Legal Center
Most companies write legal documents to protect themselves, buried in language no one can parse. We write ours to protect you too. Every policy on this page is in plain English, reviewed quarterly, and means exactly what it says.
How we collect, store, and protect your information, and your rights over it.
What data we collect, why we need it, and every right you have to access, correct, or delete it.
Additional rights and disclosures for EU, EEA, UK, and Swiss residents, under GDPR and Swiss law.
Your rights under CCPA and CPRA: the right to know, to delete, and to opt out of data sale.
How Verifox operates as a GDPR-compliant data controller and processor, with full DPA support.
Every cookie we place, why we place it, and a plain guide to disabling any or all of them.
What you can expect from us and what we ask of you in return.
The agreement governing your account: your rights, our obligations, and the rules between us.
If we fall short, we make it right. Here are the terms, timelines, and exactly how to claim.
Our guarantee on verification accuracy: what you are owed and how to claim it when we miss.
Our marks and logos: what you may use without asking, what you may not, and how to request permission.
Who we work with, how we secure your data, and what we do with it.
Every third-party vendor that processes your data, the role they play, and how we audit them.
The technical and procedural safeguards protecting your data, and our incident response process.
How we use verification data to study email deliverability, and the hard limits on that use.
How email verification actually works, what we do with your data, and what we never do.
Quick navigation across everything Verifox publishes.
Got a question?
Not a bot. Not a template. A member of our legal team reads your email and answers your specific question — no run-around, no canned responses.
Email Our Legal TeamEvery layer of the stack carries a third-party attestation, so you can ship into regulated industries without rebuilding your compliance posture.

Independently audited to the SOC 2 Type II standard.

Built for the EU with full GDPR data-subject rights.

California opt-out, do-not-sell, plus DSAR handling.

Information security held to the ISO 27001 standard.

AI governance aligned to the new ISO 42001 standard.