Privacy Policy
In force since September 25, 2026
In force from September 10, 2026 · archived September 25, 2026
sha256 0c81410c277f47380563a4c1f73e800efa14f5d0b63feb700a2a63defb13c654
1. The owner of the personal data and the scope of this Policy
1.1. This Privacy Policy (the Policy) explains what personal data are processed by Tereshchuk Andrii Oleksandrovych, a private entrepreneur — a natural person registered in Ukraine as an entrepreneur, which is not a legal entity — individual taxpayer registration number (RNOKPP) 3796706819 ("we", "us", "our"), for what purpose and on what legal grounds, to whom those data are disclosed, how long they are stored, and what rights are held by the person to whom they relate.
1.2. In respect of the data described in this Policy, we are the controller of personal data (owner of personal data — the role that determines the purpose and means of processing under Ukrainian data protection law; it is close to, but not identical with, a GDPR controller) within the meaning of article 2 of the Law of Ukraine "On Protection of Personal Data" of 01.06.2010 No. 2297-VI (hereinafter Law No. 2297-VI). Our full details are set out on the Our Details page.
1.3. Enquiries concerning personal data, in particular enquiries under section 8 of this Policy, should be sent to privacy@namespace.com.ua or by post to P.O. Box 1, Tsarychanka, Dnipropetrovsk region, 51000, Ukraine — transliterated, for a letter posted inside Ukraine: 51000, Dnipropetrovska obl., smt Tsarychanka, a/s No. 1. Such enquiries are handled personally by the entrepreneur, Andrii Oleksandrovych Tereshchuk: an individual entrepreneur personally ensures the protection of the personal data it owns (part four of article 24 of Law No. 2297-VI), and we therefore designate no separate responsible person or structural unit. The duty to designate such a unit or person and to notify the Ukrainian Parliament Commissioner for Human Rights of them applies to owners whose processing is subject to notification (part two of the same article); our processing is not subject to notification (clause 2.9).
1.4. This Policy covers the processing of the personal data of:
- registrants who order services from us directly;
- natural persons acting as contact persons, representatives or authorised employees of legal entities and of individual entrepreneurs (including purchasers);
- registrants whose data reach us from purchasers (section 6);
- visitors to the namespace.com.ua website and users of the control panel.
1.5. The data of legal entities as such are not personal data. However, particulars by which a natural person may be identified — a representative, a contact person, a signatory or an individual entrepreneur — are personal data, and this Policy covers them in full.
1.6. This Policy is a notice to the data subject within the meaning of article 12 of Law No. 2297-VI. Its text is available before the moment the data are collected: a link to it is placed in the footer of every page of the website. There is at present neither an order form nor a self-service account-creation page on the website (clause 2.7 of the Terms of Service): requests are sent by email, and a link to this Policy is given in the confirmation we send before a request is carried out. When the account-creation page and the order form go live, a link to this Policy will be placed in each of them immediately above the confirmation button.
1.7. This Policy does not describe processing that other persons carry out on their own decision and for their own purposes — in particular processing by the registries (section 4), processing by a purchaser of the data of its own customers (section 6), and processing by payment operators and banks. We do not determine the purpose or the means of such processing and do not control it.
1.8. This Policy is an integral part of the Terms of Service — as regards retail clients — and of the Distributor Agreement, which is the partner agreement with purchasers — as regards partners. There is no other partner agreement.
1.9. This Policy is set out in the state language (part fourteen of article 11 of the Law of Ukraine "On Electronic Commerce" of 03.09.2015 No. 675-VIII), the language of service is Ukrainian (article 30 of the Law of Ukraine "On Ensuring the Functioning of the Ukrainian Language as the State Language" of 25.04.2019 No. 2704-VIII), and part six of article 27 of the same Law requires that the Ukrainian-language version of a website be no smaller in volume and content than versions in other languages. None of those provisions establishes the primacy of one language version over another — that is our stipulation: the authentic text of this Policy is the Ukrainian one, versions in other languages are provided for convenience, and in the event of a discrepancy the Ukrainian version prevails.
1.10. In this Policy:
- Registry — the person that maintains the register of the domain concerned and establishes the rules for registration in it: the administrator of the public domain and/or the operator of the register within the meaning of the Regulations of the zone concerned;
- Registrant — the person in whose name a domain name is registered or is to be registered;
- Purchaser — a legal entity, an individual entrepreneur or a natural person that has joined our platform under a partner agreement and resells our services to its own customers;
- Reseller — a person engaged by a purchaser to sell the purchaser's own services; a reseller is in no contractual relationship with us (clause 6.4.1);
- Platform — our registration system, accessible through the control panel and the EPP interface (RFC 5730—5734);
- Transfer code — the secret code of a domain name, on production of which a domain name is transferred to another registrar; in the EPP protocol it is designated authInfo;
- Message Queue — the queue from which a client receives the results of asynchronous operations and service notifications; technically it is implemented by the poll command of the EPP protocol;
- WHOIS — the public look-up service of a registry, which provides access to particulars held in the registration database;
- RDAP — the same look-up service in machine-readable form, over the RDAP protocol (RFC 7480—7484).
1.11. The registries' documents to which this Policy refers. The rules by which a registry maintains the register and the public look-up services are established by it, not by us. Those documents form part of the contractual relationship between us and the registry, and publishing links to them is our obligation under the contract with the Operator of the Register. For each of them we state the full title, the person who publishes it and the address at which it is available. The addresses are given in full, and not merely as links, so that they remain readable in printed or quoted text:
| Document | Who publishes it | Address at which the document is available |
|---|---|---|
| Public Domain Regulations (edition 3.5 of 24 January 2020) | HOSTMASTER LLC — Operator of the Register | https://hostmaster.ua/policy/2ld.ua |
| Regulations on the specifics of registering private second-level domain names in the .UA domain | HOSTMASTER LLC — Operator of the Register | https://hostmaster.ua/policy/ua |
| Regulations on the specifics of registering private third-level domain names in the public domains — a separate document for each group of domains | adopted by the administrators of the public domains concerned, published by HOSTMASTER LLC | https://hostmaster.ua/policy/2ld.ua |
| Regulations of the public WHOIS Internet service (edition 1.3 of 4 October 2019) | HOSTMASTER LLC — Operator of the Register | https://hostmaster.ua/services/WHOIS-Reglament-UK.pdf |
| Regulations of the public RDAP Internet service (edition 1.0 of 1 January 2025) | HOSTMASTER LLC — Operator of the Register | https://hostmaster.ua/services/RDAP-Reglament-UK.pdf |
| Rules for the .UA Domain Name Dispute Resolution Policy (.UA-DRP) and the Supplemental Rules to them | the administrator of the .UA domain; published by HOSTMASTER LLC | https://hostmaster.ua/policy/ua-drp |
| Regulations of the public domains administered by LLC SUNIC — in particular in.ua, od.ua, odesa.ua, odessa.ua, mk.ua, mykolaiv.ua, nikolaev.ua | LLC SUNIC | https://www.sunic.ua/index.php/documents |
1.11.1. Which edition applies. The edition of a document that applies to an operation is the edition in force at the moment that operation is performed. We cannot promise you a frozen edition, because we do not control it: amendments to the Public Domain Regulations may be made 30 days before they take effect and, in a case of urgent necessity, simultaneously with their publication (clause 11 of those Regulations); the same regime is established for the Regulations of the public WHOIS Internet service (clause 6 of those Regulations) and for our relationship with the Operator of the Register. What this means for changes to this Policy itself is described in clause 14.3.
1.11.2. Previous editions. Previous editions of the Public Domain Regulations are published by the Operator of the Register itself at https://epp.hostmaster.ua/help/?archive. As at the edition stated in the heading of this Policy we keep no archive of dated copies of the registries' Regulations of our own, so in a dispute about what another party's Regulations said in the past we can rely only on the archive the registry itself maintains and on the date and time of the operation taken from our own records (clauses 7.7 and 2.11). The archive of our own editions is maintained by us (clause 14.5).
