Privacy Policy
NederlandsHow Domainio collects, uses and protects personal data. We have tried to describe what actually happens rather than what is merely permitted.
Last updated:
Who we are
Domainio is a domain registration and website service operated by Piwas, a company registered in the Netherlands. Piwas is the data controller for the personal data described in this policy.
- Piwas (Domainio)
- Saturnusstraat 93
- 2132 HV Hoofddorp, Netherlands
- KvK: 95898115
- BTW: NL005177244B88
- OIN: 00000003958981150000
- domainio@piwas.nl
- +31 6 86433636
We have not appointed a Data Protection Officer. We are not required to under Article 37 of the GDPR, as our core activities do not involve large-scale monitoring or large-scale processing of special categories of data. Data protection questions go to the address above and are handled by us directly.
What personal data we collect
We collect the following, all of it either given to us by you or generated by your use of the service:
- Account data — email address, password (stored only as a bcrypt hash, never in readable form), full name, company name and phone number where you provide them.
- Registrant contact data — the name, organisation, email, phone number and full postal address required to register a domain. This is a separate record from your account, because registries require it in a specific form.
- Two-factor authentication data — where you enable it, an encrypted TOTP secret and hashed one-time recovery codes.
- Billing data — invoices, payments, account balance and subscription tier. We do not receive or store card numbers.
- Technical and security data — audit logs of actions taken on your account, sign-in timestamps, API keys you generate, and error reports.
- AI feature data — the prompts and conversations you submit to the assistant, along with its responses.
Why we process it, and on what legal basis
- To provide the service you asked for — registering, renewing and managing domains, and operating your account. Legal basis: performance of a contract (Article 6(1)(b)).
- To meet obligations imposed on us — registry and ICANN requirements, and Dutch tax and accounting law. Legal basis: legal obligation (Article 6(1)(c)).
- To keep the service secure and working — audit logging, fraud and abuse prevention, and diagnosing errors. Legal basis: legitimate interests (Article 6(1)(f)), balanced against your rights.
- To send service messages such as expiry and renewal notices. Legal basis: performance of a contract. These are operational, not marketing; losing a domain because a notice was suppressed is not an acceptable outcome.
Domain registration data and WHOIS
Registering a domain is not a private transaction. To register or transfer a domain we transmit your registrant contact details to our registrar partner, ResellerClub, which passes them to the registry operating that extension.
Depending on the extension and the registry's own rules, some of this data may be published in the public WHOIS or RDAP directory, or disclosed to third parties who make a legitimate request to the registry. We do not control registry publication policy and cannot withdraw data once a registry has published it.
ICANN requires registrant contact data to be accurate and kept up to date. Supplying false details, or failing to respond to a verification request, can result in the domain being suspended or cancelled by the registry. This is a registry sanction, not ours.
Payment data
Payments are processed by Mollie B.V., a licensed Dutch payment institution. When you pay, you are handed to Mollie and enter your payment details there. Card numbers, bank credentials and comparable payment secrets are never sent to or stored on our systems.
We receive back from Mollie only what we need to reconcile the order: a payment identifier, the amount, the status and the method used. We retain invoices and payment records to satisfy Dutch tax law.
Who we share data with
We do not sell personal data, and we do not share it for anyone else's marketing. We use the following processors, each only for the purpose named:
- ResellerClub — domain registration, renewal, transfer and DNS. Receives registrant contact data.
- Mollie B.V. — payment processing. Receives the data you enter at checkout and the order amount.
- Sentry — error monitoring and session replay. See the section on error monitoring below.
- Google (Gemini API) — powers the AI assistant. Receives the prompt content you submit to it.
- Google Safe Browsing — checks domains and URLs against known-malicious lists.
- Our email delivery infrastructure — sends transactional email such as verification, password reset and expiry notices.
We will also disclose data where we are legally compelled to — a court order, or a binding request from a competent authority.
Error monitoring and session replay
We use Sentry to capture errors. Sentry's Session Replay feature is enabled: it records a reconstruction of a sample of browsing sessions — roughly one in ten sessions, and every session in which an error occurs — so that a fault can be reproduced rather than guessed at.
A replay can capture the pages you visited and how you interacted with them. It is a diagnostic tool, used only to fix faults, and is never used to profile you or to make decisions about you. We are naming it explicitly because it is the kind of processing a reader would reasonably want to know about and which most policies leave unmentioned.
How long we keep it
- Account data — for as long as your account is open, and for a short period afterwards so the closure can be reversed if it was a mistake.
- Invoices and payment records — seven years, the retention period required by Dutch tax law. This obligation overrides a deletion request for these specific records.
- Domain and registrant records — for the life of the domain registration, plus the period registries require for post-expiry and dispute handling.
- Audit logs — retained as a security record for as long as they remain useful for investigating account compromise.
- Error reports and session replays — a limited retention window set by our monitoring configuration, after which they are discarded.
Your rights under the GDPR
If you are in the EU or EEA, you have the right to request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability of data you supplied to us, and to object to processing we carry out on the basis of legitimate interests.
Write to domainio@piwas.nl to exercise any of these. We will respond within one month. There are two limits worth stating honestly: we cannot erase invoice records we are legally required to keep, and we cannot compel a registry to withdraw registrant data it has already published.
If you are unhappy with how we have handled your data, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also complain to the authority in your own country of residence.
Cookies and analytics
We do not run analytics. There is no Google Analytics, no advertising pixel, no tracking script and no third-party profiling on this site. That is why you are not being asked to dismiss a cookie banner.
We set one cookie: a session cookie that keeps you signed in. It is strictly necessary to operate the service and requires no consent under the ePrivacy Directive. If you block it, you cannot stay signed in.
International transfers
Our servers are in the European Union. Some of our processors — notably Google and Sentry — are established outside the EEA or may process data outside it.
Where data leaves the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision, together with the safeguards those mechanisms require.
Security
Passwords are stored only as bcrypt hashes. Two-factor authentication secrets are encrypted at rest, and recovery codes are stored hashed and are single-use. Traffic is served over HTTPS. Actions taken on an account are written to an audit log.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the Autoriteit Persoonsgegevens within 72 hours and inform you where the law requires it.
Changes to this policy
We may update this policy as the service changes. The date at the top of this page tells you when it last changed. Where a change materially affects how we handle your data, we will tell you by email rather than relying on you to notice.
How to contact us
For any question about this policy or about your personal data:
- Piwas (Domainio)
- Saturnusstraat 93
- 2132 HV Hoofddorp, Netherlands
- KvK: 95898115
- BTW: NL005177244B88
- OIN: 00000003958981150000
- domainio@piwas.nl
- +31 6 86433636