Data Processing Addendum
Effective: 2026-07-30
Scope and Roles
The customer is the controller, or a processor acting for another controller, and Esteve Castells trading as DomScan is the processor or subprocessor. For account, billing, support, security and DomScan’s own operational data, DomScan acts as controller under the Privacy Policy.
Instructions and Purpose
DomScan processes customer personal data only to provide, secure and support the features the customer uses, or as required by applicable law. The Terms, this DPA and the customer’s configuration and requests are the documented instructions. The customer confirms it has a lawful basis and all necessary rights to provide the data.
Processing Details
- Subject matter: domain-intelligence services and related support.
- Duration: while the service is used, plus the retention and deletion periods described below.
- Data subjects: account and team users, webhook recipients, and people whose data appears in customer inputs or public domain-intelligence sources.
- Data: account and team details, domains and query parameters, API and batch inputs and results, webhook configuration, request and security metadata, and support communications.
- Special-category data is not intended. Customers must not submit it unless expressly agreed in writing.
Confidentiality and Security
People authorized to process customer personal data must be subject to confidentiality obligations. DomScan maintains measures appropriate to the service, including access controls, privacy-safe logging, short retention for batch data, separation of application components, monitoring and off-site backups.
Subprocessors
The customer gives general authorization for the providers on the Subprocessors page. DomScan remains responsible for their processing to the extent required by data protection law and requires appropriate data-protection obligations. Subprocessors.
DomScan will publish changes to the list and provide advance notice where required. A customer may object on reasonable data-protection grounds by contacting us.
Assistance and Incidents
Taking account of the nature of processing, DomScan will reasonably assist with data-subject requests, security obligations and data-protection impact assessments. DomScan will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data and will provide available details in stages if necessary.
International Transfers
Where customer personal data is processed outside the European Economic Area, DomScan will use a transfer mechanism required by applicable law, such as an adequacy decision or the European Commission Standard Contractual Clauses.
Return, Deletion and Retention
Customers can request an export or deletion by email. Privacy-safe API logs are retained for 30 days. Batch inputs, results and webhook configuration are retained for 24 hours. Other customer personal data will be returned or deleted when processing ends, subject to legal duties, security records and backup copies that remain protected until their normal overwrite or deletion.
Information and Audits
DomScan will provide information reasonably necessary to demonstrate compliance with applicable processor obligations. Audits must be proportionate, protect other customers, preserve confidentiality and avoid unnecessary disruption. The parties should first use available documentation and written answers where appropriate.
Precedence and Contact
For processing subject matter, this DPA prevails over conflicting general terms. Any separate signed DPA prevails to the extent it expressly differs.