2. What data we process
2.1. Account data. Name or business name, email address, password (stored only as a cryptographic hash; we never see it in the clear), the chosen interface language, and the dates of account creation and of logins to it. For an applicant who is a natural person we additionally record the kind and number of the identity document, or the particulars of the qualified public key certificate, the date of verification and the person who carried it out (clause 4.2.2 of the Distributor Agreement). We neither require nor retain copies of identity documents.
2.2. Data of the registrant and of the domain name contacts. Name or business name, organisation name (if any), postal address (street, city, region, postal code, two-letter country code), email address, telephone and fax number (if any), and the contact identifier at the registry. The minimum mandatory composition of these particulars is established by the registry: for the public domains whose registration system is operated by the Operator of the Register, the contact identifier, the name, the city, the two-letter country code and the email address are mandatory, while the organisation name, the postal address, the postal code, the telephone and the fax are optional (clause 7.2 of the Public Domain Regulations — their full title, the person who publishes it and its address are set out in clause 1.11). Why we ask for the remaining fields is explained in clause 3.11.
2.3. Data about domain names. The domain name itself, its statuses, the dates of registration, renewal and expiry, name servers, DNSSEC records, the transfer code (authInfo), and the link to the account and, where applicable, to a purchaser.
2.4. Settlement data. The state of the ledger account, the history of debits and top-ups, the numbers and content of invoices and services-rendered certificates (bilateral certificates), the payment reference, and the particulars that arrive with the bank statement for an incoming payment (name or business name of the payer, the payer's account, the amount, the date, the payment reference). We do not collect payment card details: we do not accept card payments and engage no payment operator (acquirer). Payment is made by bank transfer to our accounts set out on the Our Details page. No payment card number — neither full nor masked — exists in our systems. Funds are credited from the bank statement we receive from the bank (clause 4.7), and what that statement contains is listed above.
2.5. Technical connection data. The IP addresses from which the panel and the EPP interface are accessed; the EPP login identifier; the particulars of the client TLS certificate; the client transaction identifier (clTRID) and the tracing identifier derived from it; the time, duration and result code of every operation; the browser type and the session identifier.
2.6. The EPP frame log. We keep a complete log of the exchange of commands in both directions — between the client and us, and between us and the registry. Such a record by its nature contains the content of the command, including the registrant's contact data. Passwords — both the current one and a new one — and transfer codes are masked before the record reaches the disk; the rest of the content of the command is stored as it is. The purpose of this log is evidence in settlement and technical disputes (clause 3.7).
2.7. Correspondence and enquiries. Enquiries to the support service, financial and legally significant enquiries, abuse reports, and the service messages we send together with the records of their delivery.
2.8. Documents confirming identity or authority. We require them only in the cases and to the extent set out in clauses 5.5 and 9.5 of the Terms of Service — that is, on a claim for a refund, on a change of Registrant, on the restoration of access to an Account, on a reasoned suspicion of unauthorised use of an Account, and to confirm the accuracy of the particulars supplied — and in section 4 of the Distributor Agreement as regards the accreditation of a purchaser. We accept, in descending order of preference: an enquiry signed with a qualified electronic signature; an enquiry from the email address stated in the Account or in the particulars of the domain name; and, for a legal entity or an individual entrepreneur, particulars from the Unified State Register (EDR, the Ukrainian state register) together with a document evidencing the representative's authority (a power of attorney, an order, minutes). We do not require a copy of a passport where identity or authority can be confirmed by any of those means.
2.9. Data we do not collect. We do not collect and do not ask for special categories of personal data — on racial or ethnic origin, political, religious or ideological beliefs, membership of political parties and trade unions, criminal conviction, and data concerning health, sexual life, biometric or genetic data (article 7 of Law No. 2297-VI). Please do not send such data in your enquiries. We do not carry out processing that requires notification of the Ukrainian Parliament Commissioner for Human Rights under article 9 of Law No. 2297-VI.
2.10. Age. The services are intended for persons with full civil capacity (article 34 of the Civil Code of Ukraine) and for individual entrepreneurs and legal entities. Creating an Account and ordering services is not permitted to persons under eighteen; by ordering a service the Client confirms that they have reached the age of eighteen or have full civil capacity on another ground established by law. We do not verify age against documents: doing so would require collecting an identity document from every client, that is, more data than is necessary to conclude and perform a transaction (clause 3.11 and part four of article 7 of Law No. 675-VIII). We do not knowingly collect children's data; if we learn that data have been obtained contrary to this clause, we will delete them, having regard to section 7.
2.11. Evidence of acceptance of documents. At the moment the Terms, this Policy and the partner agreement are accepted, we record: the edition number of each document accepted; the date and time of acceptance in Coordinated Universal Time (UTC); the Account identifier; the IP address from which the act was performed; and the manner of acceptance (an action in the Panel, an application sent, or the payment by which acceptance was made), together with a link to the archived copy of that same edition (clause 14.5). We need those particulars as evidence that the document was available and was accepted in a specific edition; they are stored for the period set for the account in clause 7.2. That record is kept for every order placed under the Terms of Service. For the partner agreement the record is kept by the Provider separately (clause 5.4 of the Distributor Agreement).
3. Grounds and purposes of processing
3.1. The principal processing is not founded on consent. Consent may be withdrawn at any moment, yet most of the processing described here cannot be stopped for as long as a domain name is registered to you: the registry needs the registrant's particulars for the domain itself to exist, and we have neither the right nor the technical ability to remove them from its database on demand. To justify such processing by consent would be to promise something we cannot deliver. The grounds are therefore the performance of a transaction, the performance of an obligation imposed by law, and legitimate interest, while consent is used only where refusing it genuinely breaks nothing (clause 3.9 and section 10).
3.2. The legal grounds are given by reference to part one of article 11 of Law No. 2297-VI and, for persons who are in the European Union, additionally by reference to article 6 of Regulation (EU) 2016/679 (hereinafter GDPR; see section 13).
3.3. Creating and maintaining an account, providing access to the panel and to EPP. Purpose — to provide the service ordered. Ground — clause 3 of part one of article 11 of Law No. 2297-VI (conclusion and performance of a transaction to which the data subject is a party); article 6(1)(b) GDPR.
3.4. Registration, renewal, transfer, modification and deletion of domain names, including the transmission of particulars to the registry. Purpose — to fulfil the order. Ground — clause 3 of part one of article 11 of Law No. 2297-VI; additionally clause 6 of the same part (legitimate interest) as regards the performance of our obligations under the contract with the registry as an accredited registrar; articles 6(1)(b) and 6(1)(f) GDPR. The data leave our system at the moment the application is submitted to the registry; see sections 4 and 5 for more detail.
3.5. Settlements, accounting and tax records, drawing up invoices and services-rendered certificates. Purpose — performance of an obligation imposed on us by law. Ground — clause 5 of part one of article 11 of Law No. 2297-VI; article 9 of the Law of Ukraine "On Accounting and Financial Reporting in Ukraine" of 16.07.1999 No. 996-XIV; article 44 of the Tax Code of Ukraine; article 6(1)(c) GDPR.
3.6. Platform security. Authentication, checking of allowed IP addresses, rate limiting, detection and investigation of abuse and incidents, protection against unauthorised access. Ground — clause 6 of part one of article 11 of Law No. 2297-VI (legitimate interest in maintaining the operability and security of the service, shared with all customers); article 6(1)(f) GDPR.
3.7. Evidential record of operations. Keeping the EPP frame log, the history of changes to objects, the operator action log and the message queue — so that in the event of a dispute it can be established which command arrived, what we transmitted to the registry, what it answered, and when and whom we notified. Ground — clause 6 of part one of article 11 of Law No. 2297-VI; article 6(1)(f) GDPR; as regards settlement documents, also clause 5 of the same part. The separate record of operations on personal data and of access to them is described in clause 7.7.
3.8. Service messages. Order confirmations, reminders about a domain's term, notices of the outcome of an asynchronous operation, of changes to the terms, of incidents and of the state of the account. These are not advertising and cannot be opted out of while the contract lasts: an order confirmation is mandatory under part eleven of article 11 of Law No. 675-VIII, and the remaining messages are part of the service. Ground — clauses 3 and 6 of part one of article 11 of Law No. 2297-VI; articles 6(1)(b) and 6(1)(f) GDPR.
