Privacy Policy
How we handle your data
Effective date: 25 August 2026
Our promise, in one line: Safilist will never sell, share, or monetize your data. This binds every current and future leader of the company.
1. About Safilist
Safilist is an email verification service operated by Safilist Email Services, a business registered in Kenya, with a registered address at P.O. Box 10911-00200 City Square, Nairobi.
Safilist Email Services is a distinct entity, not a product of any other company. Safilist Email Services is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya under identification 861-6075-EA98:
- Data Controller — Certificate Serial 24823, valid 04/08/2026 to 04/08/2028
- Data Processor — Certificate Serial 25734, valid 25/08/2026 to 25/08/2028
2. What data we collect
2.1 Your account data
When you sign up, we collect your name, your email address, and a hashed version of your password (we never store passwords in plain text). If and when subscription billing becomes available, we will also collect billing information necessary to process payments.
2.2 Email lists you upload
When you use Safilist to verify emails, you upload a list containing email addresses. Each address is checked for deliverability, and the results (Safe, Risky, or Invalid) are stored so you can view and download them.
2.3 Usage data
We record basic activity data — when you log in, how many verifications you have performed, and how many credits you have consumed — to operate the service and protect it from abuse.
2.4 Technical data
Our servers record your IP address, browser type, and access times in standard server logs. This information is used for security, debugging, and preventing abuse. We do not use tracking cookies, advertising cookies, or analytics that identify you personally.
3. Our dual role: Controller and Processor
Under the Kenya Data Protection Act, 2019, Safilist has two distinct roles depending on which data is being discussed:
- For your account data (your name, email, password, usage), Safilist is the Data Controller. We decide why and how this data is handled.
- For the email lists you upload, Safilist is the Data Processor. The people whose addresses appear on your list are the data subjects; you are the Data Controller for that list. We process it on your instruction, solely to run the verification you requested.
This dual role is why we are registered with the ODPC for both roles separately.
4. Why we process your data (lawful basis)
- To provide the service you signed up for — running verifications, showing you results, keeping your account working. (Performance of contract.)
- To protect the service from abuse — rate limiting, spam prevention, security monitoring. (Legitimate interest.)
- To meet legal obligations — retaining minimal billing records for tax purposes when billing becomes available. (Legal obligation.)
We do not process your data for advertising, behavioural profiling, or any purpose beyond running the service you are using.
5. How long we keep your data
5.1 Email lists you upload
Uploaded email addresses are automatically deleted 7 days after verification.
After 7 days, every uploaded email address is redacted — the original address is replaced with a placeholder, and any personally identifiable details in the verification metadata are scrubbed. We retain only the aggregate statistics (how many addresses were Safe, Risky, or Invalid) and the verdicts — no personal data remains.
This is a scheduled, automated process. You do not need to request it.
5.2 Your account data
We keep your account data for as long as your account is active. When you delete your account, we remove your personal data within 30 days, except where we are legally required to retain some records (for example, billing history for tax purposes).
5.3 Server logs
Technical logs (IP addresses, access times) are retained for up to 30 days and then discarded.
6. Sub-processors
To operate the service, we work with a small number of external providers ("sub-processors") for infrastructure such as server hosting. Each is contractually or technically limited to only what is necessary for their role.
Email deliverability checks are performed entirely on our own infrastructure — the actual verification process does not involve any third party.
For security reasons, we do not publicly disclose the specific vendors we use. A current list of sub-processors is available on written request to mail@safilist.com, and we will disclose it to regulators, auditors, or when required by law.
We will update our sub-processor list before engaging any new provider.
7. International data transfers
Our servers are hosted in Germany. Your data is transferred from Kenya to Germany for storage and processing.
The European Union has data protection standards comparable to Kenya's KDPA, and both frameworks provide similar rights to data subjects. We rely on this equivalence as the safeguard for this transfer.
8. Your rights under the KDPA
Under the Kenya Data Protection Act, 2019, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data (subject to legal retention requirements)
- Restrict or object to how we process your data
- Receive a copy of your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with the ODPC
9. How to exercise your rights
Email us at mail@safilist.com with your request. We will respond within 30 days.
10. Right to complain
If you are not satisfied with how we have handled your personal data, please contact us at complaints@safilist.com so we can investigate and respond.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya.
11. Security
We protect your data through:
- HTTPS encryption for all data in transit
- Password hashing — we never store passwords in plain text
- Access controls limiting who can reach production systems
- The 7-day auto-purge described above, which minimizes the personal data we hold at any given time
- Regular security updates to our software stack
No system is perfectly secure. If a breach occurs that affects your data, we will notify you and the ODPC as required by law.
12. Cookies
We use only essential cookies:
- Session cookies to keep you logged in
- CSRF tokens to protect against certain kinds of attacks
We do not use tracking, advertising, or analytics cookies that identify you.
13. Children
Safilist is not intended for use by people under 18. We do not knowingly collect data from anyone under 18. If you believe we have such data, please contact us and we will remove it.
14. Changes to this policy
We may update this policy from time to time. When we make significant changes, we will notify registered users by email and post a notice on the site. The effective date at the top of this policy will always show the most recent revision.
15. Contact us
Safilist Email Services
P.O. Box 10911-00200 City Square
Nairobi, Kenya
Email: info@safilist.com