
What we hold on our own account — our own verdict memory, and the addresses our "find" feature produced: for these Amelys Ltd is the controller, except that where an address comes from an external source, that source keeps its own holding, with its own opt-out. Exercise your rights with us. For erasure, our form: https://app.fidamail.com/effacement. For the others, write to [email protected].
A list submitted by one of our customers — for these we are only the processor, and that customer is the controller: exercise your rights with them. Write to us and we will tell you how to proceed.
You can lodge a complaint with the Information Commissioner's Office (ico.org.uk) or with the supervisory authority of your country of residence.
Amelys Ltd, established in the United Kingdom, has designated a representative in the European Union within the meaning of article 27 of the GDPR, reachable at [email protected].
If you are located in Brazil (LGPD)
Where Brazilian law applies, Law no. 13.709/2018 (LGPD) uses the same split as this policy: for your account data Amelys Ltd is the controlador; for the addresses a customer submits, Amelys Ltd is the operador and that customer is the controlador.
You have the rights set out in article 18 of the LGPD. Our encarregado is reachable at [email protected].
International transfers are carried out under article 33 of the LGPD. You may lodge a complaint with the ANPD (gov.br/anpd).
Cookies
The site uses only the cookies strictly necessary for it to work: sign-in session and cross-site request forgery protection. No analytics or advertising cookie is set, and fonts are served from our own domain.
Contact
For any question about this policy: [email protected].