Data processing agreement
For business customers who need one on file. It applies automatically to every paid account — you do not have to sign anything to rely on it.
Last updated 2026-08-01
This page is incomplete.
Missing operator details: legal entity name, registered address and Chamber of Commerce number. Set the matching
LEGAL_* environment variables before going live.
Parties and roles
You are the controller of the personal data processed through your account. We are the processor, acting only on your documented instructions — which, in practice, are the settings you choose in the product and the terms you accepted.
What we process on your behalf
| Category | Data | Purpose |
|---|---|---|
| Account contacts | Name, email address | Signing in, and telling you when a record changed |
| Domain data | Domains, their SPF records, published records, change history | Providing the service |
| Billing | Company name, address, VAT number, invoices | Charging you and meeting tax law |
DNS records themselves are public information about a domain rather than personal data. We do not process message content, recipient lists, or anything else about the mail you send: we do not see your mail.
Sub-processors
The current list is on the privacy page and forms part of this agreement. We tell you at least 30 days before adding one, so you have time to object. If you do object on reasonable grounds, you may terminate without penalty for the remainder of the paid period.
Security
The measures we take are described on the security page: access to production is restricted and individually attributable, data is encrypted in transit, and there are no passwords in the product to be leaked or reused. We notify you without undue delay, and within 48 hours of becoming aware, of any breach affecting your data.
International transfers
Some sub-processors are based in the United States. Transfers to them rely on the EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
Your rights as controller
- You may audit our compliance once a year, on 30 days' notice, at your cost.
- We assist you with data subject requests, and forward any we receive directly.
- We delete or return your data within 30 days of the account closing, except invoices, which tax law requires us to keep for seven years.
Signed copy
If your procurement process needs a countersigned PDF, write to privacy@flat-spf.com and we will send one.