Data Processing Addendum

Effective: 2026-07-30

This Data Processing Addendum forms part of the Terms of Service when DomScan processes personal data on a customer’s behalf.

Scope and Roles

The customer is the controller, or a processor acting for another controller, and Esteve Castells trading as DomScan is the processor or subprocessor. For account, billing, support, security and DomScan’s own operational data, DomScan acts as controller under the Privacy Policy.

Instructions and Purpose

DomScan processes customer personal data only to provide, secure and support the features the customer uses, or as required by applicable law. The Terms, this DPA and the customer’s configuration and requests are the documented instructions. The customer confirms it has a lawful basis and all necessary rights to provide the data.

Processing Details

Confidentiality and Security

People authorized to process customer personal data must be subject to confidentiality obligations. DomScan maintains measures appropriate to the service, including access controls, privacy-safe logging, short retention for batch data, separation of application components, monitoring and off-site backups.

Subprocessors

The customer gives general authorization for the providers on the Subprocessors page. DomScan remains responsible for their processing to the extent required by data protection law and requires appropriate data-protection obligations. Subprocessors.

DomScan will publish changes to the list and provide advance notice where required. A customer may object on reasonable data-protection grounds by contacting us.

Assistance and Incidents

Taking account of the nature of processing, DomScan will reasonably assist with data-subject requests, security obligations and data-protection impact assessments. DomScan will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data and will provide available details in stages if necessary.

International Transfers

Where customer personal data is processed outside the European Economic Area, DomScan will use a transfer mechanism required by applicable law, such as an adequacy decision or the European Commission Standard Contractual Clauses.

Return, Deletion and Retention

Customers can request an export or deletion by email. Privacy-safe API logs are retained for 30 days. Batch inputs, results and webhook configuration are retained for 24 hours. Other customer personal data will be returned or deleted when processing ends, subject to legal duties, security records and backup copies that remain protected until their normal overwrite or deletion.

Information and Audits

DomScan will provide information reasonably necessary to demonstrate compliance with applicable processor obligations. Audits must be proportionate, protect other customers, preserve confidentiality and avoid unnecessary disruption. The parties should first use available documentation and written answers where appropriate.

Precedence and Contact

For processing subject matter, this DPA prevails over conflicting general terms. Any separate signed DPA prevails to the extent it expressly differs.

[email protected]