Legal
Privacy
What we hold, why we hold it, and what you can ask us to do with it.
Last updated 22 August 2026
Who we are
RelayDNS is operated by Sukses360 Ltd, registered in England and Wales. For questions about this page or about your data, email privacy@relaydns.dev.
Two different roles
RelayDNS sits between two groups of people, and our responsibility differs for each.
- For account holders, meaning you and your colleagues who sign in, we are the controller. We decide what to collect and why.
- For your customers, meaning the people who connect a domain through your product, we are a processor acting on your instructions. You decide what to send us. We use it to run the setup you asked for, and for nothing else.
What we collect
For account holders:
- Your email address, and a display name if you give one.
- Authentication events, such as when you signed in and from roughly where, kept so we can investigate account takeover.
- The organisations, projects and API keys you create. API keys are stored only as a hash.
For domain setups your product creates:
- The domain name being connected, and the DNS records requested for it.
- What we learned about that domain's DNS provider from public DNS, so we can offer the right flow and explain later why a setup went the way it did.
- A record of each verification attempt, including what public resolvers answered.
- Delivery attempts for any webhooks you have configured.
A domain name can identify a person, which is why it is treated as personal data here even though it is published in DNS.
Why we are allowed to hold it
- To perform our contract with you: running the setups you create, and giving you an account to manage them.
- For our legitimate interests: keeping the service secure, investigating abuse, and understanding failures well enough to fix them.
- To meet legal obligations, such as keeping business records.
We do not sell personal data, and we do not use it to advertise to anyone.
Who else processes it
We use these providers to run the service. Each one processes data on our instructions.
- Supabase, for the database and authentication.
- Vercel, for hosting the dashboard.
- Railway, for hosting the API.
- Inngest, for running background work such as detection and verification.
- Cloudflare, for DNS and for protecting our own domain.
- Google, only where you choose to sign in with a Google account.
Some of these operate outside the United Kingdom. Where they do, transfers rely on the safeguards those providers offer, such as standard contractual clauses.
How long we keep it
- Account data is kept while your account exists, and removed when you close it.
- Domain setups expire on the date shown in the API response, and are removed once they are no longer needed to answer questions about a domain you connected.
- Verification and webhook logs are kept as long as they are useful for diagnosis, and are not retained indefinitely.
If you close your account, ask us and we will delete what remains rather than waiting for it to lapse.
Your rights
Under UK GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong.
- Delete it, where we have no continuing reason to keep it.
- Restrict or object to how we use it.
- Send it to you, or to someone else, in a portable form.
Email privacy@relaydns.dev and we will respond within one month. If you are an end user who connected a domain through someone else's product, contact them first: they decide what happens to that data, and we act on their instructions.
If you think we have handled your data badly you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, so we can put it right.
Changes
If this page changes in a way that affects you, we will say so rather than quietly updating the date at the top.