3.9. Marketing mailings. As at the edition stated in the heading of this Policy we send no marketing mailings at all: there is neither a separate mailing list nor a one-click unsubscribe mechanism on the platform, and we collect no consent to mailings. We will not begin sending them until all of the following are in place: prior consent, separate from consent to anything else; an unsubscribe link in every message; and the service message headers provided for by the RFC 2369 and RFC 8058 standards, which allow unsubscribing with a single press from within the mail program itself. We will announce the introduction of mailings by updating this Policy before they begin (clause 14.2). The legal ground for such processing, once it exists, will be consent alone — clause 1 of part one of article 11 of Law No. 2297-VI; article 10 of Law No. 675-VIII (commercial electronic messages); article 6(1)(a) GDPR. Withdrawing consent to mailings does not affect the provision of the services and does not stop the service messages under clause 3.8.
3.10. Whether supplying the data is mandatory. The data listed in clauses 2.1—2.4 are necessary: without them we cannot conclude and perform the contract, submit an application to the registry or carry out a settlement. The data in clauses 2.7 and 2.8 are supplied to the extent needed for the particular enquiry. Failure to supply the necessary data means the service cannot be provided; this is not a refusal to conclude a public contract.
3.11. The data we collect beyond what the registry requires. The registry requires only four contact fields (clause 2.2). We collect the rest for our own purposes and are obliged to explain why, since a seller may require only those data without which a transaction cannot be concluded and performed (part four of article 7 of Law No. 675-VIII):
- postal address and the payer's identifying particulars — to draw up invoices and services-rendered certificates and for tax records (clause 3.5);
- telephone number — for urgent contact in cases where delay leads to the loss of a domain or to financial consequences; supplied at your option: the telephone field is not mandatory either at the registry (clause 2.2) or on our platform — the contact creation command is accepted without it;
- IP addresses and technical identifiers — for security and for the evidential record (clauses 3.6 and 3.7).
3.12. We do not sell personal data, do not transfer them for third-party advertising and do not use them for profiling for advertising purposes.
4. To whom we disclose data
4.1. Below is an exhaustive list of the categories of recipients. Article 12 of Law No. 2297-VI requires notification precisely of the persons to whom data are transferred, and so the generic formula "to third parties" does not appear here.
4.2. Our own platform. The data are processed in our own registration system. That system belongs to us and is operated by us: its operator is the same person as the owner of the personal data under clause 1.1, so there is no separate processor here and no written processing instruction under part four of article 4 of Law No. 2297-VI is required. The namespace.com.ua website and the control panel run on the same server as the registration system; the suppliers who provide the infrastructure itself are listed in clause 4.8.
4.3. The registry operator and the administrator of the public domain. The particulars of the registrant and of the domain name contacts are transferred to the operator of the register and to the administrator of the relevant public domain. We name them individually, with their full official name and official website, because article 12 of Law No. 2297-VI does not permit the generic formula "third parties". The list is complete — every administrator and every registry operator of every Ukrainian domain zone, not only those data reach today (why, below the table):
| Person | Role | Official website | Domain zones |
| --- | --- | --- | --- |
| HOSTMASTER LLC | administrator of public domains and registry operator | https://www.hostmaster.ua | ua, com.ua, if.ua, ivano-frankivsk.ua, kiev.ua, kyiv.ua, pl.ua, poltava.ua, uz.ua, uzhgorod.ua, uzhhorod.ua, zakarpattia.ua |
| LLC SUNIC | administrator of public domains and registry operator | http://sunic.ua | in.ua, mk.ua, mykolaiv.ua, nikolaev.ua, od.ua, odesa.ua, odessa.ua |
| ChP Koordynator LLC (EUNIC) | administrator of public domains and registry operator | http://coordinator.ua | dn.ua, donetsk.ua, kh.ua, kharkiv.ua, kharkov.ua, lg.ua, lugansk.ua, luhansk.ua, net.ua, sm.ua, sumy.ua, zaporizhzhe.ua, zaporizhzhia.ua, zp.ua |
| TRAIFL Research and Production Enterprise LLC | administrator of public domains and registry operator | https://nic.dp.ua | dnepropetrovsk.ua, dnipropetrovsk.ua, dp.ua |
| EKSINTEKH LLC (UARnet) | administrator of public domains and registry operator | https://nic.lviv.ua | lviv.ua |
| Servis Onlain LLC (DRS.UA) | administrator of private second-level domains and registry operator | https://drs.ua | biz.ua, co.ua, pp.ua |
| UANIC (TCI) | administrator of the Cyrillic top-level domain of Ukraine | http://uanic.net | xn--j1amh |
| ORG.UA LLC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | http://www.org.ua | org.ua |
| UNITRADE PRO LLC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://nic.te.ua | cv.ua, chernivtsi.ua, chernovtsy.ua, te.ua, ternopil.ua |
| Sinet CJSC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://www.cn.ua | cn.ua, chernihiv.ua, chernigov.ua |
| KS-HOST LLC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://nic.ks.ua | ks.ua, kherson.ua |
| RIFT LLC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://www.rift.org.ua/ | rv.ua, rivne.ua, rovno.ua |
| Impuls LLC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | not published | zt.ua, zhytomyr.ua, zhitomir.ua |
| Host Research and Production Firm LLC | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | http://nic.kr.ua | kr.ua, kropyvnytskyi.ua, kirovograd.ua |
| individual entrepreneur Vovk Viacheslav Volodymyrovych | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://nic.km.ua | km.ua, khmelnytskyi.ua, khmelnitskiy.ua |
| individual entrepreneur Lunov Valerii Volodymyrovych | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://nic.ck.ua | ck.ua, cherkasy.ua, cherkassy.ua |
| Vinnytsia Chamber of Commerce and Industry | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://vnic.vn.ua | vn.ua, vinnytsia.ua, vinnica.ua |
| Vizor Enterprise | administrator of a public domain (the registration system is run by HOSTMASTER LLC) | https://nic.lutsk.ua | lt.ua, lutsk.ua, volyn.ua |
| — | administrator of a public domain; the .UA register does not publish its name | http://www.crimea.ua | crimea.ua, sebastopol.ua, yalta.ua |
The source of this table is the register published by the administrator of .UA at https://www.hostmaster.ua/2ld/. We also publish the administrator of each individual zone on the Domain zones page, beside that zone's rules. For three zones (crimea.ua, sebastopol.ua, yalta.ua) the .UA register publishes no administrator name; we do not name one either, because only what is known can be named.
Why the list is complete rather than limited to the routes we use today. Clause 14.2 of this Policy obliges us to give 30 calendar days' notice before the list of recipients is widened. If we begin serving a new zone, its administrator would be a new recipient — and the service could not start before that period had run. Naming everyone in advance disposes of the question: no widening of the list of zones adds a recipient you were not told about.
A person's presence in this table therefore does not mean that we serve their zones or that data are transferred to them. Data are in fact transferred only to those whose zones we serve on the routes currently in force on our platform. The only confirmation that we provide services in a given zone is the list under clause 6.4 of the Our Details page, not this table. This is the only list of recipients: clause 13.4 of the Distributor Agreement points at it rather than repeating it. The table in clause 6.3 of the Our Details page answers a third question — whom we hold a direct contract with — and is not a list of recipients.
4.4. The operator of the register and the administrators of the public domains process those data as our processors of personal data, on our instruction. That is precisely the allocation of roles fixed in the contracts signed with them: we act as the controller, they as processors. They process the data only on our instruction and have no right to engage other persons in the processing without our written consent. The content of the contracts with the registries is itself confidential and we do not disclose it.
4.4.1. The limits of our instruction. An instruction to process does not make us capable of everything. The extent of publication in WHOIS and RDAP, the composition of the mandatory register fields and the registry's own storage periods are determined by the registry, in its own regulations, and we cannot change them (clauses 5.1–5.3). At the same time we are not a bystander: we are obliged to obtain your consent to publication, we are answerable for the lawfulness of the publication, and we submit to the register the command to cease publication if you withdraw your consent (clause 5.4).
