Paravane Labs
Product catalog Applied intelligence for risk, revenue, operations, compliance, data, and vendor decisions.

Risk & Trust Intelligence

Detect suspicious activity, unreliable outputs, risky communications, and fraud signals.

smtpRS | Email Risk Intelligence

Scores email risk, urgency, confidence, and unusual activity.

InvoiceGuard | Invoice Protection In development

Detects fraudulent, duplicate, inflated, or suspicious invoice activity.

Customer & Revenue Intelligence

Predict churn, renewal health, payment reliability, and revenue risk.

RetainIQ | Customer Retention Intelligence In development

Predicts customer churn, disengagement, and renewal risk.

Data & Vendor Intelligence

Improve data reliability and evaluate third-party operational risk.

VendorLens | Vendor Intelligence In development

Assesses vendor reliability, compliance, and operational dependency risk.

Resources Technical guidance for integrating and operating Paravane products.
Developer DocsAPI references, quickstarts, authentication, and integration guidance. Python SDKOfficial client and API integration resources.Open SourceSDKs and engineering tools maintained by Paravane.
Pricing
Sign in Contact

Legal

Data Processing Addendum

Processor/service-provider terms for customer personal data

Last updated: June 9, 2026 All legal resources

Resources

Terms of Service Privacy Policy Acceptable Use Data Processing Addendum Subprocessors Cookie Notice Security Overview

1. Parties and incorporation

This Data Processing Addendum ("DPA") forms part of the agreement between Paravane Labs, Inc. ("Paravane") and the customer that has accepted the Paravane Terms of Service, signed an Order, or otherwise entered into an agreement for the Services ("Customer").

This DPA applies only to the extent Paravane processes Customer Personal Data on behalf of Customer as a processor, service provider, contractor, or equivalent role under applicable Data Protection Laws. This DPA does not apply to personal information Paravane processes as an independent controller/business for its own purposes, which is addressed in the Privacy Policy.

2. Definitions

TermMeaning
AffiliateAn entity that controls, is controlled by, or is under common control with a party.
Customer Personal DataPersonal Data contained in Customer Data that Paravane processes on behalf of Customer in connection with the Services.
Data Protection LawsAll data protection, privacy, data security, breach notification, and similar laws applicable to the processing of Customer Personal Data under the Agreement, including GDPR, UK GDPR, Swiss data protection law, and applicable U.S. state privacy laws where relevant.
GDPRRegulation (EU) 2016/679, the General Data Protection Regulation.
Security IncidentA confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Paravane.
ServicesThe Paravane services purchased or used by Customer, including the smtpRS API, dashboard, documentation, and support.
SubprocessorA third party engaged by Paravane to process Customer Personal Data on behalf of Customer in connection with the Services.

Terms such as "controller," "processor," "personal data," "processing," "data subject," "business," "service provider," "contractor," "consumer," "sale," and "share" have the meanings given in applicable Data Protection Laws.

3. Roles of the parties

Customer is the controller/business or processor/service provider, as applicable, for Customer Personal Data. Paravane is a processor/service provider or subprocessor/contractor, as applicable, when processing Customer Personal Data on behalf of Customer.

Customer determines the purposes and means of processing Customer Personal Data, including what data to submit, which endpoints to call, how to configure the Services, how to interpret outputs, and what actions to take based on outputs. Paravane processes Customer Personal Data only as described in this DPA and the Agreement or as otherwise instructed by Customer in writing.

4. Customer instructions

Customer instructs Paravane to process Customer Personal Data to provide, secure, support, maintain, troubleshoot, and improve the Services; process API requests; generate outputs; authenticate users; manage accounts, sessions, email verification, password reset, API keys, subscriptions, billing status, and usage reporting; prevent abuse; enforce Usage Limits; comply with law; and perform the Agreement. Customer may provide additional documented instructions, provided they are consistent with the Agreement and lawful.

Paravane will promptly notify Customer if Paravane believes an instruction violates Data Protection Laws, unless prohibited by law. Paravane is not responsible for determining whether Customer's instructions comply with laws applicable to Customer, Customer's industry, Customer's end users, or Customer's downstream uses.

