Privacy Policy

This Privacy Policy (the “Policy”, the “Privacy Policy”) applies to the processing of personal data by Infinityscape Ltd., a company registered in England and Wales (company number: 10341460), with registered address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“Infinityscape”, “we”, “us” and “our”) in its capacity as a data controller of personal data.

It explains our data privacy practices in regard to the processing of personal data of individuals (“data subjects”, “you”, “your”) who visit our website (the “Site”) and/or use the services and/or products ordered or accessed through the Site (the “Services”). For the avoidance of doubt, this Policy does not apply to the processing of your personal data by third parties whose websites are not owned and operated by us.

I. Categories of data subjects and types of personal data 

For the purposes of this Policy, the natural persons, whose personal data is subject to data processing under this Policy, respectively the types of their personal data processed by us, may be categorised as follows:

1. Website visitors 

a. Definition: Individuals who visit our Site. For the avoidance of doubt, websites hosted by us but operated by our Customers are not part of the definition of Site. Our Site and Services may contain links to third-party websites, which are not under our control, and we are not responsible for their content. In the event that you follow a link to such pages, please note that there are other respective privacy policies that may apply and we do not have control over it. We encourage you to review the privacy policies of these parties before using such other websites.

b. Types of personal data:

          • Contact information – We may collect personal data such as first and last name, email address and other contact and personal information when you use the available contact forms.
          • Personal data, contained in log files – When you visit our Site we may process information such as your IP address, referral URL, exit URL, browser software, operating system, date/time and/or clickstream data.
          • Personal data collected through website analytics tools – We may collect information about your use of our Site, such as number of visits, pages visited, popularity of certain content. Analytics tools use tracking technologies (such as cookies) to recognise your device and compile information about you. They collect information such as what pages you visit and how much time you spend on these pages, the IP address assigned to you, what operating system and web browser you use, and what site you visited prior to visiting our Site.

2. Customers

    a. Definition: Persons who enter into an agreement with us for the provision of Services.

    b. Types of personal data:

            • Customer account information – We process personal information such as first and last name, name of the legal entity and its legal representative, address, phone number, email address, language preferences, IP address, payment and billing information (i.e. credit card information and/or GoCardless account, personal or TAX identification number etc.), so you can place orders, request information, get support and use the Services.
            • Personal data, contained in log files – When a Customer visits our Site we may process information such as IP address, referral URL, exit URL, browser software, operating system, date/time and/or clickstream data.
            • Personal data collected through website analytics tools – We may collect information about Customer’s use of our Site, such as number of visits, pages visited, popularity of certain content. Analytics tools use tracking technologies (such as cookies) to recognise the device used and compile the information. They collect information such as what pages the Customer visits and how much time the Customer spends on these pages, the IP address assigned to the Customer, what operating system and web browser the Customer uses, and what site the Customer visited prior to visiting our Site.
            • Other types of personal data – When the Customer contacts us, including via any of our support channels, we may process the personal data provided to us (including voice) in order to deal with the Customer’s query. In addition, if the Customer loses access to its account, we may request certain documents in order to verify its identity. Those documents may contain personal data such as name, address, nationality, date of birth, identification document number, etc. In addition, when you purchase a SSL certificate for your website, hosted with us, we store its key in order for the certificate to operate properly.

    3. Users

      a. Definition: Individuals who access and/or administer any of the Services for our Customers.

      b. Types of personal data:

              • User information – We may process personal information such as first and last name, address, phone number, email address, so you can access and/or administer the Services, request information and get support.
              • Personal data, contained in log files – When a User visits our Site we may process information such as IP address, referral URL, exit URL, browser software, operating system, date/time and/or clickstream data.
              • Personal data collected through website analytics tools – We may collect information about User’s use of our Site, such as number of visits, pages visited, popularity of certain content. Analytics tools use tracking technologies (such as cookies) to recognise the device used and compile the information. They collect information such as what pages the User visits and how much time the User spends on these pages, the IP address assigned to the User, what operating system and web browser the User uses, and what site the User visited prior to visiting our Site.
              • Other types of personal data – When the User contacts us, including via any of our support channels, we may process the personal data provided to us in order to deal with the User’s query.