4.4.2. If we stop working in a zone, the registry retains your data until the delegation period of the domain name expires — so that the domain name keeps working and so that you can be identified until you choose another registrar. After the contact has been deleted from the register, it has the right to retain those data for the statutory limitation period and to use them as evidence, including in proceedings involving us and/or you. For certain zones a different order applies: if the powers of the operator of the register or of the administrator of a public domain are terminated, the data from the register, including personal data, are transferred to the administrator of the relevant public domain, and the party that transferred them deletes them on its own side — under the rules of the registries, not later than the day after the transfer.
4.5. Another registrar — on a transfer of a domain name: the exchange of the particulars needed for the transfer takes place through the registry, in the manner established by the Regulations of the zone concerned (clause 1.11).
4.6. A purchaser — where the domain name was ordered through it: it has access to the registrant and domain name data that it itself passed to us, and to the particulars of operations on that domain. The converse case is described in section 6.
4.7. The bank — as regards the execution of a payment. We engage no payment operator (acquirer) and accept no payment card payments (clause 2.4). Settlements in hryvnia, in US dollars and in euro over the SWIFT route pass through JSC "UNIVERSAL BANK" (JSC "UNIVERSAL BANK", EDRPOU — the Ukrainian company register code — 21133352, MFO 322001, Ukraine); settlements in euro over the SEPA route pass through Clear Junction Limited (United Kingdom), with which our euro account is held. The bank receives those particulars about the payer that the payment document itself contains. The privacy policies of those persons are published on their official websites.
4.8. Infrastructure suppliers. As at the edition stated in the heading of this Policy:
| Purpose | Country of location |
|---|---|
| The server on which the registration system, the website and the control panel run | Poland |
| The outbound mail server | Poland |
| The delivery network and reverse proxy for the namespace.com.ua website (including TLS termination), and the service worker through which we read the bank statement | United States of America and a global network of nodes |
We give the name of each supplier on a written request sent to the address in clause 1.3. What is set out here is the purpose and the country of location, because that is what allows a transfer to be judged: article 13(1)(e) of Regulation (EU) 2016/679 speaks of “recipients or categories of recipients”.
Such persons act as processors of personal data. We engage them only under a written contract that determines the purpose and the extent of the processing and forbids them to use the data for their own purposes; without such a contract the processing of personal data may not be entrusted to anyone (parts four and five of article 4 of Law No. 2297-VI).
4.9. State authorities, courts and law-enforcement bodies — on a written demand made in accordance with the law. We verify the requester's authority and that the volume of data requested corresponds to the demand, supply only the volume stated in the demand, and notify the data subject of such a transfer unless the law prohibits it.
4.10. A domain dispute resolution provider — where a dispute over a domain name is being considered under the domain dispute resolution rules of the zone concerned, which for the .UA domain are the .UA Domain Name Dispute Resolution Policy (.UA-DRP), whose full title, publisher and address are set out in clause 1.11, we supply the administrative provider with the registrant's particulars in the manner and to the extent provided for by that procedure. We are not a party to such a dispute and do not decide it on the merits.
4.11. Transfers of data not described in this section are made by us only where a separate ground exists. Part one of article 21 of Law No. 2297-VI requires the data subject to be notified of such a transfer within ten working days only where the terms of that subject's consent so require, or unless the law provides otherwise; since the principal processing is not based on consent (clause 3.1), that duty largely does not arise — but we perform it voluntarily within the same period.
4.12. Separately: we notify the data subject and the recipients to whom the data were transferred of any alteration, deletion or destruction of personal data, or of any restriction of access to them, within ten working days (part three of article 21 of Law No. 2297-VI). For data already entered in a register, that recipient is the registry, and notification is effected by transmitting the corresponding command to it; what we cannot do is set out in clauses 4.4.1 and 5.3.
4.13. The transfers described in this section are disclosed in advance — by this very Policy, provided at the moment the data are collected (clause 1.6).
4.14. Export on a registry's demand for the restoration of the register. The operator of the register or the administrator of a public domain has the right to demand from us — in the event of a technical failure of the register and the impossibility of restoring its database by any other means — an electronic database in a format it specifies containing the contact data of every active domain name record we service. That duty is imposed on us as an accredited registrar, the period for performing it is five working days from receipt of the demand, and it extends to domain names submitted by purchasers. We perform such a demand strictly within the limits it sets and strictly for the purpose of restoring the register. Since those persons are our processors of personal data (clause 4.4), such a transfer is not a transfer to an outside person; we notify the data subjects and the purchasers concerned of the fact of the transfer within ten working days (clause 4.12).
5. Publication of data in the WHOIS and RDAP services
5.1. The registry maintains the registration database of the zone and provides public access to part of its particulars through the WHOIS and RDAP services. The extent of such access is determined by the registry in its own rules: the list and availability of the particulars supplied through WHOIS are determined by the register's policy on information supplied to third parties (clause 9 of the Public Domain Regulations), while the services themselves operate under the Regulations of the public WHOIS Internet service and the Regulations of the public RDAP Internet service. The full titles of those three documents, the persons who publish them and the addresses at which they are available are set out in clause 1.11.
5.2. This means that the set of fields that become publicly available is established not by us and may differ from zone to zone. We checked the actual WHOIS output in every zone in which we provide services, and the RDAP output in those of them where that service exists (cl. 5.6), on 31.08.2026, and as at that date it is as follows:
| Particulars | Whether published | On what basis |
|---|---|---|
| The domain name itself; its statuses; the dates of registration, of last modification and of expiry; the name servers and their glue IP addresses; particulars of the DNSSEC keys; the record's publicity flag; the identifier of the registrar servicing the record; the conventional name of the register; and, for a private second-level domain name in the .UA domain, the number of the trade mark certificate | Always published; no consent is needed for this | These are particulars about the domain name, not about a natural person; their composition is determined by the registry in its own Regulations (clauses 1.11 and 5.1) |
| Our own particulars as a registrar: name, website, city, country, and the address, telephone and email address for abuse reports | Always published; no consent is needed for this | These are particulars about us, not about you; the rules of the registries require their publication |
| The surname and given name of a natural person, or the organisation name, of the Registrant and of the administrative, technical and billing contacts; the email address of those contacts; the postal address, postal code and country code; telephone and fax numbers | Published only with the consent of the person concerned; where there is no consent, not published | The dissemination of personal data is carried out with the consent of the data subject (part one of article 14 of Law No. 2297-VI); how consent is obtained is set out in clause 5.4 |
| The transfer code of the domain name | Never published, in any zone | Production of the transfer code makes it possible to transfer a domain name to another registrar, so it is a secret and not a look-up particular |
Where no consent exists, the public output carries a not-published marker — in English, "not published" — in place of the contact fields, or the corresponding block is not output at all; that is the regime established by clause 3 of the Regulations of the public WHOIS Internet service (clause 1.11). If a registry changes the set of fields, we will update this table (clause 14.3).
5.3. We cannot change the extent of publication, but we can stop the publication itself. The composition of the fields a registry publishes is established by the registry; we have neither the right nor the technical ability to change it, and an enquiry making such a demand will be forwarded by us to the registry and we will inform you of the outcome. We can, however, stop the publication of your personal data, and are obliged to — on your refusal of consent or its withdrawal (clause 5.4.1). The two must not be confused: the first does not depend on us, the second does.
5.4. Your personal data are published only with your consent; where there is no consent we mark no field as one to be published (clause 5.4.4). Two different things must be kept apart here:
- the transfer of the particulars to the registry is an inseparable part of the service. Without it a domain name cannot exist. The ground is the performance of a transaction, not consent (clause 3.1), and it is impossible to opt out of the transfer while leaving the domain name registered;
- the publication of personal data in the WHOIS and RDAP services is a separate act, and it is carried out solely at the wish of the person concerned and on the basis of consent obtained from that person to the dissemination of its personal data, expressed in written form or in a form permitting the conclusion that consent has been given. That is what the law requires — the dissemination of personal data consists of acts transferring particulars about a natural person with the consent of the data subject (part one of article 14 of Law No. 2297-VI), and dissemination without consent is permitted only in the narrow cases set out in part two of the same article, to which publication in WHOIS does not belong. The rules of the registries require the same, and that is how we act.
