Data processing agreement
Last updated: 4 October 2026
This agreement is part of our terms of service, and meets the requirements of Article 28 of the General Data Protection Regulation (GDPR). It applies whenever Sireto BV (Zwolle, The Netherlands, KvK 73807508), "we" below, processes personal data on your behalf while providing the hosted Custom Domain API. Where it differs from the terms on personal data, this agreement applies.
1. Roles
For the personal data described in section 3, you are the controller and we are your processor. For the data about your account itself, such as your users' email addresses and billing details, we are the controller: see our privacy statement.
2. What we do with it, and for how long
We process personal data only to provide the service: to check your customers' hostnames, obtain certificates for them, forward their traffic to your origin, send the webhooks you configure, and keep the records the service needs. We do this for as long as the terms apply, and then until the data is deleted as described in section 8.
3. The personal data and the people it concerns
- Whom it concerns: your customers, and the people who visit or use your customers' hostnames.
- Traffic: visitors' requests and your origin's responses pass through your edge. That includes IP addresses, request headers and content. The edge doesn't store their content and keeps no access log of them. It counts requests and response bytes per hostname.
- Records the service keeps: your customers' hostnames, the workspace references and metadata you send with them, the results of DNS and certificate checks, your origin's address, and your webhooks' addresses. API access logs record each call's client IP address and the API key used.
- We don't intend to process special categories of personal data. Don't put such data in hostnames, references or metadata.
4. Your instructions
We process the data only on your documented instructions: these terms, and what you configure through the portal and the API. If the law requires us to process it otherwise, we tell you first, unless the law forbids that. If we believe an instruction breaks data protection law, we tell you.
5. Confidentiality and security
Only the people who operate the service have access to the data. They are bound to confidentiality. We protect the data with the measures in the annex, and keep them appropriate to the risk.
6. Subprocessors
You authorise us to use these subprocessors for the data in section 3:
- Hetzner Online GmbH (Germany) runs the servers for edges and for our control plane. Your edge runs in the location you choose: Falkenstein (Germany), Helsinki (Finland) or Ashburn (Virginia, USA). The shared Free edge runs in the European Union.
- Let's Encrypt (Internet Security Research Group, USA) issues the certificates. It receives your customers' hostnames. Every publicly trusted certificate, including these, is recorded in public Certificate Transparency logs, so the hostnames become public.
We tell you by email at least 30 days before we add or replace a subprocessor. If you object on reasonable data protection grounds and we can't resolve it, you can end the affected plan before the change, with a refund of any prepaid fees for the time after it. We impose data protection obligations on each subprocessor that are equivalent to these, and remain responsible for them.
7. Transfers outside the European Economic Area
Your data stays in the European Economic Area, unless you choose the Ashburn location or the data reaches Let's Encrypt. Such transfers are covered by the European Commission's Standard Contractual Clauses, or by another safeguard the GDPR recognises.
8. Deletion at the end
- When a paid plan ends, its edge keeps running for 14 days so you can download a backup of its data. After that, or earlier if you choose "Delete now", we delete the edge's server, with all the data on it.
- Any backups of an edge that we keep are deleted within 30 days after the edge.
- On the shared Free edge, a deleted hostname's records are kept for 90 days for auditing, then deleted. The same applies when your Free application is deleted.
9. Helping you
- Requests from data subjects: most can be handled through the portal and the API, for example deleting a hostname. For the rest, we help you within reason when you ask at info@sireto.com.
- Personal data breaches: we tell you without undue delay, and within 48 hours of becoming aware of a breach affecting your data. We tell you what we know and what we're doing, and help you meet your own obligations.
- Other obligations: we give you the information you reasonably need for a data protection impact assessment, or for consulting a supervisory authority.
10. Showing that we comply
On request, we give you the information you need to show that we meet this agreement. If that isn't enough, you may audit us, or have an independent auditor bound to confidentiality do so: once a year, with at least 30 days' notice, at your cost, and without disrupting the service or other customers' data.
11. Liability
The limits of liability in the terms of service apply to this agreement, except where the GDPR doesn't allow them.
Annex: security measures
- Encryption in transit: every hostname is served over HTTPS with its own certificate. Traffic to your origin uses HTTPS with certificate verification whenever your origin is HTTPS. Our own APIs and portal are HTTPS only.
- Isolation: each application's hostnames, keys, origins and webhooks are kept apart. Anything belonging to another application is treated as not found. Every request forwarded to your origin carries a signed statement of which application and customer it is for.
- Secrets: API keys are stored only as hashes, and are shown once when created. The tokens we use to manage your edge are encrypted, and are rotated when an edge is set up. Webhook deliveries are signed.
- Access: servers accept administrative access only by SSH key and only from our operators' addresses. Every management action is recorded in an audit log, without secrets.
- Network: each edge has a firewall that opens only the web ports to the public. Its management interfaces are reachable only by our control plane.
- Data minimisation: the content of requests and responses isn't stored. Logs leave out secrets and the query strings of sign-in links.
- Backups: our control plane's database backups are encrypted before they leave the server.
- Maintenance: software is upgraded only from tested, versioned releases.
Contact
Questions about this agreement, or about data protection: info@sireto.com.