Standard contractual clauses
1. What this document is and when it applies
1.1. This is Appendix 5 to the Distributor Agreement — Annexes I and II to the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.2. It applies where the Purchaser is established in the European Union or the European Economic Area, or transfers to the Provider the personal data of persons in the EU (clause 13.7 of the Distributor Agreement). In every other case a transfer is governed by section 12 of the Privacy Policy and by article 29 of the Law of Ukraine "On the protection of personal data" No. 2297-VI.
1.3. Module One — controller to controller. Each Party determines the purposes and means of processing for itself and is an independent controller; neither acts on the other's instruction. That matches the allocation of roles in clause 13.1 of the Distributor Agreement.
1.4. The text of the Clauses is not reproduced here and is not modified. Clause 2 of the Clauses forbids modifying them, and the official text in every EU language is published in the Official Journal of the European Union (Implementing Decision (EU) 2021/914, OJ L 199, 7.6.2021, p. 31). The Parties apply it unchanged. What is set out here is the Annexes alone — the part the Parties complete themselves and without which the Clauses do not operate.
1.5. There is no Annex III. In the Appendix to the Clauses, Annex III is headed "List of sub-processors" and applies to Modules Two and Three only. It does not apply to Module One: the Annexes in force for it are I and II.
1.6. Governing law and forum. Under Clauses 17 and 18 of the Clauses the Parties choose the law of the Republic of Poland and the courts of the Republic of Poland. Clauses 21.1 and 21.3 of the Distributor Agreement do not apply to the Clauses themselves. In so far as the Clauses cover a matter, they prevail over the Distributor Agreement (Clause 5 of the Clauses).
1.7. Why they are used. There is no European Commission adequacy decision in respect of Ukraine within the meaning of article 45 of Regulation (EU) 2016/679, so the transfer is made on the basis of appropriate safeguards under article 46(2)(c) of that Regulation.
2. Annex I
A. List of parties
Data exporter — the Purchaser. Its name, address, the name and contact details of its responsible person and its role are stated in the Application to conclude the Distributor Agreement and form part of this Annex from the moment the Contract is concluded.
| Item | Particulars |
|---|---|
| Role | Controller |
| Activities relevant to the transfer | Ordering domain name operations for its own clients and registrants — see section 3 below |
| Signature and date | Conclusion of the Distributor Agreement in the manner set out in its section 5 |
Data importer — the Provider.
| Item | Particulars |
|---|---|
| Name, address and registration particulars | Set out on the Company details page |
| Contact person for data protection matters | The address for personal-data enquiries — clause 1.3 of the Privacy Policy |
| Role | Controller |
| Activities relevant to the transfer | Carrying out domain name operations in the registration systems of the registry operators — see section 3 below |
| Signature and date | Conclusion of the Distributor Agreement in the manner set out in its section 5 |
B. Description of the transfer
| Item | Particulars |
|---|---|
| Categories of data subjects | Domain name registrants and the contact persons they name (administrative, technical and billing contacts); the Purchaser's employees and authorised persons who use the Control Panel or the technical channels |
| Categories of personal data | Given name and surname or company name; address; email address; telephone number; the contact's identifier in the register; particulars of domain names and of operations on them; for the Purchaser's representatives — name, work email address, account identifier and access logs |
| Sensitive data | Not transferred. The Distributor Agreement forbids transferring to the Provider special categories of data under article 9 of Regulation (EU) 2016/679 or criminal-conviction data under article 10 |
| Frequency of the transfer | Continuous, as Applications are submitted |
| Nature of the processing | Receipt, verification, transmission to the registry operator's registration system, storage, publication to the extent the zone's rules require, rectification and erasure |
| Purpose of the transfer | Carrying out domain name operations; settlement of accounts; performing the registrar's obligations to registry operators and to the administrators of public domains; the handling of domain disputes |
| Retention period | The periods are set out in section 7 of the Privacy Policy. Retention periods in the register are set by the registry operator and the Provider cannot change them |
| Onward transfers | The recipients are listed in section 4 of the Privacy Policy. The registry operators and the administrators of the public domains are registered in Ukraine (clause 12.1 of that Policy) |
C. Competent supervisory authority
The supervisory authority of the EU Member State in which the data exporter (the Purchaser) is established or, where the Purchaser is not established in the EU, the supervisory authority of the Member State in which its representative under article 27 of Regulation (EU) 2016/679 is established; failing both, the supervisory authority of the Member State in which the data subjects whose data are transferred are located (Clause 13 of the Clauses). The particular authority is stated in the Application to conclude the Distributor Agreement.
3. Annex II. Technical and organisational measures
The measures the Provider applies as data importer. The list is exhaustive as at the edition stated in the heading.
| Measure | How it is implemented |
|---|---|
| Pseudonymisation and encryption | Connections to the registration systems use EPP over TLS with mutual certificate authentication. The website and the Control Panel are served over HTTPS only. Backups are encrypted before they are written |
| Ensuring confidentiality of systems | Access to the Control Panel is by account and password; sessions expire on inactivity and sign-in attempts are rate-limited. Access to servers is by cryptographic key only; password authentication is disabled. Access to the registration systems is by registrar credentials held outside the application code |
| Ensuring integrity of systems | Every operation is written to a log under an immutable identifier; changes to domain name and contact particulars are kept in the object's history. Configuration changes are recorded in snapshots chained by hash |
| Ensuring availability and restoration | Encrypted backups daily; continuous archiving of the database transaction log; point-in-time restoration is exercised by a drill run from an actual backup |
| Regular testing of the effectiveness of the measures | Automated configuration and secret checks before every deployment; regular review of logs and metrics; verification of restoration from backup |
| Identification and authorisation of access | A separate account for each user; accounts are not shared; rights are granted by role and reviewed when a role changes |
| Protection of data in transit | See the encryption row. The domain from which outbound correspondence is sent publishes sender-authentication policies: SPF (forbidding delivery from any other source) and DMARC (quarantine for messages that fail the check) |
| Protection of data at rest | Data are held in a database on a server located in Ukraine; backups are held encrypted |
| Physical security | Equipment is housed in the data centre of the hosting supplier; physical access is controlled by that supplier |
| Event logging | Every operation, every command to a registration system and every sign-in to the Control Panel is recorded with a timestamp and a source identifier |
| System configuration, including default configuration | Only those services that have to be reachable are open from outside; everything else is closed by default |
| Governance and management of information systems | Changes are made through version control with checks before deployment; a deployment can be rolled back to the previous version |
| Certification and quality assurance | The Provider holds no certification under ISO/IEC 27001 or comparable standards and does not rely on one |
| Data minimisation | The Provider collects only the particulars that the zone's rules and the law require; they are listed in section 2 of the Privacy Policy |
| Data quality | Registrant particulars are transmitted to the register as the Purchaser submitted them; the rectification procedure is in section 8 of that Policy |
| Limited retention | The retention periods are in section 7 of that Policy |
| Accountability | The Provider keeps a record of processing and notifies the Purchaser of a security incident within 24 hours of detection (clause 13.6 of the Distributor Agreement) |
| Portability and erasure | The procedure for transferring domain names to another registrar is in the Distributor Agreement; erasure of data is in section 8 of the Privacy Policy |
4. Amendment
4.1. These Annexes are amended in the manner set out in section 18 of the Distributor Agreement.
4.2. Every previous edition is kept and is available in the archive of editions.