← back to home FR

Data Processing Agreement

Data Processing Agreement (DPA)

Effective: January 14, 2026 | Version 1.0

Between: [Customer Name] (“Data Controller” or “Customer”)

And: le_dns operated by Maiko BOSSUYT, EI (“Data Processor” or “Processor”)

Service: Secondary DNS Hosting

This Data Processing Agreement (“DPA”) forms part of the Secondary DNS Terms of Service and governs the processing of personal data by the Processor on behalf of the Controller in compliance with Regulation (EU) 2016/679 (GDPR).

1. Definitions

Terms used in this DPA have the meanings set forth in the GDPR. Specifically:

2. Scope and Purpose of Processing

2.1. Purpose

The Processor shall process Personal Data solely for the purpose of providing Secondary DNS Hosting services, which includes:

2.2. Duration

Processing shall continue for the duration of the service agreement and until all Personal Data is deleted as specified in Section 9.

2.3. Nature of Processing

3. Data Processor Obligations (GDPR Article 28(3))

The Processor shall:

4. Security Measures (GDPR Article 32)

The Processor implements the following technical and organizational security measures:

4.1. Access Control

4.2. Transmission Security

4.3. Storage Security

4.4. Organizational Measures

5. Sub-Processors (GDPR Article 28(2) & (4))

5.1. Authorized Sub-Processors

The Controller authorizes the Processor to engage the following sub-processors:

All sub-processors are EU-based. No data is transferred outside the European Economic Area (EEA).

5.2. Sub-Processor Changes

The Processor shall:

6. Data Subject Rights

6.1. Controller Responsibility

The Controller is responsible for responding to Data Subject requests (access, rectification, erasure, etc.). The Processor shall assist by:

6.2. Direct Requests

If the Processor receives a Data Subject request directly, it shall:

7. Data Breach Notification (GDPR Articles 33-34)

7.1. Processor Notification to Controller

In the event of a Personal Data breach, the Processor shall notify the Controller within 24 hours of becoming aware, including:

7.2. Cooperation

The Processor shall cooperate with the Controller to investigate and remediate the breach, including providing access to relevant logs and forensic data.

8. Audits and Compliance (GDPR Article 28(3)(h))

8.1. Audit Rights

The Controller may conduct audits or inspections to verify GDPR compliance, subject to:

8.2. Audit Alternatives

The Processor may satisfy audit requirements by:

9. Data Retention and Deletion

9.1. Active Zones

While zones are active, Personal Data is retained as necessary to provide the service.

9.2. Deleted Zones

9.3. Operational Logs

9.4. Termination

Upon service termination, the Processor shall:

10. International Data Transfers

No international transfers: All processing occurs within the European Union (France, Germany). No data is transferred to third countries or international organizations.

If international transfers become necessary in the future, the Processor shall implement appropriate safeguards (Standard Contractual Clauses, Adequacy Decisions, etc.) and notify the Controller in advance.

11. Liability (GDPR Article 82)

Each party shall be liable for damages caused by processing in accordance with GDPR Article 82:

12. Indemnification

The Processor shall indemnify and hold harmless the Controller against claims, fines, and losses arising from the Processor’s breach of this DPA or GDPR obligations, except where such breach results from the Controller’s instructions or negligence.

13. Termination and Effect

13.1. Termination

This DPA terminates automatically upon termination of the Secondary DNS Hosting service agreement.

13.2. Effect of Termination

14. Governing Law and Jurisdiction

This DPA is governed by French law and subject to the jurisdiction of French courts.

GDPR and applicable EU/Member State data protection laws take precedence over any conflicting provisions.

15. Order of Precedence

In case of conflict between documents:

  1. This Data Processing Agreement (DPA)
  2. GDPR and applicable data protection laws
  3. Secondary DNS Terms of Service
  4. Privacy Policy

16. Amendments

This DPA may be amended to reflect:

Material changes require 30 days notice to the Controller via email.

17. Contact for DPA Matters

Data Protection Contact: Maiko BOSSUYT le_dns Email: legal@ledns.eu Privacy inquiries: privacy@ledns.eu Security incidents: security@ledns.eu