Data Processing Agreement
Last updated: 2026-09-02
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Kexa Labs (Udyam Reg. No. UDYAM-GJ-22-0652675), a proprietary firm registered under India's MSME Udyam scheme ("Processor," "Kexa Labs," "skink," "we"), and the customer entering into the Service agreement ("Controller," "you"), and applies whenever skink processes personal data on your behalf and documented instructions in connection with the Service. In the event of a conflict between this DPA and the Terms of Service on data-protection matters, this DPA controls. See our GDPR page for a plain-language summary of this Agreement.
1. Definitions
"Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Supervisory Authority" have the meanings given in the GDPR. "Data Fiduciary" and "Data Principal" have the meanings given in India's Digital Personal Data Protection Act, 2023 ("DPDP"). "Business" and "Service Provider" have the meanings given in the California Consumer Privacy Act, as amended by the CPRA ("CCPA"). Each such term, and its jurisdiction-specific equivalent, is used interchangeably below to mean the same underlying role.
2. Subject Matter and Duration
Processing of email addresses (and derived deliverability signals) that the Controller submits to the Service via API, for the purpose described in Section 3, for the term of the underlying Service agreement plus any post-termination retention or deletion period described in Section 9.
3. Nature and Purpose of Processing
skink processes submitted email addresses solely to determine and return a deliverability verdict (status, confidence score, and supporting signals) via the API, on the Controller's documented instructions (i.e., the API request itself and the Controller's own account settings, including its elected retention period, whether the submitted address is retained in encrypted readable form — the default — or as a hash only, and whether zero-retention mode is requested for a given real-time request). skink does not process this data for any other purpose, including marketing, profiling, or enrichment.
Shared accuracy learning — a separate, optional feature under which skink would process eligible outcome signals from a Controller's account, linked at the domain level rather than to the specific recipient, to evaluate and improve verification accuracy — is currently disabled and not available to opt into. Section 3a of the Privacy Policy describes how it works when available.
4. Categories of Data and Data Subjects
- Categories of data: email addresses; derived deliverability signals (e.g., mailbox-existence indicators, domain configuration); no other personal data is required or accepted by the verification endpoints.
- Categories of Data Subjects: the Controller's contacts, leads, customers, or prospects whose email addresses are submitted for verification.
5. Processor Obligations
skink shall:
- Process Personal Data only on the Controller's documented instructions (the API request), including with regard to international transfers, unless required to do otherwise by law applicable to skink, in which case skink will inform the Controller before processing, unless that law prohibits such notice.
- Ensure persons authorized to process the Personal Data are subject to confidentiality obligations.
- Implement the technical and organizational security measures described in our Security page, including hashing at rest, encryption in transit, least-privilege access, and key rotation.
- Not engage a sub-processor without providing notice of intended changes and giving the Controller an opportunity to object, and impose data-protection obligations on any sub-processor that are no less protective than those in this DPA.
- Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures in responding to Data Subject/Data Principal requests.
- Notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data, and provide reasonably requested assistance with the Controller's own notification obligations.
- At the Controller's choice, delete or return all Personal Data after the end of the provision of the Service, and delete existing copies, except where retention is required by applicable law (see our Data Retention schedule).
- Make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits of compliance with this DPA as set out in the "Audit Rights" section below.
Audit Rights
Given the scale of skink's operations (a sole proprietorship), compliance audits under this DPA are conducted on a document-review basis, not as on-site inspections. The Controller may, no more than once per 12-month period and on at least 30 days' written notice, request copies of the documentation establishing skink's compliance with this DPA (including its Security page, current sub-processor list, and breach-response records that do not disclose another Controller's data). The Controller may engage an auditor reasonably acceptable to skink to review those documents; both the Controller and any auditor must keep the documents and any findings confidential. Document review is conducted at skink's then-current reasonable cost to the Controller for time spent assembling the documentation. On-site inspections are not offered at this time; where a Controller's own regulator requires one, we will assess it in good faith on a case-by-case basis.
6. Sub-processors
The Controller provides general authorization for skink to engage sub-processors for hosting, object storage, payment processing, mailbox-existence and breach-presence verification queries, and transactional email delivery. The current list of sub-processor categories is set out in our Privacy Policy, Section 8; a named, current list is available on request at privacy@skink.dev.
