Effective Date:July 29, 2026 Last Updated: July 29, 2026
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "Last Updated" date. We encourage you to review this policy periodically.
1. Introduction & Scope
This Privacy Policy applies specifically to all official WhoisFreaks Connectors, Plugins, Extensions, and Integration Apps (collectively, "Connectors") available on third-party automation and workflow platforms, including but not limited to Microsoft Power Platform (Power Automate, Power Apps, Azure Logic Apps, Microsoft Copilot Studio), Zapier, Make, n8n, and any future official connectors released under the WhoisFreaks brand.
This policy explains how WhoisFreaks processes, handles, and protects data when you connect your workspace or automated workflows to WhoisFreaks services through our platform connectors.
This policy does not cover the WhoisFreaks main website, API dashboard, or general account services except where they directly relate to Connector authentication and usage. Those services are governed by the main WhoisFreaks Privacy Policy available at whoisfreaks.com.
Third-party platforms.Each host platform (Microsoft, Zapier, Make, n8n, etc.) has its own, separate privacy policy governing how it stores your credentials, logs workflow activity, and handles your account on that platform. This policy covers only WhoisFreaks' own processing once a request reaches our servers. We encourage you to also review the relevant host platform's policy.
2. Definitions
- Connector: an official WhoisFreaks integration, plugin, or app distributed on a third-party automation platform.
- Host Platform: the third-party platform (e.g., Zapier, Make, n8n, Microsoft Power Platform) through which a Connector is accessed.
- Connector Request Input: any parameter (domain, IP, DNS query, etc.) submitted by a user when triggering a Connector action.
- Personal Data:any information relating to an identified or identifiable natural person, as defined under GDPR/UK-GDPR, or "Personal Information" as defined under CCPA/CPRA.
- Sub-processor: a third party engaged by WhoisFreaks to process data on our behalf.
3. Legal Entity & Contact Information
This Connector Privacy Policy is issued by:
- Operating Legal Entity: Jfreaks Software Solutions (doing business as WhoisFreaks)
- Country of Establishment: United States
- Registered Business Address: 7345 West Sand Lake Road Ste 210, Orlando, Florida, United States
- Website: https://whoisfreaks.com
- Dedicated Privacy Email: [email protected]
For GDPR / UK-GDPR inquiries, questions regarding EU/UK representative status, or to request a Data Processing Addendum (DPA), please contact [email protected].
4. Understanding Our Privacy Role
To ensure transparency under global privacy frameworks (including GDPR, UK-GDPR, and CCPA/CPRA):
- WhoisFreaks as a Data Controller: WhoisFreaks acts as a data controller for account registration, authentication, billing, fraud prevention, server logs, API usage monitoring, platform security, and support requests related to your WhoisFreaks account.
- WhoisFreaks as a Data Processor / Service Provider: When processing Connector request inputs solely to execute and return API query results on behalf of a customer within their automated workflow, WhoisFreaks acts as a data processor (under GDPR/UK-GDPR) or service provider (under CCPA/CPRA). Business customers requiring a signed Data Processing Addendum may request one via [email protected].
Legal Basis for Processing (GDPR/UK-GDPR)
Where WhoisFreaks acts as a controller, we rely on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account authentication, API key issuance | Performance of a contract |
| Billing and subscription management | Performance of a contract; legal obligation |
| Security monitoring, fraud/abuse prevention | Legitimate interest |
| Server and access logs | Legitimate interest |
| Responding to support requests | Performance of a contract; legitimate interest |
Where WhoisFreaks acts as a processor (executing Connector requests on your behalf), our legal basis is the instruction of the controller i.e., you or your organization, under the applicable terms of service or DPA.
5. Information We Process
A. Authentication Credentials
We do not collect or receive the passwords or authentication credentials for your Microsoft, Zapier, Make, n8n, or other host-platform accounts.
We process your WhoisFreaks API key solely to authenticate API requests and enforce applicable subscription rate limits. The host integration platform is responsible for storing and protecting the API key within its own connection or credential-management system. That storage is governed by the host platform's security practices, terms, and privacy policy. WhoisFreaks receives the key only when necessary to authenticate requests.
B. Connector Request Inputs
When a Connector action is executed, the parameters selected or provided by the user such as domain names, IP addresses, email addresses, and DNS query parameters are transmitted to the WhoisFreaks API solely to process and return the requested result.
These parameters are processed only for the purpose of fulfilling the specific API request. They are not used for marketing, profiling, advertising, or any secondary purpose.
C. Upstream Data Sources
Where necessary to fulfill a request, WhoisFreaks may query authoritative or publicly available sources (such as WHOIS/RDAP registries or DNS infrastructure) using WhoisFreaks infrastructure. We do not intentionally transmit the user's host-platform account identity or unrelated workflow metadata to those sources. Only the query parameters necessary to fulfill the requested lookup may be processed by the relevant source.
D. Technical & Usage Data
We may process limited technical data such as request timestamps, response status codes, and aggregated usage metrics for security monitoring, rate-limit enforcement, system stability, and service improvement. This data is not linked to individual end-users of your workflows beyond what is necessary for account-level quota management.