5.4.1. Refusing consent, and withdrawing it, cost you nothing. A refusal to give consent to publication, or its withdrawal, does not affect the validity of the contract for the registration and maintenance of a domain name, is not a ground for refusing registration, for suspending the services or for terminating the contract, and entails no other adverse consequence. We are answerable for obtaining that consent and for the lawfulness of the publication. On receiving a withdrawal, we submit to the register without delay the command to cease publication.
5.4.2. What we cannot do even so. The extent of the fields a registry publishes where consent exists is established by it (clause 5.2). Nor do we control third parties' archives and caches in which particulars may have been retained while publication was in force, or a registry's own storage periods (clause 5.7).
5.4.3. Clauses 5.4—5.4.4.1 concern the personal data of natural persons. Particulars of a legal entity as such are not personal data, and the manner of their publication is determined by the Regulations of the zone concerned (clause 1.11).
5.4.4. How this is done technically. We hold each contact's publication policy as the directive provided for by the EPP protocol (RFC 5733) and transmit it to the registry exactly as it is recorded. That directive has only two forms: a permission to publish the fields it names — where consent exists, and in that case it names only the fields the consent covers; or a prohibition on publishing the fields it names — where consent was refused or withdrawn, and in that case it names every field: name, organisation name, postal address, telephone, fax and email address. The exact form of that directive is determined by the protocol; it is of no significance for understanding this clause.
5.4.4.1. No directive means a prohibition, not a permission. Where no publication policy is recorded for a contact — including where the contact reached us together with a domain name transferred in from another registrar and that registrar left no such directive — we apply a prohibition on publication in respect of every field — name or business name, organisation name, postal address, telephone, fax and email address — and it is that prohibition we transmit to the registry. This matters because the registry's own rule is not favourable to you: the Regulations of the public WHOIS Internet service (clause 1.11) places the choice of which particulars to publish on the registrar and provides that a not-published marker appears where the registrar has restricted access — so in the absence of a directive the contact fields would be published. Silence never results in your data being published. Independently of this, clause 5.4.1 remains available to you at any time — on your enquiry under clause 1.3 we submit the command to cease publication without delay and inform you of the outcome.
5.5. Anonymisation of a registrant's particulars (proxy contact). We do not offer an anonymisation (proxy contact) service in any zone. The particulars of the domain name state the registrant's true particulars, and protection from publication is achieved by refusing consent under clause 5.4 — which is free of charge, available at any time and carries no adverse consequence (clause 5.4.1). If we ever introduce anonymisation, we are obliged to warn you of the other side of it as well: even where the rules of a zone (clause 1.11) permit anonymisation in the public output, the registry still receives the registrant's true data, and on the demand of a competent authority or within a domain dispute those data may be disclosed; furthermore, anonymisation means the potential impossibility of identifying you as the holder of the domain name in the event that the registrar ceases its activity, of technical failures or of loss of data. That warning is our obligation under the contract with the administrator of the public domains and under clause 9.8 of the Terms of Service.
5.5.1. On the service contact that the rules of some zones require. The contract of the administrator of biz.ua, co.ua, pp.ua and the Cyrillic zone xn--j1amh obliges a registrar to make available to a registrant the possibility of registering a domain name to a service contact, if the registrant wishes to keep their contact data confidential.
5.5.1.1. That possibility is provided by the non-publication under clause 5.4, and it operates field by field. A contact's particulars — name or title, organisation, postal address, telephone, fax, e-mail — are entered by whoever creates the contact (you, or the Purchaser through whom the domain name was ordered), and for each of those fields separately it is stated whether it is to be published. A field not marked for publication does not appear in the public output. This is free, always available, and carries no adverse consequence (clause 5.4.1).
5.5.1.2. What we do not do — and what that is precisely what keeps possible. We do not substitute our own particulars for the registrant's in a domain name's record: the registrant remains the person themselves. That is why the risk clause 5.5 warns about, and which the requirement to keep the registrant identifiable is aimed at — being unable to identify the holder of a domain name if the registrar ceases business, or on a technical failure or data loss — does not arise. If the Purchaser through whom the domain name was ordered offers anonymisation of their own, they are obliged to warn you of that risk (clause 11.2.13 of the Distributor Agreement).
5.6. RDAP. Three of the four registration systems we work with have an RDAP service. As at 25.08.2026:
- the .UA domain and the zones whose registration system is kept by HOSTMASTER LLC — at https://rdap.hostmaster.ua/. That is the address listed for the
uadomain in the official IANA RDAP Bootstrap registry; - the zones whose registration system is kept by SUNIC — in.ua, od.ua, odesa.ua, odessa.ua, mk.ua, mykolaiv.ua, nikolaev.ua — at https://rdap.sunic.ua/ (a request to
rdap.hostmaster.uais redirected there automatically); - the zones whose registration system is kept by EUNIC — net.ua, dn.ua, donetsk.ua, lg.ua, luhansk.ua, lugansk.ua, kh.ua, kharkiv.ua, sm.ua, sumy.ua, zp.ua, zaporizhzhia.ua, zaporizhzhe.ua — at https://rdap.eunic.net.ua/.
The biz.ua, co.ua and pp.ua zones and the Cyrillic zone xn--j1amh have no RDAP service. Their registration system is kept by Servis Onlain LLC (DRS.UA), and data about domain names in them are available through WHOIS alone (clause 5.2). In those zones the public WHOIS output publishes the registrant's full contact particulars — surname and given name, address and telephone number. The extent of that publication is set by the administrator of those zones; take it into account before registering a name in them.
Where an RDAP service exists, the extent of its output matches that of WHOIS (clause 5.2): where no consent exists, the contact record is returned with a not-published marker and a remark about the data processing rules. The service operates under the Regulations of the public RDAP Internet service (clause 1.11). Clauses 5.1—5.5 apply to RDAP.
5.7. After a domain name is deleted, particulars about it may remain in the registry's database and archives for the periods it has established. We do not control those periods.
5.8. The public nature of WHOIS means that your contact data may be harvested automatically by third parties, in particular for the sending of unwanted correspondence and of offers to "renew your domain" that do not come from us. We have nothing to do with such approaches and recommend that you check the sender before paying.
5.9. What exactly we keep about consent. For each contact we keep the publication policy in force — the set of fields the consent covers (clause 5.4.4) — and the history of its changes: the date and time of each change and the party who made it (a purchaser's or an operator's account). That change history is kept for 1,095 days (clause 7.2). We do not keep a separate consent register recording the manner in which consent was obtained or the document evidencing it. Where the data reached us through a purchaser, the documents evidencing the registrant's consent are collected and kept by the purchaser (clause 6.4), and it is the purchaser who produces them on request; that does not relieve us of our own answerability to the registries for the lawfulness of the publication. We undertake to introduce a separate consent register recording the manner in which consent was obtained and the source it came from before we begin accepting orders under the Terms of Service. On your enquiry under clause 1.3 we will tell you what the records we do hold contain.
6. Registrants' data received from purchasers
6.1. Where a domain name is ordered through a purchaser, the registrant's data reach us from that purchaser. In that case:
- the Purchaser is an independent controller of personal data in respect of its own customers: it collects the data, concludes the contract with the customer and determines how it serves that customer;
- we are an independent owner in respect of the data we have received, since we ourselves determine their storage periods, transfer them to the registry and answer for them to the registry as an accredited registrar.
6.2. We do not act as the purchaser's processor of personal data. This means that each party answers for its own part of the processing and independently responds to data subjects' enquiries in its own part.
6.3. The grounds for processing such data are clause 6 of part one of article 11 of Law No. 2297-VI (legitimate interest in providing the service ordered by the purchaser and in performing our obligations as a registrar) and clause 3 of the same part, as regards the performance of the chain of contracts that makes the registration of the domain name possible; articles 6(1)(f) and 6(1)(b) GDPR.
