Data processing agreement

Last updated: 6 September 2026

This service is operated by Kilo Spark LLC, a limited liability company based in the United States.

This service is operated from the United States.

This agreement forms part of the Terms of Service and takes effect when you accept them. There is nothing to sign. If your team needs a countersigned copy, write to hello@dnsmint.com and we will send one.

1. Scope and roles

This agreement applies where your use of the Service involves personal data protected by the EU General Data Protection Regulation, the UK GDPR, or the Swiss Federal Act on Data Protection.

You are the controller of that data and Kilo Spark LLC is the processor. Where you are yourself a processor acting for your own customers, we are a sub-processor and the same obligations apply to us.

Customer Personal Data means personal data you submit to the Service to register and operate hostnames. It does not mean your own account, billing, and contact details. We decide how to handle those, so we are the controller of them and the Privacy Policy governs them rather than this agreement.

2. What we process

Categories of data

  • The subdomain and the domain it lives on
  • The IP addresses you attach to it, including their update history
  • Record types and TXT record contents you publish, for example DNS-01 challenge records
  • Timestamps for creation, renewal, and expiry
  • The API key that performed each action
  • For a hostname where you ask us to manage the certificate, the certificate and its private key, encrypted at rest

Categories of data subject

Your personnel, and your own end users where an IP address or a label you choose identifies one.

Purpose and duration

To register hostnames, answer DNS queries for them, and run the account they belong to, for as long as you hold the hostname and then as set out in section 10.

3. What we do not process

These are properties of how the Service is built rather than promises about how we behave, which is why they are worth stating in a contract.

  • We answer DNS and nothing else. Connections go directly from clients to your server, so we never see your application traffic and, unless you ask us to manage a certificate, never hold a TLS private key.
  • Our nameservers keep no query log. They count requests and bytes per zone and record when a zone was last queried. No source address and no queried name is written down, so there is nothing to hand over, subpoena, or leak.
  • We do not use Customer Personal Data to train models.
  • We do not sell it or use it for advertising.

4. What is public by design

A hostname you register is an answer to a public DNS query, and anyone who asks can learn the IP address behind it. Certificates issued against it are recorded in public certificate transparency logs, which include the hostname.

So do not put personal data into a subdomain label you choose. We cannot make a published record private, and no term in this agreement changes what a public DNS answer is. Random labels are the default for this reason.

5. Our instructions

We process Customer Personal Data only on your documented instructions. Your instructions are the Terms of Service, this agreement, and the requests you make through the API and the dashboard.

If the law requires us to process it otherwise, we will tell you before we do unless that law forbids us from telling you. If we think an instruction breaks data protection law, we will say so.

6. Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, and access is limited to those who need it to run the Service.

7. Security

The measures we take, stated specifically rather than as a claim to be secure:

  • All API and dashboard traffic is encrypted in transit over HTTPS.
  • An API key secret is shown once and never stored. We keep a SHA-256 hash of it, so a copy of our database does not yield a working key.
  • Session tokens are stored hashed, on the same reasoning.
  • Credentials for the services we depend on are encrypted at rest, and a private key we hold for a managed certificate is encrypted under a key scoped to that order.
  • The nameservers answer from memory and never reach the database on the query path, so a query cannot read anything the database holds.
  • The write path is rate limited, per account and per key.
  • Error reports are stripped of stack traces in production before they leave our systems.

We do not hold SOC 2 or ISO 27001 certification. We would rather tell you that than let a procurement form assume otherwise.

8. Sub-processors

You authorise the sub-processors below. Each is bound to terms no less protective than these and may use the data only to provide their service to us.

Vercel for hosting for the website, dashboard, and API. Requests to the Service, including IP address and user agent.

MongoDB Atlas for the database behind the Service. Account information and registration data.

Hetzner for the servers running our authoritative nameservers. The DNS queries we answer and the metadata described above.

Vultr for servers running our authoritative nameservers. The DNS queries we answer and the metadata described above.

Redis Cloud for short-lived caching and rate-limit counters. Configuration values and per-key request counts.

Polar for payment processing, as Merchant of Record. Your email address and payment information.

Resend for sending account email. Your email address and the contents of those messages.

Better Stack for error tracking and uptime monitoring. The error reports described above, held in the European Union or the United States.

Google Analytics for website analytics, only if you accept it. Pages you view on our website, your IP address, and your browser and device type.

Before a new sub-processor begins processing Customer Personal Data we will update this page and email the address on your account. You have 30 days to object on reasonable data protection grounds. If we cannot resolve your objection, you may cancel the affected part of the Service without penalty for the remainder of your term.

9. International transfers

We operate from the United States and most Customer Personal Data is processed there. Error reports are processed in the European Union or the United States.

For transfers out of the European Economic Area, the United Kingdom, or Switzerland, the European Commission Standard Contractual Clauses are incorporated into this agreement: Module Two where you are a controller, and Module Three where you are yourself a processor. The UK International Data Transfer Addendum applies to transfers from the United Kingdom. Where a term of those clauses conflicts with a term of this agreement, the clauses prevail.

10. Assistance

Requests from data subjects

You can read, change, and delete Customer Personal Data yourself through the dashboard and the API, which answers most requests without us. If a request reaches us directly we will not answer it on your behalf; we will pass it to you and help you respond.

Assessments

We will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a regulator.

Personal data breach

If we become aware of a breach affecting Customer Personal Data we will tell you without undue delay, with what we know at the time: what happened, which data it touched, what we are doing about it, and where to reach us. We will keep telling you as we learn more rather than waiting until the picture is complete.

11. Deletion and return

You can release a hostname at any time through the dashboard or the API, which removes its records from the nameservers. Deleting your account erases what identifies you and revokes the credentials issued to you.

Two things do not go, and you should know about them before you rely on this clause. A record that the subdomain once existed remains, with nothing linking it to you. It is what stops a released name being handed to someone else and quietly inheriting whatever reputation or certificate history the old holder left behind. It holds no personal data once your account is erased.

The second one does. For anti-abuse and accountability purposes we retain a record of what was done on an account, including who did it, so that deleting an account is not a way to erase what was done with it. We keep it for as long as those purposes require and no longer, and your data export covers those records.

Backups age out on their own schedule rather than being edited, so a copy may persist there for a short period after deletion.

12. Audits and information

We will give you the information reasonably necessary to show that we meet Article 28. If that is not enough, you may audit us once a year on reasonable notice, at your expense, under confidentiality, and without disrupting the Service. A regulator may audit us as the law allows.

13. Changes

We may update this agreement. If a change materially reduces your rights or our obligations we will post it here with a new date and email the address on your account before it takes effect.

14. Contact

For anything in this agreement, including a countersigned copy or a question about a sub-processor, write to hello@dnsmint.com.