Privacy Policy#
Last updated: 2026-08-20
GraceDNS is a protective DNS service operated by botBrains GmbH, Osloer Str. 83, 13359 Berlin, Germany ("we", "us"). This policy explains what personal data we process, why, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller and contact#
botBrains GmbH Osloer Str. 83 13359 Berlin, Germany Email: legal@gracedns.eu
2. What data we process#
2.1 DNS queries#
When your device uses GraceDNS resolvers, we technically receive the domain name you look up, the record type, your client IP address, the protocol used (Do53, DoT, DoH) and the configuration identifier. What we store depends entirely on the logging mode of your configuration:
- none (default for individuals): queries are answered and immediately forgotten. Nothing is written to storage.
- blocked_only: only blocked queries are stored (timestamp, configuration id, domain, record type, verdict and the list that caused the block). Client IP addresses are not stored in this mode.
- all: full query logs including the client IP address, chosen by business customers who need them for security operations.
You (or your organization's administrator) select the logging mode per configuration and can change it at any time. Query logs are stored exclusively on servers in Germany (Hetzner Online GmbH).
2.2 Account and configuration data#
To provide the service we store account data (email address, organization name where applicable), your configurations (custom allow/deny lists, linked client IP ranges, feature toggles) and billing data for paid plans.
2.3 Website#
Our website is static. We do not use cookies, analytics scripts, tracking pixels or third-party embeds. Our web server keeps short-lived technical access logs (IP address, requested URL, timestamp) for security and abuse prevention, deleted automatically within 14 days.
3. Purposes and legal bases#
- Providing DNS resolution and filtering: Art. 6(1)(b) GDPR (performance of contract).
- Query logging in the mode you selected: Art. 6(1)(b) and, for security logging, Art. 6(1)(f) GDPR (legitimate interest in network and information security).
- Billing and accounting: Art. 6(1)(c) GDPR (legal obligation).
- Abuse prevention and web server security logs: Art. 6(1)(f) GDPR.
4. Retention#
- Logging mode none: no retention.
- Logging modes blocked_only and all: retention is controlled by the customer per configuration; logs are deleted at the end of the configured retention period or on customer request.
- Account data: for the duration of the contract and thereafter as required by statutory retention obligations (e.g. German tax law, up to 10 years for invoices).
- Web server access logs: 14 days.
5. Recipients#
We use a small number of subprocessors, listed with their roles at Subprocessors. All customer data is hosted with Hetzner Online GmbH in Germany. We do not sell or share personal data for advertising. Blocklist feed providers are data sources we read from; they never receive your data.
6. International transfers#
Customer data is stored and processed in Germany. We do not transfer personal data to third countries.
7. Your rights#
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Contact legal@gracedns.eu. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit.
8. Security#
Traffic to our resolvers and website is encrypted in transit (TLS for DoT, DoH and the website). Data at rest is stored on encrypted volumes. See the compliance page for our full security posture.
9. Children#
GraceDNS is used to protect children's devices, but accounts are created and managed by adults (parents, guardians, schools). We do not knowingly collect personal data from children beyond the DNS queries technically necessary to answer them, handled per the logging mode above.
10. Changes#
We will post updates to this policy on this page and update the date above. Material changes to how we process customer data are announced to account holders by email.