Help Center

Trustame Privacy Policy

Fewmoretaps OÜ doing business as Trustname

Effective Date: 9 August 2026


Trustname is committed to protecting privacy while providing secure, reliable domain name registration and related Internet services.


This Privacy Policy explains how Fewmoretaps OÜ doing business as Trustname (“Trustname”, “we”, “us”, or “our”) collects, uses, verifies, stores, transfers, discloses and otherwise processes personal data when you use our websites, account systems, APIs, domain registration services and other products or services (collectively, the “Services”).


This Policy also explains the specific treatment of domain name Registration Data, including registrations using Trustname's Suggested Default Contact Proxy Service and Two-Tier Privacy.

This Policy should be read together with the Trustname Universal Terms of Service, Domain Name Registration Agreement, NIS2 Domain Name Registration Data Verification Policy, applicable Privacy/Proxy Service terms, Cookie Policy, and any product-specific privacy notice applicable to a Service you use.


1. Who Is Responsible for Your Personal Data

For the processing described in this Privacy Policy, the primary data controller is:

Fewmoretaps OÜ doing business as Trustname
Legal and Privacy Department
Roseni tn 13
Harju maakond
Kesklinna linnaosa
Tallinn 10111
Estonia

Privacy and Data Protection Contact: [email protected]

Trustname is established in Estonia and is therefore established within the European Union.

For core Trustname activities—including account administration, domain name registration, Registration Data verification, fraud prevention, security, regulatory compliance, billing administration and legal-request handling—Trustname generally acts as a data controller.

For certain separately contracted hosted or business services, Trustname may process personal data on behalf of a customer as a data processor. Where applicable, that processing is governed by the relevant Data Processing Addendum or other product-specific agreement.

Registry Operators, payment providers, verification providers, Privacy/Proxy Service Providers, ICANN and other recipients may act as independent controllers, joint controllers or processors depending on the particular processing activity and applicable agreements.


2. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed through:

  • Trustname websites;

  • Trustname customer accounts and account panels;

  • domain name registration, transfer, renewal and management;

  • Privacy and Proxy Services;

  • DNS services;

  • reseller and API services;

  • hosting and server-related Services;

  • email Services;

  • SSL and security-related Services;

  • payment and billing systems;

  • customer support;

  • legal and compliance processes;

  • fraud, abuse and security systems;

  • marketing and promotional communications;

  • analytics and website technologies; and

  • other Trustname Services referring to this Policy.

Where a particular Service has a separate privacy notice, that notice supplements this Policy.


3. Categories of Personal Data We Collect

Depending on the Services you use, we may collect the following categories of information.

3.1 Account and Identity Information

This may include:

  • name;

  • legal entity name;

  • postal address;

  • country;

  • email address;

  • telephone number;

  • account username;

  • customer or account identifier;

  • preferred language;

  • account settings; and

  • information concerning an authorized representative.

3.2 Domain Name Registration Data

Depending on the TLD, registration structure and applicable requirements, this may include:

  • domain name;

  • date of registration;

  • Registered Name Holder information;

  • organization name;

  • postal address;

  • email address;

  • telephone number;

  • administrative or technical contact information where applicable;

  • Registry-generated identifiers;

  • nameserver information;

  • DNSSEC information;

  • registration, renewal and expiration dates;

  • registrar and Registry status information; and

  • other Registration Data required or permitted under applicable ICANN policy, Registry requirements or law.

3.3 Underlying Privacy/Proxy Customer Data

Where a Privacy Service or Proxy Service is used, Trustname may collect and maintain the underlying information of the Privacy/Proxy customer or licensee, including:

  • name or legal entity name;

  • postal address;

  • email address;

  • telephone number;

  • Account information; and

  • information reasonably required to identify or contact the underlying customer.

The use of a Privacy Service or Proxy Service does not eliminate the obligation to provide accurate underlying information to Trustname where such information is required.

3.4 Verification and Compliance Information

Depending on the circumstances, we may process:

  • email-verification results;

  • telephone or one-time-code verification results;

  • legal entity registration information;

  • public company or business-register information;

  • supporting documentation;

  • identity or authority documentation where reasonably required;

  • sanctions or compliance screening results where applicable;

  • fraud indicators;

  • risk indicators;

  • registration-data accuracy reports; and

  • records of verification and correction procedures.

We do not require identity documentation in every case. Verification measures depend on the Service, applicable law, Registry or ICANN requirements, risk and the circumstances of the transaction.

