← Back to Domzor

Privacy Policy

Last updated: 29 July 2026

Before launch The bracketed fields must be completed with the operating company's registered details and its actual hosting and email providers, and the whole document reviewed by someone qualified in data protection law. It is written specifically for Domzor rather than adapted from a template, but it is not legal advice.

1. Data controller

Domzor (Bombus Interactive i Sverige AB), registration number 559010-1225, Övägen 8, 216 42 Limhamn, Sweden, is the controller for the personal data described in this policy. Contact us at info@domzor.app.

[IF A DATA PROTECTION OFFICER IS APPOINTED, ADD THEIR CONTACT DETAILS HERE. One is not required for an operation of this size and nature, but state the position either way.]

2. Data you give us

When you create and use an account we process:

  • Identity and contact data — first and last name, email address, country, and optionally job title, company and a profile picture.
  • Authentication data — a hashed password, email verification codes (also stored hashed) and session information. We never store your password in readable form.
  • Workspace content — the domains you monitor together with any tags, notes, internal owner and client names you add. Free-text fields may contain personal data if you choose to put it there; you decide what goes in them.
  • Correspondence — messages you send us for support.

3. Data generated by your use

  • Technical data — IP address, browser and request metadata in server and security logs.
  • Monitoring history — the results of each check, stored as snapshots, change events and alerts.
  • Delivery records — whether an alert email was queued, sent, skipped or failed.

We do not use analytics, advertising or behavioural tracking, and we do not profile you. See section 10 on cookies.

4. Registration data about other people

This section deserves particular attention, because it concerns people who are not our customers.

To monitor a domain, Domzor retrieves registration data from registries via RDAP or WHOIS and stores the response so that changes can be detected over time. Depending on the registry and the top-level domain, that response may contain personal data about the domain's registrant or its administrative and technical contacts — typically a name, and sometimes an email address, postal address or telephone number.

This applies whether or not the registrant is a Domzor user, and it applies to any domain you add. Most registries now redact contact details for private individuals, but not all of them do, and practice differs between top-level domains.

We process this data on the basis of legitimate interest (Article 6(1)(f) GDPR): the interest of domain holders, agencies and businesses in detecting unauthorised changes to registrations they are responsible for or have a legitimate reason to watch. We limit that processing as follows:

  • we retrieve only what the registry publishes, and never attempt to defeat redaction;
  • the data is visible only inside the workspace that added the domain, never publicly and never to other customers;
  • we do not use it for marketing, do not enrich it with other sources and do not sell or share it;
  • raw responses are deleted according to the retention window of the workspace's plan (section 7).

If you are a registrant and object to us storing registration data about you, contact info@domzor.app. We will assess the objection under Article 21 GDPR and, unless we can demonstrate compelling legitimate grounds that override your interests, erase the data.

5. Why we process your data, and on what basis

Purpose Data Legal basis
Providing the service and your account Identity, authentication, workspace content Performance of a contract, Art. 6(1)(b)
Sending alerts and service messages Email address, monitoring history Performance of a contract, Art. 6(1)(b)
Verifying your email address Email address, verification code Performance of a contract, Art. 6(1)(b)
Registration data about third parties RDAP/WHOIS responses Legitimate interest, Art. 6(1)(f) — see section 4
Security, abuse prevention and rate limiting IP address, request metadata Legitimate interest, Art. 6(1)(f)
Billing and accounting Identity, plan and payment records Contract and legal obligation, Art. 6(1)(b) and (c)
Handling support requests Correspondence Legitimate interest, Art. 6(1)(f)

6. Who we share data with

We do not sell personal data. We share it only with providers who process it on our instructions under a data processing agreement:

  • Hosting and database — Hetzner Online GmbH, Germany, with the servers located in Finland. All monitoring data and account data is stored there.
  • Email delivery — [PROVIDER NAME, e.g. Brevo, France] for verification and alert emails.
  • DNS resolution diagnostics — dns.google. Each monitored domain name is sent to this resolver so we can tell a domain that does not exist apart from one whose nameservers are failing. No account details, only the domain name.
  • Error monitoring — Sentry. When something goes wrong we receive a diagnostic report containing the page address, your account identifier and a technical stack trace. It does not include your name, email address, IP address or anything you submitted in the request.
  • Payments[ADD WHEN BILLING IS LIVE. A payment processor is normally an independent controller for card data, which should be stated rather than listing them as a processor.]

We may also disclose data where required by law or to establish, exercise or defend legal claims. Note that adding a domain necessarily sends its name to the relevant registry, to the resolver named above and to the domain's own servers; those parties are independent controllers for the requests they receive.

7. How long we keep it

  • Account data — for as long as the account exists.
  • Monitoring history — snapshots, change events, check records and DNS records are deleted automatically once they are older than the retention window of the workspace's plan, which currently ranges from 30 to 730 days. Pruning runs daily.
  • Current state — the single most recent result of each check type is kept for as long as the domain is monitored, even if it is older than the retention window. It is not archive material: it is what the domain page shows and what the next check is compared against, so deleting it would both empty the page and make the service unable to detect the next change. It is deleted when you remove the domain or your account.
  • Verification codes — cleared as soon as they are used, expire, or are replaced.
  • Security logs[STATE THE ACTUAL LOG RETENTION, e.g. 90 days.]
  • Accounting records — kept for seven years as required by the Swedish Accounting Act.

Deleting your account removes your user record, your workspaces and all domains, monitoring history and alerts belonging to them. Records we are legally required to keep, such as accounting data, are retained for the statutory period and nothing else.

8. Transfers outside the EU/EEA

We aim to keep all processing within the EU/EEA and select providers accordingly. [IF ANY PROVIDER PROCESSES DATA OUTSIDE THE EU/EEA, NAME IT HERE TOGETHER WITH THE TRANSFER MECHANISM — adequacy decision or Standard Contractual Clauses — AND THE SUPPLEMENTARY MEASURES APPLIED.]

RDAP and WHOIS queries are by nature sent to registries worldwide, since that is where the data is published. Those queries contain the domain name being looked up, not your account details.

9. Security

Traffic is encrypted with TLS. Passwords and verification codes are stored hashed. Access to each workspace's data is enforced server-side on every request, and the application sets a content security policy along with other protective HTTP headers. Administrative access to production systems is limited to those who need it.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and inform you where the law requires it.

10. Cookies

Domzor sets a session cookie to keep you signed in and a CSRF token cookie to protect forms against cross-site request forgery. Both are strictly necessary for the service to function, so no consent banner is required for them.

We use no analytics, advertising or third-party tracking cookies. Fonts and icons are served from our own servers rather than a content delivery network, so loading a page does not disclose your IP address to any third party.

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased where the conditions in Article 17 are met;
  • restrict processing while a dispute is resolved;
  • receive data you provided in a machine-readable format, and have it transferred;
  • object to processing based on legitimate interest, including that described in section 4;
  • withdraw consent where processing is based on consent, without affecting prior processing.

You can access and correct your account details, export your domain list as CSV and delete your account directly in the application. For anything else, write to info@domzor.app. We answer within one month and may ask you to verify your identity first.

12. Complaints

If you believe we process your personal data unlawfully, we would like to hear from you first. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se, or with the supervisory authority in your country of residence.

13. Changes to this policy

We may update this policy as the service develops. The version in force is the one published here, with the date shown above. We notify account holders by email before changes that materially affect how personal data is processed.