      4. Registrants

      a. Definition: Owners of domain names, registered with us.

      b. Types of personal data:

              • Domain name ownership information – We process personal data such as first and last name, name of the legal entity and its legal representative, address, phone number and email address of the Registrants, as well as the domain name and its status, name server, IP address etc.

      5. End Users

      a. Definition: Persons who visit, access, use and/or interact with our Customers’ websites.

      b. Types of personal data:

              • Personal data, contained in log files – When an End User visits our Customer’s website we process End User’s information such as IP address, domain name, date, request method, URI user agent, referrer, TLS version, cache data.

      6. Affiliates

      a. Definition: Persons who participate in our Affiliate Program.

      b. Types of personal data:

              • Affiliate account information – We process personal information such as first and last name, name of the legal entity and its legal representative, address, phone number, email address, IP address, payment information (i.e. PayPal account and/or bank account information, personal or TAX identification number etc.).
              • Personal data, contained in log files – When an Affiliate visits our Site we may process information such as IP address, referral URL, exit URL, browser software, operating system, date/time and/or clickstream data.
              • Personal data collected through website analytics tools – We may collect information about Affiliate’s use of our Site, such as number of visits, pages visited, popularity of certain content. Analytics tools use tracking technologies (such as cookies) to recognise the device used and compile the information. They collect information such as what pages the Affiliate visits and how much time the Affiliate spends on these pages, the IP address assigned to the Affiliate, what operating system and web browser the Affiliate uses, and what site the Affiliate visited prior to visiting our Site.
              • Other types of personal data – When the Affiliate contacts us, including via any of our support channels, we may process the personal data provided to us in order to deal with the Affiliate’s query. In addition, if the Affiliate loses access to its account, we may request certain documents in order to verify its identity. Those documents may contain personal data such as name, address, nationality, date of birth, identification document number etc.

      7. Other individuals

      a. Definition: Individuals, who may not fall under the scope of the definitions listed above, such as potential customers, third parties, part of ownership account disputes, complainants, followers in our social media channels, etc.

      b. Types of personal data:

              • Contact information – We may process information such as  first and last name, name of the legal entity and its legal representative, email address, address, phone number,  social media username, etc.
              • Other types of personal data – We may process your voice, if you contact us by phone, and/or your image, in case you share such data with us. We may process any other types of personal data provided to us in order to deal with your query.

      II. Sources of data collection

      Apart from you, being the main source of information, we collect about you, we may also collect information from publicly accessible sources and/or third parties, such as our affiliates, trusted partners, including but not limited to marketing, advertising, security service providers, etc.

      III. Purposes of and legal basis for data processing 

      We strive to collect only the minimum personal data necessary for the completion of the purposes of data processing, as set out below:

          • To provide, maintain and secure the Services (including our network, information systems and the server infrastructure operated by us) and fulfil our obligations under the applicable agreements and terms, including to administer any promotions (co)organised and/or sponsored by us. In such cases the legal basis for the data processing is the performance of a contract and compliance with a legal obligation.
          • To maintain and secure our Site, network, information systems and the server infrastructure operated by us, including but not limited to investigating and preventing fraudulent transactions, unauthorized access to the Services and other illegal activities, to address any queries, to enforce our terms, to defend against claims and protect the rights, property or safety of Infinityscape Ltd, to improve and/or develop the Services for the benefit of our Customers, and for statistical purposes. In such cases the legal basis for the data processing is our legitimate interest.
          • To promote our brand and Services, including to send marketing communication, newsletters, surveys, monitor and analyze activities for advertising purposes etc. In such cases the legal basis for the data processing is your consent.
          • To fulfil our legal obligations, such as compliance with court orders, orders/requests or other documents issued by competent authorities, applicable legislation, etc. In such cases the legal basis for the data processing is the compliance with a legal obligation to which we are subject.
          • For other purposes which may not fall under the scope of the above-mentioned purposes we will obtain your consent.