7. International Transfers
skink and its sub-processors may process Personal Data in the United States, Germany, India, and other locations listed in the current Subprocessor Register; skink (the Processor) is operated from India. Personal Data originating in the EEA, UK, or Switzerland that reaches infrastructure outside those regions is transferred outside the EEA/UK under GDPR/UK GDPR Chapter V; the parties incorporate by reference the Standard Contractual Clauses annexed hereto as Annex 4 (Module Two: Controller to Processor), or the UK International Data Transfer Addendum where applicable, together with a transfer risk assessment covering each destination, which shall govern in the event of any conflict with this DPA on transfer-specific terms. Personal Data that stays within the EEA requires no additional transfer safeguard for EEA-, UK-, or Swiss-origin Personal Data, per the UK's and Switzerland's own adequacy findings for the EEA. skink's remote administrative access from India is an additional transfer covered by the same Clauses, regardless of which region the Personal Data resides in. Transfers of India-origin Personal Data are governed by DPDP's restricted-country transfer model described in our Privacy Policy, Section 5.
8. Breach Notification
skink will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data breach affecting Personal Data processed under this DPA, describing the nature of the breach, likely consequences, and measures taken or proposed.
9. Deletion and Return of Data
On termination of the Service agreement, skink will, at the Controller's election, delete the Controller's Personal Data or provide an export of the data skink actually holds for the Controller, within a commercially reasonable period, subject to skink's standard retention schedule and any legal-hold or tax-record retention obligations. The export will consist of the derived verification signals and, unless the Controller elected hashed-only storage, the submitted address itself; an address stored only as a cryptographic hash cannot be returned in plaintext. See our Data Retention schedule for default timelines.
10. Jurisdiction-Specific Terms
India — DPDP Act, 2023
The Controller is the Data Fiduciary; skink processes strictly on the Data Fiduciary's documented instructions and supports the Data Fiduciary's Grievance Officer obligations (DPDP §13) by forwarding any Data Principal request received directly to the Controller, unless the Controller has authorized skink to respond directly.
United States — CCPA/CPRA
skink acts as a Service Provider under Cal. Civ. Code §1798.140(ag) and agrees that it will not: (a) sell or share the Personal Data processed under this DPA; (b) retain, use, or disclose the Personal Data for any purpose other than performing the services specified in this DPA and the underlying Service agreement; (c) retain, use, or disclose the Personal Data outside the direct business relationship between skink and the Controller; or (d) combine the Personal Data with personal data that skink receives from or on behalf of another source, except as permitted by the CCPA. skink will notify the Controller if it determines it can no longer meet these obligations.
10a. Territorial Scope
Nothing in this DPA, the Standard Contractual Clauses, any UK transfer mechanism, or skink's provision of contractual data-protection safeguards constitutes an admission or agreement that the EU GDPR, UK GDPR, or any other privacy law applies directly to skink, except to the extent such law independently applies under its own territorial-scope provisions. These safeguards are provided, where applicable, to support the Controller's own controller, processor, and international-transfer obligations, not to establish skink's own direct regulatory status.
11. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service.
12. Precedence and Term
This DPA remains in effect for as long as skink processes Personal Data on the Controller's behalf under the Service agreement.
Annex 1 — Description of Processing
- Subject matter — Email deliverability verification.
- Duration — Term of the Service agreement.
- Nature of processing — Automated verification via API; addresses stored by default in encrypted readable form (AES-256-GCM) and deleted on the Controller's elected schedule (1-365 days, 365 by default); the Controller may instead elect hashed-only storage from day one; full plaintext additionally held transiently in memory during the check.
- Purpose — Return a deliverability verdict to the Controller.
- Categories of data — Email addresses; derived deliverability signals.
- Categories of Data Subjects — Controller's contacts/leads/customers.
Annex 2 — Sub-processors
See Privacy Policy, Section 8, for current sub-processor categories; a named list is available on request.
Annex 3 — Security Measures
See our Security page for the full list of technical and organizational measures.
Annex 4 — Standard Contractual Clauses
The parties incorporate by reference the Standard Contractual Clauses set out in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor). skink is the "data importer"; the Controller is the "data exporter." For the purposes of those Clauses:
- Annex I.A (parties) — the data exporter is the Controller identified in the Service agreement; the data importer is:
Kexa Labs (a proprietary firm registered under India's MSME Udyam scheme) Udyam Registration No. UDYAM-GJ-22-0652675 - Annex I.B (description of transfer) — as set out in Annex 1 of this DPA. - Annex II (technical and organizational measures) — as set out in Annex 3 of this DPA / our Security page. - Annex III (sub-processors) — as set out in Annex 2 of this DPA / our Privacy Policy, Section 8. - Competent supervisory authority and the data exporter's specific signatory details are completed at the time of execution between skink and each Controller, and are available as a fully executed document on request at privacy@skink.dev.