Data Processing Addendum Note

Provider: Andrew Reinhard d/b/a Domainvane, 148 Coleto Trail, Bastrop, TX 78602. Effective date: September 29, 2026.

This is a complete fact sheet for owner and counsel review, not an executed Data Processing Addendum and not something a customer can sign. Counsel must convert it into a binding DPA if Andrew Reinhard d/b/a Domainvane chooses to offer one.

Roles and instructions

For client hostnames and client labels an agency supplies, the intended position is that the agency is controller and Andrew Reinhard d/b/a Domainvane is processor. Andrew Reinhard d/b/a Domainvane is controller for its own account, billing, security, and business records. Counsel must confirm these roles.

Documented instructions are the hostnames, report pages, destinations, notification settings, and plan the customer configures, together with the Terms and a future signed DPA. Domainvane will refuse an instruction that weakens controls against private, loopback, link-local, metadata, or other non-public targets.

Processing details

ItemDescription
Subject and durationCertificate and domain-expiry monitoring during the account relationship, plus deletion and backup-expiry periods described below
Data subjectsCustomer account users and people who may be identifiable from customer-selected hostnames or client labels
DataAccount email; normalized hostnames; TLS and RDAP results; client labels and report-token hashes; settings; encrypted webhook URLs; alert recipient, content, and delivery records
PurposesPerform checks, show results and reports, deliver alerts, secure the service, support the customer, and administer the selected plan
Sensitive dataNot requested or intended; customers must not submit private keys, passwords, payment-card data, or special-category data

Subprocessors

SubprocessorService and relevant data
HetznerVM hosting of application and live database; customer, monitoring, report, and operational data. Production region must be confirmed by the owner.
CloudflareDNS, CDN/security edge, named tunnel, and Email Routing; request metadata and routed support-email data as applicable
StripeMonthly subscription checkout, payments, portal, and webhooks; billing identity, payment data supplied to Stripe, customer and subscription data
PostmarkTransactional email; recipient address, relevant hostname and monitoring finding, message and delivery metadata

A future DPA should specify advance notice and an objection process for material subprocessor changes. RDAP registries, monitored hosts, and customer-selected webhook receivers are destinations required or chosen by the customer rather than Domainvane subprocessors.

Confidentiality and security

Access should be limited to people who need it and who are bound by confidentiality. Current technical controls include scrypt password hashing with per-user salt, hashed session and report tokens, encrypted webhook URLs, CSRF protections, structured logs designed to omit secrets, HTTPS-only RDAP and webhooks, and outbound address guards. Domainvane does not claim whole-database encryption, a penetration test, SOC 2, ISO 27001, or a customer audit mechanism.

Assistance and incidents

A future DPA should require reasonable assistance with data-subject requests, security obligations, breach assessment, and regulator inquiries, considering the nature of processing and information available. The owner and counsel must choose a breach-notification deadline and contact path; the application's scheduler-stall notice is not a personal-data breach notice.

Deletion and return

Signed-in account deletion hard-deletes live account, session, settings, report, billing, outbox, account rate-limit, hostname, history, alert, and notification rows in one transaction. Retained analytics are de-linked and scrubbed of email-, hostname-, and token-named properties. Local backups expire under the configured period, currently 14 days by default, and are not edited to remove one customer immediately. External provider and support-mail records follow their own retention and legal requirements.

There is no machine-readable customer export. A future DPA must not promise immediate erasure from backups or all subprocessors, or a data export, unless the operation changes.

Transfers, audits, and governing law

The owner must confirm the Hetzner production region and decide the transfer mechanism for relevant international processing. Counsel must define reasonable audit evidence or procedures, liability alignment, priority against the Terms, termination, and governing law under Texas law.