Data Protection for Customers
Last updated: 2026-09-14
skink provides contractual privacy and transfer safeguards — including the roles, rights process, retention practices, and transfer mechanisms described below — to support customers whose own processing is subject to the EU General Data Protection Regulation, UK GDPR, or similar data-protection law. This page is a plain-language summary, provided for convenience and as a description of what we honor as a matter of practice; it does not itself determine whether EU GDPR or UK GDPR applies directly to skink (see our DPA's Territorial Scope section). Where anything here conflicts with our Privacy Policy or Data Processing Agreement ("DPA"), those documents govern.
1. Our Roles
Two categories of data are processed under the Service, in different roles:
- Account data (your name, email, billing details) — skink is the data controller.
- Submitted address data (the email addresses you send to our API for verification) — you are the controller, and skink acts solely as a data processor on your documented instructions. This relationship is governed by our DPA, incorporated by reference into our Terms of Service.
2. Legal Basis for Processing
- Account data is processed under contract performance (Art. 6(1)(b)) — to provide the Service you signed up for.
- Submitted address data is processed strictly on the documented instructions of our customer, the Controller for that data. The Controller determines its own lawful basis for submitting each address (this may be legitimate interest, consent, contract, or another Art. 6 basis, depending on its own relationship with the data subject) — skink does not determine or substitute its own basis for the Controller's processing. Customers warrant that they hold an independent lawful basis for every address they submit.
3. Data Minimization
We collect only what the Service requires to operate: account and billing details, and the email addresses you choose to submit. We do not request a phone number, physical address, or government ID, and we do not enrich submitted addresses with names, job titles, or other identity data.
4. Your Rights
Subject to the conditions and exceptions set out in the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request erasure of your personal data.
- Restrict or object to certain processing.
- Receive your personal data in a portable format.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The deliverability verdict our Service returns is an automated output provided to our customer for its own use; skink does not itself use that output to make such a decision.
To exercise any of these rights, contact privacy@skink.dev, including the specific email address(es) at issue. We respond without undue delay and ordinarily within one month of receipt, subject to the extensions permitted under Art. 12(3) GDPR for complex or numerous requests, and route requests concerning submitted address data to the customer that submitted it where we are acting as a processor.
UK — right to complain to us first. Since this requirement came into force in June 2026 under the Data (Use and Access) Act 2025, UK-based individuals have a statutory right to raise a data protection complaint directly with us before or alongside contacting the ICO. Send it to privacy@skink.dev; we acknowledge receipt within 30 days, investigate appropriately, keep you informed, and respond with the outcome without undue delay. You may also complain to the ICO (ico.org.uk) or, for EU/EEA matters, to your local supervisory authority at any time — you do not have to complain to us first or wait for our response before doing so. Primary source: Information Commissioner's Office, "New data protection complaints law now in force," June 2026.
5. International Transfers
skink and its sub-processors may process data in the United States, Germany, India, and other locations listed in our current Subprocessor Register. Personal data originating in the EEA, UK, or Switzerland that reaches infrastructure outside those regions is transferred under GDPR/UK GDPR Chapter V. We rely on the Standard Contractual Clauses (2021 EU SCCs, Module Two: Controller to Processor) and the UK International Data Transfer Addendum to govern these transfers, annexed to our DPA, together with a transfer risk assessment covering each destination. Personal data that stays within the EEA needs no additional transfer mechanism for EEA-, UK-, or Swiss-origin data, per the UK's and Switzerland's own adequacy findings for the EEA. See our Subprocessor Register for the full, current list of processing locations.
6. Retention
Verification records are deleted on a schedule each customer sets in its own account settings, from 1 to 365 days (365 days by default). See our Data Retention page for the full schedule by data type.
Real-time API requests may additionally use zero-retention mode (retain:false), and customers can delete an individual verification record directly from the product. Neither retroactively affects data already retained, and neither is a recipient-wide erasure across every record that might reference that address. See our Data Retention page for the exact behavior and boundaries.
6a. Shared Accuracy Learning
Shared accuracy learning is currently disabled. skink does not use customer verification data for shared accuracy learning while this feature is unavailable. When available, it is optional and off by default. A customer's own enablement of it is their authorization to participate — it is not GDPR consent obtained from the underlying email recipients. The resulting evidence is linked at the domain level, not to a specific recipient address, but remains pseudonymous rather than anonymous given the account- and time-scoped context it's collected in. Disabling the setting stops new contributions; it does not automatically erase evidence already collected. See Section 3a of our Privacy Policy for the full description.
7. Security Measures
Submitted addresses are stored in readable form by default, encrypted at rest (AES-256-GCM); a customer may instead elect hashed-only storage in account settings. See our Security page for the full description of the technical and organizational measures we apply.
8. Breach Notification
We notify affected customers without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach, per our DPA.
9. Sub-processors
A current list of sub-processor categories is set out in our Privacy Policy; a named, current list is available on request at privacy@skink.dev.
10. Data Processing Agreement
Customers that process personal data through the Service should rely on our DPA as the binding agreement governing skink's role as processor. This page summarizes that Agreement and does not modify or supersede it.
11. Contact
GDPR inquiries and Data Subject requests: privacy@skink.dev.