Data processing agreement

Last updated .

For customers who need a DPA under Article 28 GDPR. This page is the agreement; it applies automatically to every account, so there is nothing to sign unless your organisation requires a countersigned copy, in which case write to privacy@home.network.

Roles

You are the controller. We are the processor for the personal data you place in the service, principally the email address on the account and any personal data you choose to encode in a hostname.

Subject matter and duration

Provision of authoritative DNS and ACME challenge publication, for as long as your account exists.

Instructions

We process only on your documented instructions, which for this service means the operations you perform through the dashboard and API, plus what is necessary to run and secure the service.

Confidentiality and security

Access is limited to the operator. Credentials are stored hashed. Backups are encrypted, including a copy encrypted with a key held offline. Database access is least-privilege, and zone-signing keys are unreachable from the web application by design.

Sub-processors

Listed in the privacy policy and kept current there. We give notice before adding one, with the notice period on our commitments page.

Assistance, breach notification, deletion

We assist with data-subject requests and provide self-service export and deletion. We notify you without undue delay after becoming aware of a personal data breach affecting your data. On termination, data is deleted per the retention schedule in the privacy policy.

Transfers

Customer data at rest stays in EU datacentres. Where a non-EU-headquartered processor is involved, being the three named in the privacy policy, processing is in an EU region and covered by standard contractual clauses.