This Privacy Policy explains what personal data we collect, the sources from which we obtain it, the purposes and legal grounds on which we process it, to whom we may transfer it, how long we retain it, as well as what rights the personal data subject has and how to exercise them.

Hosting.XYZ LTD is the personal data owner and, where the European Union General Data Protection Regulation (GDPR) applies, the personal data controller. The Policy applies to website visitors, registered Subscribers, their representatives, and other persons whose personal data are processed by the Provider.

1. PURPOSES AND LEGAL GROUNDS FOR PROCESSING

1.1. The Provider is the owner of the personal data processed in accordance with this Policy. This Policy is an integral part of the Public Offer and applies to website users, registered Subscribers, and representatives of Subscribers.

1.2. Personal data are processed for the purposes of:

  • registering and maintaining an account;
  • entering into and performing the agreement;
  • arranging, providing, renewing, and terminating the Services;
  • conducting settlements and generating invoices, statements, and other documents;
  • providing technical support and communicating with the Subscriber;
  • registering, renewing, transferring, and servicing domain names;
  • ensuring the operation and security of the website, Control Panel, and Services;
  • detecting and preventing fraud, abuse, unauthorized access, and other unlawful activities;
  • remedying technical malfunctions and protecting the rights, property, and legitimate interests of the Provider, its customers, and third parties;
  • complying with legal requirements, court decisions, and lawful demands of authorized bodies;
  • asserting, substantiating, and defending legal claims.

1.3. Depending on the purpose, the legal grounds for processing personal data are:

  • entering into and performing the agreement or taking actions necessary to enter into it;
  • fulfilling the Provider’s obligations prescribed by law;
  • protecting the legitimate interests of the Provider or a third party, unless the rights and freedoms of the personal data subject override such interests;
  • the consent of the personal data subject — in cases where such consent is required by law.

If processing is based on consent, the personal data subject may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal or processing performed on other lawful grounds.

1.4. Data provided by the user.

During registration, order placement, receipt of Services, verification, or contact with the support service, the Provider may collect personal data necessary for the relevant purpose.

Depending on the Services used by the person, such data may include:

  • first name, last name, and patronymic;
  • the name and details of a legal entity or individual entrepreneur;
  • email address, telephone number, and postal address;
  • account data and means of its identification;
  • payment, settlement, and tax data;
  • information about orders and Services received;
  • data required for the registration and servicing of domain names;
  • documents and information required for identity verification;
  • the content of support requests and correspondence with the Provider.

The specific composition of the data is determined by the purpose of its processing and is indicated in the relevant form or when it is obtained. The Provider may request additional data only when it is objectively necessary for the provision of a Service, identity verification, ensuring security, or compliance with legal requirements, with the purpose of such request specified.

1.5. Cookies and similar technologies

The website may use cookies, local storage, and other similar technologies for:

  • the operation of the website, Control Panel, and authentication tools;
  • saving the selected language and other settings;
  • ensuring security and preventing fraud;
  • analyzing website use and improving its operation;
  • personalizing content;
  • displaying advertising and evaluating its effectiveness.
  • 1.6. Technical information and visit logs

When the website, Control Panel, and Services are used, the Provider’s information systems may automatically record technical information, including:

  • IP address;
  • date and time of the request;
  • address of the requested page or resource;
  • address of the page from which the user was referred;
  • browser type and version;
  • device and operating system type;
  • browser language;
  • session identifiers;
  • information about errors and request execution results.

This information is processed to ensure the operation and security of systems, authenticate users, diagnose malfunctions, prevent abuse and fraud, investigate incidents, and compile aggregated statistics. Its retention period is determined in accordance with the purpose of processing and the rules established by this Policy.

1.7. Data obtained from partners

If a user orders Services through a partner website or another partner service, the Provider may receive from the relevant partner the data necessary to arrange and fulfill the order. Such data may include identification and contact details, information about the ordered Service, its payment, and the order fulfillment status.

The Provider processes personal data obtained from partners in accordance with this Policy. Information about the partner, the composition of the data, the purpose of its transfer, and the role of each party in personal data processing must be provided to the user when placing the order or before the data are transferred.

1.6. The Provider may process personal information on servers in the USA, the EU, Ukraine and in other countries. In some cases, users’ personal data are processed outside the user’s country.

2. ACCESS TO AND TRANSFER OF PERSONAL DATA

2.1. The Provider grants access to personal data or transfers it to third parties only where there is a proper legal basis and to the extent necessary to achieve the specified purpose. 
Personal data may be provided or transferred in the following cases:

2.1.1. With the consent of the personal data subject. If consent is the legal basis for the transfer, data are transferred only to the recipients specified in the consent, for the stated purposes, and to the agreed extent.