3.5 Transaction and Payment Information

This may include:

  • billing name and address;

  • payment method;

  • transaction amount;

  • currency;

  • invoice information;

  • transaction identifier;

  • payment-provider identifier;

  • refund information;

  • chargeback information;

  • cryptocurrency transaction or wallet-related information where applicable; and

  • fraud and payment-risk indicators.

Where payment information is entered directly into a payment provider's systems, the payment provider may process sensitive payment credentials without providing the full credentials to Trustname.

3.6 Technical and Security Information

We may collect:

  • IP address;

  • date and time of access;

  • browser type;

  • operating system;

  • device characteristics;

  • language and regional settings;

  • login history;

  • API activity;

  • session identifiers;

  • security events;

  • authentication events;

  • referral source;

  • pages or functions accessed;

  • network and connection information;

  • cookies and similar identifiers; and

  • device or browser signals reasonably used for security and fraud prevention.

3.7 Customer Support and Communications

We may retain:

  • support tickets;

  • emails;

  • live-chat communications;

  • complaint records;

  • escalation records;

  • telephone or other support records where applicable;

  • legal correspondence;

  • documents submitted to Trustname; and

  • other communications relating to your Account or Services.

3.8 Abuse, Security and Legal Information

Where relevant, we may process:

  • abuse complaints;

  • DNS Abuse reports;

  • cybersecurity reports;

  • threat-intelligence information;

  • URLs and technical indicators;

  • screenshots and supporting evidence;

  • correspondence from rights holders;

  • court orders;

  • subpoenas;

  • governmental requests;

  • law-enforcement requests;

  • UDRP or URS documentation;

  • other dispute-resolution documentation; and

  • records of Trustname's review and response.

3.9 Marketing and Preference Information

This may include:

  • marketing preferences;

  • newsletter subscriptions;

  • campaign interactions;

  • referral information;

  • promotion use;

  • advertising identifiers where permitted; and

  • preferences concerning non-essential cookies.


4. How We Obtain Personal Data

We may obtain information:

Directly from You

For example, when you:

  • create an Account;

  • register or transfer a domain;

  • purchase a Service;

  • provide underlying Privacy/Proxy Customer information;

  • contact Support;

  • submit a legal or compliance request;

  • participate in a promotion;

  • update Account information; or

  • communicate with Trustname.

From Your Authorized Representative

This may include:

  • employees;

  • agents;

  • resellers;

  • technical administrators;

  • account managers; or

  • another person acting with your authority.

From Registries, Registrars and Domain Name Service Providers

We may receive information when:

  • a domain is transferred;

  • a Registry processes a transaction;

  • a reseller submits a registration;

  • registration information is synchronized;

  • a Registry provides status or lifecycle information; or

  • another registrar participates in a transfer or change.

From Payment and Fraud-Prevention Providers

We may receive transaction confirmations, fraud indicators, chargeback information and payment-related metadata.

From Verification and Public Sources

Where reasonably required, we may obtain information from:

  • public company registers;

  • governmental registers;

  • authoritative databases;

  • verification providers;

  • sanctions lists;

  • fraud-prevention providers; or

  • other lawful sources.

From Third-Party Reports

Information concerning a Domain Name or Account may be provided to us through:

  • abuse complaints;

  • registration-data accuracy reports;

  • cybersecurity reports;

  • legal complaints;

  • intellectual-property complaints;

  • court proceedings; or

  • law-enforcement or governmental requests.

Automatically

Certain technical information may be generated when you use our websites, APIs, Account systems or Services.


5. Why We Process Personal Data

Trustname processes personal data only where an appropriate legal basis exists.

Depending on the processing activity and applicable law, the legal basis may include:

  • performance of a contract;

  • steps requested before entering into a contract;

  • compliance with a legal obligation;

  • legitimate interests pursued by Trustname or another party;

  • consent, where consent is the appropriate legal basis;

  • establishment, exercise or defence of legal claims; or

  • another basis recognized by applicable law.

We do not treat acceptance of this Privacy Policy as blanket consent to every form of personal-data processing.


6. Performance of Our Contract With You

We process information where necessary to provide the Services you request.

This may include processing required to:

  • create and administer your Account;

  • register, transfer or renew a Domain Name;

  • process Domain Name modifications;

  • provide DNS or hosting Services;

  • process payments;

  • administer subscriptions;

  • operate Privacy and Proxy Services;

  • communicate about your Services;

  • provide customer support;

  • authenticate Account instructions;

  • provide API access; and

  • enforce applicable agreements.

