Privacy Policy

Last updated: 19 July 2026

Template — review before launch. This policy is a starting point drafted from how DNSconfig actually works. It is not legal advice. Fill in every [BRACKETED] value and have it reviewed by qualified counsel before you rely on it. German/EU operators typically also need a separate Impressum.

1. Who we are (Controller)

The controller responsible for the processing of personal data described here is:

[COMPANY LEGAL NAME]
[STREET ADDRESS]
[POSTAL CODE, CITY, COUNTRY]
Email: privacy@dns-config.net
Data protection contact: [DPO / CONTACT NAME & EMAIL, if applicable]

2. Scope

This policy covers the DNSconfig website (dns-config.net), the DNSconfig console, and the DNSconfig verification service (together, the “Service”). Where our business customers (“tenants”) use DNSconfig to monitor their own customers’ domains, the tenant is the controller for that end-customer data and we act as their processor under a data processing agreement.

3. What we collect and why

DataPurposeLegal basis (GDPR Art. 6)
Account email address (magic-link sign-in / sign-up) Authenticate you and operate your account Performance of a contract, Art. 6(1)(b)
DNS records you configure & verification results Provide the verification and monitoring service Performance of a contract, Art. 6(1)(b)
Server & security logs (IP address, request metadata, timestamps) Operate, secure, and debug the Service; prevent abuse Legitimate interests, Art. 6(1)(f)
Email delivery data (recipient address, delivery status) Send sign-in links and drift alerts Performance of a contract / legitimate interests
Analytics & usage data (via Google Analytics — see §5) Understand and improve the website Consent, Art. 6(1)(a)

4. Cookies

We keep cookies to a minimum:

5. Analytics — Google Analytics 4

With your consent we use Google Analytics 4 (provided by Google Ireland Limited) to measure website usage. We enable IP anonymization and load Google’s tag only after consent (Google Consent Mode). Analytics data may be transferred to Google servers, including outside the EU/EEA; such transfers rely on the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses. See Google’s privacy policy. Configure retention in your GA4 property under Data Settings → Data Retention.

6. Hosting & sub-processors

The Service runs on infrastructure located in the EU (Google Cloud, region europe-west1). We rely on the following processors:

Keep this list current; add any further sub-processors you introduce.

7. How long we keep data

Account and service data are retained for as long as your account is active and then deleted or anonymized within [RETENTION PERIOD, e.g. 90 days] of account closure, unless we must keep it longer to meet legal obligations. Server logs are retained for [LOG RETENTION, e.g. 30 days]. Analytics retention follows your GA4 configuration.

8. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. To exercise these rights, contact privacy@dns-config.net. You also have the right to lodge a complaint with a supervisory authority ([YOUR COMPETENT AUTHORITY, e.g. your state Datenschutzbehörde]).

9. International transfers

Where data is transferred outside the EU/EEA (e.g. certain analytics processing), we rely on adequacy decisions, the EU–U.S. Data Privacy Framework, or Standard Contractual Clauses with appropriate safeguards.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to account holders.

11. Contact

Questions about this policy or your data: privacy@dns-config.net.

← Back to home