Last updated 19 September 2026
How KumoDNS handles personal data in connection with KumoDNS
| Organisation | KumoDNS |
| Effective date | 24 August 2026 |
| Version | 1.0 |
| Applies to | KumoDNS.com, customer accounts, DNS services, support, billing, security and abuse handling |
This Privacy Policy explains how KumoDNS (“we”, “us” or “our”) collects, uses, discloses, protects and retains personal data in connection with KumoDNS websites, customer accounts, DNS hosting and related services (the “Services”). “Personal data” means data, whether true or not, about an individual who can be identified from that data or from that data together with other information to which an organisation has or is likely to have access.
This Policy should be read with the KumoDNS Terms of Service and Acceptable Use Policy. It does not apply to a customer’s independent handling of personal data outside KumoDNS’s Services, or to third-party sites and services governed by their own policies.
KumoDNS acts for its own purposes when it manages accounts, contracts, billing, website operations, security, support, abuse reports, legal compliance and business administration. In that role, KumoDNS determines the purposes and means of handling the relevant personal data and is responsible for applicable obligations under Singapore’s Personal Data Protection Act 2012 (“PDPA”).
KumoDNS may process personal data on behalf of a business customer when the customer uses the Services to host or manage DNS data or supplies personal data for support or service operations under written instructions. In that role, the customer remains responsible for its notices, lawful basis, instructions and responses to individuals, while KumoDNS is responsible for obligations applicable to data intermediaries and the parties’ contract. If a request concerns customer-controlled data, KumoDNS may refer the requester to that customer.
Depending on how the Services are used, KumoDNS may collect the following categories:
Name, username, organisation, job title, business contact details, account identifiers, authentication settings and records needed to verify identity, authority or domain control.
Plan, order, subscription, invoice, payment status, billing contact and transaction reference. Payment-card details may be collected directly by an external payment provider rather than stored by KumoDNS.
Domain names, hosted zones, DNS records, nameserver configuration, DNSSEC-related data, record-change history, API activity, query metadata and service usage. Query statistics are aggregate daily totals for each zone — the number of queries answered and how many resolved normally, returned no such name, or failed. They are not per-query records and identify no individual.
IP address, browser and device type, operating system, referring page, pages or features used, session identifiers, approximate location inferred from IP address, and cookie or similar-technology data.
Emails, tickets, calls or chats, attachments, diagnostic information, survey responses, preferences and records of notices or consent.
Login attempts, access logs, threat indicators, fraud signals, reported domains or records, evidence supplied by reporters, investigation notes and communications with customers, providers, authorities or affected parties.
Data from authorised users, resellers, payment providers, registrars, registries, security researchers, threat-intelligence providers, public sources, law-enforcement bodies or other persons who report or help resolve an issue.
Please do not provide personal data that is unnecessary for the relevant purpose, particularly in DNS records, support attachments or abuse reports. Public DNS records can be queried globally and should not be used to publish secrets or private personal information.
KumoDNS may collect, use or disclose personal data for purposes that a reasonable person would consider appropriate in the circumstances, including to:
Where consent is required, KumoDNS will notify the individual of the relevant purposes and obtain consent in an appropriate form. Consent may also be deemed under the PDPA in applicable circumstances, including where an individual voluntarily provides personal data for an evident purpose, where handling is reasonably necessary to perform a contract, or where notification and opt-out requirements for deemed consent by notification are satisfied. KumoDNS may also handle personal data without consent where an exception under law applies.
An individual may withdraw consent for future collection, use or disclosure by contacting the DPO with reasonable notice. KumoDNS will explain likely consequences and will cease the relevant handling after a reasonable period unless continued handling is required or permitted by law. Withdrawal may prevent KumoDNS from maintaining an account, delivering a feature, providing support or fulfilling a requested transaction. It does not affect lawful handling that occurred before withdrawal.
The KumoDNS website and control panel use cookies and similar technologies for authentication, security and session continuity. The bot check on the signup and contact forms is provided by Cloudflare Turnstile, which sets its own. These are necessary for a service the user has requested: blocking them prevents sign-in and form submission from working.
