Cobydomains is the data controller responsible for the personal data covered by this notice, and we handle it in line with the UK General Data Protection Regulation (UK GDPR) and other applicable UK data protection law.
This notice explains how personal information belonging to those who deal with us or use our services is gathered, used, retained, and kept secure.
Where Your Data Comes From
We may gather personal data in a variety of ways, for instance when you:
- Use or navigate our website
- Contact us via email, phone, or post
- Register a domain with us, or ask us to manage one on your behalf
- Raise a query or ask our support team for help
- Get in touch about your account or a service you’re using
What We May Hold
The specific data we hold will depend on how you’ve interacted with us, but could include:
- Details we’re required to keep on file under Nominet’s registration rules
- Standard contact information — name, email address, phone number, postal address
- A history of the communications and interactions we’ve had with you
- Payment or billing details, where these are needed to take payment or issue a refund
- Limited technical information used solely to assist with support
Our Reasons for Using It
Personal data is processed only where there’s a proper reason to do so — for example, to:
- Contact you about your account, upcoming renewals, or support requests
- Carry out domain registration and management on your behalf
- Look into and respond to complaints or reports of misuse
- Fulfil legal or regulatory requirements, including those imposed by Nominet
We do not sell personal data under any circumstances, nor do we send marketing you haven’t asked to receive.
Who We Might Share It With
We only disclose personal data in specific, limited situations — to:
- Suppliers who assist with technical or domain-related operations
- Nominet, in its role as the UK’s registry, where needed to meet registration requirements
- Law enforcement or regulatory authorities, when we’re legally obliged to provide it
- Payment processors, strictly for the purpose of completing a transaction
Keeping Your Data Secure
Appropriate technical and organisational measures are in place to protect personal data from misuse, loss, or unauthorised access. Access is limited to staff who require it to do their jobs.
How Long We Keep Data
We retain personal data only for as long as it serves an operational, legal, or support purpose. Once that need has passed, the data is either securely erased or anonymised.
Your Rights
UK data protection law gives you a number of rights over your personal data — including the ability to request a copy of it, ask for corrections, restrict how it’s processed, or request its deletion. To exercise any of these rights, please reach out using the contact details on our website.
If you feel we haven’t handled your personal data appropriately, you also have the right to raise the matter with the Information Commissioner’s Office (ICO).