Legal

Data Processing Agreement

Last updated:

September 8, 2026

  1. Purpose and scope

This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between you (“Customer”) and K-COMBO s.r.o., operating as Redirect Supply (“Processor,” “we,” “us”). It applies whenever we process personal data on your behalf as a result of your use of the Service, and reflects the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). By using Redirect Supply, this DPA takes effect automatically, without requiring separate signature.

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between you ("Customer") and K-COMBO s.r.o., operating as Redirect Supply ("Processor," "we," "us"). It applies whenever we process personal data on your behalf as a result of your use of the Service, and reflects the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). By using Redirect Supply, this DPA takes effect automatically, without requiring separate signature.

  1. Definitions

Terms such as "personal data," "processing," "controller," "processor," "data subject," and "sub-processor" have the meanings given to them in the GDPR.

  1. Roles of the parties

When you connect a domain and configure redirects through Redirect Supply, you act as the controller of any personal data relating to visitors of that domain (for example, their IP address and browsing activity as it passes through our redirect infrastructure). We act as your processor with respect to that data. This is distinct from our relationship regarding your own account data, where we act as controller — that relationship is governed by our Privacy Policy, not this DPA.

When you connect a domain and configure redirects through Redirect Supply, you act as the controller of any personal data relating to visitors of that domain (for example, their IP address and browsing activity as it passes through our redirect infrastructure). We act as your processor with respect to that data. This is distinct from our relationship regarding your own account data, where we act as controller — that relationship is governed by our Privacy Policy, not this DPA.

  1. Subject matter, duration, nature, and purpose of processing

We process personal data on your behalf for the purpose of operating the redirect, DNS, and related services you configure — specifically, receiving and routing HTTP/HTTPS requests from your domains' visitors, and where applicable, logging technical request data to provide analytics and maintain service security. Processing continues for as long as your subscription is active, and ends in accordance with Section 12 (Deletion or return of data) once it ends.

  1. Categories of data subjects and personal data

Data subjects: visitors to the domains and websites you connect to Redirect Supply. Categories of personal data: IP address, browser and device information (user agent), referrer URL, requested URL, and timestamp of the request. We do not intentionally process special categories of personal data (as defined in GDPR Article 9) through the Service.

  1. Our obligations as processor

We will process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Czech law, in which case we will inform you of that legal requirement first, unless the law prohibits us from doing so. We ensure that anyone with access to personal data under our authority is bound by an obligation of confidentiality. We implement appropriate technical and organizational security measures under GDPR Article 32, described further on our Security & Compliance page. We assist you, insofar as reasonably possible, in responding to requests from data subjects exercising their GDPR rights, and in fulfilling your obligations regarding data security, breach notification, and data protection impact assessments where applicable.

We will process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Czech law, in which case we will inform you of that legal requirement first, unless the law prohibits us from doing so. We ensure that anyone with access to personal data under our authority is bound by an obligation of confidentiality. We implement appropriate technical and organizational security measures under GDPR Article 32, described further on our Security & Compliance page. We assist you, insofar as reasonably possible, in responding to requests from data subjects exercising their GDPR rights, and in fulfilling your obligations regarding data security, breach notification, and data protection impact assessments where applicable.

  1. Sub-processors

You provide general authorization for us to engage sub-processors to help deliver the Service. Our current list of sub-processors, including their location and purpose, is published on our Subprocessors page. If we intend to add or replace a sub-processor, we will update that page at least 30 days before the change takes effect, giving you the opportunity to object on reasonable data protection grounds. If you object and we’re unable to resolve the concern, either party may terminate the affected part of the Service. We remain responsible for our sub-processors’ compliance with data protection obligations equivalent to those in this DPA.

You provide general authorization for us to engage sub-processors to help deliver the Service. Our current list of sub-processors, including their location and purpose, is published on our Subprocessors page. If we intend to add or replace a sub-processor, we will update that page at least 30 days before the change takes effect, giving you the opportunity to object on reasonable data protection grounds. If you object and we're unable to resolve the concern, either party may terminate the affected part of the Service. We remain responsible for our sub-processors' compliance with data protection obligations equivalent to those in this DPA.

  1. International data transfers

Where personal data is transferred outside the European Economic Area by us or our sub-processors, we ensure this happens under a valid legal transfer mechanism, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses, as detailed in our Privacy Policy and Subprocessors page.

Where personal data is transferred outside the European Economic Area by us or our sub-processors, we ensure this happens under a valid legal transfer mechanism, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses, as detailed in our Privacy Policy and Subprocessors page.

  1. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any case within 72 hours of becoming aware of it, with the information reasonably available to us at that time to help you meet your own notification obligations.

  1. Audits and compliance

On reasonable request, we will make available the information necessary to demonstrate compliance with this DPA, including relevant security documentation. Given the nature and scale of our service, we provide this through documentation and completed security questionnaires rather than on-site audits; formal audit rights may be made available under a separate agreement for Enterprise customers.

  1. Deletion or return of data

Upon termination of your subscription, we will delete personal data processed on your behalf within a reasonable period, except where we are required by law to retain it for longer, consistent with the retention terms described in our Privacy Policy.

Upon termination of your subscription, we will delete personal data processed on your behalf within a reasonable period, except where we are required by law to retain it for longer, consistent with the retention terms described in our Privacy Policy.

  1. Liability

Each party’s liability under this DPA is subject to the limitation of liability set out in our Terms of Service.

Each party's liability under this DPA is subject to the limitation of liability set out in our Terms of Service.

  1. Governing law

This DPA is governed by the laws of the Czech Republic, consistent with our Terms of Service.

This DPA is governed by the laws of the Czech Republic, consistent with our Terms of Service.