Zyloriso

Privacy policy

Last updated: 17 September 2026

1. Who we are

Zyloriso (“we”, “us”) operates the email verification service available at zyloriso.com and api.zyloriso.com. Questions about this policy go to privacy@zyloriso.com.

2. Two roles: controller and processor

Account data, meaning your name, email, billing details and API usage logs: we are the data controller.

Email addresses you submit for verification: we are a data processor acting on your instructions. You remain the controller and are responsible for having a lawful basis to process those addresses. A data-processing agreement under Article 28 GDPR is available on request.

3. What we do with submitted email addresses

We do not use submitted addresses for any purpose other than returning results to you. We do not sell, share, enrich or build marketing lists from them.

4. Retention

DataRetention
Uploaded lists and result filesDeleted automatically 30 days after job completion, or immediately on request.
Verification results, meaning the address and its outcomeReused for up to 30 days so the same address is not re-checked on overlapping lists, then deleted. The exact period depends on the result: 7 days for a deliverable or accept-all address, up to 30 days for a malformed or non-existent one. Inconclusive results are never stored.
Account and billing recordsThe duration of the account, plus the statutory retention period for invoices.
Technical logs, meaning IP, timestamps and request metadata90 days, for security and abuse investigation.

5. Where data is processed

All verification infrastructure is hosted on servers we operate in Helsinki, Finland, inside the European Union. We do not transfer submitted email addresses outside the EU or EEA.

6. Sub-processors

Hosting: Hetzner Online GmbH, Germany and Finland. Payment processing: our payment providers receive billing details only, never verification data. A current list is available on request.

7. Security

Encrypted transport with TLS for all API and dashboard traffic, key-based server access, firewalled infrastructure, encrypted backups, and automatic deletion schedules.

8. Your rights

If you are in the EU, EEA or UK, you may request access, rectification, erasure, restriction or portability of your account data, and you may object to processing. Individuals whose address was verified by one of our customers should contact that customer, who is the controller; we will assist them as required. You may lodge a complaint with your supervisory authority.

9. Cookies

The public website uses no tracking cookies. The dashboard uses a session cookie that is strictly necessary for login.

10. Changes

We will post updates on this page and notify account holders by email of any material change.