This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Controller", "you") submits for verification email addresses relating to data subjects in Germany. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with the EU General Data Protection Regulation ("GDPR") as applicable in Germany and Section 7 of the German Act Against Unfair Competition ("§7 UWG") when acting as a data processor (Auftragsverarbeiter) on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the GDPR, "Controller" means you and "Processor" means BounceZero (GDPR Art. 4(7), 4(8)).
We process personal data on EU infrastructure (OVH, France). Where the GDPR applies, this Addendum operates together with the Master DPA as the contract required by GDPR Art. 28(3).
2. Governing Law and Regulator
The processing described in this Addendum is governed by the GDPR as in force in Germany, its national implementing statute (the Federal Data Protection Act, BDSG), and, so far as the resulting email is a commercial electronic communication, Section 7 UWG, which requires prior express consent of the recipient for unsolicited advertising email.
The supervisory authorities are the German federal and state data protection authorities, including the Federal Commissioner for Data Protection and Freedom of Information (BfDI) for federal bodies. Sanctions for non-compliance include administrative fines of up to €20,000,000 or 4% of annual global turnover for the gravest infringements (GDPR Art. 83), and fines of up to €50,000 for violations of Section 7 UWG.
3. Role and Scope
For the email verification services described in the Master DPA, you act as the Controller and we act as the Processor (Auftragsverarbeiter). The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise. This Addendum and the Master DPA together satisfy the content requirements of GDPR Art. 28(3) for a processor contract.
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under the GDPR (Arts. 15-22), including the rights to:
- Access and obtain a copy of their personal data and information about the processing.
- Rectification of inaccurate or incomplete personal data.
- Erasure (right to be forgotten).
- Restriction of processing.
- Data portability, on your instruction.
- Object to processing, including direct marketing.
- Not be subject to automated decision-making that produces legal or similarly significant effects.
Email verification involves automated scoring. Where that scoring amounts to automated decision-making with legal or similarly significant effects within GDPR Art. 22, we will support you in carrying out the assessments and safeguards required. If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within 72 hours of becoming aware of it, consistent with the Master DPA and GDPR Art. 33(2). You, as the Controller, are responsible for notifying the competent German data protection authority and, where required, affected data subjects (GDPR Art. 34). We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of German data subjects is processed on EU infrastructure (OVH, France). Processing within the EEA does not require an additional transfer mechanism. Any onward transfer from the EEA relies on an adequacy decision or, failing that, on the Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- §7 UWG consent: under Section 7(2) UWG, advertising by electronic mail without the recipient's prior express consent is an unfair commercial practice. We do not verify the recipient's consent and do not check the Robinson List (Robinsonliste); that is the advertiser's (your) duty. On your instruction we will suppress and mark any address you designate so that it is not used for marketing.
- Consent records: we retain the evidence of lawful processing instructions you rely on as your legal basis, so that you can demonstrate consent under GDPR Art. 7 and Section 7 UWG.
- Processor records: we maintain records of the categories of processing carried out for you, consistent with GDPR Art. 30.
- Security: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with GDPR Art. 32.
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.