Legal

Openprovider Privacy Policy

This page contains Openprovider privacy policies.

This Privacy Policy explains how Hosting Concepts B.V., trading as Openprovider (“Openprovider”, “we”, “us” or “our”), collects, uses, discloses, stores and protects personal data in connection with our websites, reseller control panel, application programming interfaces, products, services, communications and business operations. It also explains the rights available to individuals under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

1. Who we are

Openprovider is a trade name of Hosting Concepts B.V., a company established in the Netherlands and registered with the Dutch Chamber of Commerce under number 24277249.

For the processing described in this Privacy Policy, Hosting Concepts B.V. generally acts as the data controller. Privacy enquiries and requests may be submitted to privacy@openprovider.com or through the contact details published on our website.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed in connection with:

  • openprovider.com and related websites and subdomains;
  • the Openprovider reseller control panel, APIs and related account services;
  • domain registration, renewal, transfer, restoration, suspension and other lifecycle services;
  • products and services supplied directly by Openprovider or through third-party providers;
  • sales, marketing, support, billing, security, fraud prevention and compliance activities; and
  • communications with customers, resellers, registrants, prospective customers, suppliers, authorities and other business contacts.

Where Openprovider processes personal data solely on behalf of a customer or reseller, Openprovider acts as a processor or subprocessor. That processing is governed by the applicable Data Processing Addendum (“DPA”), customer agreement and documented instructions. This Privacy Policy primarily describes processing for which Openprovider acts as controller.

3. Personal data we collect

3.1 Account and business contact data

We may collect names, company names, job titles, postal and billing addresses, email addresses, telephone numbers, usernames, account identifiers, language preferences and details of authorised users or representatives.

3.2 Domain registration and service data

We may process registrant and contact data, domain names, registrar and registry identifiers, registration status and lifecycle data, nameserver information, transfer records, WHOIS or RDAP data, service configuration information and communications relating to a domain or service.

3.3 Transaction and payment data

We may collect order details, invoices, payment status, transaction history, VAT or tax information and limited payment-related information. Payment card or bank details may be processed by authorised payment service providers rather than stored directly by Openprovider.

3.4 Identity verification and compliance data

Where required for fraud prevention, sanctions compliance, regulatory obligations, registry requirements or verification of authority, we may collect copies of identity documents, date of birth, address evidence, corporate documents, beneficial ownership information, facial images, liveness or similarity results and related verification metadata.

3.5 Support, complaint and legal-process data

We may process support tickets, call or chat records, complaint and abuse reports, evidence submitted in connection with disputes, correspondence with authorities, court orders, subpoenas, disclosure requests and other legal or compliance records.

3.6 Technical, device and usage data

When you use our websites, control panel or APIs, we may automatically collect IP addresses, browser and device information, login and authentication records, API requests, timestamps, system and application logs, security events, cookie identifiers and information about how our services are used.

3.7 Marketing and preference

We may collect newsletter subscriptions, communication preferences, campaign interactions, event registrations and information about your interest in our products or services.

4. How we collect personal data

We collect personal data:

  • directly from you when you create an account, contact us, submit a form, place an order or use our services;
  • from customers, resellers or other parties that submit data in connection with domain registrations or services;
  • from registries, registrars, service providers, payment providers, identity-verification providers and fraud-prevention providers;
  • from public sources, sanctions lists, corporate registers, WHOIS or RDAP services and competent authorities; and
  • automatically through cookies, logs, APIs and similar technologies.

5. Purposes and legal bases

Purpose Examples Legal basis
Provide and administer services Create accounts, process orders, register and manage domains, provide support and billing. Performance of a contract; steps taken at your request before entering into a contract.
Security and fraud prevention Authenticate users, monitor logs, prevent abuse, investigate suspicious activity and protect systems. Legitimate interests; compliance with legal obligations.
Legal, regulatory and registry compliance Comply with ICANN, registry, tax, accounting, sanctions, disclosure, preservation and law-enforcement requirements. Compliance with legal obligations; legitimate interests; establishment, exercise or defence of legal claims.
Identity and authority verification Verify registrants, customers, representatives, beneficial owners or parties requesting account or domain changes. Compliance with legal obligations; legitimate interests; contract performance; consent where specifically required by law.
Service improvement and analytics Analyse performance, troubleshoot, test, improve usability and develop services using aggregated or appropriately protected data. Legitimate interests; consent for non-essential cookies where required.
Communications and marketing Send operational notices, product updates, newsletters, surveys and relevant offers. Contract performance or legitimate interests for service communications; consent where required for marketing.
Corporate administration Manage suppliers, business contacts, audits, corporate transactions, insurance and disputes. Legitimate interests; legal obligations; performance of a contract.

Where we rely on legitimate interests, we consider whether the processing is necessary and balanced against the rights and interests of affected individuals. Where processing is based on consent, consent may be withdrawn at any time without affecting processing already carried out.

6. Domain registration data and public disclosure

Domain name services may require Openprovider to provide registration data to registries, registry operators, escrow providers, ICANN, other registrars, dispute-resolution providers or competent authorities. Certain registration data may be published or made available through WHOIS, RDAP or similar registration data services where required or permitted by applicable law, ICANN policy or registry rules.

Where public disclosure is restricted, Openprovider may provide access to non-public registration data only where there is an appropriate legal basis and the request has been assessed under applicable disclosure procedures

7. Cookies and similar technologies

We use cookies and similar technologies to operate our websites, maintain sessions, remember preferences, protect accounts, analyse usage and improve our services. Essential cookies are used where necessary to provide requested functionality. Analytics, advertising or other non-essential technologies are used on the basis of consent where required by law.

Further details about the cookies and providers currently used, their purposes and available choices should be presented through the cookie notice or consent-management tool made available on the relevant website. You can also manage cookies through your browser settings, although disabling essential cookies may affect functionality.

