Secure Domains

Privacy Policy

DNS Armor™ by Secure Domains

Effective Date1 May 2026
Last Updated28 July 2026
Document Version1.2
ClassificationPublic
Part I

Privacy Policy

1. Introduction and Scope

This Privacy Policy (“Privacy Policy”) describes how Secure Domains (“Secure Domains,” “we,” “us,” or “our”) handles personal information in connection with the DNS Armor™ family of products and services (collectively, the “Service”). The Service includes:

  • Our website at secure-domains.org and any other websites we own and operate that link to this Privacy Policy.
  • The DNS Armor™ administration portal.
  • The cloud DNS Security Platform.
  • The DNS Armor™ endpoint agents for Microsoft Windows, Apple macOS, Linux distributions (including Ubuntu and Debian), Google Android, and Apple iOS.
  • On-premises and cloud-deployed local DNS Security resolver appliances that fulfil the same role at the network level.
  • Marketing, sales, customer support, and operational communications associated with the foregoing.

Many features of the Service involve processing personal information on behalf of organizations that purchase and deploy DNS Armor™ for their employees, contractors, students, or other end users (each, a “Customer Organization”). In those cases Secure Domains acts as a data processor and the Customer Organization is the data controller. End users covered by a Customer Organization deployment should consult their organization’s own privacy notice for information about how their personal information is governed.

Secure Domains may revise this Privacy Policy from time to time. The “Last Updated” date above reflects the most recent revision. Material changes will be communicated to Customer Organizations in advance through the administration portal or by email, in accordance with the notice periods agreed in the applicable service agreement.

2. Our Role — Data Processor and Data Controller

When DNS Armor™ is deployed by a Customer Organization to its devices, that organization is the data controller of personal information processed about its users. Secure Domains acts as a data processor under a written Data Processing Addendum (see Part II of this document).

For our website visitors, prospective customers, marketing contacts, and Customer Organization administrators registering on our portal, Secure Domains is the data controller and processes personal information directly under this Privacy Policy. For self-signup accounts — Personal, Business and Education & Library — Secure Domains is the data controller of the account holder’s registration, billing and portal data. Where a Business or Education & Library account is used to protect the devices of an organisation’s employees, students, patrons or other end users, that organisation is the data controller of its end users’ personal information and Secure Domains processes it as a data processor under the Data Processing Addendum in Part II of this document. For Personal accounts, Secure Domains is the data controller.

3. Information We Collect

3.1 Information from the Service in operation

DNS Armor™ enforces the Customer Organization’s web-filtering policy by handling only the device’s domain-name lookups (DNS queries) and forwarding them to the cloud DNS Security Platform — or to a local DNS Security resolver hosted in the Customer Organization’s own network — for evaluation. To deliver this Service we process:

  • DNS query content. The domain name your device’s applications attempt to resolve, the query type, and a coarse approximate-location hint used to return geographically appropriate answers. DNS query content travels through an encrypted channel to the DNS Security Platform serving the Customer Organization.
  • Device identifiers. Device serial number or hardware identifier, MAC address (where applicable), public IP address, private IP address, hostname, operating system version, and DNS Armor™ agent version. These are used to authenticate the device against the Customer Organization’s tenant, allow administrators to inventory enrolled devices, and apply the correct policy.
  • Tenant credential. A short registration code issued by the Customer Organization administrator, used once at first launch to enroll the device. The credential is stored in the device’s operating-system secure storage.
  • Connection status. A periodic operational signal indicating whether protection is currently active, so administrators can confirm device coverage.

The same set of information is processed regardless of platform. On laptops and desktops the agent installs as a local service that intercepts DNS traffic and forwards it for evaluation. On mobile devices the agent uses the operating system’s standard VPN or DNS-proxy permission to handle the device’s DNS queries. The agent does not process, store or transmit the content of other network traffic. In on-premises or cloud network deployments, a local DNS Security resolver fulfils the same role at the network level and forwards queries to the upstream cloud DNS Security Platform through the same secure encrypted channel.