Some information is necessary for us to provide a requested Service.

If required information is not provided, we may be unable to provide or continue the relevant Service.


7. Legal and Regulatory Obligations

Trustname may process personal data where necessary to comply with obligations arising under:

  • applicable European Union law;

  • applicable Estonian law;

  • applicable national law;

  • cybersecurity legislation;

  • NIS2 and applicable national implementing legislation;

  • ICANN agreements and Consensus Policies;

  • applicable Registry agreements and policies;

  • tax and accounting requirements;

  • court orders;

  • legally binding governmental requirements; or

  • other legal or regulatory obligations.

Processing necessary to satisfy a legal or regulatory obligation does not depend solely on your consent.


DOMAIN REGISTRATION DATA

8. Domain Registration Data

Domain name registration involves processing that differs from ordinary website or account processing.

Trustname may collect, maintain, verify, transfer, escrow, publish, redact, retain and disclose Registration Data where required or permitted by:

  • applicable ICANN policies;

  • the applicable Registry;

  • applicable Registry-Registrar Agreements;

  • NIS2-related requirements;

  • applicable law;

  • a binding dispute-resolution process; or

  • another applicable registration requirement.

The precise data processed and the parties receiving it may differ by TLD.


9. NIS2 Domain Registration Data

Where applicable NIS2 requirements or national implementing legislation apply, Trustname processes Registration Data for purposes including contributing to the security, stability and resilience of the Domain Name System.

Trustname maintains procedures designed to:

  • collect required Domain Name Registration Data;

  • maintain accurate and complete data;

  • verify Registration Data proportionately;

  • correct inaccurate data;

  • make applicable non-personal Registration Data publicly available where legally required;

  • receive lawful and duly substantiated requests for access to specific Registration Data; and

  • provide lawful access where the applicable requirements are satisfied.

Trustname's detailed verification procedures are described in the Trustname NIS2 Domain Name Registration Data Verification Policy.

Where applicable law imposes a particular response period for lawful and duly substantiated requests from legitimate access seekers, Trustname processes those requests within the legally applicable period.

The existence of a request does not itself establish an entitlement to personal Registration Data.


PRIVACY AND PROXY SERVICES

10. Suggested Default Contact Proxy Service

For eligible registrations using Suggested Default Contact, Perfect Privacy LLC acts as the Registered Name Holder and Proxy Service Provider.

The end customer is the P/P Customer and licensee and is not the Registered Name Holder while the Proxy Service remains active.

The P/P Customer must nevertheless provide Trustname with accurate underlying contact information.

Trustname maintains the required underlying customer information in non-public registrar records.

Trustname may process that information for:

  • domain administration;

  • operation of the Proxy Service;

  • verification;

  • security;

  • fraud prevention;

  • abuse investigation;

  • regulatory compliance;

  • support;

  • Registrar Data Escrow;

  • legal obligations;

  • dispute resolution;

  • lawful disclosure; and

  • enforcement of applicable agreements.

Trustname may provide underlying information to Perfect Privacy LLC where reasonably necessary for Perfect Privacy LLC to perform its obligations as Registered Name Holder, administer the Proxy Service, respond to a legally sufficient requirement, address an applicable domain dispute, or comply with the agreements governing the registration.

Underlying customer information is not made public merely because Suggested Default Contact is used.


11. Two-Tier Privacy and WHOISPPS

For eligible registrations, Trustname may also use WHOIS Privacy Protection Service LLC (“WHOISPPS”) as a second-layer Privacy Service.

Perfect Privacy LLC remains the Registered Name Holder and Proxy Service Provider.

WHOISPPS does not become the Registered Name Holder solely because WHOISPPS contact information or a WHOISPPS communication-relay mechanism is used in connection with the registration.

WHOISPPS may provide alternative reliable contact information or communication-relay functionality for use in RDAP/RDDS or equivalent registration-data systems to the extent permitted by applicable ICANN policy, Registry requirements and law.

Trustname does not provide the end customer's underlying personal Registration Data to WHOISPPS merely for operation of the standard second-layer Privacy Service.

If additional processing by WHOISPPS becomes necessary for a specific request, legal obligation or other exceptional circumstance, Trustname will process only the information reasonably necessary and only where an appropriate legal basis exists.


12. Registrar Data Escrow

Trustname deposits Registration Data into Registrar Data Escrow where required by applicable ICANN requirements.

For Privacy and Proxy Services offered or made available by Trustname or an applicable affiliated provider, this may include the required underlying information concerning:

  • customers of Privacy Services; and

  • licensees of Proxy Services.

