Privacy Policy

Version 2.0 – Updated: June 26, 2026


1. Introduction

This Privacy Policy describes how Deltadromeus collects, uses, retains, stores, protects, and processes personal data in connection with the use of the website, API, and related services.

It applies to all processing activities carried out by Deltadromeus, whether they concern website users, service customers, or data transmitted through the API.

Privacy and the protection of personal data are fundamental commitments of Deltadromeus.

Processing activities are carried out in accordance with Regulation (EU) 2016/679 of April 27, 2016 ("GDPR") and applicable French laws and regulations.

2. Data Controller

For processing activities related to user account management, billing, customer support, and operation of the service, the data controller is:

AVX E-BOOST (Alexis VIOUX EI)
Business Registration Number (SIRET): 983 409 731 00012
510 rue du Boulidou
34980 Saint-Clément-de-Rivière
France

The data controller determines the purposes and means of the relevant data processing activities.

For any questions regarding data protection or the exercise of your rights, you may use the contact form available on the website.

3. Deltadromeus' Role Regarding Verified Email Addresses (Article 28 GDPR)

3.1 Qualification of the Parties

When a Customer submits email addresses for verification:

  • the Customer acts as the data controller within the meaning of the GDPR
  • Deltadromeus acts as the data processor within the meaning of Article 28 of the GDPR

3.2 Customer Obligations

The Customer warrants, in particular, that it:

  • has a valid legal basis for processing the submitted data
  • informs data subjects where required
  • complies with all obligations applicable to it as a data controller

3.3 Deltadromeus Obligations

Deltadromeus undertakes to:

  • process data only on the documented instructions of the Customer
  • not use the data for any purpose other than providing the service
  • ensure the confidentiality of the processed data
  • implement appropriate security measures
  • assist the Customer in complying with its GDPR obligations within the limits of the service

3.4 Data Processing Agreement (DPA)

Use of the service implies acceptance of a data processing agreement compliant with Article 28 of the GDPR, incorporated into these contractual terms.

4. Data Collected

Account Data

  • first and last name
  • email address
  • company (where applicable)
  • postal address (where applicable)
  • billing information (where applicable)
  • order history
  • customer support information

Verification Data

  • email addresses submitted for verification
  • verification results
  • IP address associated with the request
  • technical data necessary for the operation of the service

Technical Data

  • technical logs
  • browser information
  • connection information
  • security and abuse prevention data
  • service performance and usage metrics

5. Purposes and Legal Bases

Personal data is processed for the following purposes and legal bases:

Purpose Legal Basis
Creation and management of user accounts Performance of a contract
Provision of verification services Performance of a contract
Billing and accounting obligations Legal obligation
Customer support Performance of a contract and legitimate interests
Security, fraud prevention, and abuse prevention Legitimate interests
Management of complaints and disputes Legitimate interests
Statistics and service improvement Legitimate interests

6. Data Retention

Verification Data

Email addresses submitted for verification and the requester’s IP address are retained for a maximum period of 60 days to allow access to reports and verification history.

The Customer may, via their account settings, fully disable the retention of verification data. In this mode:

  • email addresses and the requester’s IP address are not retained
  • processing is performed on a non-persistent basis
  • only strictly anonymised or aggregated data may be retained for strictly technical purposes

Account Data

User account data is retained for as long as the user account remains active.

It may be retained beyond this period where necessary to comply with:

  • legal obligations
  • accounting and tax obligations
  • or the defence of Deltadromeus’ legal rights

Dormant accounts may be deleted or anonymised after a prolonged period of inactivity.

Billing Data

Certain billing data may be retained for the duration required by applicable legal and accounting obligations.

7. No Commercial Reuse of Verified Email Addresses

Email addresses submitted to the verification service:

  • are not sold
  • are not rented
  • are not shared or exchanged with third parties
  • are not used for marketing purposes
  • are not used for advertising or profiling purposes

They are processed exclusively for the performance of the service requested by the Customer.

8. Data Recipients

Personal data may be accessed, to the extent necessary for their respective duties:

  • authorised Deltadromeus personnel subject to confidentiality obligations
  • technical service providers strictly necessary for the operation of the service
  • payment service providers used for order processing (Stripe, PayPal), which act as independent data controllers for payment processing, regulatory compliance, and fraud prevention purposes
  • legally authorised public authorities where required by law

The Customer remains solely responsible for its contractual relationship with its payment service providers and for their respective data processing activities.

9. Payment Providers

Payments are processed by specialised providers such as Stripe and PayPal.

These providers ensure the secure processing of payments and act as independent data controllers for payment processing activities, regulatory compliance, and fraud prevention purposes.

Deltadromeus does not store any sensitive banking data.

10. International Data Transfers

Data is hosted on technical infrastructure operated by hosting providers acting as data processors, including OVH.

The technical architecture of the service relies on distributed systems to ensure the provision of email verification processing and service performance.

The main infrastructure is located in France.

Certain processing operations may be carried out on infrastructure located in Canada, acting as technical data processors.

These infrastructures temporarily receive only the data strictly necessary for processing execution, without retention or use for their own purposes.

Data is processed exclusively for the purpose of service execution and is immediately returned to the main system without being stored.

These processing activities constitute transfers of data outside the European Union, governed by appropriate safeguards in accordance with the GDPR.

11. Security

Deltadromeus implements strengthened technical and organisational measures to ensure data security, including:

  • TLS encryption of communications
  • isolation of production environments
  • strict access controls to systems
  • logging and audit trails of access
  • mechanisms for detecting abuse and abnormal behaviour
  • secure backups

12. Your Rights

In accordance with the GDPR, you have the following rights:

  • right of access
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to object
  • right to data portability
  • right to withdraw consent where applicable

These rights may be exercised via the contact form available on the website.

13. Complaint to the CNIL

If you believe that your rights are not being respected, you have the right to lodge a complaint with the CNIL (French Data Protection Authority – Commission Nationale de l'Informatique et des Libertés).

14. Cookies

The website uses only technical cookies that are necessary for its proper functioning.

The website also uses Matomo for audience measurement and service improvement.

Matomo is configured to minimise the collection of personal data and to comply with CNIL recommendations.

Users can configure their browser to refuse or delete cookies.

15. Changes to this Policy

This policy may be modified at any time to reflect legal, regulatory, technical, or organisational changes.

The applicable version is the one published on the website at the time of consultation.