3.2 Information from Customer Organization administrators (web portal)

When Customer Organization administrators access our portal, we collect:

  • Authentication identifiers (administrator email, password hash, multi-factor tokens, session cookies).
  • Audit-log entries for administrator actions (policy changes, enrollments, configuration edits).
  • Standard server access logs (IP address, user-agent, timestamp), used solely for security and operational monitoring.

The portal uses strictly-necessary session cookies. We do not deploy advertising or behavioral-tracking cookies on the portal. For self-signup accounts we also process billing information — billing name, email address, and subscription and invoice records. Payment card details are entered directly with our payment provider, Stripe; we do not store full card numbers on our systems.

3.3 Information from website visitors

Our public marketing pages collect minimal data: standard server logs (IP address, page, referrer, user-agent) retained briefly for security monitoring; a first-party visitor count that derives a short-lived, non-reversible identifier from the visitor’s IP address and browser user-agent using a salt that changes daily — so visits cannot be linked across days or to a person — together with the page requested, the browser user-agent and the country; and optional contact-form submissions used solely to respond to inquiries. We do not use third-party advertising networks, third-party behavioral-analytics services, or social-media tracking pixels, and we set no analytics or advertising cookies.

4. How We Use Information

We use the information described above only to:

  • Provide the Service — evaluate DNS queries against the Customer Organization’s policy and return resolved or blocked responses.
  • Authenticate enrolled devices and apply the appropriate filtering policy.
  • Allow administrators to inventory devices, view audit logs, and manage configuration through the portal.
  • Maintain operational quality and security of the Service.
  • Respond to support inquiries.
  • Comply with legal obligations or respond to valid legal requests.

5. What We Do NOT Do With Your Information

  • We do NOT read, store, or transmit the contents of web pages, email, messages, application data, photos, contacts, calendars, or any non-DNS network traffic.
  • We do NOT include third-party advertising SDKs or behavioral-analytics SDKs in the agents. Where diagnostic or crash information is collected to diagnose faults, it is limited to technical fault data and is never used for advertising or profiling.
  • We do NOT collect advertising identifiers (such as Google AAID or Apple IDFA), location coordinates, microphone, camera, contacts, photos, calendar, SMS, or call-log data.
  • We do NOT sell, rent, exchange, or share Customer Organization data with any third party for marketing or any other purpose. The only third parties that process Customer Organization data on our behalf are the Sub-processors described in Annex D, who act only on our instructions.
  • We do NOT mine or profile Customer Organization data across tenants, and we do NOT use one Customer Organization’s data to build products or services for another. Volume, availability and threat-detection metrics used to operate, secure and size the platform are counted at an aggregate level and are not used to identify any individual or organization.

6. How Information Is Protected

DNS Armor™ encrypts DNS traffic between the device and the DNS Security Platform, and control-plane traffic between the device and the portal, using industry-standard transport encryption. The agent validates the identity of the DNS Security Platform endpoint before connecting, which is designed to prevent redirection to a substitute endpoint. Data at rest in our systems is encrypted using industry-standard mechanisms provided by the underlying cloud platform, and each tenant’s data is held in storage scoped to that tenant. Tenant credentials are stored in the operating system’s secure storage on each device.

We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The specific measures we apply are described in Annex C.

No method of transmission over the Internet or method of electronic storage is fully secure. While we use reasonable efforts to protect personal information, we cannot guarantee absolute security.

7. Where Information Is Stored — Data Residency

DNS Armor™ honors regional data residency. DNS query processing and log archival take place within the geographic region assigned to each Customer Organization at the time of provisioning, or selected by the account holder at signup for self-signup accounts. Personal information is not routinely transferred outside its assigned region; where remote administrative access from another country is necessary to operate or support the Service, it takes place under the safeguards described in Section 11. Both DNS Armor™ Protect and DNS Armor™ Resolve are delivered from cloud regions operated by Microsoft Azure and/or Huawei Cloud, depending on the region serving your account. The applicable region — for example the European Economic Area, the United Kingdom, North America, the Middle East and North Africa, or Asia-Pacific — is documented in the Customer Organization’s service agreement or shown in your account.

