# Data Processing Agreement

> How InfraNest processes personal data on behalf of its customers, under GDPR Article 28.

Source: https://infranest.io/dpa

---

_Last updated: 21 July 2026._

This Data Processing Agreement ("**DPA**") forms part of the InfraNest Terms of Service between you ("**Customer**", the **controller**) and **Jaspar Steenman**, Hansaring 79, 50670 Köln, Germany, operating InfraNest ("**InfraNest**", "**we**", the **processor**). It applies whenever we process personal data on your behalf under the GDPR, and takes effect when you accept our Terms.

**In plain terms:** when you use InfraNest to manage domains, DNS, servers, monitoring and the rest — for yourself or for your clients — some of what you put in is personal data that belongs to you (or your clients). This DPA sets out how we handle that data strictly on your instructions, keep it secure, and help you meet your own GDPR obligations. If you need a signed copy, email **privacy@infranest.io**.

## 1. Roles

For the personal data you put into InfraNest, **you are the controller** and **we are the processor** (and, where you act for your own clients, a sub-processor). We process that data only to provide the service to you. For the data we handle as a controller in our own right — your account and billing, and public status-page subscriptions — see our [Privacy Policy](/privacy).

## 2. Our instructions

We process personal data only on your documented instructions. Those instructions are: (a) using the service as described in the Terms and our documentation, and (b) the settings and requests you make in the product or via the API. If we believe an instruction breaks data-protection law, we'll tell you. We never use your data for our own purposes, and we don't sell it.

## 3. What we process

The categories of data subjects and personal data are set out in **Annex 1**. You decide what personal data you put into InfraNest.

## 4. Confidentiality

Everyone we allow to process your data is bound to keep it confidential.

## 5. Security

We maintain appropriate technical and organisational measures to protect your data, described in **Annex 2**, in line with GDPR Article 32.

## 6. Sub-processors

You give us general authorisation to use the sub-processors listed in **Annex 3** to help provide the service. Each is bound by data-protection terms that meet the requirements of Article 28 GDPR, and we remain responsible for what they do.

Registrars, DNS hosts, cloud providers, and chat channels (such as Slack, Teams, Discord, PagerDuty, or a Telegram bot of your own) that **you** connect using your own credentials are **your** processors, not ours — you decide what they receive, under your own agreement with them. The same is true of a calendar feed you add to Google, Apple or Outlook Calendar.

Two alert channels are **ours**, not yours, because we operate the connection rather than you: **email**, which we send through Cloudflare Email Service, and the **shared Telegram bot**, which runs on our bot token instead of one you supply. Both appear in Annex 3.

We keep Annex 3 current. Before we add or replace one of the sub-processors listed there, we'll update the list and give at least **30 days' notice** — you can **subscribe to be notified** of changes. Where a change has to be made urgently, to keep the service secure or running, we'll tell you as soon as we reasonably can instead. The sub-processors in Annex 3 may engage their own sub-processors under their agreements with us; we stay responsible to you for what they do. If you have a reasonable, data-protection-based objection, tell us within that window and we'll work with you on a solution; if we can't find one, you may stop using the affected part of the service and terminate.

## 7. Helping you meet your obligations

Taking into account the nature of the processing, we'll help you as far as we reasonably can to:

- respond to individuals exercising their rights (access, correction, deletion, and so on) — the product's own tools let you handle most of this yourself;
- keep the data secure, handle personal-data breaches, and carry out data-protection impact assessments and any required prior consultation.

## 8. Personal data breaches

If we become aware of a breach affecting your data, we'll notify you **without undue delay** — and aim to within **72 hours** — with the information you need to meet your own notification duties.

## 9. International transfers

Most of your data stays in the EU/EEA. Some sub-processors process data outside the EU (see Annex 3 — including our **worldwide monitoring probes** and providers such as Stripe, Sentry, Cloudflare, Intercom, Gravatar and Telegram). Where they do, the transfer is covered by an appropriate safeguard such as the EU **Standard Contractual Clauses**.

## 10. Audits

On request, we'll give you the information you reasonably need to show we meet this DPA — including this document, our security measures (Annex 2), and the certifications our infrastructure providers hold. Where that isn't enough, we'll allow an audit on reasonable prior notice, during business hours, without disrupting the service and subject to confidentiality.

## 11. Returning and deleting data

When your account ends, we'll delete or return your personal data **within 30 days**, except anything we must keep by law (for example, invoice records). Backups are deleted on their normal rotation.

## 12. Liability and term

Our liability under this DPA is subject to the limits in the Terms. This DPA lasts for as long as we process personal data on your behalf.

## 13. Governing law

This DPA is governed by the laws of **Germany**, and the German courts have jurisdiction — without affecting any mandatory rights you have where you live.

## Annex 1 — What we process

**Subject matter & duration:** providing the InfraNest service to you, for as long as your account is active.

**Nature & purpose:** hosting, storing and processing the data you put into InfraNest so we can manage your domains, DNS, servers, certificates, monitoring, dynamic IP, drop-catching, automations, status pages and the related notifications — on your instructions.

**Categories of data subjects:**

- your **team members** and other app users you invite;
- **domain contacts** you store — registrant, admin and technical contacts, and your domain address book;
- **recipients of your notifications** — alert, monitoring and automation recipients you configure;
- any other individuals whose personal data you choose to add.

_(Public status-page subscribers are **not** in scope here — they self-subscribe to your status page, so we are the controller for that data; see our Privacy Policy.)_

**Categories of personal data:**

- names, email addresses, phone numbers and postal addresses;
- organisation and registration details (e.g. VAT and Chamber-of-Commerce numbers);
- notification identifiers (webhook URLs, and chat IDs such as Slack, Telegram or Discord);
- IP addresses and technical/usage logs;
- any other personal data contained in the resources you manage.

We don't intentionally process special-category data — please don't put it into free-text fields.

## Annex 2 — Technical & organisational measures

- **Encryption in transit** — all traffic over HTTPS/TLS.
- **Encryption at rest** — provider credentials, API tokens and other secrets are stored encrypted; access is strictly limited to the systems that need them to carry out your requests.
- **Access control** — least-privilege access, with **two-factor authentication** available on accounts.
- **Tenant isolation** — customers' data is logically separated.
- **Audit logging** — actions are logged so changes stay traceable.
- **Backups** — regular backups with defined retention.
- **Certified infrastructure** — we host with providers that maintain recognised certifications (for example, Hetzner and our other providers hold certifications such as ISO 27001; Stripe is PCI-DSS Level 1).
- **Breach response** — a process to detect, assess and notify personal-data breaches.

## Annex 3 — Sub-processors

| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner | Hosting: app, back-office, database and marketing infrastructure | Germany, EU |
| Cloudflare | Marketing-site hosting, CDN, security and bot protection (Turnstile); transactional email | EU / global |
| OVH | Servers that run our monitoring probes | Worldwide |
| Backblaze B2 | Off-site storage of our database backups | EU region; US company |
| Sentry | Error tracking and diagnostics | EU / US |
| Stripe | Payment processing | EU / US |
| Telegram | Delivering your alert notifications to the Telegram chats you configure | Outside EU |
| Gravatar / Automattic | Avatar images, fetched by a hash of a user's email, when avatars are enabled | US |
| Intercom | Support chat on our website and contact-form messages | US |

Analytics is handled by **Umami, self-hosted on our own infrastructure** — no third-party analytics processor is involved.

## Contact

Data-protection questions or a signed copy of this DPA: **privacy@infranest.io** · Jaspar Steenman, Hansaring 79, 50670 Köln, Germany.