E. Cookies & Tracking Technologies
The Connectors themselves are server-to-server integrations and do not set cookies, browser storage, or client-side tracking technologies. Cookie usage, if any, on the main WhoisFreaks website or dashboard is governed separately by the main WhoisFreaks Privacy Policy at whoisfreaks.com.
6. How We Use the Information
We use the information described above only for the following purposes:
- Authenticating and authorizing API requests
- Executing the requested WHOIS, DNS, or related lookup and returning the result
- Enforcing subscription plan limits and preventing abuse
- Maintaining the security, integrity, and availability of our services
- Troubleshooting, auditing, and improving the Connectors
- Complying with legal obligations
We do not sell personal information. We do not use Connector request data for advertising or to build marketing profiles.
7. Data Retention Schedule
| Data Category | Retention Period & Handling Criteria |
|---|---|
| Connector Request Inputs | Processed transiently in memory only. Discarded immediately after the API response is returned. Not persistently stored in databases. |
| API Response Data | Generated dynamically and returned to the host platform. Not persistently stored in WhoisFreaks databases. |
| Nginx Web Access Logs | Retained for a maximum of 30 days for security auditing, system stability, and troubleshooting, then automatically purged. |
| API Key Records & Hashes | Retained for as long as your WhoisFreaks account remains active. Instantly invalidated when a new key is generated. |
| Aggregated Usage & Quota Records | Retained for the lifetime of the active account to measure quota limits, calculate usage statistics, and maintain plan history. |
| Account & Billing Records | Retained for as long as your WhoisFreaks account remains active. |
| Support Communications | Retained for lifetime to handle follow-up queries and maintain service records. |
| System Backups | Encrypted backups expire and roll over on a strict 7-day rolling retention cycle. |
Upon account closure, data categories not subject to a statutory retention requirement (e.g., accounting or tax law) are deleted or anonymized within a commercially reasonable period, consistent with the schedule above.
8. Data Security
- Encryption in Transit: All communication between host automation platforms and WhoisFreaks servers is encrypted using industry-standard HTTPS / TLS 1.2+ protocols.
- Header-Based Authentication: Connector API keys are transmitted via secure HTTPS Authorization headers (not as plaintext URL query parameters) so they are excluded from standard web server access logging.
- Key Storage: API keys stored in the WhoisFreaks account system are hashed at rest.
- Access Controls: Internal access to systems that process Connector data is restricted on a need-to-know basis and protected by multi-factor authentication and logging.
- Incident Response & Breach Notification: In the event of a confirmed security incident affecting personal data processed through the Connectors, WhoisFreaks will notify affected customers and, where legally required, relevant supervisory authorities without undue delay and in accordance with applicable law (including, where applicable, the 72-hour notification standard under GDPR Article 33).
9. International Data Transfers
WhoisFreaks is based in the United States. Due to the globally distributed nature of cloud infrastructure and network services, data processed through the Connectors may be handled in the United States and other countries where WhoisFreaks or its service providers operate.
10. Sub-Processors
We do not engage third-party sub-processors to process Connector request inputs or responses beyond the upstream authoritative sources (WHOIS/RDAP registries and DNS infrastructure) that are required to fulfill the requested lookup. Those upstream sources operate independently and are not under our control. A current list of any additional infrastructure sub-processors (e.g., hosting providers) is available upon request at [email protected].
11. Your Rights & Choices
Managing Access
- You can revoke Connector access at any time by deleting the WhoisFreaks connection within your host platform's connection settings.
- Generating a new API key in your WhoisFreaks User Dashboard instantly invalidates all prior keys across active Connectors.
Data Subject Rights
Depending on your jurisdiction (including the EU, UK, California, and other applicable regions), you may have the following rights regarding your personal data:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent (where processing is based on consent)
- Right to lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, please contact us at [email protected]. We will respond to valid requests within 30 days, or such other timeframe as required by applicable law, and may extend this period where legally permitted, in which case we will notify you.
California Residents (CCPA/CPRA)
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act. California residents may submit requests to know, delete, or correct personal information, or to opt out of any sale/sharing, by contacting [email protected]. We will not discriminate against you for exercising any of these rights.
12. Children's Privacy
The WhoisFreaks Connectors are business and developer tools not directed at children. We do not knowingly collect personal information from children under 13 (as defined under COPPA) or under 16 where a higher minimum age applies under local law (e.g., GDPR-adjacent jurisdictions). If you believe we have inadvertently collected such information, please contact us at [email protected] so we can delete it.
13. Automated Decision-Making
We do not use Connector data to make solely automated decisions that produce legal or similarly significant effects concerning individuals.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page. Where changes are significant, we will make reasonable efforts to provide additional notice (e.g., via email or an in-product notice) before they take effect. Continued use of the Connectors after the effective date of any changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Postal Address: Jfreaks Software Solutions
7345 West Sand Lake Road Ste 210
Orlando, Florida, United States
We will respond as promptly as possible and in accordance with applicable law.