Who is responsible for your data
Silurian SL is the data controller for the personal data described in this policy when you visit a Silurian website, contact us, create an account, purchase a service or use Workspace. For services where a customer determines why and how Silurian processes data on its behalf, Silurian may instead act as that customer's processor under the applicable service agreement.
For registrant and contact data used to register and manage a domain through Netim, Silurian and Netim act as joint controllers under Article 26 GDPR. Silurian selects the customer and domain operation and manages the customer relationship; Netim determines the technical and regulatory processing required as the official registrar, including identity verification, registration-data publication and transmission to the responsible registry.
- Controller
- Silurian SL
- VAT number
- ESB86389889
- Postal address
- Portugalete 46, 28223 Madrid, Spain
- Privacy contact
- Secure Privacy & data protection ticket
- Historical AEPD file registration
- 2181343370
The AEPD number is retained for historical transparency. The former Spanish obligation to register personal-data files was abolished when the GDPR became applicable and was replaced by the controller's internal record of processing activities; it is not a current certification or approval.
We apply data minimisation: service, account and security data are used only where needed to deliver the requested relationship, comply with law, protect the platform or support a choice you have made.
Data we use
Identity and account
Name, email, language, country, profile and authentication evidence.
Customer and billing
Company, address, tax profile, orders, invoices, subscriptions and payment status. Card credentials remain with the payment provider.
Support and communications
Messages, tickets, attachments and the preferences needed to respond or send requested information.
Technical and security
IP address, timestamps, session and device signals, audit events and logs used to operate and secure the service.
Domain registration contacts
Domain name, holder, administrative, technical and billing contact details, eligibility information and verification evidence.
Where the data comes from
Most data comes directly from you. It may also come from an authorised administrator of your organisation, identity providers when you choose a social sign-in, payment and service providers involved in your transaction, public company or tax registers used for verification, and technical events generated when you use or secure the platform.
Sensitive data and children
Our services are not designed to collect special-category data. Please do not include health, biometric, political, religious or similarly sensitive information in tickets unless it is strictly necessary for your request. Silurian's commercial services are not directed to children, and we do not knowingly create customer accounts for children acting on their own behalf.
Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, orders, subscriptions, support and contracted services | Contract or steps requested before a contract |
| Verify customer, tax and payment information; issue and retain accounting records | Contract and legal obligations |
| Prevent fraud, abuse and unauthorised access; investigate incidents; maintain audit evidence | Legitimate interests in protecting customers, Silurian and the integrity of the service, and legal obligations where applicable |
| Operate, diagnose and improve the reliability and usability of the platform | Contract and legitimate interests, using proportionate and minimised operational data |
| Respond to privacy requests, disputes and regulatory enquiries | Legal obligations and the establishment, exercise or defence of legal claims |
| Send requested service communications | Contract or the action you requested |
| Register, renew, transfer and manage domains; maintain accurate registration data; meet registrar, registry and ICANN requirements | Contract, steps requested before a contract, and legal or regulatory obligations applicable to the domain service |
| Send optional marketing or load optional analytics, preference or marketing technologies | Your consent, which you may withdraw at any time |
Required information
Fields marked as required are necessary to create the requested account, ticket, order or service, or to meet billing and legal requirements. If you do not provide them, we may be unable to complete that request. Optional fields can be left blank without losing access to unrelated services.
If you provide personal data for another domain contact, you must be authorised to do so and must give that person the same domain-registration privacy information available to you. Silurian records and transmits only the contact roles and data required for the selected registration and extension.
Automated processing and AI
Silurian does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Automated security and fraud signals may flag activity for restriction or human review. Helpdesk AI may classify, summarise, translate or suggest a draft, but a Silurian agent remains responsible for customer-facing decisions and replies.
Services and providers
This register names the principal external services that may receive personal data in a current Silurian journey. A provider is not given every category of data listed in this policy: it receives only what is needed for the stated journey. Its role may vary between processor, independent controller or separate service supplier according to the service and applicable agreement.
Cloudflare
Network delivery and securityProcesses network and request information needed to deliver Silurian websites, mitigate attacks, manage challenges and protect the origin. Cloudflare-backed products ordered by a customer are a separate service journey.
