Draft&Check Home · Terms

Privacy Policy

Last updated: 29 August 2026

This policy explains how SovereignShield BV (Nieuwpoortsesteenweg 162, 8400 Oostende, Belgium, enterprise no. 1038.469.726, VAT BE 1038.469.726), operator of Draft & Check, handles personal data. We are the data controller for your account data. Contact: [email protected].

1. Data we process

CategoryWhatWhy
AccountYour email address, a hashed password, and verification-count totalsTo create and run your account and bill usage
PaymentHandled by Stripe. We receive a customer identifier and payment status; we never see or store your card details.To take payment for credits
Submitted addressesThe email addresses you send for verificationTo produce a verification result; see section 2
TechnicalIP address, request timestamps, and basic server logsSecurity, abuse prevention, and reliability

2. The addresses you submit

Email addresses submitted to the API are processed transiently to produce a result. We do not store the submitted addresses, build a database of them, log them in full, or sell or share them. We keep only the aggregate number of verifications for billing. For these addresses, you are the data controller and we act as your processor, on your instructions. A data processing agreement (DPA) is available on request. You are responsible for having a lawful basis to submit and verify those addresses.

3. Legal bases (GDPR Art. 6)

4. Processors we use

We share the minimum data necessary with vetted providers who process it only on our behalf:

5. Retention

Account data is kept while your account is active and for as long as needed for legal and accounting purposes after closure. Submitted addresses are not retained (section 2). Server logs are kept for a short period for security.

6. Your rights

Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To exercise these rights, email [email protected]. You may also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, dataprotectionauthority.be).

7. International transfers

Our infrastructure is EU-based. Where a processor transfers data outside the EEA, that transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

8. Cookies

We use a single, essential cookie to keep you logged in to the dashboard. We do not use advertising or third-party tracking cookies.

9. Changes

We may update this policy; the “last updated” date reflects the current version, and material changes will be notified by email where appropriate.