Privacy Policy
Version: 2026-09-23
This Privacy Policy explains what personal data RedundantDNS ("RedundantDNS", "we", "us") collects when you use the RedundantDNS service, dashboard and API (the "Service"), why we collect it, how long we keep it and how you can exercise your rights. It applies together with our Terms of Service. We process personal data in line with the Brazilian General Data Protection Law (LGPD, Law 13,709/2018) and, where it applies, the EU and UK General Data Protection Regulation (GDPR).
For account and usage data we act as the controller. For personal data that you place inside your DNS zones (for example a name in a TXT record) we process it on your behalf, as a processor, only to provide the Service.
1. Data we hold
- Account data: your e-mail address, your user ID, the organizations you belong to and your role in each, when you signed up and when you last signed in.
- Sign-in data: one-time login codes, stored only as a hash and deleted when used or after 10 minutes; a signed session cookie.
- Zone data: the zones, records, TTLs and settings you manage, their change journal (who changed what and when), and the sync and delegation status we compute.
- Provider credentials: the keys you give us to reach your DNS provider accounts, stored encrypted and never shown again. We keep only a short hint (for example the last characters of a key ID) so you can recognize them.
- API tokens: the name, scopes, IP allowlist and expiry of each token. The token itself is stored only as a hash.
- Audit logs: who did what in your organization (actor, action, target, time and source: dashboard, API or system).
- Legal acceptance: the versions of these documents you accepted, when, and the IP address used.
- Billing data: when you subscribe to a paid plan, Stripe processes your payment details. We receive and keep the customer and subscription identifiers, invoices and the last digits and brand of your card, never the full card number.
- Technical data: IP addresses and request metadata in our server logs, used for security and troubleshooting.
We do not use advertising or tracking cookies. The dashboard uses one strictly necessary session cookie and stores your language and active organization in your browser's local storage.
2. Why we use it
- To provide the Service: sign you in, keep your zones in sync across your providers, check delegation and show you status and history (performance of our contract with you).
- To secure the Service: detect abuse, investigate incidents, enforce IP allowlists and keep audit logs (our legitimate interest in protecting you, other customers and the Service).
- To bill paid plans and keep accounting records (contract and legal obligation).
- To send service e-mails: login codes, security notices and important changes to these documents (contract and legitimate interest). We do not send marketing e-mails without your consent.
- To comply with the law and answer lawful requests from authorities (legal obligation).
We do not sell your personal data and we do not use your zone data for any purpose other than providing the Service.
3. Retention
- Account data: while your account is active. After you ask us to delete your account we delete it within 30 days.
- Zone data and provider credentials: until you delete the zone or connection, or your account. Deleted data leaves our backups within 90 days.
- Login codes: at most 10 minutes. Sessions expire after 12 hours.
- Audit logs and change journals: 12 months, or until your account is deleted if earlier, unless we need them longer to investigate a security incident.
- Billing records: for the period required by tax and accounting law (currently up to 5 years in Brazil).
- Server logs: up to 90 days.
4. Sub-processors
We use the following service providers to run the Service. Each one processes personal data only on our instructions and under a data processing agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, object storage, key management; Route 53 for managed provider accounts | United States and other regions |
| Oracle Cloud Infrastructure (OCI) | Hosting, object storage and backups; OCI DNS for managed provider accounts | United States, Brazil and other regions |
| Cloudflare | Network edge, TLS termination and protection against attacks | Global |
| Stripe | Payment processing and invoicing | United States and other regions |
| Transactional e-mail provider | Delivery of login codes and service e-mails | United States |
DNS providers that you connect with your own credentials are not our sub-processors: the data you send them is governed by your own agreement with each provider. We will update this list before adding a new sub-processor, and the version date at the top of this page will change.
5. International transfers
Some sub-processors are located outside Brazil and the European Economic Area. When personal data is transferred, we rely on the safeguards provided by law, such as standard contractual clauses approved by the Brazilian National Data Protection Authority (ANPD) or the European Commission.
6. Security
- Each organization's data is encrypted at rest with its own data encryption key (AES-256-GCM), and that key is itself encrypted with a master key held apart from the data.
- Provider credentials are write-only: they are decrypted only inside the service that talks to the provider and are never returned by the API or shown in the dashboard.
- Login codes and API tokens are stored only as SHA-256 hashes; sessions are signed and expire.
- All traffic uses TLS. Access by our staff is limited to what is needed to operate and support the Service, and platform administration actions are audit-logged.
- There is no password to steal: sign-in uses one-time codes sent to your e-mail.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authorities as required by law.
7. Your rights
Under the LGPD you may ask us to confirm whether we process your data, to access, correct, anonymize, block or delete it, to port it to another provider, to know with whom we share it, and to revoke consent where processing is based on consent. Under the GDPR you also have the rights of access, rectification, erasure, restriction, objection and data portability.
How to exercise them:
- Export: you can export any zone at any time from the dashboard or the API as a standard zone file. For a copy of all the personal data we hold about you, write to legal@redundantdns.com from the e-mail address of your account.
- Deletion: write to legal@redundantdns.com from the e-mail address of your account. We delete your account and personal data within 30 days, except the records we must keep by law. Zones at your providers are not touched unless you ask us to delete them.
- Correction and other requests: write to legal@redundantdns.com.
We may ask you to confirm your identity before acting on a request. We answer within 15 days, as required by the LGPD, and in any case within one month. You also have the right to lodge a complaint with the ANPD in Brazil or with the data protection authority of your country.
8. Children
The Service is not directed to anyone under 18 and we do not knowingly collect their data.
9. Changes to this policy
We may update this policy. Each version is identified by its date at the top of this page. When a change is material we will notify you in the dashboard and ask you to review and accept the new version before you continue using the Service.
10. Contact
For privacy questions or to reach our data protection officer (encarregado), write to legal@redundantdns.com.