Autheona is actively working toward full GDPR compliance. This document reflects our current data protection practices and will be updated as we continue to develop our compliance program. We are committed to transparent, lawful, and secure data processing.
Introduction
This document explains how Autheona ("we," "us," or "our") complies with the General Data Protection Regulation (GDPR) when providing our intelligent verification platform (the "Service").
Autheona provides real-time email analysis and validation for SaaS applications. We help businesses assess email addresses during signup flows to detect fraud, reduce abuse, and improve onboarding quality.
If you have questions about our GDPR compliance, contact us at: legal@autheona.com
Who Controls Your Data?
Understanding who controls data is essential under GDPR.
For Your Account Information
When you create an Autheona account, we are the Data Controller for:
Your name and email address
Company information
Billing details
API credentials
Usage statistics
For Email Addresses You Analyze
When you submit email addresses through our API, you are the Data Controller and Autheona acts as your Data Processor.
This means:
You decide what email addresses to analyze
You obtain necessary consents from your users
You provide privacy notices to your users
You respond to data subject requests from your users
We process the data according to your instructions (via API calls)
These providers are bound by contract to protect data and use it only for specified purposes.
Legal Requirements
We may disclose data if required by:
Court orders
Legal obligations
Law enforcement requests
Protection of our legal rights
Your Rights Under GDPR
If you are in the EU/EEA, you have the following rights:
Right to Access: Request copies of your personal data
Right to Rectification: Correct inaccurate information
Right to Erasure: Request deletion of your data (subject to legal requirements)
Right to Restriction: Limit how we process your data
Right to Data Portability: Receive your data in a portable format
Right to Object: Object to processing based on legitimate interests
Right to Withdraw Consent: Where processing is based on consent
Right to Lodge a Complaint: File a complaint with your supervisory authority
How to Exercise Your Rights
For Your Account Data:
Email us at legal@autheona.com with your request. We will respond within 30 days.
For Email Addresses You Submitted:
Since you are the Data Controller for email addresses you analyze, your users should contact you first. You can then request deletion or export from Autheona on their behalf.
Data Export: Available now - contact legal@autheona.com (manual process)
Self-Service Tools: Currently in development
How Long Do We Keep Data?
Account Information:
Kept while your account is active
Retained for a limited period after account closure for legal and operational purposes
Analyzed Email Addresses:
Controlled by you via API parameters
When analytics storage is enabled: retained for service improvement
When analytics storage is disabled: processed in real-time without long-term storage
Technical Logs:
Typically retained for 90 days to 12 months
Used for security monitoring and troubleshooting
Backup Data:
May be retained for up to 30 additional days for disaster recovery
International Data Transfers
Currently, all data is stored and processed within the EU region.
If we expand processing outside the EU in the future, we will:
Notify affected customers in advance
Implement appropriate safeguards (such as Standard Contractual Clauses)
Ensure compliance with GDPR transfer requirements
Cookies and Tracking
We use cookies and similar technologies for authentication, security, and analytics. See our Cookie Policy for full details.
Children's Privacy
Our Service is not intended for children under 16 (or applicable age in your jurisdiction). We do not knowingly collect data from children.
If you believe we have inadvertently collected such data, contact us immediately at legal@autheona.com.
Your Supervisory Authority
If you are in the EU/EEA and believe we have not complied with GDPR, you have the right to lodge a complaint with your national data protection authority.