      IV. Cookies, beacons, tags, pixels

      We use cookies to collect some of the information set out in this Policy. Cookies can store your account identifier, ordering status, personalisation or website tracking. They can also be used for technical purposes such as keeping track of your current shopping session and enabling you to proceed to checkout and pay for your according order or to save information which has already been entered (languages preference, and your region), so that we can offer improved and more personalised Services, products and other relevant communication tailored to you. Cookies also allow us to fulfil our contractual obligations to third parties and partners if you have made a purchase on our Site by following a link from theirs.

      You can find detailed information about our use of cookies in our Cookie Policy.

      V. Sharing of personal data

      We disclose entire or part of your personal data in the following circumstances and always ensure that the appropriate safeguards on your privacy are undertaken:

      1. To provide the Services and run our business – We may engage third-party service providers in the delivery of the Services and also for administrative, billing, tax and all other purposes related to the management of your account and our operations. In such cases your personal data may be shared with business partners, independent contractors, external consultants, auditors, collaborators, etc. Those third-party service providers include companies that operate in different industries such as fraud detection, technology service, internet information providers, payments and data processors, couriers, providers from the finance, media, internet content and information industries, advertising and marketing, technologies, analytics, etc. and that may be located worldwide (including but not limited to the EU, EEA, Switzerland, UK, USA, Australia, Singapore, Japan, etc.).

      1.1. We also may share data with Google for use of Google Products and services. For example we use invisible reCaptcha service to protect our website from malicious activity. Use of the invisible reCaptcha and other Google products/services is subject to Google’s Privacy Policy and Terms of Service.

      2. To comply with the applicable legislation and to exercise rights – We may share personal data with companies, organisations or individuals when we believe in good-faith that access, use, preservation or disclosure of such data is necessary to meet any applicable law, comply with regulations, legal procedures, enforceable requests and/or competent authority requirements; to enforce our terms, defend against claims and protect the rights, property or safety of Infinityscape Ltd, our Customers and/or the public as required and/or permitted by law.

      3. To comply with ICANN’s and ICANN-accredited registrar providers’ rules, regulations and policies – Infinityscape Ltd, in its capacity as a reseller of domain names, shares Registrant’s data for the purposes of domain name registration and/or to comply with the applicable rules, regulations and policies of ICANN and the relevant registrar providers (such as TuCows (OpenSRS), ENOM, Openprovider, etc.).

      4. In case of business reorganization, transfers and/or acquisitions – We may share your information to third parties in connection with any prospective or completed business reorganization, merger, sale of company assets, or acquisition of all or a portion of our business by another entity, or in the unlikely event that Infinityscape Ltd goes out of business or enters bankruptcy. If any of these events happens, we may take any reasonable steps to notify you and this Policy would continue to apply to your personal data processing.

      5. To comply with your instructions – We may share your information with third parties with your explicit consent or at your direction. We will not, however, sell, rent, share or otherwise disclose personal data for commercial purposes in any way that is contrary to the commitments made in this Policy.

      VI. International data transfers

      In the course of our business operations and for the delivery of the Services we may transfer personal data around the world (including but not limited to the USA, Australia, Singapore, Japan) where we and/or the third parties, specified in Section III above, use data centers, facilities and/or maintain data processing operations.

      1. Transfers between the UK and the EU/EEA

      When transferring personal data from the UK to the EU/EEA we rely on the data adequacy granted to the EU/EEA by the UK government. For data that flows from the EU/EEA to the UK we rely on the adequacy decisions of the European Commission in relation to the UK. This means that the EU and the UK have both determined each region’s data protection laws to be sufficiently robust to ensure data can safely flow between the UK and the EU/EEA.

      2. Transfers outside the UK and the EU/EEA

      In the event that we transfer personal data from the EU/EEA and/or the UK to countries which are not considered to provide an adequate level of data protection, we will ensure that:

                          • we have provided appropriate and proportional technical and organisational data protection and cybersecurity risk mitigation measures, as well as we have performed the appropriate risk assessments when transferring your personal data outside of the EU, EEA and the UK;
                          • we have provided appropriate safeguards to protect your personal data by virtue of making available the Standard Contractual Clauses, approved by the the European Commission (when the data subject is located in the EU/EEA) or the International Data Transfer Agreement, issued by the competent authority in the UK (when the data subject is located in the UK), as transfer mechanisms.

