Privacy Policy
PRIVACY POLICY.
This policy is effective 31 July 2026.
This Privacy Policy explains how Pan Domains Ltd (“Pan Domains”, “We”, “Us”, “our”) collects and uses personal data, and what rights You have over it. It applies if You obtain domain name registration or related services from Us (“Services”), visit this website, provide Us with personal data, or if someone else provides Us with Your personal data — for example because You are named as an administrative, technical or billing contact for a domain name, or because You are named in a complaint or abuse report.
Pan Domains Ltd is a company registered in England and Wales, with its registered office at 124 City Road, London EC1V 2NX. We are the controller of the personal data described in this policy. For the registration data We are required to send to a registry, We act as a joint controller together with the registry operator for the extension concerned and, for generic top-level domains, with ICANN. This policy should be read alongside our Domain Name Registration Agreement, which governs the Services themselves.
Some of the processing described below is not optional. Registering a domain name requires Us to collect registration data and to pass it to registry operators, escrow providers and other parties under rules set by ICANN, by the registry for the relevant extension, and (for .uk domains) by Nominet. We cannot register or maintain a domain name for You without it.
DATA PROTECTION CONTACT
For any question about this policy, or to exercise any of the rights described below, contact Us at compliance@pandomains.com, or write to:
Pan Domains Ltd 124 City Road London EC1V 2NX United Kingdom
PERSONAL DATA WE PROCESS
We process the following categories of personal data:
- Registration data. The contact details recorded against a domain name: registrant, administrative, technical and billing contact names, organisation, postal address, email address and telephone number. Under our Domain Name Registration Agreement You are required to keep this information current, complete and accurate.
- Account data. The information associated with Your account and Your use of our domain name management portal, including the name and email address on the account, and records of Your instructions and transactions.
- Payment data. The payment method associated with Your account and the record of payments taken. Card details are processed by our payment provider; We do not store full card numbers.
- Correspondence. Messages You send Us through the contact form on this website (Your first name, last name, email address and the content of Your message), by email, or by telephone, together with our replies. The contact form does not require an account. We use what You send Us to answer Your enquiry, and where the enquiry relates to a complaint, dispute or abuse report We also keep it as part of our records of that matter.
- Technical data. Information generated automatically when You visit this website, including Your IP address, the pages requested, the time of the request, and Your browser’s user agent. This is processed by our hosting provider to serve the site and to protect it from attack and abuse.
- Compliance records. Records relating to complaints, abuse reports, disputes, and requests from law enforcement or dispute resolution providers, including any personal data contained in them.
We do not deliberately collect special category data (such as health, political opinions or biometric data), and We ask that You do not send it to Us.
WHERE WE GET YOUR DATA
Most of the personal data We hold comes from You. If You are named as an administrative, technical or billing contact for a domain name, We obtained Your name, organisation, postal address, email address and telephone number from the registrant, who is required by our Domain Name Registration Agreement to have told You and obtained Your consent first. If You are named in a complaint or abuse report, We obtained Your details from the person who made the report and from public registration records. The purposes, legal bases, retention periods and rights set out in this policy apply to You in the same way, and We will provide a copy of this policy to any such contact on request.
WHY WE PROCESS IT, AND OUR LEGAL BASIS
Under the UK GDPR We must have a lawful basis for each purpose:
- To provide the Services — registering, renewing, transferring and managing domain names, verifying registrant eligibility where an extension requires it, operating Your account, taking payment, and providing support. Legal basis: performance of a contract with You, or steps taken at Your request before entering one.
- To answer enquiries sent through the contact form or otherwise. Legal basis: legitimate interests (responding to people who contact Us), or performance of a contract where the enquiry concerns Services You already hold.
- To meet registry, ICANN and Nominet requirements — including publishing and disclosing registration data as described below, depositing data with an escrow agent, retaining records for prescribed periods, and responding to compliance enquiries. Legal basis: performance of a contract with You, because We cannot register or maintain a domain name without meeting these requirements, and legitimate interests in maintaining our accreditations, in the stability and resiliency of the domain name system, and in mitigating DNS abuse. Our agreements with ICANN, the registries and Nominet are contractual commitments rather than obligations imposed on Us by UK law, so We do not rely on legal obligation for them.
- To keep the Services and this website secure — detecting and preventing abuse, fraud, spam and attacks. Legal basis: legitimate interests in protecting our systems, our customers and third parties.
