InfraNestInfraNest

Data Processing Agreement

How InfraNest processes personal data on behalf of its customers, under GDPR Article 28.

Data Processing Agreement (DPA)

Last updated: 21 July 2026.

This Data Processing Agreement ("DPA") forms part of the InfraNest Terms of Service between you ("Customer", the controller) and Jaspar Steenman, Hansaring 79, 50670 Köln, Germany, operating InfraNest ("InfraNest", "we", the processor). It applies whenever we process personal data on your behalf under the GDPR, and takes effect when you accept our Terms.

In plain terms: when you use InfraNest to manage domains, DNS, servers, monitoring and the rest — for yourself or for your clients — some of what you put in is personal data that belongs to you (or your clients). This DPA sets out how we handle that data strictly on your instructions, keep it secure, and help you meet your own GDPR obligations. If you need a signed copy, email [email protected].

1. Roles

For the personal data you put into InfraNest, you are the controller and we are the processor (and, where you act for your own clients, a sub-processor). We process that data only to provide the service to you. For the data we handle as a controller in our own right — your account and billing, and public status-page subscriptions — see our Privacy Policy.

2. Our instructions

We process personal data only on your documented instructions. Those instructions are: (a) using the service as described in the Terms and our documentation, and (b) the settings and requests you make in the product or via the API. If we believe an instruction breaks data-protection law, we'll tell you. We never use your data for our own purposes, and we don't sell it.

3. What we process

The categories of data subjects and personal data are set out in Annex 1. You decide what personal data you put into InfraNest.

4. Confidentiality

Everyone we allow to process your data is bound to keep it confidential.

5. Security

We maintain appropriate technical and organisational measures to protect your data, described in Annex 2, in line with GDPR Article 32.

6. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex 3 to help provide the service. Each is bound by data-protection terms at least as protective as this DPA, and we remain responsible for what they do.

Registrars, DNS hosts, cloud providers, and chat channels (such as Slack and Discord) that you connect using your own credentials are your processors, not ours — you decide what they receive, under your own agreement with them.

We keep Annex 3 current. Before we add or replace a sub-processor, we'll update the list and give at least 30 days' notice — you can subscribe to be notified of changes. If you have a reasonable, data-protection-based objection, tell us within that window and we'll work with you on a solution; if we can't find one, you may stop using the affected part of the service and terminate.

7. Helping you meet your obligations

Taking into account the nature of the processing, we'll help you as far as we reasonably can to:

  • respond to individuals exercising their rights (access, correction, deletion, and so on) — the product's own tools let you handle most of this yourself;
  • keep the data secure, handle personal-data breaches, and carry out data-protection impact assessments and any required prior consultation.

8. Personal data breaches

If we become aware of a breach affecting your data, we'll notify you without undue delay — and aim to within 72 hours — with the information you need to meet your own notification duties.

9. International transfers

Most of your data stays in the EU/EEA. Some sub-processors process data outside the EU (see Annex 3 — including our worldwide monitoring probes and providers such as Stripe, Sentry, Amazon SES, Gravatar and Telegram). Where they do, the transfer is covered by an appropriate safeguard such as the EU Standard Contractual Clauses.

10. Audits

On request, we'll give you the information you reasonably need to show we meet this DPA — including this document, our security measures (Annex 2), and the certifications our infrastructure providers hold. Where that isn't enough, we'll allow an audit on reasonable prior notice, during business hours, without disrupting the service and subject to confidentiality.

11. Returning and deleting data

When your account ends, we'll delete or return your personal data within 30 days, except anything we must keep by law (for example, invoice records). Backups are deleted on their normal rotation.

12. Liability and term

Our liability under this DPA is subject to the limits in the Terms. This DPA lasts for as long as we process personal data on your behalf.

13. Governing law

This DPA is governed by the laws of Germany, and the German courts have jurisdiction — without affecting any mandatory rights you have where you live.

Annex 1 — What we process

Subject matter & duration: providing the InfraNest service to you, for as long as your account is active.

Nature & purpose: hosting, storing and processing the data you put into InfraNest so we can manage your domains, DNS, servers, certificates, monitoring, dynamic IP, drop-catching, automations, status pages and the related notifications — on your instructions.

Categories of data subjects:

  • your team members and other app users you invite;
  • domain contacts you store — registrant, admin and technical contacts, and your domain address book;
  • recipients of your notifications — alert, monitoring and automation recipients you configure;
  • any other individuals whose personal data you choose to add.

(Public status-page subscribers are not in scope here — they self-subscribe to your status page, so we are the controller for that data; see our Privacy Policy.)

Categories of personal data:

  • names, email addresses, phone numbers and postal addresses;
  • organisation and registration details (e.g. VAT and Chamber-of-Commerce numbers);
  • notification identifiers (webhook URLs, and chat IDs such as Slack, Telegram or Discord);
  • IP addresses and technical/usage logs;
  • any other personal data contained in the resources you manage.

We don't intentionally process special-category data — please don't put it into free-text fields.

Annex 2 — Technical & organisational measures

  • Encryption in transit — all traffic over HTTPS/TLS.
  • Encryption at rest — provider credentials, API tokens and other secrets are stored encrypted; access is strictly limited to the systems that need them to carry out your requests.
  • Access control — least-privilege access, with two-factor authentication available on accounts.
  • Tenant isolation — customers' data is logically separated.
  • Audit logging — actions are logged so changes stay traceable.
  • Backups — regular backups with defined retention.
  • Certified infrastructure — we host with providers that maintain recognised certifications (for example, Hetzner and our other providers hold certifications such as ISO 27001; Stripe is PCI-DSS Level 1).
  • Breach response — a process to detect, assess and notify personal-data breaches.

Annex 3 — Sub-processors

  • Hetzner (Germany, EU) — hosting: app, back-office, database and marketing infrastructure.
  • Cloudflare (EU / global) — marketing-site hosting, CDN, security and bot protection (Turnstile).
  • OVH (worldwide) — servers that run our monitoring probes.
  • Sentry (EU / US) — error tracking and diagnostics.
  • Stripe (EU / US) — payment processing.
  • Amazon SES (EU / US) — transactional email delivery.
  • Telegram (outside EU) — delivering your alert notifications to the Telegram chats you configure.
  • Gravatar / Automattic (US) — avatar images, fetched by a hash of a user's email, when avatars are enabled.

Analytics is handled by Umami, self-hosted on our own infrastructure — no third-party analytics processor is involved.

Contact

Data-protection questions or a signed copy of this DPA: [email protected] · Jaspar Steenman, Hansaring 79, 50670 Köln, Germany.