Privacy policy
1. Data controller
The controller of personal data is WEBINVEST® di Schiappacassa Marco, Italian sole proprietorship, Via Gambolina 42, 27029 Vigevano (PV), Italy, VAT IT02467160186, REA PV-314717, email [email protected], PEC [email protected], telephone 02.21119017.
No Data Protection Officer (DPO) has been appointed. For any personal-data matter, use the controller contact details shown above.
2. Categories of data processed
Enquiries and commercial negotiations
- full name, email address, any telephone number and company name;
- domain of interest, indicative offer, reason for contact and message text;
- subsequent communications relating to the enquiry or negotiation.
Domain owners and WHOIS/RDAP checks
- identity and contact details of the owner or representative, proof of ownership, engagement or proposal terms and domain-related communications;
- domain name, registrar, status, nameservers and creation, update and expiry dates;
- where available through a registry, registrar, NIC or WHOIS/RDAP service, the registrant name or organisation and the technical response required for verification.
These data may be collected directly from the data subject or obtained from the sources listed above to verify domain ownership, status, availability and transferability. WEBINVEST does not indiscriminately publish full registrant contact details in the catalogue.
Customer account
- full name, email address and account verification status;
- password stored only as a hash, technical verification and recovery tokens, and session data;
- order and offer history associated with the account.
Orders, invoicing and domain transfers
- full name or account holder, email, telephone and company name;
- VAT number or tax code, SDI code or certified email, address, postal code, city, province and country;
- domain, price, order status, Stripe payment references and data required for invoicing and transfer.
- for withdrawal requests: name, email, order or contract reference, domain, statement, request date and time, and technical transmission data.
Technical, security and website-use data
- IP address, user agent, date and time, requested page, security events and server logs;
- technical cookies, language preferences, cookie choices and data required for login, security and checkout;
- only with prior consent, identifiers and browsing data processed through Google Analytics, Google AdSense and Microsoft Clarity for measurement, advertising and usability analysis.
Parking landing pages and first-party statistics
This section applies to domains using WEBINVEST nameservers and displaying the parking landing page. No analytics event is recorded before a choice is made. The server still processes data strictly necessary to deliver and protect the page, under the normal technical security logs.
Only after analytics consent, the following are recorded: date and time, domain and requested path, external source and its path, any search terms transmitted by the browser or search engine, UTM parameters, language, broad device category, browser and operating system, bot classification, and clicks leading to the listing or auction. The IP address and user agent are not stored in the analytics database: they are used only to generate, through HMAC, a pseudonymous identifier that changes daily. This identifier cannot recognise the same person across different days or domains.
Landing-page statistics are managed directly by WEBINVEST, without third-party analytics or advertising scripts. The choice is stored in a signed technical cookie specific to the visited domain and can be changed at any time through “Privacy choices” in the footer.
We do not request special categories of data under Art. 9 GDPR. Users should not enter such data in free-text fields. For cookies, durations, providers and how to change or withdraw choices, see the Cookie policy.
3. Purposes and legal basis of processing
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Answering enquiries, evaluating domains, managing negotiations and taking pre-contractual steps requested by the user | Point b (pre-contractual measures and contract requested by the data subject) |
| Verifying domain ownership, status, availability and transferability and keeping the catalogue accurate | Point f (legitimate interest in catalogue accuracy, transaction security and the prevention of errors or fraud) and point b where the check is required for a negotiation or transfer |
| Creating and managing the customer account, authentication, access recovery and personal area | Point b (performance of the requested service) |
| Managing the order, payment, invoice, support and domain transfer | Point b (performance of the contract) and point c (tax and legal obligations) |
| Receiving, recording and handling withdrawal requests and sending the related receipt | Point c (consumer-law obligations) and point f (establishment, exercise or defence of legal claims) |
| Sending transactional communications about accounts, enquiries, orders and transfers | Point b and, for support and traceability requirements, point f |
| Preventing abuse, spam, fraud and attacks, protecting the website and establishing potential liability | Point f (controller's legitimate interest in service security) |
| Measuring website use, analysing usability and serving or measuring advertising not necessary for the service | Point a (consent, withdrawable at any time through cookie settings) |
| Measuring traffic to parking landing pages and commercial interest in domains | Point a (optional consent, withdrawable at any time through “Privacy choices” on the landing page) |
Data marked as required in each form is necessary to provide the requested service. Failure to provide it prevents the enquiry, account creation or order from being processed. Other data is optional. Processing necessary for a contract or pre-contractual steps is not based on consent.