5. Customer obligations

Customer is responsible for:

  • Providing all notices, obtaining all consents, establishing all lawful bases, and honoring all opt-outs required for Customer Personal Data.
  • Ensuring Customer Personal Data is accurate, lawful, relevant, and limited to what is necessary for Customer's permitted use.
  • Ensuring Customer has the right to submit Customer Personal Data to Paravane and instruct Paravane to process it.
  • Complying with Data Protection Laws, the Terms of Service, the AUP, and Documentation.
  • Not submitting prohibited sensitive, regulated, or special-category data unless expressly authorized in a separate written agreement.
  • Responding to data subject/consumer requests where Customer is the controller/business and instructing Paravane where assistance is needed.
  • Securing Customer systems, credentials, API keys, sessions, integrations, exports, logs, payment-provider accounts, and downstream uses of outputs.

6. Paravane processing obligations

Paravane will:

  • Process Customer Personal Data only on documented instructions from Customer, including this DPA, the Agreement, Orders, Documentation, API calls, dashboard settings, and written instructions accepted by Paravane.
  • Ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations.
  • Implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Annex B.
  • Assist Customer with data subject/consumer requests, security obligations, data protection impact assessments, and regulatory consultations to the extent required by Data Protection Laws and taking into account the nature of processing and information available to Paravane.
  • Notify Customer of Security Incidents as described in this DPA.
  • Use Subprocessors only as described in this DPA.
  • Delete or return Customer Personal Data as described in this DPA and the Agreement.
  • Make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and operational restrictions.

7. Confidentiality and personnel access

Paravane will limit access to Customer Personal Data to personnel, contractors, and Subprocessors who need access to provide, secure, support, maintain, or improve the Services, or to comply with law. Paravane will take reasonable steps to ensure that such personnel are subject to confidentiality obligations and receive security guidance appropriate to their roles.

8. Security measures

Paravane will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. The measures are described in Annex B and may be updated over time, provided that updates do not materially reduce the overall security of the Services during an active subscription.

Customer acknowledges that security measures must account for the nature of the Services, the data submitted by Customer, Customer's configurations, Customer's integrations, and evolving threats. Customer is responsible for implementing appropriate security measures in Customer's own environment.

9. Subprocessors

Customer authorizes Paravane to engage Subprocessors to process Customer Personal Data in connection with the Services, including infrastructure, security, payment processing, email delivery, and other service providers listed in Paravane's Subprocessor List.

Paravane will impose written data protection obligations on Subprocessors that are no less protective, in substance, than the obligations in this DPA to the extent applicable to the Subprocessor's processing. Paravane remains responsible for Subprocessors' performance of their data protection obligations under this DPA.

Paravane will provide notice of material new Subprocessors by updating the Subprocessor List or providing another notice mechanism. Customer may object to a new Subprocessor on reasonable data protection grounds within 30 days of notice. If the parties cannot resolve the objection, Customer may terminate the affected Services as its sole remedy, unless the parties agree otherwise.

10. Data subject and consumer requests

If Paravane receives a request directly from an individual relating to Customer Personal Data, Paravane will, where reasonably identifiable as Customer Personal Data and legally permitted, either direct the individual to Customer or notify Customer. Paravane will not respond to the substance of the request except on Customer's documented instructions or as required by law.

Taking into account the nature of processing, Paravane will provide reasonable assistance to Customer to fulfill Customer's obligations to respond to requests for access, deletion, correction, portability, restriction, objection, opt-out, appeal, or similar rights under Data Protection Laws.

11. Security Incident notification

Paravane will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to Paravane, which may include the nature of the incident, categories of affected data, approximate number of affected records if known, likely consequences if known, mitigation measures, and a contact point for follow-up.

Paravane's notification of, or response to, a Security Incident is not an admission of fault or liability. Customer is responsible for determining whether notification to individuals, regulators, customers, or others is required, unless applicable law requires Paravane to notify directly.

12. Assistance with DPIAs and consultations

Taking into account the nature of processing and information available to Paravane, Paravane will provide reasonable assistance to Customer with data protection impact assessments, transfer impact assessments, and prior consultations with regulators where required by Data Protection Laws and related to Paravane's processing of Customer Personal Data.

13. Deletion and return

Upon termination or expiration of the Services, Paravane will delete or return Customer Personal Data in accordance with the Agreement, Documentation, retention schedules, and Customer's documented instructions, unless retention is required by law or permitted for security, fraud prevention, dispute resolution, backup, or compliance purposes.

