Skip to content
Register.ly
Register.ly
Sign inHelp Center
? Sign in

GDPR Compliance

Learn how Register.ly approaches data protection and supports privacy rights under the General Data Protection Regulation.

Last Revised: August 20, 2026

This GDPR Compliance Statement explains how ASTRO REGISTER DOMAINS INC., trading as Register.ly (“Register.ly,” “we,” “us,” or “our”), approaches compliance with the European Union General Data Protection Regulation (“GDPR”) when the GDPR applies to our processing of personal data.

This Statement should be read with our Privacy Notice, Data Processing Addendum (“DPA”), Terms of Service, Cookie Notice, and applicable Service Order. It describes our framework and commitments; it is not a certification, legal advice, or a representation that a customer’s use of every Service is automatically GDPR compliant.

Scope and territorial application

The GDPR may apply to Register.ly when we process personal data in connection with offering services to individuals in the European Economic Area (“EEA”) or monitoring their behavior there, or when we process personal data on behalf of a customer whose processing is subject to the GDPR.

Whether the GDPR applies depends on the facts, including the parties’ location and role, the people concerned, and the nature of the processing. Other privacy laws may apply alongside or instead of the GDPR.

Our roles

Register.ly may act in different roles depending on the processing.

Controller: Register.ly acts as a controller when it determines why and how personal data is processed for account creation, billing, customer support, security, fraud prevention, service administration, legal compliance, and our own communications.

Processor: Register.ly generally acts as a processor when it processes personal data contained in Customer Content solely to provide services under the customer’s instructions. If the customer is itself a processor, Register.ly acts as its subprocessor.

Customer: The customer remains responsible for determining whether its processing is lawful, giving required notices, selecting appropriate Service settings, responding to data subjects, and issuing lawful documented instructions.

Data-protection principles

Where the GDPR applies, our processing framework is based on the following principles:

  • Lawfulness, fairness, and transparency.
  • Purpose limitation.
  • Data minimization.
  • Accuracy.
  • Storage limitation.
  • Integrity and confidentiality.
  • Accountability.

Register.ly applies these principles in accordance with its role, the processing context, and the requirements of applicable law.

Lawful bases

When Register.ly acts as a controller, we rely on an appropriate lawful basis for each processing purpose. Depending on the circumstances, this may include:

  • Performance of a contract or steps requested before entering a contract.
  • Compliance with a legal obligation.
  • Register.ly’s or a third party’s legitimate interests, where those interests are not overridden by individual rights.
  • Consent, where consent is required or appropriate.
  • Protection of vital interests or performance of a public-interest task in the limited circumstances where those bases apply.

Our Privacy Notice provides more detail about the purposes and lawful bases relevant to our controller processing. Consent can be withdrawn at any time where processing relies on consent, without affecting processing that was lawful before withdrawal.

Customer instructions and the DPA

Where Register.ly acts as a processor, the DPA forms part of the Agreement. It addresses the subject matter and duration of processing, processing instructions, confidentiality, security, subprocessors, assistance with data-subject requests, personal-data breaches, deletion or return, audits, and international transfers.

We process Customer Personal Data only on documented instructions, including the Agreement, the customer’s configuration and use of the Services, and authorized support requests, unless applicable law requires other processing. Where legally permitted, we will inform the customer of such a legal requirement before processing.

Privacy by design and default

Register.ly considers privacy and security when designing, selecting, and operating systems and processes that handle personal data. Measures are proportionate to the purpose, data, available technology, implementation cost, and risk to individuals.

Customers must configure their Services appropriately. Where options are available, customers should limit collection, access, retention, public exposure, logging, and permissions to what their use case requires.

Security of processing

Register.ly maintains technical and organizational measures designed to provide security appropriate to the risk. Depending on the Service and processing, measures may include:

  • Role-based access and least privilege.
  • Authentication and account-security controls.
  • Encryption in transit and encryption options where supported.
  • Network, system, and application safeguards.
  • Logging, monitoring, and abuse detection.
  • Vulnerability, patch, and change management.
  • Backup and continuity controls where included in the Service.
  • Incident response and escalation procedures.
  • Personnel confidentiality and awareness measures.
  • Supplier and subprocessor controls.

No system can be guaranteed completely secure. Customers remain responsible for the controls within their environments, including user permissions, credentials, software security, application configuration, encryption choices, and independent backups where not included in the Service.

Personal-data breaches

Register.ly maintains procedures to assess, contain, investigate, and remediate suspected personal-data breaches.

Where Register.ly acts as a processor, we will notify the affected customer without undue delay after becoming aware of a confirmed breach involving Customer Personal Data, and provide the information needed for the customer’s assessment and any legally required notifications.

Where Register.ly acts as a controller, we will notify the competent supervisory authority and affected individuals when and within the period required by the GDPR. A notification may be provided in phases as information becomes available.

Data-subject rights

Subject to the GDPR’s conditions and exceptions, individuals may have rights to:

  • Receive information about processing.
  • Access their personal data.
  • Correct inaccurate or incomplete data.
  • Request erasure.
  • Restrict processing.
  • Receive portable data in applicable circumstances.
  • Object to certain processing.
  • Withdraw consent where consent is the lawful basis.
  • Receive safeguards relating to qualifying solely automated decisions.
  • Complain to a competent supervisory authority.

Rights are not absolute. Register.ly may need to verify identity and authority and may retain or continue processing information where permitted or required by law.

Submitting a rights request

For personal data that Register.ly controls, submit a request to [email protected] or through https://my.register.ly. Describe the request and the relevant account or relationship, but do not send passwords, private keys, or unnecessary identity documents through ordinary email.