Registrar Data Escrow is a non-public registration-data continuity safeguard.

The inclusion of underlying information in escrow does not make that information public and does not, by itself, authorize its disclosure to third parties.

Data held in escrow is subject to the applicable escrow arrangement and ICANN requirements.


13. Transfers to Registry Operators

A Registry Operator may require Trustname to transmit certain Registration Data in order to create, maintain, renew, transfer or administer a Domain Name.

The Registration Data transferred varies according to:

  • TLD;

  • Registry technical requirements;

  • applicable ICANN policy;

  • Registry agreements;

  • applicable law; and

  • the registration structure.

Trustname seeks to transmit only the Registration Data required or otherwise permitted for the applicable purpose.

Where applicable law requires a data-protection arrangement concerning such transfers, Trustname will use the applicable contractual or legal mechanism.


14. Public RDAP/RDDS Registration Data

Trustname may publish or make Registration Data available through:

  • RDAP;

  • RDDS;

  • WHOIS where still applicable;

  • a Registry-operated registration-data service; or

  • another applicable domain registration-data mechanism.

The information published depends on:

  • whether the registrant is a natural or legal person;

  • applicable ICANN policy;

  • applicable Registry implementation;

  • TLD-specific requirements;

  • use of a Privacy or Proxy Service;

  • applicable law; and

  • any valid consent to publication where consent is an appropriate legal basis.

Personal data are not made public merely because they form part of Trustname's registrar records.

Where Suggested Default Contact is active, Perfect Privacy LLC remains the Registered Name Holder.

Where Two-Tier Privacy is enabled, applicable Privacy Service information or alternative contact mechanisms may be displayed to the extent permitted by applicable requirements.

Underlying P/P Customer information is not made public merely because Trustname collects, verifies, retains or escrows it.


15. Legal-Person Registration Data

Registration Data relating to a company or other legal person may be treated differently from data relating to a natural person.

Where applicable law requires publication of non-personal Domain Name Registration Data concerning a legal person, Trustname may publish the required information.

A registration record concerning a legal person can still contain personal data—for example, a named employee's email address or telephone number.

Where appropriate, Trustname may distinguish between personal and non-personal elements of a legal-person registration before publication.


16. Requests for Non-Public Registration Data

Trustname may receive requests for access to non-public Registration Data from:

  • law-enforcement authorities;

  • courts;

  • governmental authorities;

  • cybersecurity authorities;

  • CERTs or CSIRTs;

  • dispute-resolution providers;

  • intellectual-property rights holders;

  • security researchers;

  • legal representatives;

  • other legitimate access seekers; or

  • other persons asserting a lawful basis for access.

A request does not automatically create a right to disclosure.

Depending on the request, Trustname may assess:

  • requester identity;

  • authority to act;

  • legal basis;

  • jurisdiction;

  • purpose;

  • specificity;

  • supporting evidence;

  • necessity;

  • proportionality;

  • requested data;

  • data minimization;

  • applicable Privacy/Proxy procedures;

  • legal restrictions; and

  • procedural safeguards.

Trustname may request further information where needed to evaluate a request.

Trustname may reject, restrict or defer a request where it is:

  • incomplete;

  • inadequately substantiated;

  • overly broad;

  • disproportionate;

  • unlawful;

  • outside the requester's authority;

  • inconsistent with applicable data-protection requirements; or

  • otherwise insufficient to establish an appropriate basis for disclosure.

Where applicable NIS2 implementing law requires a response to a lawful and duly substantiated request from a legitimate access seeker within a specific period, Trustname applies the legally required timeframe.

Underlying P/P Customer data are not automatically disclosed merely because a standard Registration Data disclosure request has been submitted.

Privacy and Proxy Service disclosure procedures may additionally apply.


17. Court Orders, Subpoenas and Government Requests

Trustname reviews legal process before disclosing personal data.

Depending on the circumstances, we may assess:

  • authenticity;

  • issuing authority;

  • jurisdiction;

  • enforceability;

  • legal basis;

  • scope;

  • necessity;

  • proportionality; and

  • whether the requested information is held by Trustname.

Trustname may seek clarification or additional documentation where appropriate.

Trustname may disclose information where disclosure is legally required or otherwise supported by an applicable lawful basis.

Where legally permitted and appropriate, Trustname may notify the affected customer before or after disclosure.

