Privacy Policy for nic.rich
Last updated: October 2, 2026
1. Controller
The controller responsible for the processing of personal data in connection with this Website is:
iRegistry GmbH
Friedrichstr. 171
10117 Berlin
Germany
Email: privacy (at) i-registry.com
2. Purpose and Scope
nic.rich is an informational website about the .RICH top-level domain.
nic.rich itself does not register, renew, transfer or manage .RICH domain names. The Website does not maintain registrant accounts or process payments for domain registrations. .RICH domain names are registered and managed through ICANN-accredited registrars.
This Privacy Policy applies solely to the processing of personal data in connection with the use of nic.rich, in particular the technical operation of the Website, the forms made available on the Website, the protected registrar area and communications with iRegistry.
Third-party websites and services are subject to the privacy policies of their respective operators.
3. Hosting and Server Log Data
nic.rich is hosted through GoDaddy.com, LLC, 100 S Mill Ave, Suite 1600, Tempe, Arizona 85281, United States. The hosting account is assigned to GoDaddy's “North America” data center region.
When you access the Website, technically necessary connection and server data are processed. These may include:
- your IP address;
- the date and time of access;
- the page or file requested;
- browser type and version;
- operating system and user-agent information;
- technical connection information; and
- a referring URL, where transmitted by your browser.
These data are processed to deliver the Website, maintain its functionality and security, detect technical errors and identify or prevent abusive or security-related access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and proper operation of the Website and our IT systems.
Server and access logs are generally retained for no longer than seven days and are then deleted or overwritten, unless longer retention is necessary in a particular case to investigate a security incident, comply with a legal obligation, or establish, exercise or defend legal claims.
4. Forms on nic.rich
4.1 Contact Form
You may send iRegistry a message through the contact form. We process the information you enter, in particular your name, company where applicable, email address, subject and the content of your message.
We process these data to receive, review and respond to your inquiry.
Where your inquiry relates to entering into or performing a contract with you, the legal basis is Article 6(1)(b) GDPR. In all other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the proper handling of inquiries voluntarily addressed to us.
4.2 Registrar Inquiries
ICANN-accredited registrars may use nic.rich to inquire about becoming accredited by iRegistry as a registrar for .RICH.
In connection with such an inquiry, we may process in particular information about the company and its contact person, contact details, website, the registrar name registered with ICANN, the IANA ID, and information concerning accreditation status and other requirements relevant to our review.
We use these data to assess whether the requesting registrar satisfies the requirements for accreditation by iRegistry, to process the inquiry, and to communicate with the registrar regarding the further accreditation process.
Following a successful review, registrar and contact information required for technical onboarding may be transferred to Identity Digital, the Registry Service Provider for .RICH. Identity Digital then carries out the technical onboarding process. Access to protected registrar documents is provided only in connection with the relevant accreditation and authorization.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the review and processing of accreditation inquiries and the proper management of our cooperation with registrars.
4.3 Suggestions for Organizations and Projects
Visitors may use the relevant function on nic.rich to suggest an organization or project for consideration in connection with the activities described on the Website.
We process the information entered by the user, in particular the name and email address of the person submitting the suggestion, the name and, where applicable, website of the suggested organization, and the reasons provided for the suggestion.
We process these data to receive, review and handle the voluntarily submitted suggestion. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to be able to receive and review such suggestions.
Please provide only personal data in free-text fields that are necessary for the relevant inquiry.
5. Contact by Email and Abuse Reports
If you contact us using an email address provided on nic.rich, we may process in particular your email address, your name, other contact details voluntarily provided by you, the content of your message, attachments and technical communication data.
Depending on the content of an abuse or security report, the communication may also contain personal data relating to third parties, domain names, IP addresses or other technical information.
We process these data to review and handle your message, communicate with you and, where necessary, investigate potential abuse or security matters.
Where the communication relates to entering into or performing a contract with you, processing is based on Article 6(1)(b) GDPR. Where processing is necessary to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR. In all other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interests include the proper handling of business communications and the protection of the .RICH registry, our systems and third parties against abuse and security risks.
We use Microsoft 365 Email obtained through GoDaddy for our email communications. In connection with the technical provision and security of this service, personal data may therefore be processed by GoDaddy, Microsoft group companies and technical service providers engaged by them.
6. Protected Registrar Area
Certain information and documents for accredited or otherwise authorized registrars are available only through a protected area.
When you sign in, the login credentials you enter and technically necessary connection, session and security data are processed to the extent required for authentication, session management and protection of the area against unauthorized or abusive access.
Following a successful sign-in, a technically necessary session cookie is set. This cookie is used solely to maintain the authenticated session and is not used for analytics, marketing or tracking purposes.
Use of this cookie is technically necessary to provide the protected area expressly requested by the user and therefore does not require consent under Section 25(2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act).
To the extent personal data are processed in this context, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure provision and protection of the registrar area.
Details of the security mechanisms used are not published for security reasons.
7. Cookies, Tracking and External Website Resources
nic.rich does not use analytics, marketing, advertising or tracking cookies, or comparable technologies for such purposes.
In particular, we do not use:
- Google Analytics;
- Matomo;
- Google Ads Conversion Tracking;
- tracking pixels;
- profiling or cross-site tracking technologies; or
- external captcha services such as Google reCAPTCHA.
