Privacy Policy
1. Introduction
Welcome to DomainsIntel.com. This Privacy Policy explains how MOJO Innovations Limited ("we", "us", "our") collects, uses, shares, and protects personal data in relation to our website DomainsIntel.com and our domain intelligence and brand protection services (collectively, the "Service").
It covers three groups of people: our customers and the individuals who work for them; individuals whose personal data appears in the domain registration records, websites and other public sources we analyse; and business contacts we approach about our services.
Data Controller:
MOJO Innovations Limited
CRO No. 814011
18 Mallow Street Upper, Limerick, V94 N12Y, Ireland
Contact Email: privacy@domainsintel.com
2. Our Role
For most of our processing, including the operation of our detection platform, we act as a data controller. We determine what data to collect, how it is analysed, what evidence is captured, and how long it is retained.
Where a customer supplies us with a specific dataset and instructs us to process it on their behalf, we act as a processor for that activity, and separate terms apply. Our role is assessed activity by activity rather than across the Service as a whole.
3. Information We Collect
A. Information Customers Provide to Us Directly
- Account Information: name, email address, password, company name, and job title.
- Payment Information: processed by our payment provider (Stripe). We do not store full payment card details.
- Authorisation and Rights Information: where your plan includes takedown services, your signed Letter of Authority, the name and title of the signatory, your company details, and trademark or other rights information you provide.
- Communications: the contents of messages you send us and any information you choose to include.
B. Information We Collect Automatically
- Usage Data: IP address, browser type, operating system, device information, pages viewed, features used, and dates and times of visits.
- Cookies and Similar Technologies: see section 10.
C. Information We Obtain from Public and Third-Party Sources
Our detection platform analyses data obtained from public and third-party sources rather than from the individuals concerned. This includes:
- domain registration data from RDAP and WHOIS services, and from registry zone files;
- DNS records and technical infrastructure information, including hosting, nameserver and network data;
- publicly accessible website content, including rendered pages, images and page source;
- contact and business information appearing on those websites;
- threat indicators, classifications and scores that we generate from the above.
Some of this information may constitute personal data, for example the name or contact details of a domain registrant, or contact details published on a website we capture as evidence.
Source of the data: public domain registration systems, DNS, publicly accessible websites, and commercial or open threat intelligence sources.
Purpose and legal basis: we process this data on the basis of our legitimate interests in detecting and preventing online fraud, phishing, brand impersonation and intellectual property abuse, and in protecting businesses and internet users from harm. We consider this processing proportionate given the public nature of the sources, the limited categories of data involved, and the fraud prevention purpose.
Because of the scale of the data we process and the nature of the public sources from which it is obtained, providing this information individually to every person concerned would involve disproportionate effort. We therefore make this information publicly available in accordance with Article 14(5)(b) GDPR and take appropriate measures to protect individuals' rights and interests.
D. Business Contact Information
We obtain business contact information, such as name, role, company and business contact details, from publicly available sources and third-party business information providers, in order to contact organisations that may benefit from our services. See section 4 for the legal basis and your right to object.
4. How We Use Personal Data and Our Legal Bases
Providing and administering the Service to customers
To create and manage accounts, provide support, process payments, and deliver monitoring, alerts and reporting.
Legal basis: performance of a contract with you, or our legitimate interests in administering our relationship with the organisation you represent.
Detecting and analysing threats
To identify, classify, score and evidence domains and websites that may impersonate or infringe a brand.
Legal basis: our legitimate interests, and those of the brands and internet users affected, in detecting and preventing fraud, phishing, impersonation and intellectual property abuse.
Takedown and enforcement services
To prepare, submit and pursue abuse reports, complaints and takedown requests to third parties on behalf of customers whose plans include these services.
Legal basis: our legitimate interests and those of our customers in preventing fraud and protecting brand and consumer trust, and where applicable the establishment, exercise or defence of legal claims.
Improving and securing the Service
To understand how the Service is used, develop features, and monitor for security threats and abuse.
Legal basis: our legitimate interests.
Business development and marketing
We may process business contact information to communicate with organisations about our services, on the basis of our legitimate interests, where permitted by applicable law. Where consent is required for a particular marketing communication, we rely on consent.
You have the right to object to direct marketing at any time. If you no longer wish to receive communications from us, reply to any message asking to be removed, or contact privacy@domainsintel.com, and we will stop and record your objection.
Complying with legal obligations
To meet accounting, tax and other legal requirements.
