Loading…
Last updated: 2026-05-20
This Data Processing Addendum ("Addendum" / "DPA") between Name AI LLC ("Name.ai") and the Customer (as defined in the Terms of Service) forms part of the Name AI LLC Terms of Service at https://name.ai/legal/terms, or such other written or electronic agreement incorporating this Addendum, governing Customer's access to and use of the Services. Customer enters into this Addendum on behalf of itself and any Affiliates authorised to use the Services under the Agreement who have not entered into a separate contractual arrangement with Name.ai.
legal.dpaPage.dpo.withDpo Data Protection Officer. legal.dpaPage.dpo.contact [email protected].
In this Addendum, the following terms have the meanings set out below:
This Addendum applies to Name.ai's processing of Customer Personal Data under the Agreement to the extent such processing is subject to Data Protection Laws. Name.ai processes personal data to operate a domain name marketplace — including account management, domain listing, offer negotiation, payment processing, and domain transfer facilitation.
The parties acknowledge and agree that with regard to the processing of Customer Personal Data, Customer acts as a Business or Controller, and Name.ai acts as a Service Provider or Processor. Customer is solely responsible for ensuring timely communications to its Affiliates or relevant Controllers as required by applicable Data Protection Laws. Customer is solely responsible for complying with security incident notification laws applicable to Customer.
Name.ai shall comply with all applicable Data Protection Laws and shall:
Name.ai engages the following sub-processors. Customer hereby agrees that Name.ai is generally authorised to engage and appoint sub-processors, subject to the notification obligations described above. Each sub-processor is bound by a data processing agreement consistent with applicable law.
| legal.dpaPage.subProcessorTable.subProcessor | legal.dpaPage.subProcessorTable.location | legal.dpaPage.subProcessorTable.purpose |
|---|---|---|
| Stripe, Inc. | United States | Payment processing, stored payment methods, transaction records |
| Supabase, Inc. | United States | PostgreSQL database hosting — stores user accounts, domain data, transaction history |
| Google LLC | United States | OAuth 2.0 authentication; transactional email delivery via Gmail SMTP |
| PostHog, Inc. | United States/EU | Product analytics, feature flags, user behaviour tracking (analytics cookies only, with consent) |
| Twilio Inc. | United States | SMS and OTP delivery for account verification and notifications |
| ResellerClub (Newfold Digital) | India | Domain registration, transfer, and DNS management via RTR API |
Where the transfer of Customer Personal Data from Customer to Name.ai is a Restricted Transfer and EU Area Law applies, the transfer shall be subject to the appropriate Controller to Processor SCCs, incorporated into and forming part of this Addendum:
Where a Transfer Mechanism is insufficient to safeguard transferred Personal Data, Name.ai will promptly implement supplementary measures to ensure Personal Data is protected to the standard required under applicable Data Protection Laws.
Name.ai implements and maintains the following technical and organisational security measures:
In the event of a Security Incident affecting Customer Personal Data, Name.ai will notify Customer without undue delay. Notification will include, to the extent reasonably available: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences of the breach, and measures taken or proposed to address the breach. Name.ai shall take all necessary measures to remedy or mitigate the effects of the Security Incident and keep Customer informed of developments.
Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, or denial-of-service attacks.
Personal data is retained only as long as necessary for the purposes described. Customer-collected data is stored in the database while Customer is active. Once a customer is offboarded, data will be retained for five weeks in active storage and then archived for one year in cross-region backup, after which it is deleted securely to prevent unauthorised access or recovery. On account deletion, PII fields are replaced with a redaction token within 90 days; financial fields are preserved in anonymised form for up to 10 years as required by law. Sub-processors are required to delete or return Customer Personal Data upon termination of their engagement.
Your rights regarding your personal data (access, rectification, erasure, restriction, portability, objection, and right to withdraw consent) are described in the Privacy Policy at https://name.ai/legal/privacy. To exercise these rights, contact the Data Protection Officer using the details above. Name.ai will assist Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of Customer's obligation to respond to requests for exercising data subject rights.
The parties warrant that they and any staff and/or sub-contractors will comply with their respective obligations under applicable Data Protection Laws for the term of this Addendum.
To the extent permissible by law, Customer shall defend Name.ai and its Affiliates from and against any claims, demands, suits, or proceedings made or brought against any of them by any third party, and indemnify and hold them harmless from all losses, damages, liabilities, fines, penalties, settlements, and costs arising from any breach by Customer of this Addendum or of its obligations under applicable Data Protection Laws.
This DPA is governed by the laws of the State of Wyoming, United States. Where applicable, Name.ai also complies with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and India's IT (SPDI) Rules 2011. In the event of any inconsistency between the provisions of this Addendum and the Agreement, they will take priority in this order: (a) Standard Contractual Clauses or other approved cross-border transfer mechanisms; (b) this Addendum; (c) the Agreement.
This Annex includes details of the processing of Customer Personal Data by Name.ai in connection with the Services.
| Dynadot LLC |
| United States |
| Domain registration, transfer, and DNS management |
| Cloudflare, Inc. | United States | Content delivery network, DNS, DDoS protection, SSL termination |
| Amazon Web Services (AWS) | United States/EU | Cloud infrastructure, server hosting, multi-AZ resiliency, disaster recovery |