Fonts and material JavaScript and CSS resources used by the Website are served locally and do not, during normal use of the Website, establish a connection to external font, analytics or tracking providers.
The only cookie used on nic.rich is the technically necessary session cookie for the protected registrar area described in Section 6.
As nic.rich does not use technologies requiring consent under Section 25(1) TDDDG, the Website does not display a cookie consent banner.
Technical safeguards are used to prevent automated, abusive or security-threatening form submissions. Technically necessary connection and security data may be processed for this purpose. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure operation of the Website and the protection of our systems and communications infrastructure.
8. External Links
nic.rich contains links to third-party websites and online services, in particular registrars and other external information or service pages.
The mere display of such a link does not generally establish a connection to the linked website. A connection to the relevant external provider is established by your browser only when you follow the link.
When you follow an external link, you leave the part of nic.rich operated by iRegistry. The operator of the external website is responsible for the subsequent processing of personal data on that website in accordance with its own privacy information.
This Privacy Policy does not apply to external websites and services.
9. Recipients of Personal Data
Within iRegistry GmbH, personal data are made available only to persons who require them for the relevant purpose.
Where necessary for the relevant purpose, personal data may also be processed by the following recipients or categories of recipients:
- GoDaddy as our hosting and email service provider;
- Microsoft and relevant Microsoft group companies in connection with Microsoft 365;
- technical subprocessors engaged by those providers;
- Identity Digital as Registry Service Provider in connection with the technical onboarding of a successfully accredited registrar;
- IT and security service providers, where required;
- legal, tax and other professional advisers, where required; and
- public authorities, courts or other public bodies where disclosure is required by law or necessary for the establishment, exercise or defense of legal claims.
Where a service provider processes personal data on behalf of iRegistry, the processing is governed by an appropriate data processing arrangement in accordance with Article 28 GDPR.
10. International Data Transfers
In connection with the hosting and communications services we use, personal data may be processed outside the European Union or European Economic Area, in particular in the United States.
GoDaddy.com, LLC is among the GoDaddy entities that have certified their participation in the EU-U.S. Data Privacy Framework. Microsoft likewise confirms participation in the EU-U.S. Data Privacy Framework for its covered U.S. entities.
For transfers to U.S. organizations that validly participate in the EU-U.S. Data Privacy Framework and where the relevant processing is covered by the certification, an adequacy decision of the European Commission under Article 45 GDPR applies.
Where a particular transfer is not covered by an adequacy decision, it takes place only where another lawful basis under Articles 44 et seq. GDPR is available, in particular appropriate safeguards under Article 46 GDPR such as the Standard Contractual Clauses approved by the European Commission.
You may request information about the safeguards applicable to a particular transfer by contacting privacy (at) i-registry.com, where such a right is provided by applicable law.
11. Data Retention
We retain personal data only for as long as necessary for the relevant processing purpose.
Server and access logs are generally retained for no longer than seven days.
Data from forms and email communications are deleted once the relevant inquiry has been completed and the data are no longer required, unless statutory retention requirements or other legitimate reasons require further retention.
Data relating to registrar accreditations may be retained for the duration of the review and accreditation process and, where applicable, the subsequent business relationship, and thereafter for as long as necessary to comply with legal or contractual obligations or to establish, exercise or defend legal claims.
Data relating to security and abuse matters may be retained for as long as necessary to investigate and handle the relevant matter, prevent further abuse or preserve legal claims.
12. Requirement to Provide Personal Data
When you visit nic.rich, the processing of certain technical connection data, in particular your IP address, is technically necessary. Without these data, the Website cannot be transmitted to your device.
Use of the forms and contacting us by email are voluntary. However, without the information required for the relevant inquiry, we may be unable to process or respond to it.
Use of the protected registrar area is also voluntary. To use that area, however, the data required for authentication and session management must be processed.
Otherwise, there is no statutory or contractual requirement to provide personal data to iRegistry in connection with the use of the informational website nic.rich.
13. Your Data Protection Rights
Subject to the applicable statutory requirements, you have in particular the right to:
- request access to your personal data under Article 15 GDPR;
- request rectification under Article 16 GDPR;
- request erasure under Article 17 GDPR;
- request restriction of processing under Article 18 GDPR;
- exercise the right to data portability under Article 20 GDPR, where applicable; and
- object to processing under Article 21 GDPR.
To exercise your rights, please contact us at privacy (at) i-registry.com.
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data.
Following such an objection, we will no longer process the relevant personal data on that basis unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing is required for the establishment, exercise or defense of legal claims.
14. Right to Lodge a Complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
The supervisory authority responsible for our registered office is:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59-61
10555 Berlin
Germany
Phone: +49 30 13889-0
Fax: +49 30 2155050
Email: mailbox (at) datenschutz-berlin.de
15. Automated Decision-Making, Data Security and Changes
We do not use solely automated decision-making, including profiling within the meaning of Article 22 GDPR, in connection with nic.rich.
iRegistry uses appropriate technical and organizational measures designed to protect personal data against loss, manipulation, unauthorized access, unauthorized disclosure and other unlawful processing. Transmission of nic.rich is protected by encrypted HTTPS/TLS connections.
We may update this Privacy Policy if the Website, the technical services we use, the processing of personal data or applicable legal requirements change. The version published on nic.rich at the relevant time is the current version.