Bounce Watch International Operating B.V. is a Dutch company, headquartered in Amsterdam and operating under the EU General Data Protection Regulation (GDPR). This page summarizes how we comply with the GDPR — both as a company processing your account data, and as a provider of business-intelligence services built on publicly available company information.
1. Our Approach
- We track companies, not private individuals. Our signals describe organizational events — funding rounds, hiring activity, expansions, product launches — compiled from publicly available sources.
- Business contact data is processed under legitimate interest (Art. 6(1)(f) GDPR), limited to professional context (name, role, business contact details), and removable any time via our self-service Your data page.
- EU-based by design. We are incorporated in the Netherlands and our primary processing activities are organized under EU law.
- Data minimization. We collect only what is needed to provide the Services, and our enrichment is modular so customers request only the data they need.
2. Controller and Processor Roles
| Activity | Our role | Notes |
|---|---|---|
| Your account, billing and usage data | Controller | See our Privacy Policy |
| Company & business-contact database | Controller | Compiled from public sources under legitimate interest |
| Outreach you send through connected email accounts | Processor | You are the controller of your outreach and recipient lists; we process at your direction |
For customers who require it, we offer a Data Processing Agreement (DPA) covering our processor activities. Contact us to request a signed copy.
3. Rights of Data Subjects
Anyone whose personal data we process — customers, or professionals whose business contact details appear in our database — can exercise their GDPR rights:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object, including to profiling (Art. 21)
Requests are handled within 30 days. The fastest route for erasure is our self-service Your data page, which verifies your address and removes your records without waiting on us. You can also write to [email protected], or use our contact form with the subject "GDPR request".
4. Technical & Organizational Measures
- Encryption in transit (TLS 1.2+) for all Services
- Encryption at rest for sensitive credentials (connected email accounts)
- Role-based access control and least-privilege access for personnel
- Audit logging of administrative access
- Vendor due diligence and data processing agreements with all processors
- EU–US Data Privacy Framework and/or Standard Contractual Clauses for transfers outside the EEA
- Breach notification procedures aligned with Articles 33–34 GDPR
5. Outreach Compliance Features
Signal Tracker is built to support compliant outreach:
- Volume caps and send windows that discourage bulk spam behavior
- Per-contact and per-company cooldowns
- Suppression of contacts that have bounced or opted out
- Sending exclusively through the customer's own email accounts — we never send from shared pools
These features support, but do not replace, your own legal obligations when contacting prospects. Direct-marketing rules differ per country; consult your own counsel.
6. Privacy Contact
Bounce Watch International Operating B.V. — Privacy
Singel 542, 1017 AZ Amsterdam, the Netherlands
[email protected]
Your data (self-service access and erasure) · Contact form
Supervisory authority: Autoriteit Persoonsgegevens (NL) — autoriteitpersoonsgegevens.nl