veriastra_
Legal

Subprocessors

Last updated August 3, 2026

This page lists the third parties that may process personal data on our behalf when you use Veriastra. It supports our GDPR & Compliance commitments and our Data Processing Agreement. It does not list the public reference datasets our engines are built from: those are sources we ingest, not parties we send your data to.

Infrastructure

  • Cloudflare, Inc. (USA) · DNS, TLS termination, CDN, and edge protection. Processes connection metadata such as IP address and request headers for every visit.
  • Hostinger International Ltd. · dedicated server hosting. Stores the application and its databases at rest. Hosting is a single dedicated machine, not a shared multi-tenant platform.

Accounts & payments

  • Google LLC (USA) · OAuth sign-in. Receives the authentication request and returns your email and account identifier. We never see or store a password.
  • Stripe, Inc. (USA) · payment processing and subscription billing. Receives your billing details directly. Card data never reaches our servers; we store only a customer and subscription identifier.

Enabled data providers

  • LeakCheck Ltd.· breach-exposure signal inside email verification (“Powered by LeakCheck”). The address being verified is sent to their public API, which returns the breach sources it appears in and the categories of exposed data — never the leaked data itself. Results are cached for 30 days; if the provider is unreachable, the lookup answers without the breach row.

Optional data providers

Some products are powered by an external provider and are inert unless we have enabled that provider. When a product is enabled, the specific value you look up (for example a phone number) is sent to that provider to answer your request. Products currently in this category include HLR lookup, search-intent lookup, domain SEO intelligence, phone scrub, and reverse lookup. Each product page states when it depends on an external source.

If a product is marked unavailable in your dashboard, no data is being sent to its provider and no credits are charged.

Lookup infrastructure we query

Answering a lookup requires contacting public internet infrastructure: DNS resolvers, public blocklists, mail servers for SMTP verification, and public numbering data. These are queried in real time and receive only what the protocol requires (for example a domain name during a DNS query, or an address during an SMTP check). They are not our subprocessors in the contractual sense, but we name them here because they do see part of the request.

Changes

We will update this page before adding a subprocessor that processes customer personal data, and DPA customers can request notice of changes by emailing [email protected]. If you object to a new subprocessor, tell us and we will work with you or let you terminate without penalty for the unused portion of your term.