       VII. Security measures

      We use Secure Sockets Layer (SSL) protocol to encrypt the information you enter on our Site in order to protect its security during transmission to and from our Site. When storing information, we protect its security by encrypting critical data. Access to this information is severely restricted, logged and reviewed periodically. When we collect credit card data and payments (we do not store full credit card numbers and CVV codes), the credit card data is subject to tokenisation and strong security measures applied by our payment processors in accordance with the PCI DSS requirements.

      We maintain physical, logical, electronic and procedural safeguards when collecting, storing and disclosing personal data. Our security procedures require us in some cases to request proof of identity before disclosing personal data to you.

      To protect against unauthorised access to your account and information, we implement session management, strong authentication requirements, login expiration mechanisms and the option of using 2-factor authentication for Client Area access. Authentication data is encrypted. As an additional safety measure, we ask you to sign out when you finish using your account and your computer.

      Although we take appropriate technical and organizational measures to maintain the safety and security of your personal data against loss, theft and unauthorized use, access or modification, please note that no transmission of information over the Internet is not completely secure. Consequently, please note that we cannot fully guarantee the security of any personal data that you transfer over the Internet to us.

      VIII. Retention periods

      Information collected on our Site will only be retained for as long as necessary to fulfil the purpose for which it was collected. In general, we will automatically and securely delete your Client Area account information 2 years after you no longer have any active Services with us. Since we offer a Service for customers worldwide and we need to comply with regulations across the globe in regard to retention of personal information related to contractual agreements, provision of Services, financial, billing, invoicing operations, tax calculations etc., a versioned copy of your order, payment and billing documentation may be stored for a period of 10 years after the termination of your customer account. Your personal data is deleted automatically by our systems in accordance with these retention periods.

      IX. Your rights

      By visiting the “Owner Profile Details” section in your Client Area, you can access, correct, and delete certain personal data associated with your account.

      In addition, by submitting your inquiry to the email specified in the “Contact information” section of this Policy you may request from us any of the following actions:

          • to confirm whether or not personal data about you is being processed;
          • to provide you with further details about how we process your personal data;
          • to provide you with a copy of any data which we hold about you;
          • to withdraw your consent to processing your personal data, where we rely on your consent as a legal basis for processing;
          • to consider any valid objection to the processing of your personal data, including the right to object to processing where we are relying on our legitimate interests as a legal basis for processing;
          • to request an update, rectification or deletion of your personal data, which we process about you;
          • to restrict the way that we process your personal data;
          • to consider any valid request to transfer (if technically feasible) your personal data to a third-party service provider.

      We will review and address your request(s) within one month as of the date of receipt. Please note that if your request is particularly complex or you have made a number of requests, it may take us longer than a month to respond to you. In this case, we will notify you and keep you updated. Please note that we may ask you to provide us with additional information necessary to verify your identity prior to our response. However, in certain circumstances such as to comply with the applicable legislation, we may be unable to honour your request, for which you will be duly notified.

      X. Age Restrictions

      In accordance with Infinityscape Ltd Terms of Service, our Site and the Services are designated for use by individuals who are at least 18 years old. If you are under the age of 18, you must request your parent or guardian to use the Site instead. Should you have evidence that someone under the age of 18 has bought Services and provided their personal data to us, please contact us using the details set out in the “Contact information” section on the website. If we become aware that we process personal data of a person under the age of 18, we will delete the data and terminate the use of the Services.

      XI. Changes to the Privacy Policy

      We reserve the right to modify this Policy at any time. If we decide to change our Policy, we will post the updates in the Site and in any other place we deem appropriate, so that you are aware of what personal data we collect, how we use it, and under what circumstances, if any, we disclose it.

      If we make material changes to this Policy, we will notify you by email, or by means of a notice via our Site, at least ten (10) calendar days before the changes take effect.

      XII. Data Protection Authority

      You have the right to direct questions or lodge a complaint about the processing of your personal data at any time with the competent supervisory authority for data protection – the Information Commissioner’s Office in the UK, at https://ico.org.uk.

      XIII. Contact information

      For any data processing related questions and/or requests, please contact us at dpo@infinityscape.co.uk.

      Latest revision: 04.09.2022.