Trustname may delay or withhold notice where:

  • notification is legally prohibited;

  • a binding order prohibits notification;

  • notification would create a material security risk;

  • notification could compromise a lawful investigation; or

  • another valid legal basis exists.


18. UDRP, URS and Domain Dispute Proceedings

Registration Data and related information may be processed or disclosed where reasonably necessary in connection with:

  • UDRP proceedings;

  • URS proceedings;

  • court proceedings;

  • applicable ccTLD dispute policies;

  • Registry disputes; or

  • another binding domain-name dispute mechanism.

The existence of a trademark, copyright or other complaint does not automatically mean that underlying personal data will be disclosed.


OTHER PROCESSING ACTIVITIES

19. Security, Fraud Prevention and Abuse Mitigation

Trustname has legitimate interests in protecting:

  • Accounts;

  • customers;

  • infrastructure;

  • payment systems;

  • Domain Names;

  • Registry connections;

  • APIs;

  • DNS infrastructure; and

  • the security and stability of the Domain Name System.

We may therefore process information including:

  • IP addresses;

  • device information;

  • browser signals;

  • authentication history;

  • transaction data;

  • payment-risk signals;

  • Account activity;

  • support history;

  • Registration Data;

  • technical security indicators; and

  • information provided in abuse or fraud reports.

Processing may involve automated tools and manual review.

Trustname may associate technical or risk information with an Account where reasonably necessary to detect or investigate:

  • account compromise;

  • unauthorized access;

  • fraud;

  • phishing;

  • malware;

  • botnets;

  • DNS Abuse;

  • payment abuse;

  • security incidents; or

  • other harmful or unlawful activity.


20. Automated Processing and Profiling

Trustname may use automated systems to assist with:

  • fraud detection;

  • payment-risk assessment;

  • abuse detection;

  • account security;

  • technical verification;

  • Registration Data validation;

  • spam prevention; and

  • transaction monitoring.

Automated indicators may be used to prioritize or trigger manual review.

Where applicable law restricts decisions based solely on automated processing that produce legal or similarly significant effects, Trustname will apply the legally required safeguards.

Where applicable, you may request information or human review in accordance with your rights under applicable data-protection law.


21. Customer Support and Service Communications

Trustname uses Account and contact information to:

  • respond to support requests;

  • investigate technical problems;

  • authenticate customers;

  • send security notifications;

  • provide transaction confirmations;

  • communicate Registry or ICANN notices;

  • send renewal and expiration notices;

  • communicate verification requests;

  • notify you about Service changes; and

  • provide other contractual or legally required communications.

Service, security, verification, legal and other mandatory communications are not promotional communications and generally cannot be disabled while the relevant Service remains active.


22. Promotional Communications

Trustname may use contact information to send information about:

  • new products;

  • promotions;

  • discounts;

  • product updates; and

  • other commercial offers.

Depending on applicable law, promotional processing may rely on:

  • your consent; or

  • a permitted legitimate-interest basis.

You may unsubscribe from promotional email through the unsubscribe mechanism or applicable Account preferences.

Unsubscribing from marketing does not stop necessary:

  • security;

  • billing;

  • legal;

  • support;

  • domain expiration;

  • verification; or

  • other Service communications.


23. Cookies and Similar Technologies

Trustname may use:

  • session cookies;

  • persistent cookies;

  • local-storage technologies;

  • analytics technologies;

  • web beacons;

  • referral identifiers; and

  • similar technologies.

These technologies may be used to:

  • maintain sessions;

  • authenticate users;

  • remember preferences;

  • secure Accounts;

  • detect fraud;

  • measure website performance;

  • diagnose errors;

  • understand website usage; and

  • support marketing where permitted.

Strictly necessary technologies may operate where necessary to provide or secure a Service.

Where applicable law requires consent before using non-essential analytics or advertising technologies, Trustname will request that consent through the applicable cookie or preference mechanism.

You may modify applicable preferences using the Trustname cookie preference interface.


24. Device and Browser Security Signals

Certain Trustname security and fraud-prevention technologies may use device or browser characteristics even where ordinary cookies are unavailable.

These signals may help identify:

  • suspicious logins;

  • automated abuse;

  • Account takeover;

  • repeated fraudulent transactions;

  • circumvention attempts; or

  • other security risks.

Such information is processed only where reasonably necessary and proportionate for the applicable security, fraud-prevention or legal purpose.


25. Analytics

Trustname may use analytics providers, including Google Analytics or similar services, to understand and improve use of our websites and Services.

