Legal
Data Processing Agreement
Last updated:
September 8, 2026
Purpose and scope
Definitions
Terms such as "personal data," "processing," "controller," "processor," "data subject," and "sub-processor" have the meanings given to them in the GDPR.
Roles of the parties
Subject matter, duration, nature, and purpose of processing
We process personal data on your behalf for the purpose of operating the redirect, DNS, and related services you configure — specifically, receiving and routing HTTP/HTTPS requests from your domains' visitors, and where applicable, logging technical request data to provide analytics and maintain service security. Processing continues for as long as your subscription is active, and ends in accordance with Section 12 (Deletion or return of data) once it ends.
Categories of data subjects and personal data
Data subjects: visitors to the domains and websites you connect to Redirect Supply. Categories of personal data: IP address, browser and device information (user agent), referrer URL, requested URL, and timestamp of the request. We do not intentionally process special categories of personal data (as defined in GDPR Article 9) through the Service.
Our obligations as processor
Sub-processors
International data transfers
Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any case within 72 hours of becoming aware of it, with the information reasonably available to us at that time to help you meet your own notification obligations.
Audits and compliance
On reasonable request, we will make available the information necessary to demonstrate compliance with this DPA, including relevant security documentation. Given the nature and scale of our service, we provide this through documentation and completed security questionnaires rather than on-site audits; formal audit rights may be made available under a separate agreement for Enterprise customers.
Deletion or return of data
Liability
Governing law