- To handle complaints, abuse reports and legal claims, and to comply with court orders, regulators and lawful requests from law enforcement. Legal basis: legal obligation, and legitimate interests in establishing, exercising or defending legal claims.
- To meet our accounting and tax obligations. Legal basis: legal obligation.
Where We rely on legitimate interests, We have considered whether those interests are overridden by Your interests, rights and freedoms. You may object to that processing; see “Your Rights” below.
We do not sell personal data, and We do not use it for automated decision-making that produces legal or similarly significant effects.
REGISTRATION DATA, WHOIS AND RDAP
Domain name registration is a public system, and this is the part of our processing that most often surprises people.
When You register a domain name, We are required to transmit the registration data to the registry operator for that extension, and to a third-party data escrow agent. Data held by the escrow agent can be used to restore a registrar’s records after a catastrophic failure, so that registrations survive the failure of any single provider. Some of that data is then published through public registration data services (historically WHOIS, now the Registration Data Access Protocol, or RDAP).
What is published depends on the extension and on the rules in force:
- For generic top-level domains, ICANN’s Registration Data Policy requires most personal data of an individual registrant to be redacted from the public record. An anonymised or role-based email or web form is usually published in place of the registrant’s own contact details.
- Registries, and parties with a legitimate interest — such as law enforcement, intellectual property owners investigating infringement, and dispute resolution providers — may request disclosure of the non-public data. See “Registration Data Disclosure Requests” below.
- For .uk domains, publication is governed by Nominet’s rules. Nominet does not display a registrant’s name or address in the .uk WHOIS unless the registrant has given permission for it to do so, and its Searchable WHOIS includes contact details only where the registrant has consented. Nominet may release registration data to third parties who have a legitimate reason for it, such as the enforcement of legal rights or its Dispute Resolution Service. See the Nominet Terms and Conditions of Domain Name Registration.
- Registration data is also used to operate ICANN’s Registration Data Reminder Policy (formerly the Whois Data Reminder Policy), under which We send You an annual reminder to review the accuracy of Your registration data, and the transfer and dispute processes described in our Domain Name Registration Agreement.
Once registration data has been published, We cannot control how members of the public use it.
If You register a domain name using another person’s or organisation’s details, You must have told them their data will be handled this way and obtained their consent, as our Domain Name Registration Agreement requires.
WHO WE SHARE PERSONAL DATA WITH
We disclose personal data to:
- Registry operators and their back-end service providers, for the extension concerned, so the registration can be created and maintained.
- Data escrow agents appointed or approved by ICANN or by the relevant registry.
- ICANN and, for .uk domains, Nominet, where their agreements or policies require it.
- Buyers, sellers and the public, where a domain name is sold or purchased through our marketplace: the domain name, the price and the timing of the sale.
- Our service providers, who process data only on our instructions and under contract: our hosting and network provider, our email provider, and our payment provider.
- Professional advisers, such as our accountants and lawyers, where necessary.
- Law enforcement, regulators, courts and dispute resolution providers, where We are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims.
- A buyer or successor, if We sell or reorganise our business, subject to this policy continuing to apply.
REGISTRATION DATA DISCLOSURE REQUESTS
If You believe You have a legitimate interest in obtaining non-public registration data for a domain name We sponsor, You may submit a request to compliance@pandomains.com. Your request must include:
- Your identity and contact details, the type of legal entity You are, and — where You are acting for someone else — evidence of Your authority to do so;
- the domain name or names concerned;
- the specific data You are requesting;
- the legitimate interest You are relying on, and why disclosure is necessary and proportionate to it;
- an affirmation that the request is being made in good faith; and
- an undertaking to use the data only for the purpose stated.
We will acknowledge a properly-formed request by email within two business days of receipt, and will respond by email within thirty calendar days of that acknowledgement, absent exceptional circumstances.
We will assess each request on its merits, balancing the requester’s interest against the rights and freedoms of the registrant, and We may refuse a request that is unfounded, excessive, or not properly substantiated. Where We refuse, We will give the specific reasons, including an explanation of how the registrant’s rights and freedoms were weighed against Your interest. We may notify the registrant of the request unless We are prohibited from doing so.
INTERNATIONAL TRANSFERS
Registry operators, escrow agents and some of our service providers are located outside the United Kingdom, so registration data will in many cases be transferred abroad — including to the United States. This is inherent in how the domain name system works.
