GDPR Compliance & Data Processing Addendum – VerifiSaaS

VerifiSaaS is fully committed to GDPR and UK GDPR compliance. Our Data Processing Addendum (DPA) outlines how we process personal data as a processor on behalf of our customers.

Data Processing Addendum Overview

Compliance Framework

Data Processing Addendum (DPA)

Last Updated: February 21, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms and Conditions entered into between:

Hitori Tech Limited

Company Number: 14860700

5 Kinross Close, Harrow, England, HA3 0UE, United Kingdom

(“Processor”, “VerifiSaaS”, “we”, “us”)

and the entity using VerifiSaaS services (“Customer”, “Controller”). This DPA applies to services provided through verifisaas.com and app.verifisaas.com.

1. Purpose and Scope

This DPA governs the processing of Personal Data by VerifiSaaS on behalf of the Customer. The Customer confirms that it acts as the Data Controller, and VerifiSaaS acts solely as a Data Processor strictly in accordance with documented instructions.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.

  • Processing: Any operation performed on Personal Data.

  • Data Subject: The individual to whom Personal Data relates.

  • Personal Data Breach: A breach of security leading to accidental or unlawful destruction, loss, or unauthorised disclosure.

3. Nature, Purpose & Duration

3.1 Nature: Processing includes syntax validation, domain verification, mail server response analysis, and deliverability scoring.

3.2 Purpose: Exclusively to verify email validity and assess risk. We do not use data for marketing, profiling, or reselling.

3.3 Duration: Processing continues for the duration of the active subscription. Data is processed transiently and not retained longer than necessary.

4. Categories of Data

The Customer may submit email addresses and associated business contact info. No special category data (health, financial, government IDs) should be submitted.

5. Processor Obligations

  • Process data only under documented instructions
  • Ensure personnel confidentiality
  • Implement appropriate technical measures
  • Assist with data subject rights
  • Notify of breaches without undue delay

6. Security Measures

We maintain HTTPS encryption (TLS 1.2+), role-based access controls, multi-layer authentication, firewall protection, and infrastructure monitoring.

7. Subprocessors

We engage subprocessors for cloud infrastructure, hosting, and payments. All are contractually bound by confidentiality and security requirements.

8. International Transfers

Where data is transferred outside the UK/EEA, we rely on adequacy decisions or Standard Contractual Clauses (SCCs).

© 2026 VerifiSaaS — GDPR Compliance Office

Request Subprocessor List