Compliance

Subprocessors

ZentraLink is self-hosted. Apart from your hosting provider, every external service is opt-in - you only engage subprocessors that you have configured. The lists below reflect the components in the codebase.

Always engaged

Your hosting provider

Where the Ubuntu host runs (e.g. Hetzner, IONOS, on-prem).

Purpose: Run the ZentraLink application and PostgreSQL.

Location: Operator choice - default install guides target Germany.

Let's Encrypt (optional)

TLS certificate authority used by the install script's certbot integration.

Purpose: Issue certificates for the marketing and dashboard domains.

Location: Global anycast (USA-based root CA).

IANA RDAP bootstrap

https://data.iana.org/rdap/dns.json - read-only lookup table.

Purpose: Find the right RDAP server for each TLD.

Location: Global anycast.

Engaged on demand

DNS provider APIs

Cloudflare, Hetzner DNS, DigitalOcean, AWS Route53, PowerDNS, IONOS, Gandi, GoDaddy, Namecheap, OVH or Porkbun - only the providers you connect.

Purpose: Read and write the zones the customer has explicitly linked to ZentraLink; for registrars (Cloudflare, IONOS, Gandi, GoDaddy, Namecheap, OVH, Porkbun) also fetch registration / expiry / lock metadata.

Location: Per provider (EU / global).

DENIC port-43 WHOIS (only when a .de domain is monitored)

Single TCP query to whois.denic.de:43 carrying the bare domain name; no contact data is requested or returned.

Purpose: Fill the registry-status + DNSSEC fields for .de domains - DENIC operates no RDAP server, so this is the only machine-readable lookup. Disable per deployment with WHOIS_DISABLE=1.

Location: Germany (EU).

SMTP provider

Whichever transactional mail provider you point ZentraLink at (e.g. Mailgun, Postmark, your own postfix).

Purpose: Deliver notification emails and reports.

Location: Per provider; configurable per account.

Mollie (optional)

Payment provider, only when Mollie is configured for billing.

Purpose: Process subscription payments.

Location: Netherlands (EU).

Last updated: deployment of this codebase. We do not engage any analytics or behavioural tracking provider on the marketing site or the dashboard.