This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Controller", "you") submits for verification email addresses relating to data subjects in Spain. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with the EU General Data Protection Regulation ("GDPR"), the Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantees ("LOPDGDD"), and Article 21 of Law 34/2002 on Information Society Services and Electronic Commerce ("LSSI") when acting as a data processor (encargado de tratamiento) on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the GDPR, "Controller" means you and "Processor" means BounceZero (GDPR Art. 4(7), 4(8)).
We process personal data on EU infrastructure (OVH, France). Where the GDPR applies, this Addendum operates together with the Master DPA as the contract required by GDPR Art. 28(3).
2. Governing Law and Regulator
The processing described in this Addendum is governed by the GDPR as in force in Spain, the LOPDGDD, and, so far as the resulting email is a commercial electronic communication, Article 21 LSSI, which requires the prior express consent of the recipient for advertising communications sent by electronic mail.
The supervisory authority is the Spanish Data Protection Agency (AEPD) and, for processing by public bodies in their territory, the regional data protection authorities. Sanctions include administrative fines of up to €20,000,000 or 4% of annual global turnover for the gravest infringements (GDPR Art. 83), and fines under the LSSI of up to €600,000 for the most serious infringements (LSSI Art. 39).
3. Role and Scope
For the email verification services described in the Master DPA, you act as the Controller and we act as the Processor (encargado de tratamiento). The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise. This Addendum and the Master DPA together satisfy the content requirements of GDPR Art. 28(3) for a processor contract.
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under the GDPR and the LOPDGDD (Arts. 15-22), including the rights to:
- Access and obtain a copy of their personal data and information about the processing.
- Rectification of inaccurate or incomplete personal data.
- Erasure (right to be forgotten).
- Restriction of processing.
- Data portability, on your instruction.
- Object to processing, including direct marketing.
- Not be subject to automated decision-making that produces legal or similarly significant effects.
Email verification involves automated scoring. Where that scoring amounts to automated decision-making with legal or similarly significant effects within GDPR Art. 22, we will support you in carrying out the assessments and safeguards required. If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within 72 hours of becoming aware of it, consistent with the Master DPA and GDPR Art. 33(2). You, as the Controller, are responsible for notifying the AEPD and, where required, affected data subjects (GDPR Art. 34). We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of Spanish data subjects is processed on EU infrastructure (OVH, France). Processing within the EEA does not require an additional transfer mechanism. Any onward transfer from the EEA relies on an adequacy decision or, failing that, on the Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- LSSI Art. 21 consent: advertising by electronic mail requires the prior express consent of the recipient. Art. 21.2 LSSI provides a limited carve-out for existing customers who previously purchased similar products or services, provided they were given an easy way to object. We do not verify the recipient's consent and do not check marketing suppression lists such as the Lista Robinson or the advertising preference services; that is the advertiser's (your) duty. On your instruction we will suppress and mark any address you designate so that it is not used for marketing.
- Consent records: we retain the evidence of lawful processing instructions you rely on as your legal basis, so that you can demonstrate consent under GDPR Art. 7 and LSSI Art. 21.
- Processor records: we maintain records of the categories of processing carried out for you, consistent with GDPR Art. 30.
- Security: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with GDPR Art. 32.
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.