Analytics information may include:

  • IP-derived information;

  • device characteristics;

  • browser information;

  • pages viewed;

  • interactions;

  • referral information;

  • approximate location;

  • session duration; and

  • technical performance data.

Where permitted and reasonably necessary for security, fraud prevention or Service improvement, analytics information may be associated with existing Trustname Account or operational information.

Non-essential analytics technologies are subject to applicable cookie and consent requirements.


26. Public Content

Information you intentionally submit to a public area—such as a public review, testimonial, forum, blog comment or other publicly accessible feature—may become publicly available.

Do not submit information to a public feature that you do not wish to make public.

Where legally and technically possible, you may request removal of personal information that you previously made public through a Trustname-controlled feature.


27. Testimonials

Where Trustname publishes a testimonial that identifies an individual, we will use an appropriate legal basis and obtain consent where required.

You may contact Trustname to withdraw applicable consent or request removal.


28. Payments

Payment transactions may be processed by external payment providers.

Depending on the payment method, payment providers may independently collect:

  • card information;

  • bank information;

  • payment-account information;

  • identity information;

  • fraud-prevention information; and

  • other data required to complete or secure the transaction.

Trustname receives and stores only the payment information reasonably necessary for:

  • transaction administration;

  • accounting;

  • fraud prevention;

  • refunds;

  • dispute handling;

  • chargebacks; and

  • compliance.

Cryptocurrency transactions may be publicly visible on the applicable blockchain and therefore should not be treated as inherently private.


SHARING OF PERSONAL DATA

29. When We Share Personal Data

Trustname does not sell customer personal data as an ordinary part of providing the Services.

We may share personal data where reasonably necessary with categories of recipients described below.

Registry Operators and Registry Service Providers

For registration and administration of Domain Names.

ICANN

Where required or permitted under applicable ICANN agreements or policies.

Registrar Data Escrow Providers

Where required for Registrar Data Escrow.

Privacy and Proxy Service Providers

Where necessary to provide, administer or comply with an applicable Privacy or Proxy Service.

Payment Providers

To process and protect financial transactions.

Fraud, Security and Verification Providers

Where necessary for security, fraud prevention or Registration Data verification.

Hosting and Infrastructure Providers

Where necessary to provide and secure Trustname's systems and Services.

Communication Providers

For email, notifications, support and other communication functionality.

Analytics and Technology Providers

Where permitted and subject to applicable privacy and cookie requirements.

Professional Advisers

Such as attorneys, auditors, accountants, insurers and consultants where reasonably necessary.

Dispute-Resolution Providers

Including providers administering UDRP, URS or other applicable domain-name disputes.

Authorities and Legal Requesters

Where disclosure is required or permitted by applicable law and the applicable requirements for disclosure are satisfied.

Affiliates and Corporate Group Entities

Where reasonably necessary to provide Services, administer the business, maintain security or perform legitimate internal operations, subject to appropriate privacy safeguards.

Corporate Transactions

Information may be transferred as part of:

  • merger;

  • acquisition;

  • financing;

  • restructuring;

  • sale of assets;

  • registrar portfolio transfer;

  • insolvency process; or

  • similar corporate transaction,

subject to applicable law and confidentiality safeguards.


30. No Sale of Personal Data

Trustname does not sell personal information for monetary consideration as part of its ordinary business model.

Certain privacy laws may define “sale,” “sharing,” “targeted advertising” or similar concepts more broadly than an ordinary commercial sale.

Where applicable law gives you rights concerning analytics, advertising or related technologies, Trustname provides applicable choices through its cookie preference tools or jurisdiction-specific privacy notices.


INTERNATIONAL PROCESSING

31. International Transfers

Trustname is established in Estonia, but some providers, Registry Operators, Privacy/Proxy Service Providers, infrastructure providers or other recipients may be located outside Estonia or outside the European Economic Area.

Where personal data are transferred from the EEA to a country not benefiting from an applicable adequacy decision, Trustname will use an appropriate legal transfer mechanism where required.

Depending on the circumstances, such mechanisms may include:

  • European Commission Standard Contractual Clauses;

  • an applicable adequacy decision;

  • another approved contractual mechanism;

  • an applicable statutory derogation; or

  • another transfer mechanism permitted by data-protection law.

Trustname applies data minimization and seeks to transfer only information reasonably required for the applicable purpose.

The fact that a third-party recipient is located outside the EEA does not automatically mean that all Trustname customer data are transferred to that recipient.

In particular, operation of the standard WHOISPPS second-layer Privacy Service does not itself require Trustname to provide WHOISPPS with the end customer's underlying personal Registration Data.


