Last updated: August 1, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Tech Forge Rocks LLC (“RedirRocks”, “we”, “us”) and the customer (“you”, “Customer”), and applies wherever we process personal data on your behalf in providing the Service.
1. Roles and scope#
For personal data contained in visitor requests that the Service processes to evaluate and perform your redirect rules (“Customer Personal Data”), you are the controller and RedirRocks is the processor. For data we collect as a controller (such as your account and billing information), our Privacy Policy applies instead. This DPA applies to the extent the EU GDPR, UK GDPR, or comparable data-protection laws apply to that processing.
2. Subject matter, nature, and purpose#
- Subject matter and duration — processing of Customer Personal Data for the term of your subscription and until deletion as described in Section 7.
- Nature and purpose — receiving visitor requests and evaluating them against your rules to route traffic to the correct destination, and providing related Service features, security, and support.
- Types of personal data — online identifiers such as IP address, approximate location derived from it, device and browser information, request headers, query parameters, cookies present on the request, and timestamps.
- Categories of data subjects — visitors to the domains and links you configure.
3. Our obligations#
We will:
- Process Customer Personal Data only on your documented instructions, including for transfers, unless required by law (in which case we will inform you where legally permitted);
- Ensure personnel authorized to process the data are bound by confidentiality;
- Implement appropriate technical and organizational security measures (Section 5);
- Assist you, taking into account the nature of the processing, with your obligations to respond to data-subject requests and to ensure security, breach notification, and data-protection impact assessments; and
- Make available information reasonably necessary to demonstrate compliance and allow for audits as described in Section 8.
4. Sub-processors#
You provide general authorization for us to engage sub-processors to process Customer Personal Data. Our current sub-processors are:
| Sub-processor | Purpose | Primary location |
|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure for the redirect engine | United States |
| Cloudflare | Network, content delivery, and security | Global |
| Stripe | Payment processing | United States |
| Resend | Transactional email | United States |
| PostHog | Product analytics | United States |
We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you advance notice of any new or replacement sub-processor and a reasonable opportunity to object on legitimate data-protection grounds.
5. Security#
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit, access controls and authentication, network protections, logging and monitoring, and periodic review of our security practices. Further detail is available on request.
6. Personal data breaches#
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to help you meet your own notification obligations.
7. Return and deletion#
On termination of the Service, or on your written request, we will delete or return Customer Personal Data and delete existing copies within a reasonable period — and in any case within 90 days — except where law requires continued retention. Data held in backups is deleted on its normal expiry cycle.
8. Audits#
On reasonable prior notice, and no more than once per year (unless required by a supervisory authority), we will make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to confidentiality and to not compromising the security of other customers.
9. International transfers#
Where Customer Personal Data is transferred out of the EEA, the UK, or Switzerland, the parties agree that the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum) are incorporated into and form part of this DPA, with RedirRocks acting as data importer. We apply supplementary measures where required.
10. Your obligations#
You are responsible for the lawfulness of the Customer Personal Data and your processing instructions, for having a valid legal basis, and for providing all required notices to and obtaining any required consents from your visitors — including for any cookies or similar technologies used on your domains.
11. Order of precedence#
If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA controls.
Contact#
Questions about this DPA:
- Email: privacy@redir.rocks
- Entity: Tech Forge Rocks LLC
- Mailing address: PMB 1701, 1000 Brickell Ave, Ste 715, Miami, FL 33131, United States