Published: 26 August 2026
We’ve updated our Privacy Policy and Data Processing Agreement (DPA). The updated documents provide more detail about how MillionVerifier processes data, the service providers we work with, international data transfers and how our data-processing relationship with Customers works.
The updated policies are now in effect. Here’s an overview of the main changes.
Clearer controller, processor and subprocessor roles
Our DPA now more clearly covers different ways Customers may use MillionVerifier.
If you submit Personal Data for your own organisation, you will normally act as the controller and MillionVerifier acts as your processor. If you process Personal Data on behalf of another organisation, MillionVerifier may instead act as your subprocessor.
The DPA also provides more detail about Customer instructions and the respective responsibilities of MillionVerifier and its Customers.
More transparency about our service providers and subprocessors
We now maintain a dedicated Service Providers, Recipients and Subprocessors page.
It provides more information about the third parties we use, what they help us with, the types of processing involved and whether they are relevant to our Privacy Policy, DPA, or both.
For future additions or replacements of subprocessors that process Customer Personal Data, we will provide reasonable advance notice through the Customer’s Account. Customers who need to review subprocessor changes should therefore monitor Account notifications.
Clearer information about how Customer Personal Data is used
The updated DPA makes clear that we do not use Customer Personal Data for our own direct marketing or to create a persistent reputation database, marketing list or other data product for another Customer’s independent use.
It also explains that submitted addresses and verification results may be held in a temporary operational cache for up to seven days where reasonably necessary to provide, secure, optimise or support the Services. Cached data automatically expires or is deleted and is not used for model training.
More detail about international data transfers
We have expanded the information available about international processing and data-transfer safeguards.
Our Privacy Policy and DPA explain that, where required, we use lawful transfer mechanisms such as adequacy decisions, Standard Contractual Clauses or other safeguards permitted by applicable law. Where appropriate, supplementary contractual, technical or organisational safeguards may also be used.
Our Service Providers, Recipients and Subprocessors page provides additional information about the relevant providers and locations.
Clearer deletion, compliance and audit processes
The DPA now gives more detail about how Customers can access, export and delete Customer Personal Data, including the normal deletion of uploaded files and result files within 30 days and the treatment of backup copies.
It also provides a clearer process for compliance information, Customer assistance and audits, including making use of available documentation and compliance materials before requesting bespoke assistance or an audit.
Security and breach notifications
The security provisions have been aligned more explicitly with the requirements of Article 32 of the GDPR and clarify that individual technologies and controls may evolve as our Services and security risks change.
If a Personal Data Breach affecting Customer Personal Data occurs, required contractual notifications will be sent to the primary email address associated with the Customer’s Account. Customers should make sure this address remains current and appropriately monitored.
Privacy Policy updates
Most of the Privacy Policy remains unchanged.
The main updates provide greater transparency about our service providers and subprocessors and more detailed information about where processing may take place and the safeguards used for international transfers.
Do I need to do anything?
No separate handwritten signature is generally required for the updated DPA.
We recommend reviewing the updated Privacy Policy and DPA and making sure the primary email address on your MillionVerifier Account is current. Customers who monitor subprocessor changes should also keep an eye on Account notifications.
If you have questions about the updated policies, please contact our support team.
Read the policies
Published: 20 July 2026
We have updated our Terms of Service, Privacy Policy and Data Processing Agreement. The updated documents are now in effect and apply whenever MillionVerifier is used, including through the website, application, API, integrations or automated processes.
The updates use clearer language and align the policies with how MillionVerifier works today. Here is an overview of the main points.
MillionVerifier is a business service
MillionVerifier is provided for business, trade and professional use. It is not intended for personal, family or household use.
Customers using an individual billing profile must still be acting as a sole trader, self-employed professional or other business user. Customers are responsible for keeping their business, billing and Account information accurate.
Email data must be obtained and used lawfully
Email addresses submitted to MillionVerifier do not have to belong to subscribers or people who have directly opted in to a Customer’s own list.
Customers may use data collected directly or lawfully obtained from a data provider, broker, licensor or other source, including purchased, rented or licensed business data. Customers remain responsible for ensuring that they are legally entitled to obtain, submit and use the data for their intended purpose, and for meeting any applicable privacy, marketing, notice, objection and suppression requirements.
Where reasonably necessary, MillionVerifier may ask for information showing the source and permitted use of submitted data.
Paid and Promotional Credits
The updated Terms distinguish between Paid Credits and Promotional Credits.
Paid Credits are Credits purchased by the Customer. Promotional Credits are provided without charge and may include registration Credits, purchase bonuses, Auto Top-Up extras, percentage-based bonuses, MillionEvergreen Credits, support or goodwill Credits, and Credits offered for certain risky verification results.
Credits are used in the order in which they were added to the Account. Promotional Credits have no cash refund value.
Promotional programmes and free-credit benefits are available only while offered. A promotion available today does not create a promise that the same promotion, amount or benefit will remain available in the future. We may introduce, change, limit, pause or discontinue future promotional offers without changing the Terms. Credits already granted remain subject to the conditions shown when they were issued.
Unknown and catch-all results
Where available, Credits provided in connection with unknown or catch-all results are Promotional Goodwill Credits. They are not cash refunds and are not guaranteed as a permanent Service feature. The treatment available for a particular workflow will be shown in the Service or our Help Center.
Inactive Accounts and Credit recovery
An Account may be treated as inactive after 12 consecutive months with no Credit purchase and no Credit use. We will email the Account owner at least one month before an inactive Account is removed.
Using at least one Credit during that notice period prevents the planned removal and restarts the inactivity period.
Removing an inactive Account does not make its remaining Credits expire. We keep a limited protected recovery record so that an eligible Customer can create a new Account, contact support and request restoration of the remaining Credit balance after ownership is verified.
Account use and compliance
Customers are responsible for their Account, credentials, API keys, Authorized Users and integrations. We may restrict or suspend processing where reasonably necessary to protect the Service, investigate misuse, verify compliance or respond to unlawful activity.
A Customer that materially breaches the Terms may lose eligibility for refunds, the Money Back Guarantee and promotional or goodwill benefits, subject to any rights that cannot legally be excluded.
Privacy and data processing
The Privacy Policy explains how GBD handles Account, billing, security, support and other information for which it acts as controller.
When a Customer submits Personal Data for email verification, the Customer normally acts as controller and GBD acts as processor. The updated Data Processing Agreement explains the instructions, security measures, subprocessor rules, international-transfer safeguards, assistance and deletion arrangements that apply to that processing.
How the updated policies apply
The updated policies take effect when published. New Customers review and accept the Terms during Account creation.
Existing Customers receive an in-app notice at their next login, and Customers who have purchased Paid Credits will also receive an email notice. The policies are not delayed until the notice is opened or displayed. Any continued use of MillionVerifier after publication—including use through an API key, integration or automated process—is subject to the updated Terms.
A Customer that does not agree with the updated Terms must stop using MillionVerifier and disable automated access.