RETENTION

32. How Long We Keep Personal Data

Trustname retains personal data only for as long as reasonably necessary for the purposes for which it is processed, including applicable legal, contractual, security and regulatory requirements.

Retention periods vary according to the category of information and Service.

Factors determining retention include:

  • whether an Account remains active;

  • whether a Domain Name remains sponsored by Trustname;

  • applicable ICANN retention requirements;

  • Registrar Data Escrow requirements;

  • Registry requirements;

  • accounting and tax laws;

  • limitation periods;

  • fraud or abuse investigations;

  • pending disputes;

  • legal holds;

  • court orders;

  • security requirements; and

  • establishment, exercise or defence of legal claims.

Closing an Account does not necessarily result in immediate deletion of all associated information.

Some information may be retained in restricted or archived form where continued retention is required or legally justified.

When information is no longer required, Trustname will delete, anonymize or otherwise dispose of it in accordance with applicable retention practices.


33. Domain Registration Data Retention

Domain Registration Data may be subject to specific retention requirements arising from:

  • ICANN;

  • the RAA;

  • the ICANN Registration Data Policy;

  • Registry rules;

  • Registrar Data Escrow requirements;

  • NIS2-related legislation;

  • dispute-resolution requirements; or

  • applicable law.

A request to delete Registration Data cannot be fulfilled where continued processing is necessary for an active registration or another applicable legal or contractual requirement.

Where deletion of necessary Registration Data would make continued provision of a Domain Name registration impossible, Trustname may require:

  • corrected or replacement data;

  • removal of an applicable Service;

  • transfer of the Domain Name; or

  • termination of the affected registration Service.


SECURITY

34. How We Protect Personal Data

Trustname implements technical and organizational safeguards appropriate to the nature of the information and risks involved.

Measures may include:

  • encrypted transmission;

  • authentication controls;

  • access restrictions;

  • account-security controls;

  • network protections;

  • logging and monitoring;

  • backup and recovery measures;

  • fraud detection;

  • incident-response procedures;

  • employee access controls;

  • provider due diligence; and

  • other appropriate organizational and technical measures.

No Internet transmission or electronic storage method can be guaranteed to be completely secure.

Customers are responsible for protecting their own:

  • passwords;

  • authentication methods;

  • support credentials;

  • API keys;

  • email Accounts; and

  • devices.

Please notify Trustname promptly if you believe your Account has been compromised.


35. Personal Data Breaches

Trustname maintains procedures for identifying, investigating and responding to personal-data breaches.

Where applicable law requires notification to a supervisory authority or affected individuals, Trustname will provide such notification in accordance with the applicable legal requirements.

Trustname may also take measures to:

  • contain the incident;

  • preserve evidence;

  • secure affected systems;

  • reset credentials;

  • reduce risk; and

  • prevent recurrence.


YOUR RIGHTS

36. GDPR and EEA Data Protection Rights

Where the GDPR applies, you may have the right, subject to applicable conditions and exceptions, to:

  • obtain information about processing;

  • access your personal data;

  • correct inaccurate personal data;

  • complete incomplete personal data;

  • request deletion;

  • request restriction of processing;

  • object to certain processing;

  • receive applicable personal data in a portable format;

  • withdraw consent where processing is based on consent;

  • object to direct marketing;

  • exercise applicable rights concerning automated decision-making; and

  • lodge a complaint with a competent supervisory authority.

These rights are not absolute.

For example, Trustname may need to continue processing particular information where necessary to:

  • perform a contract;

  • comply with law;

  • comply with ICANN or Registry obligations;

  • maintain Registrar Data Escrow;

  • maintain an active Domain Name registration;

  • investigate fraud or abuse;

  • protect security; or

  • establish, exercise or defend legal claims.

Withdrawal of consent affects processing relying on that consent but does not invalidate processing already lawfully performed or processing supported by another legal basis.


37. How to Exercise Your Rights

Privacy requests may be sent to:

[email protected]

Trustname may need to verify your identity or authority before acting on a request.

We will request only information reasonably necessary to perform that verification.

Where a request concerns a Domain Name or Account, Trustname may require authentication through the relevant Account or another secure process.

Trustname will respond within the period required by applicable law.

Where permitted by law, we may refuse or charge an appropriate fee for a request that is manifestly unfounded or excessive.


38. Supervisory Authority

Because Trustname is established in Estonia, individuals may have the right to lodge a data-protection complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or, where applicable, another competent supervisory authority.