Customer acknowledges that Customer Personal Data may remain in encrypted backups and logs until overwritten or deleted in the ordinary course of business, subject to access restrictions and retention controls. Paravane will not restore backup data except for disaster recovery, security, legal, or operational purposes.

14. Audits and information rights

Upon reasonable written request and subject to confidentiality, security, and availability restrictions, Paravane will make available information reasonably necessary to demonstrate compliance with this DPA. This may include security documentation, summaries, questionnaires, third-party certifications, audit reports if available, or written responses.

On-site audits are permitted only where required by Data Protection Laws and only after the parties agree on scope, timing, confidentiality, security controls, auditor qualifications, and cost allocation. Audits must not unreasonably interfere with Paravane operations, compromise security, expose other customers' information, or require disclosure of trade secrets or highly sensitive information.

15. International transfers

Customer authorizes Paravane and its Subprocessors to process Customer Personal Data in the United States, the European Economic Area, and other countries where Paravane or its Subprocessors operate, subject to applicable transfer safeguards.

Where Customer Personal Data protected by GDPR, UK GDPR, Swiss data protection law, or similar laws is transferred to a country without an applicable adequacy decision, the parties will use an appropriate transfer mechanism, such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss addendum terms, a lawful data privacy framework if Paravane later becomes certified under that framework, or another lawful mechanism.

16. Government and legal requests

If Paravane receives a government, law-enforcement, national-security, court, or regulatory request for Customer Personal Data, Paravane will review the request and, where legally permitted and commercially reasonable, notify Customer before disclosure so Customer may seek protective relief. Paravane may disclose Customer Personal Data where Paravane reasonably believes disclosure is required by law.

17. U.S. state privacy law service-provider terms

To the extent Customer Personal Data is subject to U.S. state privacy laws that require service-provider, processor, contractor, or similar contract terms, Paravane will:

  • Process Customer Personal Data only for the business purposes described in the Agreement, this DPA, Documentation, and Customer instructions.
  • Not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising as those terms are defined by applicable law.
  • Not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law.
  • Not combine Customer Personal Data with personal information received from other sources except as permitted by applicable law, such as for security, fraud prevention, debugging, analytics, service improvement, or other permitted business purposes.
  • Provide the same level of privacy protection required by applicable law for the processing activities covered by this DPA.
  • Notify Customer if Paravane determines it can no longer meet its obligations under applicable law.
  • Allow Customer to take reasonable and appropriate steps to help ensure Paravane uses Customer Personal Data consistently with Customer's obligations, through the audit and information mechanisms in this DPA.

18. De-identified and aggregated data

Paravane may process data derived from Customer Personal Data in de-identified, anonymized, or aggregated form for security, analytics, service improvement, benchmarking, research, and business purposes, provided that Paravane maintains and uses such data in de-identified or aggregated form and does not attempt to re-identify individuals except to test or validate de-identification or as permitted by law.

19. Order of precedence

If there is a conflict between this DPA and the Terms of Service, this DPA controls for the processing of Customer Personal Data. If there is a conflict between this DPA and Standard Contractual Clauses or another mandatory transfer mechanism, the transfer mechanism controls to the extent of the conflict. A signed enterprise agreement may modify this DPA only if it expressly states that it does so.

20. Limitation of liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by applicable law or expressly modified in a signed written agreement.

21. Contact

Legal and DPA questions may be sent to legal@paravane.io. Privacy questions and rights requests may be sent to privacy@paravane.io. Security questions and reports may be sent to security@paravane.io. General information requests may be sent to contact@paravane.io. Legal notices may also be mailed to: 11166 Fairfax Blvd Suite 500 #1378, Fairfax, VA 22030, United States; Phone: (703) 972-1286.

