Legal

Data Processing Agreement

Last updated: 5 April 2026  ·  Effective immediately upon account creation

This Data Processing Agreement ("DPA") forms part of the Terms of Service between DomainGuard ("Processor") and the customer ("Controller") and is required under Article 28 of the UK GDPR.

1. Definitions

"Controller" means the customer organisation that determines the purposes and means of processing personal data.

"Processor" means DomainGuard, which processes personal data on behalf of the Controller.

"Personal Data" means any information relating to an identified or identifiable natural person processed under this agreement.

"Processing" has the meaning given in UK GDPR Article 4(2).

"UK GDPR" means the UK General Data Protection Regulation as retained in UK law.

2. Subject Matter and Duration

DomainGuard processes personal data on behalf of the Controller for the purpose of providing the DomainGuard browser extension and admin console service ("the Service"). Processing continues for the duration of the subscription and ceases upon termination.

3. Nature and Purpose of Processing

DomainGuard processes personal data solely to provide the Service, which includes:

4. Categories of Personal Data

CategoryExamplesPurpose
Admin identityEmail address, password hashConsole authentication
Audit eventsBrowser activity timestamps, matched policy rulesCompliance logging
Device identifiersMachine ID generated by extensionPolicy sync tracking
Authentication tokensAPI tokens (hashed), JWT tokensService access control

5. Data Subject Categories

6. Processor Obligations

DomainGuard shall:

7. Sub-processors

DomainGuard currently uses the following sub-processors:

Sub-processorPurposeLocation
Railway (PaaS)API and console hostingUnited States
PostgreSQL via RailwayDatabase storageUnited States
ResendTransactional email deliveryUnited States
StripePayment processingUnited States
CloudflareDNS, CDN and DDoS protectionUnited States

DomainGuard will notify the Controller of any intended changes to sub-processors with at least 14 days notice.

8. International Transfers

Where personal data is transferred outside the UK, DomainGuard ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms as approved by the UK ICO.

9. Security Measures

DomainGuard implements the following technical and organisational measures:

10. Data Retention

11. Data Subject Rights

DomainGuard will assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability) within the timescales required by UK GDPR. Requests should be directed to privacy@domainguard.co.

12. Data Breach Notification

DomainGuard will notify the Controller without undue delay and within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons.

13. Termination

Upon termination of the Service, DomainGuard will, at the Controller's choice, delete or return all personal data and delete existing copies unless storage is required by applicable law.

14. Contact

For data protection enquiries, contact: privacy@domainguard.co

For security concerns: security@domainguard.co