6.4. The partner agreement imposes on the Purchaser the obligation to: collect accurate data; provide its own customer with the notice required by article 12 of Law No. 2297-VI together with a link to this Policy and to the Regulations of the zone concerned (clause 1.11) — at the moment the data are collected, and not later; obtain from that customer a separate consent to the publication of personal data in the WHOIS and RDAP services and transmit to us the indication that it exists — without such consent no publication takes place (clause 5.4); include in its own contract with the customer the confirmation and agreement as to the processing of personal data in the terms set out in clause 11.2.2 of the Distributor Agreement, and retain the documents evidencing that this information was given for the whole period of the processing; warn the customer that where it transfers third parties' data (administrative, technical and billing contacts) it warrants the lawfulness of that transfer and undertakes itself to inform those persons of the composition of the data, the purposes of processing, the recipients and how their rights may be exercised; transfer to us only the volume of data needed for registration; transfer changes in good time, including a withdrawal of consent to publication; notify us without delay of data subjects' enquiries and of incidents; and pass on to its customer, without delay and unaltered, our notices addressed to the registrant, in particular the notice under clause 6.5.
6.4.1. Where a Purchaser engages Resellers. The partner agreement permits a Purchaser to engage other persons — Resellers — in the sale of its own services. In that case the registrant's data are collected not by the purchaser but by the Reseller, and this is where the chain breaks most easily: article 12 of Law No. 2297-VI requires the data subject to be notified at the moment the data are collected, whereas the purchaser's own contract with the customer does not reach that moment, because it has no customer — the customer belongs to the Reseller. The purchaser is therefore obliged to pass the obligations under clause 6.4 on to every Reseller it engages, in full, and above all the obligation to give the notice under article 12 together with a link to this Policy at the very moment the data are collected, and the obligation to obtain separate consent to publication in the WHOIS and RDAP services before the data are transferred to us. The purchaser answers to us for the performance of those obligations by the whole chain of persons it has engaged, however long that chain may be, and at our demand is obliged to tell us through which Reseller a particular registrant's data arrived — otherwise we can neither deal with a data subject's enquiry nor establish the source of collection for the record under clause 7.7.
6.4.2. For the registrant this changes nothing. However many persons there may be in the chain, we notify the registrant of the processing ourselves in the manner set out in clause 6.5, deal with its enquiries under clause 8.3, and do not make this depend on whether the purchaser or the Reseller has performed its obligations or on the state of settlements between them (clause 8.4). We are in no contractual relationship with a Reseller and make no demands of our own on it — we make them of the purchaser.
6.5. We cannot verify compliance with clauses 6.4 and 6.4.1 in every individual case, and the purchaser's compliance does not discharge our own duty under article 12 of Law No. 2297-VI. Therefore, where a registrant's data have reached us from someone other than the registrant, we notify the registrant of the processing ourselves — to the email address stated in the particulars of the domain name, without delay after the first registration of a domain name and in any event within thirty working days of receiving the data (part two of article 12 of Law No. 2297-VI). The notice contains a link to this Policy and particulars of the composition of the data, the purpose of processing and the recipients. If we hold no usable email address for the registrant, we deliver that notice through the purchaser, on which clause 6.4 imposes the duty to pass it on immediately and unaltered; that does not discharge our duty under article 12, so we repeat the notice directly as soon as a usable address appears. As at the edition stated in the heading there is no automatic sending of that notice on the platform: every platform notice is addressed to the purchaser, and the direct notice to the registrant is sent by a separate act. We undertake to introduce automatic direct notification of the registrant and, until then, to send it by a separate act for every new registration submitted by a purchaser.
6.5.1. If you are a registrant who learned of us only after the domain name had been registered, this Policy is the full text of the notice about the processing, and you may contact us under clause 1.3 regardless of whether the purchaser has performed its obligation.
6.6. The data of a purchaser's representatives — contact persons, technical staff, persons who sign documents — are processed by us on the ground set out in clause 6 of part one of article 11 of Law No. 2297-VI, in order to perform the partner agreement, to secure access and to maintain the evidential record.
6.7. We do not use the data of a purchaser's customers for our own marketing and do not offer them services directly. Such data are processed solely in order to provide the service ordered through the purchaser.
6.8. Test environment (OT&E). The test environment is not production: registrations in it are not real, the data in it may be purged without notice, and some responses are emulated. Do not send real personal data to the test environment.
7. Storage periods
7.1. We store personal data no longer than is needed for the purposes set out in section 3, or than the law requires (article 6 of Law No. 2297-VI). Once the period expires, the data are deleted or anonymised.
7.2. Periods by category:
| Category of data | Storage period | Basis of the period |
|---|---|---|
| Account and the correspondence relating to it | For the term of the contract and three years after its termination | The general limitation period is three years — article 257 of the Civil Code of Ukraine |
| Registrant and domain name data | For as long as we service the domain name, and three years after servicing ends | The general limitation period is three years — article 257 of the Civil Code of Ukraine |
| Invoices, acts of services rendered, bank statements, income records | Not less than 1,095 days from the day the reporting for which they were used was submitted, and not less than five years in total | Clause 44.3 of article 44 of the Tax Code of Ukraine; the List of Standard Documents approved by Order of the Ministry of Justice of Ukraine No. 578/5 |
| EPP frame log (clause 2.6) | 1,095 days | 1,095 days is the three years of the general limitation period under article 257 of the Civil Code of Ukraine: throughout that period a dispute about an operation remains possible |
| History of changes to objects — domain names, contacts, name servers | 1,095 days | 1,095 days is the three years of the general limitation period under article 257 of the Civil Code of Ukraine: throughout that period a dispute about a change to an object remains possible |
| Operator action log | 1,825 days | 1,825 days is five years; longer than the limitation period, because an operator's acts are pricing and accounting decisions and are checked together with the settlement documents |
| Service messages and the Message Queue | 1,095 days | 1,095 days is the three years of the general limitation period under article 257 of the Civil Code of Ukraine; these records are evidence of notification of a change of terms and of the outcome of an operation |
| Technical operation traces | 7 days | Needed only for current diagnostics; they have no evidential value |
| Technical queues for performing operations | 30 days | Needed only for the current processing of operations |
| Raw registry responses and the log of processing them | 1095 days | Acknowledging a message destroys it at the registry, so our record is the only surviving copy of what it said; a dispute over a refund or a forced renewal remains possible throughout the three-year general limitation period (article 257 of the Civil Code of Ukraine) |
| Website and panel access logs | 30 days | Platform security (clause 3.6); 30 days is the retention period of the log collection system |
| Backups | Daily copies: the newest 14 on the main server, 30 days in the encrypted off-box store; the database write-ahead log — 5 days | Recovery after a failure; how data disappear from copies is described in clause 7.6 |
| The publication policy in force and the history of its changes (clause 5.9) | The history of changes — 1,095 days; the policy in force — for the whole period of processing of the data concerned | It is we who answer to the registries for the lawfulness of publication, so we must be able to show what was marked as publishable, and when |
| The record of operations on personal data (clause 7.7) | Not less than one year from the end of the year in which the operations concerned were performed | The minimum period established by the rules of the registries |
7.3. The periods set out in the table in clause 7.2 were reconciled with the actual storage configuration on the platform on 31.08.2026 and correspond to it: the published period is not shorter than the actual one. If an actual period is extended, we will update this table before the change takes effect (clause 14.2).
7.4. The periods may be extended where a dispute, an inspection by a supervisory authority, court proceedings or a domain dispute is under way — until they conclude and the periods for appeal expire (clause 44.4 of article 44 of the Tax Code of Ukraine). We store settlement documents for longer than three years for that same reason — because of the periods established by tax legislation and by the List of Standard Documents (clause 7.2), and not on some separate ground.
7.5. Data already transferred to a registry are stored according to its own periods (clause 5.7); deletion of data by us does not cause their deletion at the registry.
7.6. Data disappear from backups once the full backup rotation cycle has completed, not at the moment of deletion from the production system. Until the cycle completes, the backups remain encrypted and are used solely for recovery after a failure.
