Data Processing Addendum (DPA)

Version 1.0 · Effective date: 29 June 2026

This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Terms and Conditions (the “Agreement”) between you (“Customer”) and K&V KIELVES LEGACY VENTURES, SLU, operator of Bounceless (“Bounceless”, “we”). It governs Bounceless’s processing of Customer Personal Data on the Customer’s behalf. Where this DPA and the Agreement conflict on data-processing matters, this DPA prevails (Agreement Sections 3.3, 11.3, 12.4, 18.2). Capitalised terms not defined here have the meaning given in the Agreement.

1. Definitions and roles

Data Protection Law” means the EU General Data Protection Regulation (EU) 2016/679 (“EU GDPR”), the UK GDPR and the Data Protection Act 2018 (“UK GDPR”), Andorran Qualified Law 29/2021 on the Protection of Personal Data, the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”), and any other applicable data-protection or privacy law. “Customer Personal Data” means personal data within Customer Data that Bounceless processes on the Customer’s behalf under the Agreement. The terms controller, processor, sub-processor, data subject, processing, and personal data breach have the meanings given in the EU GDPR.

For Customer Personal Data, the Customer is the controller (or a processor acting for a third-party controller) and Bounceless is the processor (and, under the CCPA/CPRA, the Customer is the business and Bounceless is its service provider). Each party complies with its own obligations under Data Protection Law.

2. Scope and documented instructions (Art 28(3)(a))

Bounceless processes Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to process by EU/Member-State or other applicable law (in which case Bounceless informs the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest). The Customer’s instructions are: (a) the Agreement and this DPA; (b) the Customer’s use and configuration of the Service (including submitting lists and requesting verification, exports, deletion, and related functions); and (c) any further written instructions agreed by the parties. Bounceless informs the Customer if, in its opinion, an instruction infringes Data Protection Law. The details of processing required by Article 28(3) are set out in Annex I.

3. Confidentiality of personnel (Art 28(3)(b))

Bounceless ensures that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality (contractual or statutory), are subject to access controls on a need-to-know basis, and are trained on their data-protection responsibilities.

4. Security measures (Art 28(3)(c); Art 32)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk to data subjects, Bounceless implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. Bounceless may update its measures provided the level of protection is not materially reduced.

5. Sub-processors (Art 28(3)(d))

5.1 The Customer grants Bounceless general authorisation to engage sub-processors to process Customer Personal Data for the purpose of providing the Service. A current list of sub-processors is set out in Annex III and is also available via the Privacy Policy (Agreement Section 4.3).

5.2 Bounceless will give the Customer prior notice of the addition or replacement of a sub-processor (by updating Annex III and/or notifying the account) and a reasonable opportunity to object on reasonable data-protection grounds before that sub-processor begins processing. If the Customer reasonably objects and the parties cannot agree a resolution, the Customer may terminate the affected part of the Service.

5.3 Bounceless imposes on each sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA (flow-down), and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

6. Assistance with data-subject rights (Art 28(3)(e))

Taking into account the nature of the processing, Bounceless assists the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer’s obligation to respond to requests by data subjects to exercise their rights (access, rectification, erasure, restriction, portability, and objection). If Bounceless receives such a request directly, it will not respond on its own behalf but will, without undue delay, inform the Customer and direct the data subject to the Customer, except where law requires otherwise.

7. Assistance with Articles 32–36 (Art 28(3)(f))

7.1 Taking into account the nature of processing and the information available to it, Bounceless assists the Customer in ensuring compliance with the obligations in Articles 32–36 GDPR (security, personal-data-breach notification, communication to data subjects, data protection impact assessments, and prior consultation).

7.2 Personal-data-breach notification. Bounceless notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, and provides the information reasonably available to enable the Customer to meet its own notification obligations, with further information provided in phases as it becomes available.

8. Return or deletion of data (Art 28(3)(g))

On termination or expiry of the Agreement, and at the Customer’s choice, Bounceless deletes or returns all Customer Personal Data and deletes existing copies, unless EU/Member-State or other applicable law requires storage. Deletion may be asynchronous and applies subject to the bounded retention described in the Privacy Policy and to records that must be retained for billing, tax, legal, security, fraud, dispute, or audit purposes — which are retained only for the period and purpose so required and remain protected under the Agreement and this DPA.

9. Audit and information (Art 28(3)(h))

Bounceless makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. The parties will agree the reasonable scope, timing, notice (ordinarily at least 30 days), frequency (ordinarily once per 12-month period unless required more frequently by a supervisory authority or following an incident), confidentiality, and cost-bearing of any audit, conducted so as not to compromise the security or confidentiality of other customers’ data. Bounceless may satisfy an audit request by providing relevant certifications, reports, or summaries of its measures where these reasonably address the request.