8. Tenant Isolation

Each Customer Organization’s data, including DNS query logs and audit records, is held in logically isolated storage scoped to that organization, addressed only by credentials issued for that tenant. Access is restricted to administrators authorized for that specific tenant. We do not share, exchange, or correlate data between Customer Organizations. Administrative access spanning tenants is limited to a small number of authorized support personnel, granted on least-privilege terms and logged.

9. Retention of Information

  • DNS query logs are retained for the period contracted with each Customer Organization (typically 30, 60, or 90 days). Customer administrators may request shorter retention or earlier deletion.
  • Device enrollment records are retained for the lifetime of the enrollment, plus a short period after de-registration for audit purposes.
  • Aggregated, non-identifying operational metrics are retained for service-level monitoring and capacity planning.
  • For self-signup accounts, DNS query logs are retained on a rolling basis for the retention period shown in the Service for your plan. Deleting your account erases your account data, configuration and DNS logs, and an account left without an active payment is deleted after the grace period shown in the Service. Invoices and billing records are kept where law requires.

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, to satisfy any legal, accounting, or reporting requirements, and to establish or defend legal claims.

10. Your Rights

Subject to applicable law (including the EU and UK General Data Protection Regulations, the California Consumer Privacy Act and California Privacy Rights Act, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the Saudi Personal Data Protection Law, and similar frameworks) and the role of the Customer Organization as data controller, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete personal information.
  • Delete your personal information (“right to be forgotten”), subject to lawful retention obligations.
  • Restrict or object to certain processing of your personal information.
  • Receive your personal information in a portable, machine-readable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the data-protection supervisory authority in your jurisdiction.

If you are an end user whose device runs DNS Armor™ under your organization’s deployment, rights requests should normally be directed to your organization’s administrator first, since they control how your information is processed. If your organization cannot resolve the request, contact us at privacy@secure-domains.org and we will assist as the data processor.

For website visitors and prospective customers, contact us directly at privacy@secure-domains.org to exercise your rights.

11. International Transfers of Information

Where personal information is transferred between regions to deliver the Service, we rely on appropriate transfer mechanisms recognized in the originating jurisdiction. These include the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum, and equivalent transfer instruments under the laws of other jurisdictions in which we operate. Our default posture is to keep each Customer Organization’s data within its assigned region as described in Section 7 (Data Residency).

12. Children’s Privacy

The Service is not directed to or marketed to children, and account holders must be at least 18 years of age. Where DNS Armor™ is deployed by a Customer Organization — including in education settings, where the school, district or institution is the data controller — that organization is responsible for any applicable child-protection compliance, including the Children’s Online Privacy Protection Act (COPPA) in the United States and equivalent laws.

13. Third-Party Sites and Services

The Service may contain links to other websites operated by third parties. We do not control those sites and are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you visit.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this document reflects the most recent revision. Material changes will be communicated to Customer Organizations and to self-signup account holders through the administration portal or by email in advance of their effective date, normally at least thirty (30) days beforehand.

15. Contact Us

If you have questions about this Privacy Policy or our handling of personal information, please contact us:

Privacy & Data Subject Rights
privacy@secure-domains.org
Security Disclosure
security@secure-domains.org
Postal Address

Secure Domains Dubai United Arab Emirates

For Customer Organization administrators with questions about the data-processor relationship, the applicable Data Processing Addendum (Part II of this document), or our list of sub-processors, please contact your account manager or privacy@secure-domains.org.

