Privacy policy
Last updated 28 Sep 2026
Domain Health Hub is run by Brindleford Technologies Ltd, a company registered in England and Wales (number 16871436), registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. This policy explains how we handle personal data on this website and in the app. Questions or requests: hello@domainhealthhub.com.
Our role
For your account, billing and our own marketing, we are the controller of your personal data. For information you add about your clients (their names, report contacts and domains) and the reports we receive for their domains, we act as a processor on your behalf: you decide what goes in, and we use it only to provide the service to you. The data processing terms cover that part.
What we collect
- Your account: name, email address and a securely hashed password; the workspaces you belong to and your role in them.
- Billing: your country, business name and address, VAT number and subscription status. Card details go straight to Stripe; we never see or store them.
- Your clients: client names, the email addresses report cards go to, and the domains you monitor, with their public DNS records and check results.
- DMARC and TLS reports: mail providers send these for your domains. We keep daily totals (sending servers' IP addresses and host names, message counts and pass or fail results) and delete the report files once read. We never accept forensic reports, which can contain message content.
- Support chat: messages you send us through the chat in the app, with your name, email and workspace, so we know who we're helping.
- Usage: pages visited, counted by our own analytics (Rybbit, which runs on our servers). It uses no cookies and doesn't identify you. Invite links are recorded without their code.
- Security logs: IP addresses of sign-in and sign-up attempts, kept briefly to stop password guessing.
- The free checker: the domain you check. Results are kept in memory for ten minutes and not stored.
Why, and on what basis
- To provide the service you signed up for, including billing and support (performing our contract with you).
- To keep the service secure and working, and improve it (legitimate interests).
- To keep accounting and tax records (legal obligation).
- To tell you about your account, payments and changes to the service. We don't send marketing email without your consent.
Who processes data for us
We use a small number of providers, each only for what's listed:
| Provider | What for | Where |
|---|---|---|
| Contabo | Servers that run the app, its database, support chat and analytics | France (EU) |
| Backblaze | Database backups | Netherlands (EU) |
| Stripe | Subscriptions, payments, invoices and tax | Ireland (EU) and the US |
| Postmark | Sending alert emails and report cards | US |
| Cloudflare | Publishing the DNS records we host for your domains | Global |
Where data leaves the UK and EU (Stripe and Postmark in the US), it's protected by the UK International Data Transfer Addendum and the EU standard contractual clauses, or an adequacy decision. We don't sell personal data.
How long we keep it
- Your workspace's data stays while the workspace exists. Deleting a workspace (an owner can, on the Workspace page) removes it within the hour; backups containing it roll off within 30 days.
- DMARC and TLS report totals: 12 months.
- If a trial or subscription ends without a plan: the workspace and its data are deleted after 90 days.
- Invoices and payment records: kept for six years, as UK tax law requires.
- Security logs of sign-in attempts: a day.
Cookies
We only use cookies the service needs: one keeps you signed in, one remembers which workspace you're in, and one remembers light or dark mode. There are no advertising or tracking cookies, so we don't ask for consent. Stripe sets its own cookies on its checkout and billing pages to prevent fraud.
Your rights
You can ask for a copy of your personal data, have it corrected or deleted, object to how we use it, or ask us to restrict using it. Owners can export or delete a whole workspace's data themselves on the Workspace page. For anything else, email hello@domainhealthhub.com; we'll reply within a month. If you're a client of one of our customers, contact the agency that looks after your domains first, as they control that data.
You can complain to the Information Commissioner's Office (ico.org.uk) if you're unhappy with how we've handled your data, though we'd like the chance to put it right first.
Security
Everything is encrypted in transit. Webhook secrets and mail credentials are encrypted at rest, and each workspace's data is kept strictly separate.
Changes
If we change this policy in a way that matters, we'll tell account owners by email before it takes effect. The date at the top shows when it last changed.