Where registrant data is not collected directly from the data subject, the source is a registry, registrar, NIC or WHOIS/RDAP service. The data subject may request the source, access, rectification, restriction or object using the contact details in this policy.
WEBINVEST does not make solely automated decisions that produce legal effects on users. Any advertising personalisation is enabled only according to the choices made in the cookie banner.
4. Recipients and non-EU transfers
Data is processed by the controller, authorised persons and the following providers. Depending on the service, a provider may act as a processor or as an independent controller for its own activities:
| Provider | Role | Location | Safeguards |
|---|---|---|---|
| SiteGround Spain S.L. | Website and database hosting | EU (Spain) | GDPR applicable |
| Aruba S.p.A. | Dedicated-server infrastructure, network and parking-system backups | EU (Italy) | GDPR applicable and data-processing terms |
| Cloudflare, Inc. | CDN, security, anti-DDoS | USA | EU Standard Contractual Clauses (SCC) |
| Stripe | Payments, fraud prevention and transaction management | EU / USA | SCCs and other applicable safeguards |
| Workspace/email, CMP, Analytics and AdSense according to cookie choices | EU / USA | SCCs and other applicable safeguards | |
| Microsoft Clarity | Usability analytics only with prior consent | EU / USA | SCCs and other applicable safeguards |
| Resend / Amazon Web Services | Transactional email delivery | EU / USA | SCCs and other applicable safeguards |
| Zelatech S.r.l. | Operational technical partner (catalogue sync) | EU (Italy) | GDPR applicable |
Data is not sold. It may also be disclosed to professional advisers, registrars and registries involved in a transfer, public authorities or other parties where necessary for the contract or required by law.
Where a provider processes data outside the European Economic Area, the transfer relies on an adequacy decision, the Data Privacy Framework where applicable, Standard Contractual Clauses or another safeguard under Arts. 44 et seq. GDPR.
5. Retention period
- Enquiries: kept for 24 months from receipt, unless a negotiation or sale justifies longer retention.
- Owner proposals and engagements: 24 months for proposals not accepted; up to 10 years for engagements and completed transactions or to protect a legal claim.
- WHOIS/RDAP checks: current technical status for the duration of publication or the transaction; any personal data and raw responses are generally kept for no more than 12 months unless required for a contract, proof of ownership, an incident or a dispute.
- Customer account: for the lifetime of the account and afterwards for as long as necessary to handle enquiries, orders, disputes and legal obligations.
- Orders, payments and invoices: kept for 10 years or for any different period required by applicable civil and tax law.
- Withdrawal requests and related receipts: kept with the contractual documentation for the period necessary to demonstrate proper handling of the request and protect the parties' rights, generally no longer than 10 years.
- Technical logs (IP, user-agent, access logs): kept only as long as strictly necessary for security monitoring, generally no more than 12 months.
- Parking landing analytics events: kept for a maximum of 90 days; the technical cookie remembering the choice lasts 180 days. Aggregate statistics published in the catalogue contain no visitor identifier and are periodically overwritten.
- Cookies and analytics/advertising data: according to the durations stated in the Cookie policy and the relevant provider notices.
6. Data subject rights
At any time you may exercise the rights granted by Arts. 15-22 GDPR:
- Access to the data concerning you
- Rectification of inaccurate or incomplete data
- Erasure ("right to be forgotten") when no longer necessary
- Restriction of processing in certain cases
- Objection to processing based on legitimate interest
- Portability of data in a structured, readable format
- Withdrawal of consent for processing based on consent, without affecting the lawfulness of processing carried out beforehand
To exercise any of these rights, simply write to [email protected] or to the certified email (PEC) [email protected] clearly stating your request. We will reply within 30 days as required by Art. 12 GDPR.
7. Complaint to the supervisory authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante) (www.garanteprivacy.it) or with the supervisory authority of the EU member state where you reside.
8. Contact
For any question or request regarding personal data protection, contact the controller:
- Email: [email protected]
- PEC: [email protected]
- Telephone: 02.21119017
- Address: WEBINVEST® di Schiappacassa Marco, Via Gambolina 42, 27029 Vigevano (PV), Italy
This policy may be updated. Any changes will be published on this page with the new "Last updated" date shown above.