8. Marketing communications

Customers may receive operational and service-related communications concerning their account, products, security, pricing, legal terms or material service changes. These communications are not ordinarily optional where they are necessary to provide or administer the services.

Promotional messages may be sent where permitted by law, including on the basis of consent or our legitimate interests in communicating with existing business customers. You may opt out of promotional communications at any time by using the unsubscribe link or contacting us. Opting out of marketing will not prevent essential service communications

9. Sharing of personal data

We may disclose personal data to:

  • Openprovider affiliates and personnel who require access for the purposes described in this Privacy Policy;
  • registries, registry operators, ICANN, registrars, escrow providers and domain-industry service providers;
  • hosting, cloud, communications, analytics, security, support, payment, identity-verification and professional service providers;
  • banks, payment processors, insurers, auditors, legal advisers and other professional advisers;
  • competent authorities, courts, law-enforcement bodies, regulators and dispute-resolution providers where required or permitted by law;
  • a purchaser, investor or successor in connection with a merger, acquisition, reorganisation, financing or sale of assets, subject to appropriate safeguards; and
  • other parties where you have authorised the disclosure or where it is necessary to protect rights, prevent harm or enforce agreements.

Service providers that process personal data on our behalf are required to provide appropriate confidentiality, data protection and security commitments. Openprovider does not sell personal data in the ordinary meaning of that term.

10. International transfers

Openprovider operates internationally and may transfer personal data to recipients outside the European Economic Area, the United Kingdom or Switzerland. Where required, we use a recognised transfer mechanism, such as an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, the Data Privacy Framework where applicable, or another lawful safeguard.

We assess relevant transfer risks and apply supplementary contractual, organisational or technical measures where appropriate. Information about applicable safeguards may be requested through privacy@openprovider.com.

11. Data retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, comply with legal and regulatory obligations, resolve disputes, prevent fraud and enforce agreements. Retention periods depend on the type of data, the service, applicable limitation periods and mandatory registrar, registry, tax, accounting or legal requirements.

  • Domain registration and registration-data records may be retained during the active registration or account lifecycle and for at least two years after expiry, deletion, transfer or termination where required by the ICANN Registrar Accreditation Agreement, applicable registry rules or other legal obligations.
  • Copies of identity documents, facial images and comparable identity-verification inputs are ordinarily deleted or irreversibly anonymised within 30 days after completion of verification, unless a longer period is required for legal, registry, authority, fraud-prevention, dispute or legal-hold purposes. Verification outcomes, audit trails and minimum supporting evidence may be retained longer where necessary.
  • Account, transaction, billing, support, security, complaint and compliance records are retained for the period required under applicable tax, accounting, security, contractual and legal requirements.
  • Backup copies are deleted or rendered inaccessible in accordance with ordinary backup rotation and disaster-recovery processes.

12. Security

We maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, encryption, network and application security, vulnerability management, logging and monitoring, incident response, business continuity, personnel training and supplier security controls.

No method of transmission or storage is completely secure. Users are responsible for protecting their login credentials, using available security features and promptly notifying us of suspected unauthorised access.

13. Automated processing

We may use automated tools to support security monitoring, fraud detection, sanctions screening, identity verification, service operation and prioritisation of support or abuse cases. Such tools may generate indicators, risk scores or recommendations. Where a decision produces legal or similarly significant effects and is based solely on automated processing, we will provide the protections required by applicable law, which may include the right to obtain human intervention, express a point of view and contest the decision.

14. Your data protection rights

Subject to applicable law and relevant exemptions, you may have the right to:

  • request access to your personal data and information about how it is processed;

  • request correction of inaccurate or incomplete personal data;

  • request deletion of personal data;request restriction of processing;

  • object to processing based on legitimate interests or to direct marketing;

  • receive certain personal data in a structured, commonly used and machine-readable format and transmit it to another controller;

  • withdraw consent at any time where processing is based on consent;

  • request safeguards relating to certain solely automated decisions; and

  • lodge a complaint with a competent supervisory authority.
To exercise a right, contact privacy@openprovider.com. We may request information necessary to verify your identity and authority. We will respond within the period required by applicable law. Rights may be limited where retention or processing is required by law, registry or registrar obligations, legal process, security needs or the establishment, exercise or defence of legal claims.

Where personal data was submitted by an Openprovider customer or reseller and Openprovider acts only as processor, the request should ordinarily be directed to that customer or reseller. Openprovider will assist the relevant controller in accordance with the DPA and applicable law.

15. Children

Our services are intended for business customers and are not directed to children. We do not knowingly collect personal data from children for marketing or account creation purposes. Where a minor’s data is necessarily included in a lawful domain registration or other service, it will be processed only for the applicable service, legal or compliance purpose.

16. Third-party websites and services

Our websites and services may contain links to third-party websites or integrate third-party products. Those parties may process personal data as independent controllers under their own privacy notices. Openprovider is not responsible for the privacy practices of independent third parties.

17. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, regulatory guidance, our services or our processing practices. The updated version will be published on https://www.openprovider.com/legal/privacy-policy with a revised effective date. Where required, we will provide additional notice of material changes.

18. Complaints and supervisory authority

We encourage you to contact us first so that we can address your concern. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or, where applicable, the supervisory authority in the country where you live, work or consider that an infringement occurred.

19. Contact

Hosting Concepts B.V., trading as Openprovider
Privacy contact: privacy@openprovider.com
Website: https://www.openprovider.com

For questions concerning processing carried out on behalf of a customer or reseller, please also refer to the Openprovider Data Processing Addendum and the privacy information provided by that customer or reseller.

Resellers grow with us

What are you waiting for? Become a reseller today!