Part II

Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) forms an integral part of the service agreement (the “Agreement”) concluded between Secure Domains (“Processor”) and the Customer Organization identified in the Agreement (“Controller”), and supplements the obligations of the parties with respect to the processing of Personal Data in connection with the DNS Armor™ Service. For self-signup Business (SMB) and Education & Library accounts, the “Agreement” means the Self-Signup Terms of Service accepted in the Service and the “Controller” means the organisation named at signup. Where the Customer Organization itself acts as a processor on behalf of its own customers (for example as an MSP), references to the Controller include the Customer Organization in that capacity, the Customer Organization warrants that its instructions to the Processor reflect the instructions of the relevant controller, and Secure Domains acts as its sub-processor.

By executing the Agreement, the Controller and the Processor agree to be bound by the terms of this DPA. In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Personal Data.

Annex A — Data Processing Addendum

A.1 Definitions

For the purposes of this DPA, the following definitions apply. Capitalized terms not otherwise defined have the meaning given in the Agreement or in applicable Data Protection Law.

Applicable Data Protection Law
All laws and regulations governing the processing of Personal Data that apply to the Processor or Controller in connection with the Service, including without limitation the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”), the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the Saudi Arabia Personal Data Protection Law, and any other applicable national, federal, or sub-national data-protection law.
Controller
The Customer Organization identified in the Agreement.
Personal Data
Any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Service.
Processor
Secure Domains.
Data Subject
An identified or identifiable natural person to whom the Personal Data relates.
Sub-processor
Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

A.2 Subject Matter, Duration, Nature and Purpose of Processing

Subject matterProvision of the DNS Armor™ Service by the Processor to the Controller.
DurationFor the term of the Agreement, plus the retention periods set forth in this DPA and applicable law.
NatureReceipt, evaluation, forwarding, response, and logging of Domain Name System (DNS) queries originated by devices enrolled by the Controller; authentication of enrolled devices; administrative configuration of filtering policy.
PurposeEnforcement of the Controller’s web-filtering and threat-protection policy on the Controller’s managed devices; provision of audit and reporting capabilities to the Controller’s administrators.

A.3 Categories of Data Subjects and Personal Data

See Annex B (Description of Processing).

A.4 Obligations of the Processor

The Processor shall:

  1. process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Applicable Data Protection Law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
  2. ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  3. implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in particular those measures set out in Annex C of this DPA;
  4. respect the conditions referred to in Section A.5 (Sub-processors) for engaging another processor;
  5. taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, in so far as possible, in fulfilling the Controller’s obligation to respond to requests for the exercise of Data Subject rights under Applicable Data Protection Law;
  6. assist the Controller in ensuring compliance with its obligations under Applicable Data Protection Law in respect of security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor;
  7. at the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Applicable Data Protection Law requires storage of the Personal Data; and
  8. make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable confidentiality and security restrictions, in each case in the manner and subject to the limitations set out in Section A.9 of this DPA; and
  9. to the extent the CCPA/CPRA applies, act as the Controller’s “service provider”: the Processor shall not sell or share Personal Data, shall not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA/CPRA, shall not combine it with personal information received from other sources except as permitted, and shall notify the Controller if it can no longer meet these obligations.

A.5 Sub-processors

The Controller hereby grants the Processor general written authorization to engage Sub-processors to provide certain components of the Service, subject to the conditions set out below.

  1. The Processor shall maintain a current list of Sub-processors, available to the Controller on request, and as initially set forth in Annex D.
  2. The Processor shall give the Controller at least thirty (30) days’ prior notice of any intended addition or replacement of a Sub-processor through the administration portal or by email, thereby giving the Controller the opportunity to object to such change. Where a Sub-processor must be added or replaced at shorter notice to maintain the security, legality or continuity of the Service, the Processor shall give notice as soon as reasonably practicable, and the Controller’s right to object under this Section applies from the date of that notice.
  3. The Processor shall bind each Sub-processor by way of a written contract that imposes data protection obligations meeting the requirements of Article 28(4) GDPR and the equivalent provisions of Applicable Data Protection Law, including the obligation to implement appropriate technical and organizational measures.
  4. The Processor shall remain fully liable to the Controller for the performance of each Sub-processor’s obligations.
  5. If the Controller objects to an intended addition or replacement on reasonable data-protection grounds and the parties cannot resolve the objection within thirty (30) days, the Controller may terminate the affected Service on written notice.