10. International transfers

Bounceless is established in Andorra, which benefits from an EU Commission adequacy decision and corresponding UK adequacy regulations. Where Customer Personal Data is transferred to a country that does not benefit from an adequacy decision, the transfer is made under an appropriate safeguard — the EU Commission Standard Contractual Clauses (the relevant module, incorporated by reference and completed by Annexes I–III of this DPA), the UK International Data Transfer Addendum to the EU SCCs, the EU–U.S. Data Privacy Framework where the importer is certified, or another lawful mechanism. The parties agree to complete and execute any transfer mechanism reasonably required by Data Protection Law.

11. U.S. service-provider terms (CCPA/CPRA)

To the extent Bounceless processes Personal Information governed by the CCPA/CPRA, Bounceless acts as the Customer’s service provider and: (a) processes that Personal Information solely on the Customer’s behalf for the limited and specified business purpose of providing the Service; (b) does not sell or share it; (c) does not retain, use, or disclose it for any other purpose, or outside the direct business relationship, or combine it with personal information from other sources except as the CCPA/CPRA permits; (d) provides at least the level of privacy protection required of businesses by the CCPA/CPRA; and (e) certifies that it understands and will comply with these restrictions and will notify the Customer if it can no longer meet them. The Customer may take reasonable steps to ensure Bounceless’s use is consistent with the Customer’s CCPA/CPRA obligations and to stop and remediate unauthorised use.

12. EU and UK representatives (Article 27)

Because Bounceless is established outside the EU/EEA and the United Kingdom and processes the personal data of data subjects in those territories on behalf of its customers, Bounceless appoints and maintains a representative in the EU under Article 27 EU GDPR and a representative in the UK under Article 27 UK GDPR to the extent required by those Articles. Where appointed, the representatives’ identities and contact details are stated here and in the Privacy Policy; until then, enquiries that would otherwise be directed to a representative may be sent to legal@bounceless.io.

13. Liability for personal-data incidents

Each party’s aggregate liability arising out of or relating to this DPA, including for any personal-data breach or other personal-data incident, is subject to the limitation of liability in Section 11.2 of the Agreement (the greater of the fees the Customer paid for the Service in the twelve (12) months preceding the event, or USD 100), and this cap is the one intended to control over Section 11.2 for such incidents. Nothing in this DPA or the Agreement limits or excludes any liability that cannot be limited or excluded under applicable law, including a data subject’s non-excludable rights and any liability to data subjects under Article 82 GDPR. Where the parties act as joint controllers or each as an independent controller for any processing, statutory apportionment of liability applies. The precise commercial allocation in this Section is the drafted default and is subject to confirmation by qualified counsel before go-live (see the Agreement and the published legal-pages checklist).

14. General

This DPA is governed by the law and subject to the forum that govern the Agreement under its Section 15, except where Data Protection Law or an incorporated transfer mechanism requires otherwise. If any provision is held invalid, the remainder remains in effect. This DPA, the Agreement, the Privacy Policy, and the Refund Policy are the entire agreement on their subject matter. Contact for data-protection matters: legal@bounceless.io.


Annex I — Details of processing

Subject-matterProvision of the Bounceless B2B email-verification and deliverability decision-support Service to the Customer.
DurationFor the term of the Agreement plus the bounded retention and post-termination return/deletion period described in Section 8 and the Privacy Policy.
Nature and purposeAutomated technical verification of email addresses (syntax, domain/MX, mailbox-acceptance signals), generation of decision-support Results and exports, account and security operations, debugging, abuse prevention, deletion, and quality functions — all to provide the Service.
Types of personal dataEmail addresses and associated record metadata submitted by the Customer; verification Results and derived signals; and, for account/security data, business contact and authentication metadata. The Service is for B2B use and is not intended for special-category data.
Categories of data subjectsThe Customer’s contacts, leads, and recipients whose email addresses are submitted for verification, and the Customer’s own authorised users.
Controller / processorCustomer = controller (or processor for a third-party controller); Bounceless = processor (service provider under the CCPA/CPRA).

Annex II — Technical and organisational measures (Art 32)

Annex III — Sub-processors

The following are the current sub-processors engaged to process Customer Personal Data. This list is maintained as the authoritative current list and is also reflected in the Privacy Policy; updates are notified as set out in Section 5.2.

Sub-processor / categoryProcessing activity
Paddle.com Market LimitedMerchant of Record — payments, billing, tax, invoices, refunds, chargebacks (billing metadata)
Cloudflare, Inc.Public website hosting (Cloudflare Pages), CDN, DNS, and edge security
Cloud infrastructure provider(s)Hosting of the Bounceless application and verification infrastructure
Transactional email / authentication provider(s)Account verification, security, and service notifications
Security / observability toolingMonitoring, logging, abuse prevention, and incident response

Specific named entities for the categorical entries above are recorded in the operational sub-processor register and provided on request to legal@bounceless.io.