Where We transfer personal data outside the UK, We do so on one of the following bases:
- the destination country is covered by UK adequacy regulations;
- the transfer is necessary for Us to perform our contract with You. This is the basis on which registration data is transmitted to the registry operator for the extension You choose and to a data escrow agent, because Your domain name cannot be registered or maintained without it; or
- the transfer is necessary for the establishment, exercise or defence of legal claims.
You can ask Us which country a particular recipient is in, and which of these bases We are relying on for that transfer.
HOW LONG WE KEEP PERSONAL DATA
We keep personal data only for as long as We need it:
- Registration data — for the life of the registration, and afterwards for as long as ICANN, the relevant registry or Nominet requires. ICANN’s rules currently oblige registrars to retain certain registration records for a period after the registration ends.
- Account and payment records — for the life of the account and then for six years after the end of the relevant financial year, to meet UK accounting and tax requirements.
- Correspondence — for up to two years after the matter is closed.
- Complaints and abuse reports — for two years after the matter is closed. This is the shortest period consistent with our record-keeping obligations as a registrar and with the escalation window in our Complaint and Abuse Report Procedure. We keep a report for longer only where it is subject to ongoing litigation, a regulatory investigation or a law enforcement request. After that We keep only anonymised statistics on the number and types of report received, which contain no personal data.
- Technical data — request logs are kept for the retention period configured on our hosting account and are then deleted automatically. We keep an individual log entry for longer only where it forms part of the investigation of a specific security incident or abuse report.
Where We no longer need personal data, We delete it or anonymise it.
YOUR RIGHTS
Under the UK GDPR You have the right to:
- be informed about how We use Your personal data — which is the purpose of this policy;
- access the personal data We hold about You, and receive a copy of it;
- rectify personal data that is inaccurate or incomplete;
- erase personal data, where We no longer have a valid reason to keep it;
- restrict our processing of Your personal data in certain circumstances;
- portability — to receive certain data You provided to Us in a machine-readable format, or have it sent to another controller;
- object to processing We carry out on the basis of legitimate interests, and to object at any time to direct marketing; and
- withdraw consent, where We rely on consent, without affecting processing carried out before You withdrew it.
These rights are not absolute. In particular, We may be unable to erase, rectify or restrict registration data where ICANN, a registry or Nominet requires Us to retain or publish it, or where We need it to establish, exercise or defend legal claims. If We refuse a request We will tell You why.
To exercise any of these rights, contact compliance@pandomains.com. We may ask You for information to confirm Your identity. We will respond within one month; if Your request is complex We may extend that by up to two further months, and will tell You if We do. There is normally no charge.
HOW TO COMPLAIN
If You are unhappy with how We have handled Your personal data, please tell Us first at compliance@pandomains.com so We have the chance to put it right. Complaints about our Services more generally are handled under our Complaint and Abuse Report Procedure.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection:
Information Commissioner’s Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF United Kingdom Helpline: 0303 123 1113 ico.org.uk
COOKIES AND ANALYTICS
This website does not set cookies, does not use analytics or advertising tracking, and does not embed third-party scripts. Fonts and other assets are served from our own domain rather than from a third-party network.
The only information collected when You browse this website is the technical data described above, which our hosting provider processes in order to serve the site and keep it secure. If this changes, We will update this policy and, where the law requires it, ask for Your consent first.
SECURITY
We maintain appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction, and We protect the information regardless of the format in which it is held. This website is served over HTTPS.
No system is completely secure. If a personal data breach occurs and it is likely to result in a risk to Your rights and freedoms, We will report it to the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it; where We cannot report within 72 hours We will explain the reason for the delay. Where a breach is likely to result in a high risk to Your rights and freedoms, We will also tell You directly without undue delay.
CHILDREN
The Services are intended for organisations and for individuals aged 13 or over. Where a customer is under 18, our Domain Name Registration Agreement requires the permission of a parent or guardian. We do not knowingly provide Services to, or collect personal data from, children under 13. We do not rely on a child’s own consent as a lawful basis for any processing described in this policy.
If You believe a child has provided Us with personal data, contact compliance@pandomains.com. We will investigate and delete it, unless We are required to retain it — for example where it forms part of a domain name registration record We must keep under ICANN, registry or Nominet rules — in which case We will restrict its use and tell You what We have done and why.
CHANGES TO THIS POLICY
We may update this policy from time to time. The effective date at the top shows when the current version took effect. Where a change materially affects how We use personal data We already hold, We will give You notice by email or through the Services before it takes effect. Please review this page periodically.