Legal

Privacy policy

Version 2.0 — last updated 1 January 2025

This is an English translation provided for convenience. If it differs from the Swedish original, the Swedish version applies.

1. Data controller

DOT Network, reg. no. 559296-5148, VAT no. SE559296514801. Address: Mandolingatan, Västra Frölunda, Sweden. Contact: info@dotnetwork.se.

2. Data we collect

  • Accounts/orders: name, email, phone, billing address, organisation number (business customers), Swedish personal identity number (required for .se/.nu registration under the IIS policy), payment information (handled by the payment provider — we store no card details).
  • Technical data (automatic): IP address and approximate location, browser/OS, pages visited and duration, referring URL, server logs.
  • Support tickets: message content and attachments.

3. Legal basis

PurposeLegal basis
Delivering the services you orderedContract (Art 6.1b)
Billing & paymentContract + legal obligation
Technical supportLegitimate interest (6.1f)
Security/fraud preventionLegitimate interest (6.1f)
Email marketingConsent (6.1a)
Legal obligationsSwedish Bookkeeping Act (7 years)

4. Retention

Accounts: active period + 12 months after closure · Invoices: 7 years (Bookkeeping Act) · Support tickets: 2 years · Server logs: 90 days · Access logs: 30 days · Marketing: until consent is withdrawn · Domain registration data: registration period + 1 year.

5. Third parties

Domain registrars for registry submissions (e.g. IIS for .se), our payment provider, WHMCS (billing/account storage), and authorities where we are legally obliged.

6. International transfers

Data is stored primarily in Sweden. Domain registration data may be transferred to international registries (e.g. Verisign for .com) under GDPR Chapter V safeguards (standard contractual clauses).

7. Your rights

Access (Art 15), rectification (16), erasure (17), restriction (18), data portability (20), objection (21), and withdrawal of consent. We respond within 30 days — contact info@dotnetwork.se.

8. Security

TLS/HTTPS everywhere, bcrypt password hashing, role-restricted access, regular security reviews and automatic backups. In the event of a data breach we notify the supervisory authority within 72 hours, and affected customers where there is a high risk.

9. Complaints

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se.