Naar de inhoud springen
Trust & transparency

Privacy at Silurian

What we collect, why we need it, how long we keep it and the choices you have when using our website and services.

Policy version
4.4
Effective date
7 September 2026
Last updated
7 September 2026
01

Who is responsible for your data

Silurian SL is the data controller for the personal data described in this policy when you visit a Silurian website, contact us, create an account, purchase a service or use Workspace. For services where a customer determines why and how Silurian processes data on its behalf, Silurian may instead act as that customer's processor under the applicable service agreement.

For registrant and contact data used to register and manage a domain through Netim, Silurian and Netim act as joint controllers under Article 26 GDPR. Silurian selects the customer and domain operation and manages the customer relationship; Netim determines the technical and regulatory processing required as the official registrar, including identity verification, registration-data publication and transmission to the responsible registry.

Controller
Silurian SL
VAT number
ESB86389889
Postal address
Portugalete 46, 28223 Madrid, Spain
Historical AEPD file registration
2181343370

The AEPD number is retained for historical transparency. The former Spanish obligation to register personal-data files was abolished when the GDPR became applicable and was replaced by the controller's internal record of processing activities; it is not a current certification or approval.

We apply data minimisation: service, account and security data are used only where needed to deliver the requested relationship, comply with law, protect the platform or support a choice you have made.

02

Data we use

Identity and account

Name, email, language, country, profile and authentication evidence.

Customer and billing

Company, address, tax profile, orders, invoices, subscriptions and payment status. Card credentials remain with the payment provider.

Support and communications

Messages, tickets, attachments and the preferences needed to respond or send requested information.

Technical and security

IP address, timestamps, session and device signals, audit events and logs used to operate and secure the service.

Domain registration contacts

Domain name, holder, administrative, technical and billing contact details, eligibility information and verification evidence.

Where the data comes from

Most data comes directly from you. It may also come from an authorised administrator of your organisation, identity providers when you choose a social sign-in, payment and service providers involved in your transaction, public company or tax registers used for verification, and technical events generated when you use or secure the platform.

Sensitive data and children

Our services are not designed to collect special-category data. Please do not include health, biometric, political, religious or similarly sensitive information in tickets unless it is strictly necessary for your request. Silurian's commercial services are not directed to children, and we do not knowingly create customer accounts for children acting on their own behalf.

03

Purposes and legal bases

PurposeTypical legal basis
Provide accounts, orders, subscriptions, support and contracted servicesContract or steps requested before a contract
Verify customer, tax and payment information; issue and retain accounting recordsContract and legal obligations
Prevent fraud, abuse and unauthorised access; investigate incidents; maintain audit evidenceLegitimate interests in protecting customers, Silurian and the integrity of the service, and legal obligations where applicable
Operate, diagnose and improve the reliability and usability of the platformContract and legitimate interests, using proportionate and minimised operational data
Respond to privacy requests, disputes and regulatory enquiriesLegal obligations and the establishment, exercise or defence of legal claims
Send requested service communicationsContract or the action you requested
Register, renew, transfer and manage domains; maintain accurate registration data; meet registrar, registry and ICANN requirementsContract, steps requested before a contract, and legal or regulatory obligations applicable to the domain service
Send optional marketing or load optional analytics, preference or marketing technologiesYour consent, which you may withdraw at any time

Required information

Fields marked as required are necessary to create the requested account, ticket, order or service, or to meet billing and legal requirements. If you do not provide them, we may be unable to complete that request. Optional fields can be left blank without losing access to unrelated services.

If you provide personal data for another domain contact, you must be authorised to do so and must give that person the same domain-registration privacy information available to you. Silurian records and transmits only the contact roles and data required for the selected registration and extension.

Automated processing and AI

Silurian does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Automated security and fraud signals may flag activity for restriction or human review. Helpdesk AI may classify, summarise, translate or suggest a draft, but a Silurian agent remains responsible for customer-facing decisions and replies.

04

Sharing and international transfers

We disclose only the data necessary to the following categories of recipients:

  • hosting, network delivery, security, backup and operational infrastructure providers;
  • communications and support providers used to deliver requested email, SMS or ticket services;
  • payment processors, banks, accounting providers and fraud-prevention services involved in a transaction;
  • Netim as official registrar, the registry responsible for the selected extension, and other suppliers needed to perform a domain operation;
  • professional advisers, auditors and insurers subject to appropriate duties of confidentiality; and
  • courts, regulators, tax authorities, law-enforcement bodies or other recipients where disclosure is legally required or necessary to establish, exercise or defend legal claims.

Providers processing data for Silurian are limited by contract and may process it only for documented purposes. Some selected services, identity providers or infrastructure providers may process data outside the European Economic Area. Where no European Commission adequacy decision applies, Silurian relies on an applicable safeguard such as the European Commission's Standard Contractual Clauses and supplementary technical or organisational measures. You may request information about the relevant mechanism and how to obtain a copy through the privacy contact route.

