Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between ASTRO REGISTER DOMAINS INC., a Saskatchewan corporation trading as Register.ly (“Register.ly”), and the customer that purchases or uses the Services (“Customer”). It applies when Register.ly processes Customer Personal Data on Customer’s behalf. Scope and order of precedence This DPA governs Customer Personal Data processed […]
This Data Processing Addendum (“DPA”) forms part of the agreement between ASTRO REGISTER DOMAINS INC., a Saskatchewan corporation trading as Register.ly (“Register.ly”), and the customer that purchases or uses the Services (“Customer”). It applies when Register.ly processes Customer Personal Data on Customer’s behalf.
Scope and order of precedence
This DPA governs Customer Personal Data processed to provide the Services. It does not govern personal information that Register.ly processes as an independent controller for account administration, billing, fraud prevention, security, legal compliance, or marketing, which is addressed in the Privacy Notice.
If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails. A signed agreement or service order prevails only where it expressly identifies the provision it replaces.
Definitions
“Applicable Data Protection Law” means privacy and data-protection law applicable to the processing, including the GDPR, UK GDPR, and Canadian privacy law where applicable. “Customer Personal Data” means personal data contained in Customer Content that Register.ly processes on Customer’s behalf. “GDPR” means Regulation (EU) 2016/679. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Terms such as controller, processor, processing, personal data, and supervisory authority have the meanings given by Applicable Data Protection Law.
Roles and instructions
Customer is the controller and Register.ly is the processor of Customer Personal Data, except where Customer acts as a processor for another controller, in which case Register.ly is Customer’s subprocessor. Customer appoints Register.ly to process Customer Personal Data only to provide, secure, support, maintain, and improve the purchased Services; prevent abuse; comply with documented Customer instructions; and meet legal obligations applicable to Register.ly.
The Agreement, Customer’s use and configuration of the Services, and authorized support requests constitute documented instructions. Register.ly will inform Customer if an instruction appears to violate Applicable Data Protection Law, unless prohibited from doing so.
Customer responsibilities
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; providing required notices; establishing lawful bases; responding to data subjects; configuring the Services appropriately; and ensuring its instructions comply with law. Customer must not submit special-category, highly regulated, or sensitive data unless the applicable Service is expressly designed and agreed for that data.
Confidentiality and personnel
Register.ly will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security instruction. Access is limited according to role and operational need.
Security measures
Register.ly will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures are selected in light of the nature of the Services, available technology, implementation cost, and processing risks.
Measures may include access controls, authentication, least-privilege administration, encryption in transit, logging and monitoring, vulnerability and patch management, backups where included in the Service, incident response, supplier controls, physical safeguards at relevant facilities, business-continuity measures, and periodic review. Customer remains responsible for security controls under its control, including user access, application security, credentials, encryption choices, and backups not included in the Service.
Security incidents
Register.ly will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include available information about the nature of the incident, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as the investigation progresses.
Register.ly will take reasonable steps to contain, investigate, and remediate the incident and will reasonably assist Customer with legally required notifications. Notification is not an admission of fault or liability. Unsuccessful attempts, scans, and events that do not compromise Customer Personal Data are not Security Incidents.
Data-subject requests
Taking into account the nature of the processing, Register.ly will provide reasonable assistance through technical and organizational measures so Customer can respond to requests to exercise data-subject rights. If Register.ly receives a request concerning Customer Personal Data, it may direct the requester to Customer and will not respond substantively unless authorized or legally required.
Assessments, consultations, and compliance assistance
Register.ly will provide information reasonably necessary for Customer to conduct legally required data-protection impact assessments or prior consultations, taking into account the nature of processing and information available to Register.ly. Additional assistance beyond standard documentation or support may be subject to reasonable fees agreed in advance.
Subprocessors
Customer gives Register.ly general written authorization to appoint subprocessors needed to provide the Services. Register.ly will impose written data-protection obligations that provide materially equivalent protection for Customer Personal Data and remains responsible for its subprocessors’ performance to the extent required by Applicable Data Protection Law.
Register.ly will make current subprocessor information available through its website, client area, contractual documentation, or on request to cs@register.ly. Register.ly will give at least 30 days’ notice before a new subprocessor begins processing Customer Personal Data when required by law, unless an urgent replacement is reasonably necessary for security, continuity, or legal compliance.
Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith toward a commercially reasonable solution. If none is available, Customer may terminate the affected Service before the new subprocessor begins processing, and Register.ly will refund prepaid fees for the unused terminated period where required by the Agreement or law.
International transfers
Register.ly will use a lawful transfer mechanism where Customer Personal Data is transferred from the EEA, United Kingdom, or another jurisdiction that restricts international transfers to a destination not recognized as adequate. Where applicable, the parties will enter into or incorporate the relevant European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved mechanism, completed for the parties’ roles and processing.
Register.ly will provide reasonable information about relevant transfer safeguards and will implement supplementary measures where reasonably necessary. Nothing in this DPA requires disclosure prohibited by law or information that would compromise security or another customer’s confidentiality.
Government and legal requests
Register.ly will review legally binding requests for Customer Personal Data and, where lawful, notify Customer before disclosure. Register.ly will disclose only the data reasonably required and may challenge an unlawful or disproportionate request where appropriate.
Deletion and return
During the Service term, Customer may retrieve or delete Customer Personal Data using available Service features. After termination, Customer Personal Data may remain available for export for 30 days unless the Service description states otherwise or immediate restriction or deletion is required by law, security, registry rules, or the nature of the Service. Register.ly will then delete or anonymize production copies within 30 days. Residual backup copies may remain for up to 90 days and will remain protected and unavailable for ordinary use until overwritten.
Audits and information
Register.ly will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant security summaries, certifications, or independent audit reports where available and subject to confidentiality restrictions. If that information is insufficient, Customer may request one audit per year, or an additional audit following a confirmed Security Incident or supervisory-authority request.
Audits require reasonable advance notice, must occur during normal business hours, must minimize disruption, and may not expose other customers’ data or compromise security. Customer bears reasonable audit costs unless material non-compliance by Register.ly is established.
Processing details
15.1 Subject matter and duration
Processing of Customer Personal Data as necessary to provide the Services for the term of the Agreement and the deletion period described above.
15.2 Nature and purpose
Hosting, storage, transmission, retrieval, organization, backup where included, security monitoring, technical support, maintenance, troubleshooting, migration, deletion, and other processing initiated through Customer’s use of the Services.
15.3 Categories of data subjects
Customer’s users, personnel, contractors, clients, website visitors, end users, registrants, contacts, and other persons whose personal data Customer submits to the Services.
15.4 Types of personal data
Contact and account data, identifiers, communications, technical and usage data, authentication and access data, hosted files, databases, logs, website content, and other personal data selected and submitted by Customer. The exact categories depend on Customer’s use of the Services.
Liability and termination
Liability arising under this DPA is subject to the Agreement’s liability provisions to the extent permitted by law. This DPA terminates when Register.ly no longer processes Customer Personal Data, except for obligations that by their nature survive, including confidentiality, deletion, audit, and transfer obligations.
Contact
Privacy and DPA inquiries: cs@register.ly
Legal notices: legal@register.ly
Provider: ASTRO REGISTER DOMAINS INC., 3537 Green Moss Lane, Regina, Saskatchewan S4V 1L5, Canada.