GDPR Compliance

Last updated June 10, 2026

This document is a working template and not yet legal advice. It must be reviewed and approved by qualified counsel before launch.

CorrectInbox is built to be GDPR-aware. This page summarizes how we support controllers who use our service.

Roles

For verification data you submit, you are typically the controller and CorrectInbox is the processor, acting on your documented instructions.

Lawful basis & minimization

We process only what is needed to return a result and retain it for the minimum necessary period.

Data-deletion endpoint

We provide a working data-deletion endpoint so you and your data subjects can have records erased on request.

Sub-processors & transfers

Sub-processors are bound by DPAs, and international transfers rely on appropriate safeguards such as Standard Contractual Clauses.

DPA

Need a signed Data Processing Agreement? Email privacy@correctinbox.com.