Privacy Policy

Version 1.3 · Effective date: 29 June 2026

This Privacy Policy explains how K&V KIELVES LEGACY VENTURES, SLU, operator of Bounceless (www.bounceless.io), processes personal data when you use our B2B email-verification, deliverability decision-support, account, billing, and related services. It should be read together with our Terms and Conditions and our Data Processing Addendum (DPA). Privacy contact: legal@bounceless.io.

1. Controller, processor, and U.S. service-provider roles

For the email addresses and lists you submit for verification, you are normally the controller (or a processor acting for a third-party controller) and Bounceless acts as your processor under the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, and Andorran Qualified Law 29/2021. That processing is governed by our DPA, which sets out the Article 28(3) obligations and prevails over this Policy and the Terms on data-processing matters.

To the extent we process Personal Information governed by the California Consumer Privacy Act as amended by the CPRA, or other U.S. state privacy laws, Bounceless acts as your service provider: we process that Personal Information only on your behalf for the limited purpose of providing the Service, and we do not sell or share it, retain, use, or disclose it for any other purpose, or combine it with data from other sources except as permitted by the CCPA/CPRA.

For account administration, authentication, security, billing reconciliation, support, product operation, and our own legal/compliance obligations, Bounceless acts as a controller for the relevant data.

2. Data we process

3. Why we process data and legal bases

Where Bounceless is a controller, the legal basis may be performance of a contract, legitimate interests, consent, or a legal obligation, depending on context. Where Bounceless is a processor, the basis for the underlying processing is established by you as controller, and we process only on your documented instructions as set out in the DPA.

4. Verification results are not consent

A verification Result — including any status such as “valid”, “deliverable”, “accept-all/catch-all”, “risky”, or “unknown” — is a technical, probabilistic signal only. It is not consent, not a lawful basis to contact anyone, and not a guarantee that a message will be delivered, accepted, opened, or free from bounce, complaint, filtering, or reputation risk. You remain responsible for lawful collection, a valid lawful basis, consent where required, suppression, opt-outs, and compliance with applicable email, privacy, and anti-spam laws.

5. Retention and minimisation

Raw uploaded lists, raw submitted addresses, verification results, and exports are retained only for bounded operational purposes (service delivery, export availability, support, debugging, fraud/security review, and legal obligations).

After the readable retention period, Bounceless minimises verification data. Long-lived engine learning uses privacy-preserving fingerprints, HMACs, aggregate counts, and technical signals rather than reconstructable raw customer lists. Billing, tax, security, and audit records may be retained longer where required by law, security, fraud prevention, dispute handling, or accounting.

6. Customer lists are not sold or repackaged

Bounceless does not sell customer lists, does not redistribute submitted addresses, and does not use customer uploads to build a hidden prospect database. Submitted lists and verification results remain your data.

7. Paddle and payments

Paddle.com Market Limited (“Paddle”) is the Merchant of Record for paid Bounceless purchases. Paddle handles payment-method collection, taxes/VAT, invoices, refunds, chargebacks, and payment processing. Bounceless receives only limited billing metadata needed to activate subscriptions, grant credits, reconcile transactions, process reversals, and support you. We do not store raw card details. See our Refund Policy.

8. Sub-processors and sharing

We engage sub-processors to operate the Service. The categories below reflect the current sub-processors; the authoritative, current list is maintained in Annex III of the DPA (cross-referenced by Section 4.3 of the Terms) and is available on request to legal@bounceless.io. We give prior notice of new or replacement sub-processors and an opportunity to object, as set out in the DPA.

Sub-processor / categoryPurpose
Paddle.com Market LimitedMerchant of Record — payments, billing, tax, invoices, refunds, chargebacks
Cloudflare, Inc.Public website hosting (Cloudflare Pages), CDN, DNS, and edge security
Cloud infrastructure provider(s)Hosting of the Bounceless application and verification infrastructure
Transactional email / authentication provider(s)Account verification, security, and service notifications
Security / observability toolingMonitoring, logging, abuse prevention, and incident response

We may also disclose data where required by law, to protect rights or security, to prevent abuse or fraud, or in connection with a business transaction subject to appropriate safeguards.

9. Security

We apply safeguards such as encryption in transit, restricted production access, credential hashing, redaction, access controls, audit logging, and operational review. The technical and organisational measures we maintain as a processor are described in Annex II of the DPA. No system can be guaranteed perfectly secure, but we design Bounceless to treat customer lists and results as sensitive data.

10. International data transfers

Bounceless is established in the Principality of Andorra, which benefits from a European Commission adequacy decision and corresponding UK adequacy regulations. Where Bounceless or its sub-processors transfer personal data to a country without an adequacy decision, transfers are made under an appropriate safeguard — the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU–U.S. Data Privacy Framework where applicable, or another lawful mechanism — as set out in the DPA.

11. EU and UK representatives (Article 27)

Because Bounceless is established outside the EU/EEA and the United Kingdom and processes the personal data of data subjects in those territories on behalf of its customers, Bounceless appoints and maintains a representative in the European Union under Article 27 EU GDPR and a representative in the United Kingdom under Article 27 UK GDPR to the extent required by those Articles. Where a representative has been appointed, its identity and contact details are published in this Section and in the DPA. Until those details are listed here, enquiries that would otherwise be directed to a representative may be sent to legal@bounceless.io, which we monitor and route accordingly.

12. Your privacy rights

Depending on your location and role, you may have rights to access, correct, delete, port, restrict, or object to processing, to withdraw consent, and (under the CCPA/CPRA) to know, delete, correct, and to opt out of sale/sharing — noting Bounceless does not sell or share Personal Information. Where Bounceless acts as a processor, we will refer your request to the relevant controller or assist that controller as required by the DPA. Contact legal@bounceless.io. We may need to verify your identity, and may retain data where required for security, legal, tax, accounting, dispute, or fraud-prevention reasons. We will never ask for card details in a privacy request.

13. Changes

We may update this Policy as the Service, law, or our sub-processors change. The version and effective date above identify the current version; material changes are handled as set out in the Terms and the DPA.