Privacy

================================================================================
PRIVACY POLICY
================================================================================

Last Updated: July 10, 2026
Effective Date: July 10, 2026

This Privacy Policy explains how [Your Company Name] ("we", "us", "our")
collects, uses, processes, and protects your personal data when you use our
domain marketplace platform (the "Platform") at SellyDom.com.

We are committed to protecting your privacy and complying with the General
Data Protection Regulation (GDPR) and the German Federal Data Protection Act
(Bundesdatenschutzgesetz - BDSG).


§ 1 DATA CONTROLLER

The data controller responsible for the processing of your personal data is:

Noramedia
Leipziger Str. 33a
36037, Fulda
Germany

Email: info@noramedia.de

Data Protection Officer: info@noramedia.de


§ 2 SCOPE OF APPLICATION

This Privacy Policy applies to all users of our Platform, including:
- Visitors browsing domain listings
- Registered users (buyers and sellers)
- Domain owners listing domains for sale
- Bidders and purchasers

By using our Platform, you acknowledge that you have read and understood this
Privacy Policy and consent to the processing of your personal data as described
herein.


§ 3 TYPES OF DATA WE COLLECT

3.1 Data You Provide Directly

When you register, list domains, make offers, or use our services, we collect:
- Personal identification: Name, username, email address
- Contact information: Phone number, billing address
- Account credentials: Password (encrypted), security questions
- Payment information: Credit card details, PayPal email (processed by third-party providers)
- Domain information: Domain names, DNS records, ownership verification data
- Transaction data: Bids, offers, purchase history, escrow transactions
- Communication data: Messages exchanged through our platform chat system, support inquiries

3.2 Data Collected Automatically

When you access our Platform, we automatically collect:
- Technical data: IP address, browser type and version, operating system, device information
- Usage data: Pages visited, time spent on pages, click patterns, referral URLs
- Cookies and tracking data: Session cookies, preference cookies, analytics cookies
- Log files: Access times, error messages, download data

3.3 Third-Party Data

We may receive data about you from third-party services:
- Analytics data from Noralytic (visitor statistics, pageviews)
- Payment verification from Stripe and PayPal
- Domain ownership verification from DNS providers
- Social media data if you link accounts (optional)


§ 4 PURPOSE AND LEGAL BASIS FOR DATA PROCESSING

We process your personal data for the following purposes:

4.1 Contract Performance (Art. 6(1)(b) GDPR)
- Creating and managing user accounts
- Processing domain listings, bids, and sales
- Facilitating escrow services and secure transfers
- Executing payment transactions
- Providing customer support
- Enforcing our Terms and Conditions

4.2 Legal Obligations (Art. 6(1)(c) GDPR)
- Tax reporting and invoicing
- Anti-money laundering (AML) compliance
- Fraud prevention and security
- Responding to law enforcement requests
- Record-keeping as required by German commercial law

4.3 Legitimate Interests (Art. 6(1)(f) GDPR)
- Platform security and fraud detection
- Analytics and service improvement (via Noralytic)
- Marketing communications about platform features (opt-out available)
- Dispute resolution and legal claims

4.4 Consent (Art. 6(1)(a) GDPR)
- Marketing emails beyond transactional notifications (opt-in required)
- Optional cookies for enhanced user experience
- Sharing data with additional third parties not essential to service


§ 5 DATA SHARING AND DISCLOSURE

5.1 Service Providers (Data Processors)

We share your data with trusted third-party service providers who process data
on our behalf:

- Payment Processors: Stripe Inc., PayPal Holdings Inc.
Purpose: Processing payments, refunds, and escrow transactions
Data shared: Name, email, payment details, transaction amounts

- Analytics Provider: Noralytic
Purpose: Website traffic analysis, domain popularity metrics
Data shared: IP address (anonymized), pageviews, visitor behavior

- Real-Time Communication: Pusher (ws.norapush.com)
Purpose: Live bid updates, real-time chat notifications
Data shared: User IDs, message events (not message content)

- Email Service Provider: [Your SMTP Provider]
Purpose: Transactional emails (bid notifications, sale confirmations)
Data shared: Email address, name, transaction details

- Hosting Provider: [Your Hosting Company]
Purpose: Data storage, platform infrastructure
Data shared: All data stored on our servers

All data processors are contractually obligated to comply with GDPR through
Data Processing Agreements (DPAs).

