Grade A+ — Highly protective (score 100/100)
DonDominio pledges no third-party data sharing, defines retention periods for every data category, commits to encryption and pseudonymization, and grants full GDPR rights to all users regardless of region.
GDPR-compliant policy: no-sale pledge, specific retention, encryption, full Art. 15-22 rights.
DonDominio will neither transfer nor communicate your personal data to third parties, except (i) there is a legal obligation, (ii) it is necessary for the correct provision of the contracted service, or (iii) with your express consent.
The company commits not to sell or share personal data, with narrow service-delivery and legal exceptions.
Domains gTLD registration data 15 months after domain deregistration, transfer or expiration; Contractual relationship and billing data 6 years for commercial obligations (art. 30 CCom) and 4 years for tax obligations (arts. 66-70 LGT); Traffic and connection metadata (hosting/email service) <span class='mk-good' data-note='Statutory 12-month
The document defines specific, legally-backed retention periods for every data category.
DonDominio implements appropriate technical and organizational measures to: ensure the confidentiality, integrity, availability, and continued resilience of systems and data processed; restore data and access in the event of a physical or technical incident; regularly verify and evaluate the effectiveness of implemented measures; pseudonymize and encrypt personal data when necessary.
The company commits to industry-standard security practices including encryption and regular verification.
When it is necessary to transfer data to a country without an adequacy decision from the European Commission, DonDominio applies the Standard Contractual Clauses 2021/914/UE and, if applicable, additional technical measures (encryption, pseudonymization) to ensure a level of protection equivalent to that in Europe.
International data transfers outside the EEA are governed by SCCs with additional safeguards.
In accordance with Articles 15 to 22 of the GDPR, you may: Access the personal data processed by DonDominio; Rectify inaccurate or incomplete data; Erase the data when no longer necessary or under the Article 17 GDPR circumstances; Object to the processing or request its restriction; Request the portability of the data you provided; Request not to be subjected to automated individual decisions…
Users are granted comprehensive GDPR data subject rights, applied regardless of jurisdiction.
All requests, decisions, and accesses are recorded and kept for 15 months (art. 15 RDP).icann.org. The applicant may appeal to the Spanish Data Protection Agency or ICANN Compliance if they disagree with the decision.
Non-public data disclosure is gated by a formal procedure with an independent appeal channel.
In case of non-payment or delinquency of due amounts, DonDominio may communicate the necessary data to the ICIRED asset solvency file or another credit information system that complies with the RGPD and LOPDGDD, solely for managing collection and third-party credit risk assessment.
Delinquent accounts may be reported to Spanish credit bureaus under legitimate interest.
Last reviewed 2026-09-10 under rubric v3.5.