We normally respond without undue delay and within one month after receiving a valid request. Where permitted because a request is complex or numerous, the period may be extended by up to two additional months, and we will provide the required notice.

For Customer Personal Data that Register.ly processes on behalf of a customer, the customer is responsible for responding. We may direct the requester to that customer and will provide reasonable assistance as required by the DPA and applicable law.

Subprocessors

Register.ly uses service providers and subprocessors to support infrastructure, payments, communications, security, support, and service delivery. When Register.ly acts as a processor, it applies the subprocessor authorization and notice procedure in the DPA and requires subprocessors to protect Customer Personal Data through written obligations appropriate to their role.

Current subprocessor information is available on our website, in the client area, in contractual documentation, or upon request to [email protected]. Customers may object to a new subprocessor on reasonable data protection grounds, as described in the DPA.

International transfers

Register.ly and its providers may process personal data outside the EEA. Where the GDPR restricts a transfer to a country that is not recognized as providing adequate protection, Register.ly uses an applicable transfer mechanism.

Depending on the transfer, safeguards may include the European Commission’s Standard Contractual Clauses, another approved contractual mechanism, or a legally recognized derogation. We assess relevant transfer risks and apply supplementary measures where reasonably necessary.

Retention and deletion

Register.ly retains personal data only for as long as reasonably necessary for the stated purpose, the Agreement, security and fraud prevention, dispute resolution, registry or supplier requirements, and legal, tax, accounting, or regulatory obligations.

Specific retention periods are described in the Privacy Notice, DPA, Terms of Service, and service-specific terms. When data is no longer required, it is deleted, anonymized, or isolated until secure deletion under applicable backup cycles.

Records and accountability

Where required, Register.ly maintains records of relevant processing activities, processing purposes, categories of personal data and recipients, international transfers, retention criteria, and security measures.

We review relevant privacy and security controls, maintain policies and procedures, train appropriate personnel, and cooperate with customers and competent authorities as required by law.

Data-protection impact assessments

Register.ly assesses privacy risk when introducing processing that may create a high risk to individuals. Where Register.ly acts as a processor, we provide reasonable information and assistance available to us so the customer can complete a legally required data-protection impact assessment or prior consultation.

Automated processing

Register.ly may use automated tools to detect fraud, abuse, account compromise, payment risk, service misuse, or prohibited activity and to prioritize review.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects without an applicable lawful basis, required notice, and appropriate safeguards.

Cookies and consent

Our websites and client services may use cookies and similar technologies. Strictly necessary technologies support requested services, account access, security, checkout, and consent settings.

Where the GDPR and applicable electronic communications law require consent for non-essential analytics, preference, or advertising technologies, Register.ly will request consent and provide a method to withdraw or change it. See the Cookie Notice for details.

Children

The Services are not directed to children. Register.ly does not knowingly solicit account registration directly from children. If we learn that personal data was collected from a child in violation of applicable law, we will take appropriate steps to delete or otherwise address it.

Supervisory-authority complaints

Where the GDPR applies, an individual may complain to the supervisory authority in the EEA country where the individual lives or works or where the alleged infringement occurred.

We encourage individuals to contact us first so we can investigate, but doing so does not remove the right to contact a supervisory authority.

EEA representative and data-protection contacts

Where Article 27 of the GDPR requires Register.ly to appoint an EEA representative, the representative’s contact details will be published in our Privacy Notice or otherwise made available as required by law.

Register.ly has not described any person as a data protection officer unless their appointment and contact details are expressly published. General privacy requests may be sent to [email protected]. Legal notices may be sent to [email protected].

Customer compliance

Register.ly provides contractual and technical measures that can support customer compliance. Customers remain responsible for their own GDPR obligations, including:

  • Determining their controller or processor role.
  • Selecting a lawful basis.
  • Providing privacy notices.
  • Managing consent where required.
  • Responding to data-subject requests.
  • Configuring access, retention, security, and backups.
  • Completing impact assessments.
  • Ensuring their applications and content comply with law.
  • Using an appropriate international-transfer mechanism.

Changes to this Statement

We may update this Statement to reflect changes in law, guidance, services, or our practices. Material changes will be communicated as required by the Agreement or applicable law.

Contact

Privacy and GDPR inquiries: [email protected]

Legal notices: [email protected]

Client area: https://my.register.ly

Provider: ASTRO REGISTER DOMAINS INC., 3537 Green Moss Lane, Regina, Saskatchewan S4V 1L5, Canada.

Official references

General Data Protection Regulation: https://eur-lex.europa.eu/eli/reg/2016/679/oj

EU Standard Contractual Clauses: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng

  • .LY Domains
    • Pricing
    • Search
    • Transfer
    • WHOIS Lookup
    • Reseller Program
    • Requirements
  • Domains
    • Domain Search
    • Extensions
    • Pricing
    • Transfer
    • SSL
  • Hosting & Email
    • Cloud Shared Hosting
    • VPS Hosting
    • Google Workspace
    • Microsoft 365
  • Support
    • .LY FAQs
    • Contact Support
    • System Status
    • Report Abuse
  • Company
    • About Register.ly
    • Why Choose .LY?
    • .LY Success Stories
    • Blog
  • Legal
    • Terms
    • Privacy
    • Acceptable Use
    • Cookies
    • GDPR
    • Domain Agreement
Register.ly
VisaMastercardAmerican ExpressJCB
★ Trustpilot 4.7 rating from .LY customers

© 2026 Register.ly. All rights reserved.

Cookie PreferencesPrivacy PolicyAccessibility StatementRenewal PolicyRefund Policy

We use cookies to improve your experience. Privacy Policy