7.7. The record of operations on personal data. We keep a separate record of operations connected with the processing of the personal data of the registrant and of the administrative, technical and billing contacts, and of access to them. It contains: the date, time and source of collection of the data; any change to the data; any viewing of the data; any transfer or copying; the date and time of deletion or destruction; the person who performed the operation concerned; the purpose and grounds of the change, viewing, transfer, deletion or destruction; and a general description of the technical and organisational security measures. Those particulars are kept for not less than one year from the end of the year in which the operations concerned were performed; the actual storage periods of the sources from which that record is composed are set out in clause 7.2 and are longer. This record is kept in performance of the registries' requirements.
8. Rights of the data subject
8.1. You have the rights provided for by article 8 of Law No. 2297-VI, in particular the right:
- to know about the sources of collection and the location of your personal data, the purpose of their processing, and the location of the controller and of the processor;
- to receive information about the conditions on which access to the personal data is granted, in particular about the third parties to whom they are transferred;
- of access to your personal data;
- to receive an answer as to whether your data are being processed, and particulars of their content;
- to submit a reasoned demand objecting to the processing;
- to submit a reasoned demand for the alteration or destruction of the data if they are processed unlawfully or are inaccurate;
- to protection against an automated decision that has legal consequences (section 9);
- to withdraw consent where the processing is based on consent (clauses 3.9, 5.4 and 10.3);
- to complain to the Ukrainian Parliament Commissioner for Human Rights or to a court;
- to enter reservations limiting the right of processing when giving consent.
8.2. Persons who are in the European Union have additional rights under articles 15—22 GDPR; how to exercise them is described in section 13.
8.3. How to make an enquiry. Send your enquiry to the address in clause 1.3 or by post to the address in the "Our Details" section. So that we can deal with it, state: your surname, given name and patronymic (if any), and your address; the particulars that enable us to identify you in our system (the email address of the account or the domain name); the list of personal data the enquiry concerns; and the substance of your demand and its purpose or legal basis.
8.3.1. A simplified list of what a request must contain. Part four of article 16 of Law No. 2297-VI also requires a request to state the details of an identity document and particulars of the personal data base or of the owner or processor. We do not require them: obtaining a copy of an identity document merely in order to answer an enquiry would mean collecting more data than is necessary (clause 8.4). We treat an enquiry made under clause 8.3 as properly made and do not refuse it on grounds of incompleteness.
8.4. Confirmation of identity. We must be satisfied that the enquiry has come from the data subject and have no right to disclose data to an outside person. Sufficient confirmation is: an enquiry from the email address stated in the account; an enquiry from the email address stated in the particulars of the domain name, where you have no account with us because the domain name was ordered through a purchaser; an enquiry through the control panel; or an enquiry signed with a qualified electronic signature. We ask for additional confirmation only where the listed methods are unavailable, and to the minimum extent. The state of settlements between you and a purchaser, or between a purchaser and us, has no bearing on the handling of your enquiry.
8.5. Time limits. A request is examined within ten working days of receipt, and within that period we inform you whether it will be granted; the request itself is granted within thirty calendar days of receipt, unless otherwise established by law (article 16 of Law No. 2297-VI). For GDPR enquiries the period is one month, with the possibility of an extension by a further two months for complex requests (article 12(3) GDPR).
8.6. When we cannot grant a demand in full. We are obliged to explain the ground for refusal in writing. Such grounds include, in particular:
- the data are already in a registry's database and their removal from there does not depend on us (clauses 4.4.1 and 5.3); this does not apply to ceasing publication, which we carry out at your demand (clause 5.4.1);
- the data form part of documents stored for a mandatory period (clause 7.2);
- the data are evidence in a pending dispute or in the settlement records (clause 3.7);
- complying with the demand would disclose another person's personal data.
8.7. Enquiries are considered free of charge.
8.8. Complaint. You have the right to complain to the Ukrainian Parliament Commissioner for Human Rights (contact details are on the Commissioner's official website) or to a court. Persons who are in the European Union also have the right to complain to the supervisory authority of their place of residence (article 77 GDPR).
9. Automated decisions
9.1. Automatic mechanisms operate on the platform that may restrict access or the performance of an operation without human involvement: checking of allowed IP addresses, rate limiting (a shared command limit for the EPP interface), and automatic rejection of a chargeable operation for which the balance is insufficient. There is no automatic blocking on indicators of abuse on the platform: a restriction for abuse is applied by a human being — an operator, acting on an abuse report, a registry demand or a court decision — and such a restriction is reversible.
9.2. Those decisions are based on the technical parameters of the connection, the state of the ledger account and the fact of a breach of the terms, and not on an assessment of a person's personal characteristics, behaviour or preferences. We do not carry out profiling for advertising purposes.
9.3. If an automatic decision affects your rights, you may demand that it be reviewed by a human being and provide an explanation. Enquiries are made under clause 8.3. This right is provided for by article 8 of Law No. 2297-VI and, for persons in the European Union, by article 22 GDPR.
10. Cookies and analytics
10.1. Necessary cookies. The website uses a session cookie that stores the session identifier, the logged-in state and the chosen interface language, and a cookie protecting against cross-site request forgery (CSRF). The session cookie is marked so that scripts on the page have no access to it. The cross-site request forgery cookie carries no such marking and cannot: it is the page's own script that reads the value from it and returns it in a request header — that is what the protection consists of. Both cookies travel only over a secure connection and are not sent by the browser with requests initiated by another site — save for an ordinary follow of a link. The session lifetime is 120 minutes from the last activity.
10.2. Necessary cookies do not require consent: without them it is impossible to log in to the panel, to preserve the language choice or to protect the forms. Ground — clause 3 of part one of article 11 of Law No. 2297-VI.
10.3. Analytics and advertising. As at the edition stated in the heading of this Policy, we do not set analytics or advertising cookies, do not add third-party web analytics systems to the code of the site and do not insert trackers into its pages. The cookies this site sets are set out exhaustively in clause 10.1.
10.3.1. One circumstance we state plainly, although it is not our code. Our content-delivery provider (clause 4.8) adds its own visit-measurement script to the pages — at the network level, outside the code of the site. That script transmits to the provider the address of the page opened and the network address of the visitor; we receive from it only aggregate visit statistics, do not link them to accounts and do not use them for profiling or advertising. We state it here because, for you, it is a transfer of data like any other — regardless of whose code performs it.
10.3.2. If we introduce our own analytics, this Policy will be updated before it is introduced, and the analytics cookies themselves will be set only after consent has been obtained, which it will be possible to withdraw.
10.4. Cookies can be managed by means of your browser. Disabling necessary cookies makes it impossible to log in to the panel.
11. Data security and action in the event of a breach
11.1. We take organisational and technical protective measures, as required by article 24 of Law No. 2297-VI. They are described below at a level that does not disclose detail usable for an attack:
- all connections to the panel and to the EPP interface are protected by TLS;
- access to the EPP interface is restricted to a list of allowed IP addresses, which operates on the principle that only what is expressly allowed is permitted;
- sign-in attempts to the panel are rate-limited and sessions expire on inactivity;
- passwords are stored only as cryptographic hashes;
- staff access is segregated by role, and operators' actions are recorded in a separate log (clause 7.2);
- operations on personal data and access to them are recorded in a separate record (clause 7.7);
- backups are stored in encrypted form;
- secrets are masked in the logs before they are written to disk (clause 2.6), and access to the log directories is restricted at the file system level.
11.2. We do not claim that the system is absolutely secure — no system is. We claim only that what is listed in clause 11.1 is in fact applied.
11.3. In the event of a breach of personal data protection we localise the breach, assess its consequences and, without delay after becoming aware of it, notify the data subjects concerned — of the nature of the breach, its likely consequences and the measures taken. If the breach is covered by the GDPR, we additionally notify the competent supervisory authority within 72 hours (article 33 GDPR) and the data subjects in the cases provided for by article 34 GDPR.