2.1.2. For the provision of Services. The Provider’s employees, contractors, and service providers, including providers of payment, communication, information, technical, and other ancillary services, may gain access to personal data if such access is necessary for the performance of the agreement.

These persons receive only the necessary amount of data and are obliged to ensure its confidentiality, security, and use solely for the specified purpose.

2.1.3. For the registration and servicing of domain names. Registration data may be transferred to registrars, resellers, Registry Operators, domain zone administrators, ICANN, ICANN-approved escrow agents, domain dispute resolution service providers, and other recipients stipulated by the rules of the relevant domain zone.

With the Subscriber’s consent, registration data may be published in WHOIS, RDAP, or other registration data services or disclosed in response to lawful requests only in the cases and to the extent prescribed by law, the rules of the relevant domain zone, and applicable ICANN policies.

2.1.4. To comply with legal requirements. Personal data may be provided to courts, law enforcement agencies, public authorities, local government bodies, and other persons entitled to receive it under the law. Data are provided on the basis of a duly executed demand, court decision, or other legal ground prescribed by law and only to the extent necessary to comply with the relevant demand.

2.1.5. In response to an attorney’s request. Receipt of an attorney’s request is not an unconditional ground for disclosing personal data. Information is provided only when its disclosure is permitted by law, the personal data subject has provided the relevant consent, or another proper legal basis exists.

2.1.6. To ensure security and protect rights. Personal data may be transferred to competent authorities, professional advisers, or other appropriate recipients if this is objectively necessary and permitted by law for:

  • detecting, stopping, or preventing fraud and other unlawful activities;
  • investigating information security incidents;
  • remedying technical malfunctions;
  • protecting the life, health, rights, property, or security of the Provider, its users, or third parties;
  • asserting, substantiating, or defending legal claims.

Before the transfer, the Provider assesses its necessity, legal basis, and the possibility of limiting the amount of data.

2.2. Personal data are not transferred if the relevant purpose can be achieved without such transfer or by using anonymized data, except where the transfer is expressly required by law.

2.3. The Provider may transfer personal data to third parties if this is necessary to achieve the purposes specified in this Policy, perform the agreement, or comply with legal requirements. Such persons may include banks, financial institutions, payment systems, providers of technical and information services, telecommunications operators, auditors, consultants, public authorities, and other duly authorized recipients.

Only the personal data necessary for the relevant recipient for the specified purpose are transferred.

2.4. For the registration, renewal, transfer, and servicing of domain names, registration data may be transferred to registrars, resellers, Registry Operators, domain zone administrators, ICANN, ICANN-approved escrow agents, domain dispute resolution service providers, as well as other persons to whom the transfer of data is stipulated by the rules of the relevant domain zone or by law.

Registration data may be published in WHOIS, RDAP, or other registration data services or provided in response to duly executed lawful requests only to the extent and in the cases prescribed by the applicable domain zone rules, ICANN policies, and law.

2.5. Personal data are not used for a purpose incompatible with the purpose for which they were collected. If the Provider intends to carry out processing for a new, incompatible purpose, it shall notify the personal data subject in advance and obtain separate consent, unless another legal basis for such processing is prescribed by law.

3. INFORMATION SECURITY

3.1. We take all necessary measures to protect data from unauthorized access, alteration, disclosure, or destruction. These measures include, in particular, internal review of data collection, storage, and processing procedures and security measures, including appropriate encryption and measures to ensure the physical security of data to prevent unauthorized access.

4. RETENTION, UPDATING, AND DELETION PERIODS

4.1. We do everything in our power to provide you with access to your personal data and either correct it if it is inaccurate or delete it at your request, unless its retention is required by law or justified by legitimate business purposes. Before processing requests, we ask users to confirm their identity and the information they wish to access, correct, or delete.

4.2. Personal data are retained for the term of the agreement and, after its termination, no longer than necessary to conduct settlements, comply with accounting, tax, and other legal requirements, comply with domain name registration rules, and assert, substantiate, or defend legal claims.

Upon expiry of the relevant period, personal data are deleted, destroyed, or anonymized unless their further retention is required by law.

4.3. The Subscriber has the right to contact the Provider to access, correct, update, or delete their personal data. To protect the data, the Provider has the right to require confirmation of the applicant’s identity.

The Subscriber is obliged to keep the data they have provided accurate and up to date and to notify the Provider promptly of any changes.

4.4. Personal data are deleted at the substantiated request of the personal data subject, except where their processing or retention is necessary for the performance of a valid agreement, compliance with legal requirements, domain name registration rules, or the assertion, substantiation, or defense of legal claims.

If deletion of the data makes it impossible to identify the Subscriber or continue providing the Services ordered by them, the Provider shall notify the Subscriber thereof. In such a case, the relevant Services or Agreement may be terminated.