Privacy policy
Last updated: 17 September 2026
1. Who we are
Zyloriso (“we”, “us”) operates the email verification service available at zyloriso.com and api.zyloriso.com. Questions about this policy go to privacy@zyloriso.com.
2. Two roles: controller and processor
Account data, meaning your name, email, billing details and API usage logs: we are the data controller.
Email addresses you submit for verification: we are a data processor acting on your instructions. You remain the controller and are responsible for having a lawful basis to process those addresses. A data-processing agreement under Article 28 GDPR is available on request.
3. What we do with submitted email addresses
- Parse the address and check its syntax.
- Query public DNS records for the domain.
- Open a short SMTP connection to the domain's mail server to ask whether the mailbox exists. No message is sent.
- Return a status and score to you.
We do not use submitted addresses for any purpose other than returning results to you. We do not sell, share, enrich or build marketing lists from them.
4. Retention
| Data | Retention |
|---|---|
| Uploaded lists and result files | Deleted automatically 30 days after job completion, or immediately on request. |
| Verification results, meaning the address and its outcome | Reused for up to 30 days so the same address is not re-checked on overlapping lists, then deleted. The exact period depends on the result: 7 days for a deliverable or accept-all address, up to 30 days for a malformed or non-existent one. Inconclusive results are never stored. |
| Account and billing records | The duration of the account, plus the statutory retention period for invoices. |
| Technical logs, meaning IP, timestamps and request metadata | 90 days, for security and abuse investigation. |
5. Where data is processed
All verification infrastructure is hosted on servers we operate in Helsinki, Finland, inside the European Union. We do not transfer submitted email addresses outside the EU or EEA.
6. Sub-processors
Hosting: Hetzner Online GmbH, Germany and Finland. Payment processing: our payment providers receive billing details only, never verification data. A current list is available on request.
7. Security
Encrypted transport with TLS for all API and dashboard traffic, key-based server access, firewalled infrastructure, encrypted backups, and automatic deletion schedules.
8. Your rights
If you are in the EU, EEA or UK, you may request access, rectification, erasure, restriction or portability of your account data, and you may object to processing. Individuals whose address was verified by one of our customers should contact that customer, who is the controller; we will assist them as required. You may lodge a complaint with your supervisory authority.
9. Cookies
The public website uses no tracking cookies. The dashboard uses a session cookie that is strictly necessary for login.
10. Changes
We will post updates on this page and notify account holders by email of any material change.