Legal

GDPR Policy

Last updated September 4, 2026

This policy explains how LastRedirect meets its obligations under the EU General Data Protection Regulation (and the UK GDPR, where it applies) for account holders in the EEA and UK. It supplements, and should be read alongside, our Privacy Policy.

1. Data controller

LastRedirect is the data controller for the account data described in our Privacy Policy: your email address, the website and backup URLs you configure, and your billing information. For the limited visitor event data described in section 3, we act as your processor: it is collected on your behalf, used only to produce the statistics on your dashboard, and never repurposed by us. You remain the controller for your website's visitors and are responsible for disclosing this collection in your own privacy notice. Questions or requests about your data can be sent to privacy@lastredirect.com. LastRedirect is not required to, and has not, appointed a formal Data Protection Officer; the address above reaches the people responsible for data protection.

2. Legal basis for processing

We rely on performance of a contract for your email, configured URLs, and billing details — using them to create your account, generate your install script, and provide the service you signed up for. We rely on legitimate interests to send service notices (such as a failover being triggered on your site) and to detect fraud or abuse of the service. We rely on legal obligation to retain billing records for as long as tax law requires.

We do not rely on consent for account data, since it is necessary to provide the service you requested. Where we ever do rely on consent (for example, an optional product update email), you can withdraw it at any time.

3. Categories of personal data

Account holder data: your email address, the website and backup URLs you configure, and billing information processed by our payment processor, Stripe.

Visitor event data. The service worker sets no cookies and does not track anyone across websites, but it does report a check-in when it installs or starts up and a record of each failover redirect. Each carries the entry path of the page involved, with query strings and fragments stripped, and from the request we derive a truncated IP address, a coarse location (country and city), the network operator, and the browser, operating system and device type. Full IP addresses are used only for the location lookup and are never stored. These records exist solely to produce your dashboard statistics and are deleted automatically 30 days after creation. They are not used for advertising, not sold, and not combined with data from other websites.

4. Your rights

Under the GDPR, you have the right to access the personal data we hold about you, correct inaccurate or incomplete data, erase your data (the "right to be forgotten"), restrict or object to certain processing, receive your data in a portable, machine-readable format, and withdraw consent where processing is based on consent.

You can review, update, or delete your account and its data directly from your Profile page. For anything not available there, including a portability request, email privacy@lastredirect.com — we respond within 30 days, as required by Article 12.

5. International transfers

Two subprocessors may handle your data outside the EEA: Stripe for billing, and Resend for transactional email (magic links, receipts, service notices). Where either transfers data outside the EEA or UK, we rely on the safeguards they provide, such as Standard Contractual Clauses.

6. Data retention

We retain account data for as long as your account is active. When you delete your account, we remove your configured websites and personal information within 30 days, except billing records we are required to retain for tax purposes. Visitor event data (section 3) expires on its own 30 days after each record is created, whether or not your account is still active.

7. Automated decision-making

We do not use your personal data for profiling or automated decision-making that produces legal or similarly significant effects. The failover redirect itself is a fixed rule applied to a website's availability, not a decision made about any individual.

8. Children's data

LastRedirect is not directed at children, and we do not knowingly collect personal data from anyone under 16.

9. Lodging a complaint

If you believe we have not handled your data in line with the GDPR, you can contact us first at privacy@lastredirect.com so we can address it directly, or lodge a complaint with the data protection supervisory authority in your country of residence at any time.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or an in-product notice.

11. Contact

Questions about this policy or your data can be sent to privacy@lastredirect.com.