We route other companies' traffic, terminate TLS for domains we do not own, and touch DNS across many providers. That means real legal and compliance surface: data processing agreements, privacy law, a subprocessor chain, and contracts with registrars and DNS providers. This is a contract role for counsel who can handle privacy and commercial work for an infrastructure product and give plain, practical answers rather than long memos. You will help us build a compliance posture our customers can trust and verify.
What you will do
• Draft and maintain our data processing agreements and keep the subprocessor list accurate as our provider and infrastructure chain changes.
• Own privacy compliance, including GDPR and CCPA, for a product that proxies traffic and handles domain and DNS data.
• Build our customer MSAs and terms so they are fair, transparent, and hold up when an enterprise customer's legal team reads them.
• Handle the registrar, reseller, and ICANN-adjacent contracts that sit under our domain search, purchase, and transfer flows.
• Support our security and compliance posture, including the documentation customers ask for during vendor review.
What we are looking for
• You have done privacy and commercial work for a SaaS or infrastructure company and know DPAs and subprocessor obligations well.
• You are fluent in GDPR and CCPA and can apply them to a product that handles traffic and DNS data, not just marketing lists.
• You draft contracts that are transparent and defensible, and you explain the tradeoffs in plain language.
• You are comfortable being the practical legal partner to a small team that moves quickly.
Bonus
• You have worked on registrar, reseller, or ICANN-adjacent agreements.
• You have helped a company reach SOC 2 or a similar security posture and know what customers actually ask for.
• You have supported infrastructure or developer-tools companies where the data flow itself is the legal question.