A.6 Personal Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller, so as to allow the Controller to meet its own notification deadlines. The notification shall include, to the extent reasonably available at the time:

  • a description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • the name and contact details of the Processor’s data-protection contact or other contact point where more information can be obtained;
  • a description of the likely consequences of the Personal Data Breach; and
  • a description of the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

The Processor shall cooperate with the Controller and provide reasonable assistance with regard to the Controller’s obligations to notify supervisory authorities and Data Subjects.

A.7 Data Subject Rights Requests

The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures in responding to requests for the exercise of Data Subject rights. Where the Processor receives a request directly from a Data Subject in connection with Personal Data processed on behalf of the Controller, the Processor shall promptly forward the request to the Controller and shall not respond to the Data Subject directly except as instructed by the Controller or required by Applicable Data Protection Law.

A.8 International Data Transfers

The Processor shall store Personal Data in the geographic region assigned to the Controller and shall not relocate that storage to another region without the Controller’s prior written authorization. Remote access to Personal Data by the Processor’s authorized personnel from another country, where necessary to operate, maintain or support the Service, is permitted subject to the transfer mechanisms set out below and the access controls in Annex C. Where such a transfer is authorized or permitted under this Section and is to a country or international organization that does not provide an adequate level of protection under Applicable Data Protection Law, the parties shall execute the appropriate transfer mechanism, including without limitation:

  1. the Standard Contractual Clauses adopted by the European Commission pursuant to Decision 2021/914 (the “EU SCCs”), which are incorporated by reference into this DPA and shall apply between the parties as set out in Annex E;
  2. the United Kingdom International Data Transfer Addendum issued by the Information Commissioner’s Office (the “UK IDTA”), where applicable; and
  3. such other transfer mechanisms as may be required by other jurisdictions.

A.9 Audits and Inspections

The Processor shall make available to the Controller, upon reasonable written request and no more than once per calendar year (except where required following a Personal Data Breach or by a supervisory authority), information necessary to demonstrate compliance with this DPA. This obligation is ordinarily satisfied by responding to a reasonable security questionnaire and by providing the security documentation and any third-party assessment reports the Processor then holds.

Where the information provided under the preceding paragraph is not sufficient, or where an on-site inspection is required by Applicable Data Protection Law or by a supervisory authority, the Controller may conduct an audit of the Processor’s processing activities under this DPA — subject to reasonable advance written notice, confidentiality obligations, and security restrictions, limited to once per calendar year, conducted during business hours in a manner that does not disrupt the Processor’s operations, and at the Controller’s own cost.

A.10 Return or Deletion of Personal Data

Upon termination or expiry of the Agreement, or upon the Controller’s written request, the Processor shall, at the Controller’s option, return all Personal Data to the Controller or delete the Personal Data in its possession, and shall delete existing copies, unless Applicable Data Protection Law requires the Processor to retain such Personal Data. Where deletion is requested, the Processor shall carry out the deletion without undue delay and shall confirm deletion in writing on request. Personal Data held in encrypted backup media is deleted in accordance with the Processor’s backup rotation cycle, during which it remains subject to the measures set out in Annex C.

A.11 Liability

The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement.

A.12 Order of Precedence

In the event of any conflict between this DPA and the Agreement, this DPA prevails. In the event of any conflict between this DPA and the EU SCCs or other transfer mechanism, the transfer mechanism prevails to the extent of the conflict.

A.13 Governing Law and Jurisdiction

This DPA is governed by the law and subject to the jurisdiction set forth in the Agreement, except where Applicable Data Protection Law mandates a different governing law or jurisdiction in relation to the protection of Personal Data.