The public website at www.kumodns.com also uses Google Analytics 4, which sets its own cookies (_ga and _ga_<id>) to measure how the site is used — pages visited, referring source, approximate location from IP address, and device and browser type. It is used to understand and improve the website. It is not used for advertising or remarketing, and the analytics data is not combined with a customer’s account. Google acts as a processor for this data; see how Google uses data from sites that use its services. Analytics is not used in the control panel.
Cookies can be controlled through browser settings, although blocking the cookies described above will prevent sign-in and form submission from working. Analytics cookies can be refused without affecting the website, and Google publishes a browser add-on that opts out of Google Analytics on every site. KumoDNS does not use cookies or similar technologies for advertising or marketing measurement. If that changes, this Policy will be updated and any consent required will be obtained before the change takes effect.
KumoDNS does not currently send marketing communications. Operational, security, account, billing and policy notices are not marketing and are sent as part of providing the Services. If KumoDNS begins sending marketing, this Policy will be updated first, every message will carry a working opt-out, and any marketing calls, texts or faxes to Singapore telephone numbers will comply with applicable Do Not Call requirements, consent rules, identification requirements and opt-out obligations.
KumoDNS may disclose personal data only where reasonably necessary for the purposes described above, including to:
KumoDNS does not sell personal data for monetary consideration.
KumoDNS is based in Singapore, but service providers, infrastructure, support personnel or recipients may be located outside Singapore. Where KumoDNS transfers personal data overseas, it will take appropriate steps required by the PDPA to ensure that the recipient is bound to protect the transferred data to a standard comparable to the PDPA, unless a lawful exception applies. Measures may include contractual obligations, due diligence, recognised certifications or other legally enforceable safeguards.
KumoDNS retains personal data only for as long as needed for the purpose collected or another legal or business purpose. Retention depends on the account lifecycle, contract and limitation periods, security needs, dispute or investigation holds, financial record requirements, backup cycles and customer instructions. When personal data is no longer needed, KumoDNS will delete it, anonymise it, or remove the means by which it can reasonably be associated with an individual.
The periods below apply unless a longer one is required by law, or by an unresolved dispute, investigation, legal hold or regulatory request. Where a record is needed for more than one purpose, the longest applicable period governs it.
| Data category | Retention considerations | Approved period |
|---|---|---|
| Account and contract records | Account term, disputes and legal limitation periods | Your account is closed and removed from our live systems after a short settling period — currently 180 days, long enough for a final invoice, a refund or a card dispute to arrive. A limited record is then held in a separate restricted archive for 6 years from closure: your billing name and address, the plan and price agreed, and the closure record. That is the limitation period for a contract claim, and the archive is reachable only by the people who handle finance and legal matters. |
| Billing and transaction records | Accounting and legal record requirements | 5 years from the end of the financial year they relate to, as required for accounting records. Note that this is longer than 5 years from the invoice date — an invoice issued early in a financial year is kept until 5 years after that year ends. This covers two kinds of record. Invoices and credit notes are kept for that period and are also held in the same restricted archive described above, so a copy survives the account itself. Payment records — the card brand and last four digits, the payment reference, and whether the payment succeeded or was declined — are kept for the same period in the live system. If your account is closed, a copy of those payment records is also placed in the same restricted archive at the point of closure and is kept there for that same period, measured from the end of the financial year concerned; when that period ends the archived copy is deleted too. Both are kept for longer where an unresolved dispute, chargeback, investigation or legal hold requires it. |
| DNS configuration and audit history | Service operation, recovery and security | Record change history 180 days. Administrative audit history 365 days. Zone version snapshots for the Time Machine window included in the plan, and in every case the most recent version is kept while the zone exists. |
| DNS query and security logs | Threat detection, troubleshooting and capacity | Sign-in and API logs 90 days. Platform error and DNS synchronisation logs 30 days. Aggregate per-zone query counts, which identify no individual, 24 months. |
| Support and abuse cases | Resolution, recurrence and evidence preservation | 2 years after the case is closed, or longer where an unresolved dispute, investigation or legal hold requires it. |
| Backups | Rotation schedule and recovery integrity | Backups are kept to the rotation in operation and are not used to restore data deleted on request. Data removed from live systems is removed from backups within one full rotation cycle. |
KumoDNS will make reasonable security arrangements to protect personal data in its possession or control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. Measures may include access controls, authentication, encryption where appropriate, network and endpoint safeguards, logging, vulnerability management, backups, vendor controls, staff confidentiality and incident response. Security is a shared responsibility: customers must protect credentials, assign access carefully, review account activity and avoid placing sensitive personal data in public DNS records.