- Typical data
- IP address, request, device and security signals
- When
- Website delivery or a selected Cloudflare service
Stripe
Payment and fraud preventionProvides secure payment fields, tokenised payment methods, payment status and fraud-prevention controls. Card credentials are submitted directly to Stripe and are not stored by Silurian.
- Typical data
- Contact, billing, transaction, device and fraud signals
- When
- Only during an applicable payment or saved-card journey
Google Identity Services returns an identity credential and basic profile only after you choose Google sign-in. Google Workspace processes customer and end-user data under the applicable Workspace agreement when that product is contracted.
- Typical data
- Identity profile; Workspace account, administrator and service data
- When
- Google sign-in or a contracted Google Workspace service
Netim and domain registries
Official registrar and registry operationsNetim is the official registrar used for current Silurian domain registrations. For holder and contact data, Silurian and Netim act as joint controllers under Article 26 GDPR. Netim may verify identity, process registration, renewal or transfer, publish registration data where required and transmit the necessary information to the registry responsible for the selected extension. A registry may also act as a separate controller under its own legal and policy obligations.
- Typical data
- Domain, holder and contact details, eligibility, verification and transaction data
- When
- Availability checks and contracted domain operations
Communications routes
Email, SMS and support deliverySilurian uses its own systems and selected communications routes to deliver requested email, support and one-time SMS notifications. A route receives only the address or number, message and delivery metadata needed for that communication.
- Typical data
- Email address or mobile number, message and delivery status
- When
- When you request or the contracted service requires the communication
Providers, registry operators and communications routes can change as services evolve. Silurian reviews the register when a material integration changes and can provide more specific recipient and transfer information for your account or transaction through the privacy contact route.
Retention and security
We apply the following retention criteria unless a longer or shorter period is required by law, an active dispute, a security investigation or the service contract:
| Record | Retention criterion |
|---|---|
| Account and Workspace profile | While the account or customer relationship is active, followed by the period needed to resolve claims and meet legal obligations. |
| Orders, invoices, tax and accounting evidence | The statutory accounting, tax and commercial retention periods applicable to Silurian. |
| Support tickets and attachments | Ticket records are retained for support continuity and the applicable contractual, security, legal or dispute period. Attachment content is automatically deleted 24 months after the ticket closes unless a shorter or longer period is required. Authorised operators may permanently delete attachments sooner when they contain especially sensitive information or are no longer needed for the ticket process. |
| Security, access and audit events | For the period reasonably needed to detect abuse, investigate incidents, demonstrate authorised actions and defend the platform. |
| Uncompleted forms and temporary uploads | For a short operational recovery and abuse-prevention period, then deleted if no ticket or transaction is completed. |
| Consent record | For the stated consent lifetime and, where necessary, a proportionate period afterwards to demonstrate the choice, withdrawal and version that applied. |
| Domain registration and contact data | For the active registration and the additional contractual, registry, audit, dispute or legal period that applies. Netim and the relevant registry apply their own required retention periods. |
When data is no longer needed, it is deleted, securely isolated until backup rotation completes, or anonymised where practical.
Access controls, encryption in transit, audit evidence, provider boundaries and operational review help protect Silurian services. No internet service can promise absolute security; we investigate and respond to suspected incidents according to their risk.
Your rights
Subject to the conditions in applicable law, you may:
- request access to your personal data and information about its processing;
- correct inaccurate data and complete incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests or to direct marketing at any time;
- receive portable data where processing is automated and based on consent or contract;
- withdraw consent at any time without affecting processing already carried out lawfully; and
- request human intervention where a legally significant decision would be based solely on automated processing.
We may need to verify your identity and authority before acting, and we will explain if a legal exception prevents all or part of a request. Account controls can handle ordinary profile changes; use the Privacy & data protection ticket route for a formal request.
For domain holder or contact data, you may submit your request to Silurian. We will coordinate the request with Netim and, where necessary, the responsible registry. We answer without undue delay and normally within one month, subject to the extensions and exceptions allowed by applicable law.
You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority, particularly where you habitually live or work or where you believe an infringement occurred. Contacting Silurian first is optional.
Contact and policy changes
Send privacy questions, objections, withdrawal requests or requests to exercise your rights through our secure contact route. The Privacy & data protection category is selected automatically.
Contact Silurian about privacy