Annex B — Description of Processing

B.1 Categories of Data Subjects

The Personal Data processed under this DPA concerns the following categories of Data Subjects:

  • Employees, contractors, students, members, or other end users of the Controller whose devices are enrolled with the Service.
  • Authorized administrators of the Controller who access the administration portal.

B.2 Categories of Personal Data

The Personal Data processed under this DPA includes the following categories:

  • DNS query data (domain names looked up by enrolled devices, query types, approximate-location hints, timestamps).
  • Device identifiers (device serial number or hardware identifier, MAC address where applicable, public IP address, private IP address, hostname, operating system version, agent version, connection status).
  • Tenant credentials (registration code issued to each device).
  • Administrator account data (email address, password hash, multi-factor authentication tokens, session identifiers).
  • Administrator audit-log entries.

B.3 Processing Operations

The Personal Data described above is subject to the following processing operations:

  • Collection from enrolled devices and from administrator portal activity.
  • Transmission through secure encrypted channels to the cloud DNS Security Platform and control plane.
  • Evaluation against the Controller’s filtering and threat-protection policy.
  • Logging and storage in tenant-isolated containers within the Controller’s assigned geographic region.
  • Display to Controller administrators through the portal.
  • Deletion at the end of the contracted retention period or upon Controller request.

B.4 Frequency of Processing

Continuous, for the duration of the Agreement.

B.5 Retention

  • DNS query logs: as contracted with the Controller (typically 30, 60, or 90 days).
  • Device enrollment records: lifetime of enrollment plus a short audit period.
  • Aggregated, non-identifying operational metrics: as required for service-level monitoring and capacity planning.

Annex C — Technical and Organizational Security Measures

The Processor implements and maintains technical and organizational security measures appropriate to the risk, informed by recognized industry security frameworks. Such measures include without limitation:

C.1 Access Control

  • Role-based access control with least-privilege provisioning.
  • Multi-factor authentication is required for administrator accounts on the administration portal and for interactive administrative access to production systems. Non-interactive service credentials are managed separately and scoped to the function they perform.
  • Access reviews and deprovisioning upon role change or termination.

C.2 Encryption

  • DNS query traffic between the device and the DNS Security Platform is transmitted through an encrypted channel whose server identity is validated by the agent.
  • Control-plane traffic between the device and the registration system is transmitted using industry-standard secure encrypted channels.
  • Personal Data at rest is encrypted using the server-side encryption provided by the underlying cloud platform, and each Customer Organization’s data is held in storage containers scoped to that tenant.
  • Tenant credentials on each device are stored in the operating system’s secure storage facility.

C.3 Tenant Isolation

  • Each Customer Organization’s data is held in logically isolated storage, addressed only by credentials scoped to that tenant.
  • Access controls are designed to prevent cross-tenant access by customer administrators and by automated processes; tenant scoping is enforced in the application authorization layer and is subject to ongoing review and testing. Administrative access spanning tenants is limited to authorized support personnel on least-privilege terms and is logged.

C.4 Data Residency

  • DNS query processing and log archival take place within the geographic region assigned to each Controller at the time of provisioning. The platform is hosted in cloud regions operated by Microsoft Azure and/or Huawei Cloud, depending on the region serving the Controller.

C.5 Network and Application Security

  • Network segmentation between public-facing, application, and data-storage tiers.
  • Web Application Firewall protections on public endpoints.
  • Vulnerability management with regular scanning and remediation within risk-based timeframes.
  • Security testing of the platform’s externally exposed surface, carried out on a risk-driven basis and following significant changes to that surface.
  • A secure development process including peer review of code changes and automated dependency vulnerability checking.

C.6 Logging and Monitoring

  • Centralized security event logging.
  • Alerting on defined security- and availability-relevant events, reviewed by the operations team during business hours.
  • Defined incident-response procedures.

