GDPR-Aligned

Email verification & campaigns
with GDPR-aligned data handling

Clean your email list, reduce bounce rates, and send tracked campaigns — with on-demand data export, deletion, and audit trails built in for every account, not bolted on for one region.

Your data, on demandEvery account, wherever you are
  • Export everythingDownload your account data as a JSON file, without emailing anyone.
  • Delete your accountA 30-day grace period to change your mind, then a real cascade delete.
  • Audit trailEvery staff action on your account — view, export, deletion — is logged, append-only.
  • Retention windowVerification and campaign detail ages out on your plan’s own schedule.

Invoices and payment records are the exception — those are kept for as long as tax and accounting law requires. Read the privacy policy

Built for teams that care about data handling

Real-time, SMTP-level verification

Not just syntax and MX checks — Pingovo connects to the mailbox itself to confirm an address is deliverable before you send.

GDPR-aligned by design

On-demand data export and deletion, audit trails, and documented data subject rights — built in for every account, not a regional add-on.

Schedule sends in your time zone

Send now, at a date and time you pick, or on a repeating cron schedule — interpreted in your own time zone rather than UTC.

Who is the controller, and who is the processor?

Three answers, because the data is not all one kind.

You are the controller of your lists

You decide why the addresses were collected and what happens to them. The lawful basis, the records of processing, and the answer you owe a recipient are yours.

Pingovo is the processor for that data

Uploaded lists and campaign recipients are processed on your instructions — to verify and to send — and for nothing else. Sub-processors that touch it are named in the privacy policy and bound by data processing agreements.

Your own account data has one controller

Your name, login, billing records and audit trail are collected by Pingovo for its own purposes, so Pingovo is the controller of those — and the same rights below apply to you.

What happens to a list after you upload it

Five stages, with the retention window stated rather than implied.

  1. Uploaded and stored encrypted

    The file is encrypted at rest and readable only by your account. Nothing is appended, enriched, resold, or added to a shared database of addresses.

  2. Checked, not profiled

    Each address is tested for syntax, mail servers, mailbox existence, and disposable, role or catch-all patterns. The result is a status and a reason — no behavioural data, no third-party lookups about the person.

  3. Visible for your plan’s retention window

    One day on Free, up to 365 days on Pro. Within that window the results are yours to download, re-use, or delete early — deleting a job removes its results immediately.

  4. Withdrawn from your account

    When the window ends the rows stop being visible to you. They are kept for up to five years from the date of verification, reachable only by authorised administrators, for support, dispute resolution, abuse investigation and compliance.

  5. Removed with the account

    Deleting your account cascades through verification results, campaigns, recipients and tracking events after the 30-day grace period. Invoices and payment records are the documented exception — tax law requires them for seven years.

Everything you need in one platform

Single and bulk email verification (CSV/Excel)
Disposable, role-based, and catch-all detection
Drag-and-drop campaign builder with tracking
Email warmup for new sending domains
Deliver-by-time-zone campaign scheduling
REST API for programmatic verification

Exercising a data subject right

Two of these are buttons in your account. The rest are a written request, because they need a person to decide — and pretending otherwise would be the wrong kind of automation.

RightHow it works here
Access and portability (Art. 15, Art. 20)Settings → Security → Download My Data returns a machine-readable JSON copy of your account data immediately. No request, no waiting period.
Erasure (Art. 17)Delete your account and a 30-day grace period starts — recoverable until it ends, then a real cascade delete across every collection that holds your data.
Rectification (Art. 16)Account details are editable in your profile. Anything you cannot reach yourself goes to [email protected].
Restriction and objection (Art. 18, Art. 21)Written request to [email protected]. These need a human decision, so they are deliberately not a button.
Objection to direct marketing (Art. 21(2))Every campaign carries a footer unsubscribe link and a one-click List-Unsubscribe header, so a recipient can object without an account, a login, or a reply.
Complaint to a supervisory authorityAlways available, and never conditional on raising it with us first — your national DPA or the Data Protection Board of India.

If you received mail that was sent through Pingovo rather than sending it, the sender is your controller — unsubscribing reaches them directly, and [email protected] will route anything the sender cannot resolve.

What GDPR asks of you as the sender

No tool can be compliant on your behalf. These are the duties that stay yours, and what Pingovo does to make each one survivable.

Record a lawful basis for every list

Importing subscribers requires you to state the basis and confirm the contacts consented. Pingovo stores that attestation with the list and refuses an import without it — it is your record, not a verification of consent Pingovo can perform for you.

Make objecting effortless

Campaigns ship with an unsubscribe link in the footer and a one-click header mailbox providers act on. An unsubscribed address is marked on your list and skipped by every later send.

Keep the data accurate

Article 5(1)(d) asks that personal data be kept up to date. Verification and automatic bounce handling are how a list stops carrying addresses that no longer belong to anyone.

Be able to answer a request

Export and deletion are self-service, and staff access to your account is written to an append-only audit log — so “who looked at this, and when” has an answer.

Frequently asked questions

Yes. Pingovo is built with GDPR-aligned data handling, including on-demand data export and deletion and audit trails for account activity. See our Privacy Policy for the full breakdown of data subject rights.

Yes. Email verification, bulk list cleaning, campaign sending, and the REST API work the same everywhere — GDPR-aligned data handling isn't a separate regional product, it's how Pingovo handles data for every account.

Verifying addresses you already hold does not create a new purpose — it establishes whether an address you already intended to mail can receive mail, so it normally rests on the same lawful basis as the sending. What GDPR does require is that the check be data-minimised, that the results are not kept longer than they are useful, and that whoever runs it acts as your processor under a contract. Buying or scraping a list and verifying it does not become lawful because the addresses turned out to be real.

Both, for different data. For the lists you upload and the people you mail, you are the controller and Pingovo is the processor acting on your instructions. For your own account data — name, login, billing, audit records — Pingovo is the controller, and the same data subject rights apply to you.

Results are stored encrypted and stay visible in your account for your plan’s retention window — one day on Free, up to 365 days on Pro — and you can delete a job and its results at any time inside that window. After it, the rows are withdrawn from your view and kept for up to five years from the date of verification, reachable only by authorised administrators for support, dispute resolution, abuse investigation and compliance. Deleting your account removes them outright.

Settings → Security → Download My Data returns a machine-readable JSON copy of your account data immediately — that covers the right of access and the right to data portability with no request to file. Deleting your account starts a 30-day grace period during which it can be recovered; after that a cascade delete removes your data across every collection that holds it, apart from invoices and payment records that tax law requires be kept for seven years.

No. The public checker runs anonymously, consumes no credits, and stores nothing about the address after the check — it is not written to your account, because there is no account involved. It also does not run the SMTP mailbox step, which is the one check that needs a signed-in account.

All plans and credit packages are billed in USD.

Yes. Pick a date and time, or set a recurring cron schedule, and Pingovo runs the campaign in your own time zone. A scheduled campaign is a single send — every recipient receives it at the same moment rather than at their own local hour.

Yes. Upload a CSV or Excel file of any size and Pingovo verifies syntax, DNS/MX records, SMTP mailbox existence, and disposable/catch-all/role-based addresses for every entry.

Start for free

No credit card required.

We use essential cookies to run this site, and optional functional/analytics cookies to improve it. See our Privacy Policy for details.