Annex A - Details of processing

ItemDescription
Subject matterProvision of Paravane Services, including the smtpRS API, dashboard, scoring outputs, support, security, billing-adjacent account administration, and related operations.
DurationFor the term of the Agreement plus retention periods described in the Agreement, Privacy Policy, Documentation, or Customer instructions.
Nature and purposeReceiving API requests, processing customer-submitted identifiers, generating risk scores and outputs, authenticating requests, logging usage, preventing abuse, debugging, providing support, maintaining security, and complying with law.
Categories of data subjectsCustomer personnel and users; individuals associated with submitted email addresses, IP addresses, domains, or identifiers; customer end users or prospects where Customer submits their identifiers; support contacts.
Categories of personal dataBusiness contact information, account identifiers, email addresses, domain names, IP addresses, online identifiers, API request metadata, user-agent strings, timestamps, status codes, risk signals, scores, labels, reason codes, support communications, and other fields Customer submits.
Sensitive dataNot intended. Customer must not submit sensitive, regulated, or special-category data unless expressly authorized by separate written agreement.
Processing operationsCollection, receipt, transmission, hosting, storage, retrieval, consultation, analysis, transformation, scoring, logging, disclosure to Subprocessors, deletion, and related processing necessary to provide the Services.
Customer instructionsThe Agreement, this DPA, Orders, API calls, dashboard settings, Documentation, support requests, and other written instructions accepted by Paravane.

Annex B - Technical and organizational measures

MeasureDescription
Encryption in transitUse HTTPS/TLS for transmission of Customer Personal Data over public networks, with current protocol and certificate management appropriate for public web and API endpoints.
Encryption at restUse infrastructure-supported encryption or equivalent protections for production storage, managed databases, object storage, backups, or disks that hold Customer Personal Data.
Access controlsUse role-based or least-privilege access controls for production systems, with access limited to authorized personnel with a business need.
AuthenticationUse password hashing and secure authentication for user accounts. Administrative access should use strong authentication and MFA where available; customer-facing MFA and SSO/SAML are not available unless separately offered or agreed.
API credential securityIssue unique API keys/tokens, allow rotation/revocation, and monitor for suspicious usage. Customers remain responsible for keeping credentials secret.
Logging and monitoringMaintain logs for security, reliability, performance, abuse detection, and troubleshooting, subject to retention limits and access controls.
Network and infrastructure securityUse reputable hosting and security providers, firewall/WAF controls where applicable, network segmentation where appropriate, and secure configuration management.
Vulnerability managementApply security patches, dependency updates, and vulnerability remediation based on severity, exposure, and operational risk.
Secure developmentUse code review, environment separation, secrets management, dependency review, and deployment controls appropriate to the size and maturity of the company.
Backups and resilienceMaintain backups and recovery procedures appropriate to the Services, with backup retention generally targeted at approximately 30 to 90 days unless otherwise required.
Personnel securityRestrict production access to authorized personnel; use confidentiality obligations; provide security awareness appropriate to role.
Vendor managementReview subprocessors for security and privacy fit and require written data protection commitments.
Incident responseMaintain an incident response process for identifying, investigating, mitigating, and notifying customers of Security Incidents.
Data minimizationLimit stored data and logs to what is reasonably necessary for service operation, security, billing, support, improvement, and compliance.
Deletion and disposalDelete or overwrite Customer Personal Data according to retention schedules, customer instructions, and legal requirements.

Annex C - Subprocessors

The Subprocessor List published by Paravane is incorporated into this DPA and identifies third parties Paravane uses to process Customer Personal Data in connection with the Services.

Annex D - Transfer mechanisms

Where required for restricted transfers, the parties will use the EU Standard Contractual Clauses, the UK International Data Transfer Addendum for UK transfers, Swiss addendum language for Swiss transfers, or another lawful transfer mechanism applicable to the transfer. Paravane does not rely on EU-U.S. Data Privacy Framework certification unless it has completed and maintains that certification.

Annex E - Customer configuration and instructions

AreaInstruction/setting
Data submittedCustomer controls which identifiers and fields are submitted to the Services.
Retention configurationDefault position: ordinary API request metadata is retained for approximately 90 days unless a different period is required for security, abuse prevention, debugging, legal claims, compliance, or a customer agreement. Full API payloads should not be stored by default where feasible. Customer-configurable log retention, deletion, or masking settings should be described when implemented.
Access controlsCustomer controls its users, roles, API keys, and integrations through available dashboard and API controls.
Output useCustomer controls thresholds, workflows, review processes, notices, appeals, and downstream actions taken based on outputs.
Deletion requestsCustomer may request deletion/export through privacy@paravane.io or the dashboard/support process when available.

Getting Started

Contact Test smtpRS

Company

About Careers

Developers

DocumentationOpen Source
© 2026 Paravane. A DOYDL Technologies company.
Legal Terms Privacy Security