C.7 Personnel Security

  • Access to production systems restricted to personnel who require it for their role.
  • Security and privacy awareness training for personnel.
  • Confidentiality obligations included in employment terms.

C.8 Business Continuity

  • Backup and recovery procedures for platform data.
  • Reliance on the resilience features of the underlying cloud regions in which the Service is hosted.

C.9 Sub-processor Oversight

  • Due diligence on Sub-processors prior to engagement.
  • Written data-processing terms meeting the requirements of Article 28(4) GDPR and the equivalent provisions of Applicable Data Protection Law.
  • Review of each Sub-processor at engagement and thereafter on a risk-driven basis, including any independent assurance reports or certifications the Sub-processor makes available.

Annex D — List of Sub-processors

The current list of Sub-processors is published at secure-domains.org/subprocessors and is updated whenever the list changes. At the date of this DPA, the categories of Sub-processors are:

  • Cloud infrastructure providers (regional cloud regions used to host the DNS Security Platform and log storage in the Controller’s assigned geography).
  • Email and customer-support tooling (limited to administrator and support communications; not used to process end-user DNS query data).
  • Payment processing (limited to billing data for self-signup accounts; no DNS query data is shared).

A current named list, including the legal name, country of establishment, and processing activity of each Sub-processor, is available to Controllers on request and at the URL above. Licensed threat-intelligence feed providers are not Sub-processors: intelligence flows one way into the platform and they receive no Personal Data. They are disclosed at the URL above for transparency.

Annex E — Standard Contractual Clauses (Cross-Border Transfers)

Where the Processor transfers Personal Data outside the European Economic Area, the United Kingdom, or another jurisdiction whose Applicable Data Protection Law requires additional safeguards, the parties hereby incorporate by reference the following:

  1. For transfers from the EEA: Module Two (Controller to Processor) of the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”).
  2. For transfers from the EEA where the Controller acts as a processor on behalf of its own customers (for example as an MSP): Module Three (Processor to Processor) of the EU SCCs, which applies on the same terms, mutatis mutandis.
  3. For transfers from the United Kingdom: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner’s Office and laid before Parliament on 2 February 2022 (the “UK IDTA”).

The parties agree that:

  • The Controller is the “data exporter” and the Processor is the “data importer” under the EU SCCs and the UK IDTA.
  • In Clause 7 of the EU SCCs (the docking clause), the optional language is not included.
  • In Clause 9 of the EU SCCs (use of sub-processors), Option 2 (general written authorization) applies, with thirty (30) days’ notice as specified in Section A.5 of this DPA.
  • In Clause 11 of the EU SCCs (redress), the optional independent dispute resolution language is not included.
  • In Clause 17 of the EU SCCs (governing law), the Clauses are governed by the law of Ireland.
  • In Clause 18 of the EU SCCs (choice of forum and jurisdiction), disputes arising from the Clauses shall be resolved before the courts of Ireland.
  • Annex I.A of the EU SCCs is completed by reference to the Agreement and Annex B of this DPA.
  • Annex I.B of the EU SCCs is completed by reference to Annex B of this DPA.
  • Annex II of the EU SCCs is completed by reference to Annex C of this DPA.
  • Annex III of the EU SCCs is completed by reference to Annex D of this DPA.
  • For the UK IDTA, Tables 1 to 3 are completed by reference to the Agreement and Annexes B, C and D of this DPA, and either party may end the UK IDTA as set out in Section 19 of the IDTA.

For transfers from other jurisdictions, the parties shall execute such additional transfer instruments as required by Applicable Data Protection Law.

Legal Notices

DNS Armor™ is a registered trademark of Secure Domains, registered with the Ministry of Economy of the United Arab Emirates, Dubai. All other trademarks referenced in this document are the property of their respective owners.

© 2026 Secure Domains. All rights reserved.

Document classification
Public
Document owner
Legal and Compliance, Secure Domains, Dubai, United Arab Emirates
Document version
1.2
Effective date
1 May 2026
Last updated
28 July 2026