Legal basis: compliance with a legal obligation.
5. How We Share Personal Data
We do not sell personal data.
A. Service Providers and Other Recipients
We use third parties who process information on our behalf, or for their own specified purposes as applicable:
- Payment processing: Stripe.
- Cloud hosting and infrastructure: Amazon Web Services.
- Email, communication and productivity tools: including Google Workspace.
- Analytics: Google Analytics, subject to your cookie consent.
- Email delivery providers, used to send account, alert, report and other emails on our behalf.
- Sales and marketing tools and business contact data providers, used for the business development activity described in sections 3D and 4.
- AI and machine-learning service providers, which process the publicly accessible website content described in section 3C to support automated threat classification.
- Enforcement operations personnel: individuals and contractors engaged by us to prepare, submit and pursue abuse reports and takedown requests. Such personnel act only on our instructions, are bound by confidentiality obligations, and may be located outside the European Economic Area.
Some of these providers are located outside the European Economic Area (see section 6). Individuals may request further information about the recipients of their personal data by contacting privacy@domainsintel.com.
B. Third Parties in the Course of Takedown Services
Where a customer's plan includes takedown services, we disclose information to the third parties we contact in order to pursue a complaint. This may include domain registrars, registries, hosting providers, content delivery networks, e-commerce and payment platforms, and browser and reputation services, which may be located anywhere in the world. The information disclosed typically includes the customer's company name and brand, their rights or trademark information, their Letter of Authority, and evidence relating to the domain or website concerned. We disclose only what is necessary to make an effective complaint.
C. Legal Requirements
We may disclose personal data where required by law, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, protect our rights, or prevent fraud.
6. International Data Transfers
Personal data may be transferred to and processed in countries outside the European Economic Area, including the United States and India. Where personal data is transferred outside the EEA, we use an applicable lawful transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, where required.
Separately, where we submit complaints on a customer's behalf as described in section 5B, those complaints are sent to service providers who may be located in any country.
7. Data Security
We implement technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access controls, multi-factor authentication on administrative accounts, and periodic review of our security arrangements. No method of transmission over the Internet is completely secure.
8. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy.
- Account and customer records: for as long as the account is active and for a reasonable period thereafter.
- Billing and accounting records: as required by applicable tax and company law.
- Detection and threat data: for as long as it remains relevant to monitoring, and thereafter in accordance with our retention schedule.
- Evidence and case records created in the course of takedown activity: for the purposes of the case and any related dispute, for a period of up to seven years from the date the case is closed, reflecting the possibility of later challenge by a domain owner or other third party.
- Objection and suppression records: for as long as necessary to ensure we continue to respect your objection.
You may request deletion of your personal data at any time, subject to our need to retain records required by law or for the establishment, exercise or defence of legal claims.
9. Your Data Protection Rights
Where the GDPR applies to the processing of your personal data, you have the following rights:
- Access: to obtain a copy of your personal data.
- Rectification: to have inaccurate data corrected or incomplete data completed.
- Erasure: to have your data deleted, in certain circumstances.
- Restriction: to have processing restricted, in certain circumstances.
- Objection: to object to processing carried out on the basis of legitimate interests, on grounds relating to your particular situation. You may object to direct marketing at any time, and we will stop.
- Portability: to receive certain data in a portable format, in certain circumstances.
- Withdrawal of consent: where we rely on consent, to withdraw it at any time.
To exercise any of these rights, contact privacy@domainsintel.com. You also have the right to lodge a complaint with a supervisory authority. In Ireland, this is the Data Protection Commission (dataprotection.ie).
Where we act as a processor on a customer's behalf, requests should be directed to that customer as controller, and we will assist them in responding.
10. Cookies
Cookies are small text files stored on your device. We use them for:
- Strictly necessary purposes: to operate the Service, such as keeping you signed in.
- Performance and analytics: to understand how the Service is used, with your consent.
- Marketing: where applicable, with your consent.
Non-essential cookies, including analytics, are set only after you consent through our cookie banner. You can change your preferences at any time using the Cookie Preferences link in the footer of our homepage.
11. Children's Privacy
Our Service is directed at businesses and is not intended for individuals under the age of 16. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version on this page and, where changes are material, notify customers by email or other appropriate means.
13. Contact Us
Questions about this Policy, or requests to exercise your rights, should be sent to privacy@domainsintel.com.
MOJO Innovations Limited
CRO No. 814011
18 Mallow Street Upper, Limerick, V94 N12Y, Ireland