DonDominio Terms Scorecard

Grade A+ — Highly protective (score 100/100)

DonDominio pledges no third-party data sharing, defines retention periods for every data category, commits to encryption and pseudonymization, and grants full GDPR rights to all users regardless of region.

GDPR-compliant policy: no-sale pledge, specific retention, encryption, full Art. 15-22 rights.

Terms at a glance

Sells your data
NO
Forced arbitration
NO
Trains AI on your content
NO
Collects biometric data
NO
Shares data with government
LIKELY
Easy to cancel
UNCLEAR
Tells you before changes
UNCLEAR
Deletes data on request
YES

What the terms actually say

RECIPIENTS OF COMMUNICATIONS AND DATA TRANSFERS

DonDominio will neither transfer nor communicate your personal data to third parties, except (i) there is a legal obligation, (ii) it is necessary for the correct provision of the contracted service, or (iii) with your express consent.

The company commits not to sell or share personal data, with narrow service-delivery and legal exceptions.

DATA RETENTION (DURATION OF DATA PROCESSING)

Domains gTLD registration data 15 months after domain deregistration, transfer or expiration; Contractual relationship and billing data 6 years for commercial obligations (art. 30 CCom) and 4 years for tax obligations (arts. 66-70 LGT); Traffic and connection metadata (hosting/email service) <span class='mk-good' data-note='Statutory 12-month

The document defines specific, legally-backed retention periods for every data category.

ADDITIONAL INFORMATION - Security Measures

DonDominio implements appropriate technical and organizational measures to: ensure the confidentiality, integrity, availability, and continued resilience of systems and data processed; restore data and access in the event of a physical or technical incident; regularly verify and evaluate the effectiveness of implemented measures; pseudonymize and encrypt personal data when necessary.

The company commits to industry-standard security practices including encryption and regular verification.

INTERNATIONAL TRANSFERS

When it is necessary to transfer data to a country without an adequacy decision from the European Commission, DonDominio applies the Standard Contractual Clauses 2021/914/UE and, if applicable, additional technical measures (encryption, pseudonymization) to ensure a level of protection equivalent to that in Europe.

International data transfers outside the EEA are governed by SCCs with additional safeguards.

RIGHTS OF DATA SUBJECTS

In accordance with Articles 15 to 22 of the GDPR, you may: Access the personal data processed by DonDominio; Rectify inaccurate or incomplete data; Erase the data when no longer necessary or under the Article 17 GDPR circumstances; Object to the processing or request its restriction; Request the portability of the data you provided; Request not to be subjected to automated individual decisions…

Users are granted comprehensive GDPR data subject rights, applied regardless of jurisdiction.

ANNEX II - NON-PUBLIC DATA DISCLOSURE PROCEDURE

All requests, decisions, and accesses are recorded and kept for 15 months (art. 15 RDP).icann.org. The applicant may appeal to the Spanish Data Protection Agency or ICANN Compliance if they disagree with the decision.

Non-public data disclosure is gated by a formal procedure with an independent appeal channel.

CREDIT INFORMATION SYSTEMS

In case of non-payment or delinquency of due amounts, DonDominio may communicate the necessary data to the ICIRED asset solvency file or another credit information system that complies with the RGPD and LOPDGDD, solely for managing collection and third-party credit risk assessment.

Delinquent accounts may be reported to Spanish credit bureaus under legitimate interest.

Last reviewed 2026-09-10 under rubric v3.5.

Other scorecards