11.3.1. Notification of the registries. In addition, on detecting unauthorised access to our systems, to the registration system or to a client's credentials, we immediately notify the operator of the register and the administrator of the relevant public domain. That is a duty of an accredited registrar, and it arises also where it is you who reported the unauthorised access to us. The notification contains only the particulars needed to assess the threat to the register and is not a disclosure of the content of your enquiry to outside persons.
11.4. If you suspect that your credentials, EPP passwords or transfer codes have been compromised, change them immediately and notify us at security@namespace.com.ua (for abuse reports — abuse@namespace.com.ua). Both addresses are in the table of contacts on the Our Details page, and reports of an immediate threat are handled at either round the clock (clause 8.3 of that page). At your demand we will block access to the account; the manner of such a block, its limits and how it is lifted are established by clause 5.3 of the Terms of Service.
11.5. This Policy does not limit our liability for breaches of personal data protection legislation. The limitations of liability established by the Terms of Service do not in any circumstances extend to cases of intentional breach of an obligation: a transaction that excludes or limits liability for an intentional breach of an obligation is void (part three of article 614 of the Civil Code of Ukraine).
12. Cross-border transfer of data
12.1. The persons to whom we transfer personal data under clause 4.3 are registered in Ukraine, so such transfers are not cross-border. The same holds for the administrator of the public domain in which a domain name is registered. Should a recipient be a person not resident in Ukraine, article 29 of Law No. 2297-VI will apply to transfers to it, and we will say so in this clause before any such transfer begins.
12.2. Transfers connected with the location of infrastructure and with the engagement of service providers (clause 4.8) and with the execution of payments (clause 4.7) are cross-border. As at the edition stated in the heading of this Policy, the States concerned are:
- Poland — the server on which the registration system, the website and the control panel run, and the outbound mail server. The Provider reserves the right to place those systems in Ukraine or in another State of the European Economic Area; such States are recognised as ensuring an adequate level of protection of personal data (part two of article 29 of Law No. 2297-VI), so a change of location within “Ukraine or the EEA” alters neither the legal basis of the processing nor the extent of your rights, and requires no separate consent from you. An actual change is notified in the manner set out in clause 14.4, and the list in force is always the one in this clause;
- Ukraine — settlements in hryvnia, US dollars and euro over the SWIFT route;
- the United States of America and the supplier's global network of nodes — the delivery network and reverse proxy for the website;
- the United Kingdom — settlements in euro over the SEPA route.
12.3. Personal data are transferred to foreign subjects of relations in accordance with article 29 of Law No. 2297-VI. Member States of the European Economic Area and States that are parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data are recognised as ensuring an adequate level of protection. Transfers to other States are made only where the grounds provided for by that same article exist, in particular where the transfer is necessary for the conclusion or performance of a transaction in the interests of the data subject.
12.4. The conditions on which data are transferred to us from the European Economic Area are described in section 13.
13. Persons who are in the European Union
13.1. The GDPR applies to our processing in so far as we offer services to persons who are in the European Union (article 3(2)(a) GDPR). In that part we comply with both Law No. 2297-VI and the GDPR.
13.2. In respect of the data described in this Policy we act as an independent controller within the meaning of article 4(7) GDPR. The operator of the register and the administrators of the public domains act in respect of those data as our processors within the meaning of article 4(8) GDPR — that is precisely the allocation of roles fixed in the contracts signed with them; those persons process the data only on our instruction and engage no sub-processors without our written consent (clause 4.4). We do not disclose the content of the contracts with the registries themselves: it is confidential. Data subjects' requests concerning data already entered in a register we handle ourselves, in the manner set out in clause 8.6: where the demand is satisfied by a command to the register — in particular, ceasing publication — we submit that command; where performance of the demand does not depend on us, we explain the ground in writing and forward the request to the registry, informing you of the outcome (clause 5.3). A purchaser is an independent controller in respect of its own customers (section 6).
13.3. The legal grounds under the GDPR are stated in each clause of section 3. The information required by articles 13 and 14 GDPR is set out in sections 1—7 of this Policy; for data obtained otherwise than from the data subject (article 14 GDPR), clause 6.5 applies in addition. The rights of the data subject are those in articles 15—22 GDPR; the procedure for making an enquiry is in clause 8.3; the time for a response is in clause 8.5; the right to complain to a supervisory authority is in clause 8.8.
13.4. Representative in the European Union (article 27 GDPR). We do not appoint a representative in the European Union and rely on the exception in point (a) of article 27(2) GDPR: our processing of the data of persons who are in the European Union is occasional, does not include large-scale processing of special categories of data or of data on criminal convictions (clause 2.9), and is unlikely to result in a risk to the rights and freedoms of natural persons. We carry out no marketing in Member States of the European Union (clause 3.9) and do not target our offering at them; the existence of a euro account is due to settlements with particular counterparties, not to offering services to consumers in the European Union. If that processing ceases to be occasional, we will appoint a representative and state it in this Policy before that happens.
13.5. Transfers of data to us from the European Economic Area. Ukraine does not have an adequacy decision of the European Commission under article 45 GDPR. Therefore, if you transfer personal data to us from the EEA (for example, as a purchaser from a Member State), such a transfer is made on the basis of the standard contractual clauses approved by the European Commission under article 46(2)(c) GDPR, in the controller-to-controller module. We conclude such clauses at a partner's request. The standard contractual clauses apply unmodified and prevail over any other agreement between the Parties, in particular over the Distributor Agreement, in so far as they cover the matter (clause 5 of the Clauses themselves); they operate only where the Annexes to them have been completed — for the controller-to-controller module those are Annexes I and II. The completed Annexes are published: Standard Contractual Clauses (EU) 2021/914 — Annexes. They are Appendix 5 to the Distributor Agreement.
13.6. Onward transfers. The transfer of data to the operator of the register and to the administrators of the public domains in Ukraine is an onward transfer necessary for the performance of the contract with the data subject or in the data subject's interests, and is disclosed in section 4. Those persons process the data as our processors, on our instruction and within the limits set by the contracts with them (clause 13.2), and publish part of them in WHOIS and RDAP only where the data subject's consent exists (section 5).
13.7. What is stated in this section does not mean that we accept that the GDPR applies to all of our activity; it applies within the limits determined by article 3 GDPR.
14. Changes to this Policy
14.1. The edition of this Policy in force is always available at /legal/privacy. Every edition has a number and a date, stated in the heading of the document.
14.2. We give notice of material changes — those that expand the composition of the data, change the purpose or ground of processing or the list of recipients — no less than 30 calendar days before they enter into force: by email to the address on the account and by a notice in the panel. That period is the same across all our documents (clause 22.3 of the Terms of Service and clause 18.2.2 of the Distributor Agreement).
14.3. Changes brought about by the rules of the registries or by legislation are an exception to clause 14.2 and enter into force on the date established by the registry or by the law. We cannot give more time than the registry gives us: amendments to the Public Domain Regulations may be made 30 days before they take effect and, in a case of urgent necessity, simultaneously with their publication (clause 11 of those Regulations); the same regime is established for the Regulations of the public WHOIS Internet service (clause 6 of those Regulations). The full titles of those documents, the persons who publish them and the addresses at which they are available are set out in clause 1.11; which edition applies is set out in clause 1.11.1. To promise a longer period would be to promise something we do not control.
14.4. Continuing to use the services after a new edition enters into force signifies that you have familiarised yourself with it. If a change requires consent (clauses 3.9, 5.4 and 10.3), we ask for consent separately and do not carry out the processing concerned until it is obtained.
14.5. Archive of previous editions. We retain every previous edition of this Policy, stating its edition number and the period during which it was in force. The archive is shared by every document in the Legal section and is available at https://namespace.com.ua/legal/archive (clause 22.7 of the Terms of Service); there is no separate archive of this Policy. The archive page is published, and any edition can be downloaded from it directly. Independently of that, we send any edition on request to the address in clause 1.3, within the period set by clause 8.5. The edition in force at the moment you accepted this Policy (clause 2.11) remains available to you for the whole term of the contract and for three years after its termination.
14.6. If an individual provision of this Policy is found to be invalid or contrary to law, the remaining provisions remain in force.