Buying a third-party service from Silurian does not by itself authorise that provider to track your visits to this website.

05

Services and providers

This register names the principal external services that may receive personal data in a current Silurian journey. A provider is not given every category of data listed in this policy: it receives only what is needed for the stated journey. Its role may vary between processor, independent controller or separate service supplier according to the service and applicable agreement.

Cloudflare

Network delivery and security

Processes network and request information needed to deliver Silurian websites, mitigate attacks, manage challenges and protect the origin. Cloudflare-backed products ordered by a customer are a separate service journey.

Typical data
IP address, request, device and security signals
When
Website delivery or a selected Cloudflare service
Cloudflare privacy and data protection

Stripe

Payment and fraud prevention

Provides secure payment fields, tokenised payment methods, payment status and fraud-prevention controls. Card credentials are submitted directly to Stripe and are not stored by Silurian.

Typical data
Contact, billing, transaction, device and fraud signals
When
Only during an applicable payment or saved-card journey
Stripe Privacy Center

Google

Identity and Google Workspace

Google Identity Services returns an identity credential and basic profile only after you choose Google sign-in. Google Workspace processes customer and end-user data under the applicable Workspace agreement when that product is contracted.

Typical data
Identity profile; Workspace account, administrator and service data
When
Google sign-in or a contracted Google Workspace service
Google Cloud Privacy Notice

Netim and domain registries

Official registrar and registry operations

Netim is the official registrar used for current Silurian domain registrations. For holder and contact data, Silurian and Netim act as joint controllers under Article 26 GDPR. Netim may verify identity, process registration, renewal or transfer, publish registration data where required and transmit the necessary information to the registry responsible for the selected extension. A registry may also act as a separate controller under its own legal and policy obligations.

Typical data
Domain, holder and contact details, eligibility, verification and transaction data
When
Availability checks and contracted domain operations
Netim personal-data policy

Communications routes

Email, SMS and support delivery

Silurian uses its own systems and selected communications routes to deliver requested email, support and one-time SMS notifications. A route receives only the address or number, message and delivery metadata needed for that communication.

Typical data
Email address or mobile number, message and delivery status
When
When you request or the contracted service requires the communication
Ask about the route used for your service

Providers, registry operators and communications routes can change as services evolve. Silurian reviews the register when a material integration changes and can provide more specific recipient and transfer information for your account or transaction through the privacy contact route.

06

Retention and security

We apply the following retention criteria unless a longer or shorter period is required by law, an active dispute, a security investigation or the service contract:

RecordRetention criterion
Account and Workspace profileWhile the account or customer relationship is active, followed by the period needed to resolve claims and meet legal obligations.
Orders, invoices, tax and accounting evidenceThe statutory accounting, tax and commercial retention periods applicable to Silurian.
Support tickets and attachmentsTicket records are retained for support continuity and the applicable contractual, security, legal or dispute period. Attachment content is automatically deleted 24 months after the ticket closes unless a shorter or longer period is required. Authorised operators may permanently delete attachments sooner when they contain especially sensitive information or are no longer needed for the ticket process.
Security, access and audit eventsFor the period reasonably needed to detect abuse, investigate incidents, demonstrate authorised actions and defend the platform.
Uncompleted forms and temporary uploadsFor a short operational recovery and abuse-prevention period, then deleted if no ticket or transaction is completed.
Consent recordFor the stated consent lifetime and, where necessary, a proportionate period afterwards to demonstrate the choice, withdrawal and version that applied.
Domain registration and contact dataFor the active registration and the additional contractual, registry, audit, dispute or legal period that applies. Netim and the relevant registry apply their own required retention periods.

When data is no longer needed, it is deleted, securely isolated until backup rotation completes, or anonymised where practical.

Access controls, encryption in transit, audit evidence, provider boundaries and operational review help protect Silurian services. No internet service can promise absolute security; we investigate and respond to suspected incidents according to their risk.

07

Your rights

Subject to the conditions in applicable law, you may:

  • request access to your personal data and information about its processing;
  • correct inaccurate data and complete incomplete data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests or to direct marketing at any time;
  • receive portable data where processing is automated and based on consent or contract;
  • withdraw consent at any time without affecting processing already carried out lawfully; and
  • request human intervention where a legally significant decision would be based solely on automated processing.

We may need to verify your identity and authority before acting, and we will explain if a legal exception prevents all or part of a request. Account controls can handle ordinary profile changes; use the Privacy & data protection ticket route for a formal request.

For domain holder or contact data, you may submit your request to Silurian. We will coordinate the request with Netim and, where necessary, the responsible registry. We answer without undue delay and normally within one month, subject to the extensions and exceptions allowed by applicable law.

You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority, particularly where you habitually live or work or where you believe an infringement occurred. Contacting Silurian first is optional.