No system is completely secure. Individuals should notify Contact us promptly if they suspect unauthorised access or a privacy or security incident.
KumoDNS maintains procedures to identify, contain, assess and remediate data breaches. Where KumoDNS is the responsible organisation and a breach is notifiable under the PDPA, KumoDNS will notify the Personal Data Protection Commission as soon as practicable and no later than the applicable statutory deadline after determining that notification is required, and will notify affected individuals as soon as practicable where required. Where KumoDNS acts as a data intermediary, it will notify the relevant customer or public agency without undue delay after it has credible grounds to believe a breach has occurred, so that the responsible organisation can assess its notification obligations.
KumoDNS will make reasonable efforts to ensure that personal data it collects is accurate and complete where it is likely to be used to make a decision affecting an individual or disclosed to another organisation. Account holders should keep profile, billing, administrative and recovery contacts current and notify KumoDNS of material errors.
Subject to the PDPA and applicable exceptions, an individual may request access to personal data about the individual in KumoDNS’s possession or control and information about how it was used or disclosed during the preceding year. An individual may also request correction of an error or omission. KumoDNS may verify identity and authority, request information needed to locate the data, charge a reasonable access fee after giving a written estimate, or refuse or limit a request where permitted or required by law.
Requests should be made through KumoDNS's privacy request form, marked for the attention of the Data Protection Officer, and should include the requester's name, contact details, relationship with KumoDNS, account or ticket reference, the data or correction requested and suitable identity verification. KumoDNS will respond as soon as reasonably possible and within applicable statutory timelines. If more time is needed, KumoDNS will provide the required written notice. Where KumoDNS holds data solely for a customer, the request may need to be directed to that customer. A request covers the restricted archive described in section 11 as well as live systems: data held there for accounting or legal reasons is still personal data, and is searched and reported like anything else.
The Services are intended for businesses and persons at least 18 years old. KumoDNS does not knowingly offer accounts directly to children. If KumoDNS learns that it collected a child’s personal data without appropriate authority or another lawful basis, it will take reasonable steps to delete or otherwise address the data. A parent or guardian may contact the DPO with a concern.
KumoDNS may link to or interoperate with third-party websites, registrars, registries, payment providers and other services. Their privacy practices are governed by their own notices. KumoDNS is not responsible for independent third-party processing, although KumoDNS remains responsible for its own vendor selection and transfer obligations where the third party processes personal data for KumoDNS.
KumoDNS may update this Policy to reflect legal, regulatory, technical or operational changes. The current version will be posted at https://www.kumodns.com/privacy.php with its effective date. KumoDNS will provide appropriate notice of material changes and obtain fresh consent where required. Earlier versions should be archived for accountability.
Questions, complaints, withdrawal requests and access or correction requests should first be directed to KumoDNS through its contact form, marked for the attention of the Data Protection Officer. KumoDNS will investigate and respond within a reasonable time. Individuals may also contact the Personal Data Protection Commission through its official channels if they remain concerned, but KumoDNS encourages direct contact first so it can attempt to resolve the matter.
| Organisation | KumoDNS |
| UEN / registration no. | 53530479W |
| Registered address | 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051 |
| Data Privacy Contact | privacy@kumodns.com |