You are not required to contact Trustname before exercising any statutory right to lodge a complaint, although we encourage you to contact us so that we have an opportunity to address your concern.


REGIONAL PRIVACY INFORMATION

39. United Kingdom

Where the UK GDPR applies, individuals may have rights broadly corresponding to applicable UK data-protection law.

Trustname has identified the following UK representative for UK GDPR matters:

EDPO UK Ltd
8 Northumberland Avenue
London WC2N 5BY
United Kingdom

Requests may also be submitted through EDPO UK's published data-request mechanism.

The appointment of a UK representative does not reduce Trustname's responsibility for compliance with applicable data-protection law.


40. California

California residents may have additional rights under applicable California privacy law.

Depending on applicability and applicable exemptions, those rights may include rights concerning:

  • access;

  • correction;

  • deletion;

  • information concerning categories of information collected;

  • information concerning disclosures;

  • portability; and

  • sale or sharing of personal information.

The Trustname California Privacy Notice / CCPA Privacy Notice supplements this Policy where applicable.

Trustname will not discriminate against an individual for exercising rights provided by applicable California privacy law.


41. Brazil

Where Brazil's Lei Geral de Proteção de Dados (“LGPD”) applies, data subjects may have additional rights concerning personal-data processing.

The Trustname Brazil/LGPD privacy notice supplements this Policy where applicable.


42. Nevada and Other U.S. State Privacy Laws

Residents of Nevada or another U.S. state may have additional privacy rights where applicable state law applies to Trustname's processing.

Trustname does not sell personal data for monetary consideration as part of its ordinary business model.

Where a jurisdiction provides additional opt-out or privacy rights applicable to Trustname, those rights may be exercised through the methods specified in the applicable jurisdiction-specific notice or by contacting the Privacy and Legal Department.


CHILDREN

43. Children's Privacy

Trustname Services are not directed to children.

You must have the legal capacity required under the applicable Trustname agreements to open and maintain an Account.

Trustname does not knowingly solicit personal information from children in violation of applicable law.

If you believe a child has provided personal information to Trustname contrary to applicable law, contact us at [email protected].


THIRD-PARTY SERVICES

44. Third-Party Websites and Services

Trustname Services may contain links to or integrations with third-party products, websites or services.

This Privacy Policy does not govern independent third parties that Trustname does not control.

Third-party recipients may have their own:

  • privacy policies;

  • legal obligations;

  • retention periods;

  • security practices; and

  • data-subject request processes.

You should review the applicable third-party privacy information where appropriate.


CHANGES AND CONTACT

45. Changes to This Privacy Policy

Trustname may update this Privacy Policy from time to time to reflect:

  • legal developments;

  • ICANN policy changes;

  • Registry requirements;

  • changes to Services;

  • changes to Privacy/Proxy Services;

  • security requirements;

  • regulatory developments; or

  • changes in our processing practices.

The current version will be published with its effective date.

Where required by applicable law, Trustname will provide additional notice of a material change or obtain consent where consent is legally required.

Continued use of a Service does not convert processing that legally requires separate consent into consent merely because this Privacy Policy was updated.


46. Relationship With Other Trustname Policies

This Privacy Policy should be read together with, as applicable:

  • Universal Terms of Service;

  • Domain Name Registration Agreement;

  • NIS2 Domain Name Registration Data Verification Policy;

  • Cookie Policy;

  • Court Order and Subpoena Policy;

  • Privacy & Proxy Service Public Procedures;

  • Suggested Default Contact Proxy Service & Domain License Agreement;

  • Two-Tier Privacy Service Terms;

  • applicable Registry agreements;

  • California Privacy Notice;

  • Brazil/LGPD Privacy Notice; and

  • other product-specific terms.

If another applicable document provides more specific privacy information for a particular processing activity, that specific information supplements this Privacy Policy.

Mandatory applicable law, ICANN requirements and Registry requirements prevail to the extent they cannot lawfully or contractually be modified.


47. Contact Us

For privacy, personal-data and data-protection matters:

Fewmoretaps OÜ doing business as Trustname
Legal and Privacy Department
Roseni tn 13
Harju maakond
Kesklinna linnaosa
Tallinn 10111
Estonia

Email: [email protected]

For ordinary customer-support matters, please use Trustname Support.

For domain Registration Data verification, disclosure, abuse, court orders or other specialized matters, use the corresponding procedure or contact channel published by Trustname so that the request can be routed and evaluated appropriately.

Was this article helpful?

Have more questions? Submit a ticket