08

Website and cookies

Silurian uses essential browser storage for security, sessions, country and language routing, carts and the record of your cookie choice. Optional categories are disabled unless you enable them. Changing the choice stops future loading; a third party may require you to remove data it already stored through your browser settings.

When you save a choice, Silurian records the exact optional categories, the applicable cookie-text version, time and a pseudonymous browser identifier in signed integrity evidence. If you are signed in, the event may also be associated with your verified account so that it can later be shown and managed in Workspace. Rejecting or withdrawing optional categories is recorded as a choice too; it never creates marketing permission.

Campaign and affiliate attribution

If you reach a supported Silurian V2 page through a tagged link, Silurian may read bounded values from utm_source, utm_medium, utm_campaign, utm_content, utm_term, partner and click_id. Standard Google Ads (gclid, gbraid and wbraid), Microsoft Ads (msclkid) and Meta (fbclid) click identifiers are also recognised. Partners must use opaque identifiers and must not place names, email addresses, payment information or other directly identifying data in these parameters.

A qualifying arrival is held temporarily in the server-side PHP session while your choice is pending. Only after Silurian has valid signed marketing-consent evidence is it persisted as a first or last campaign touch, associated with the cart and copied as a tamper-evident snapshot into an order. The snapshot may contain the bounded campaign fields, partner and click identifiers, the landing path, external referrer host and observation time. It helps authorised Silurian staff identify the source, campaign or affiliate responsible for a sale, measure conversions and review any commission. It is visible in the restricted Operations Center order detail; it is not added to the public invoice.

Silurian does not retain a raw referrer query string and normally cannot determine the exact words used in an organic search. Rejecting or withdrawing marketing consent clears pending/session attribution and detaches it from carts so that a later order does not freeze it. Withdrawal does not rewrite an immutable order snapshot created while valid consent applied; that evidence follows the relevant order, affiliate-settlement, audit, dispute and legal retention criteria.

Cookies and browser storage currently used

This register is deliberately limited to cookies, local storage and similar browser-side technology. The separate Services and providers section explains external recipients and product suppliers. “Control” describes whether browser storage is essential, initiated by your action or governed by optional settings; “When it appears” describes the technical condition that causes it to be used.

Technology and providerPurpose and dataDurationControlWhen it appears
PHPSESSIDSilurian, first partyMaintains authenticated state, security checks, cart and request continuity. It contains a random session identifier, not the account details themselves.Session or the shorter server-configured lifetimeEssentialWhen a journey requires server-side continuity
silurian_v2_consent_v1Silurian, local storageStores the three optional-category choices, policy format version and choice timestamp.Up to 180 daysEssential recordAfter a cookie choice is saved
Consent handoffSilurian, URL fragment or signed one-use transferCarries only the consent choice when moving between Silurian country domains. The fragment is not sent to the server and is removed after validation.Immediate, one useEssential continuityOnly when changing country domain
cf_clearance / __cf_bmCloudflareChallenge proof and encrypted bot-management or browser signals used to distinguish legitimate requests from abuse.Challenge configuration; __cf_bm expires after 30 minutes of inactivityEssential securityOnly when Cloudflare security issues them
Google Identity ServicesGoogle; may use g_csrf_token and g_statePrevents sign-in request forgery and completes the optional Google sign-in you select. Google returns an identity credential and basic profile data after your action.Temporary or session/configuration dependentUser initiatedOnly after you choose Google sign-in on a page offering it
Stripe.js and payment security storageStripeProvides secure payment fields and fraud prevention. Payment details go directly to Stripe; Silurian receives transaction status and limited payment metadata.As published by Stripe for its necessary payment and fraud-prevention technologiesUser initiatedOnly when you enter an applicable payment journey
Campaign and affiliate attributionSilurian, first partyUses bounded tagged-link values, landing path and external referrer host to retain consented first/last campaign touches and an order-level conversion snapshot. No raw referrer query string is retained.Pending only for the PHP session until a choice; consented order evidence follows the applicable order, commission, audit, dispute and legal retention criteriaMarketing opt-inOn a supported tagged or externally referred V2 landing page; it is persisted and attached to commerce only with valid signed marketing consent
Other preferences, analytics and advertisingNo provider activeNo separate optional preference integration, aggregate analytics service, advertising pixel, audience-matching provider or Meta Pixel is currently enabled.NoneOptional settingsNot currently used; a future integration would load only after the corresponding opt-in and policy update

Blocking necessary storage may prevent sign-in, security checks, carts, regional continuity or payments from working. You can remove stored data in your browser, and you can change Silurian's optional categories at any time.

You remain in control

You can reopen these settings from the footer at any time. Optional technologies remain disabled unless you choose to enable their category.

09

Contact and policy changes

Send privacy questions, objections, withdrawal requests or requests to exercise your rights through our secure contact route. The Privacy & data protection category is selected automatically.

Contact Silurian about privacy