This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Personal Information Controller", "you") submits for verification email addresses relating to data subjects in the Philippines. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with the Data Privacy Act of 2012 (Republic Act No. 10173) ("DP Act") and the rules of the National Privacy Commission ("NPC") when acting as a personal information processor on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the DP Act, "personal information controller" (PIC) means you, and "personal information processor" (PIP) means BounceZero (DP Act Sec. 3(i), 3(j)).
We process personal data on EU infrastructure (OVH, France). BounceZero does not maintain an establishment in the Philippines; this Addendum governs our processing of personal data of Philippine data subjects on your behalf.
2. Governing Law and Regulator
The processing described in this Addendum is governed, so far as the data subjects are in the Philippines, by the DP Act, its Implementing Rules and Regulations, and the circulars and guidance of the National Privacy Commission (NPC), including NPC Circular No. 2022-04 (cross-border transfers) and NPC Circular No. 16-03 (breach notification). Penalties for violations include fines of up to PHP 5,000,000 and imprisonment for individuals (DP Act Sec. 29).
3. Role and Scope
For the email verification services described in the Master DPA, you act as the personal information controller and we act as the personal information processor. The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise (DP Act Sec. 11).
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under DP Act Sec. 16, including the right to:
- Be informed of the processing of their personal data.
- Access the personal data processed and information about the processing.
- Object to the processing in the circumstances set out in the law.
- Rectification of incomplete, inaccurate, or outdated data.
- Erasure or blocking of data obtained or processed unlawfully, or that is no longer necessary.
- Data portability, on your instruction.
If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within the period required to allow you to meet the NPC 72-hour notification window (NPC Circular No. 16-03). You, as the PIC, are responsible for notifying the NPC and affected data subjects as required. We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of Philippine data subjects is processed on EU infrastructure. Under NPC Circular No. 2022-04, cross-border transfers require the PIC to inform the data subjects and to adopt appropriate safeguards. This Addendum, together with the Master DPA and its Standard Contractual Clauses, provides those safeguards. A copy is available on request at [email protected].
7. Additional Obligations
- NPC registration support: both PICs and PIPs are required to register their data processing systems with the NPC (NPC Circular No. 2023-01). We will provide the information about our processing reasonably needed for your registration or notification covering this processing.
- Security: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with the NPCs expected security standards.
- Data minimisation: only the email addresses and derived metadata necessary for validation are processed (DP Act Sec. 11).
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.