5.2 Legal Requirements

We may disclose your data to:
- Law enforcement agencies in response to valid legal requests
- Tax authorities as required by law
- Courts and regulatory bodies in legal proceedings
- Government agencies for AML/KYC compliance

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be
transferred to the acquiring entity. You will be notified of any such change.

5.4 Domain Buyers and Sellers

When you engage in transactions:
- Sellers see: Bidder/buyer name, email (after sale confirmation)
- Buyers see: Seller name, email (for domain transfer)
- Public information: Domain name, listing price, sale status (not buyer identity)


§ 6 INTERNATIONAL DATA TRANSFERS

Your data is primarily stored on servers located within the European Economic
Area (EEA). However, some service providers may process data outside the EEA:

- Stripe (USA): Covered by EU-US Data Privacy Framework
- PayPal (USA): Covered by Standard Contractual Clauses (SCCs)
- Pusher (global): Data Processing Agreement with SCCs

We ensure all international transfers comply with GDPR Chapter V requirements
through appropriate safeguards.


§ 7 DATA RETENTION PERIODS

We retain your personal data only as long as necessary:

- Account data: Until account deletion + 30 days for backup deletion
- Transaction records: 10 years (as required by German tax law § 147 AO)
- Payment data: Stored by payment processors per PCI DSS standards (we do not store credit card details)
- Communication logs: 3 years for dispute resolution
- Analytics data: Aggregated and anonymized after 26 months
- Marketing consents: Until withdrawn + 3 years to prove compliance
- Log files: 30 days (unless required for security investigation)

After retention periods expire, data is securely deleted or anonymized.


§ 8 COOKIES AND TRACKING TECHNOLOGIES

8.1 Essential Cookies (No consent required)

- Session cookies: Maintain login state, shopping cart
- Security cookies: Prevent fraud, CSRF protection
- Load balancing: Distribute traffic across servers

8.2 Functional Cookies (Consent required)

- Language preference
- Display settings (dark mode, etc.)
- Chat history

8.3 Analytics Cookies (Consent required)

- Noralytic: Track visitor statistics, popular domains, user journeys
Cookie lifetime: 13 months
Anonymization: IP addresses masked

8.4 Marketing Cookies (Consent required)

- Advertising partners (if applicable): [List any ad networks]
- Retargeting pixels: [Facebook Pixel, Google Ads, etc.]

You can manage cookie preferences through our Cookie Consent Banner or browser
settings. Note that disabling essential cookies may affect platform functionality.


§ 9 YOUR RIGHTS UNDER GDPR

You have the following rights regarding your personal data:

9.1 Right of Access (Art. 15 GDPR)
Request a copy of all personal data we hold about you.

9.2 Right to Rectification (Art. 16 GDPR)
Correct inaccurate or incomplete data.

9.3 Right to Erasure (Art. 17 GDPR)
Request deletion of your data ("right to be forgotten"), subject to legal
retention requirements.

9.4 Right to Restriction (Art. 18 GDPR)
Limit processing of your data in certain circumstances.

9.5 Right to Data Portability (Art. 20 GDPR)
Receive your data in a machine-readable format (JSON/CSV) and transfer to
another service.

9.6 Right to Object (Art. 21 GDPR)
Object to processing based on legitimate interests or for marketing purposes.

9.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Withdraw consent for processing at any time (does not affect lawfulness of
processing before withdrawal).

9.8 Right to Lodge a Complaint (Art. 77 GDPR)
File a complaint with the German data protection authority:

Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Graurheindorfer Str. 153
53117 Bonn, Germany
Email: poststelle@bfdi.bund.de

To exercise your rights, contact us at privacy@[domain]. We will respond
within 30 days.


§ 10 SECURITY MEASURES

We implement appropriate technical and organizational measures to protect your
data:

10.1 Technical Measures
- SSL/TLS encryption (HTTPS) for all data transmission
- Database encryption at rest
- Secure password hashing (bcrypt algorithm)
- Regular security audits and penetration testing
- Firewall protection and DDoS mitigation
- Secure backup systems with encryption

10.2 Organizational Measures
- Access controls: Role-based permissions, need-to-know principle
- Employee training on data protection
- Data Processing Agreements with all processors
- Incident response plan for data breaches
- Regular GDPR compliance reviews

10.3 Data Breach Notification

In the event of a data breach affecting your rights and freedoms, we will
notify you within 72 hours as required by Art. 33 GDPR.


§ 11 CHILDREN'S PRIVACY

Our Platform is not intended for individuals under 18 years of age. We do not
knowingly collect data from minors. If we discover that a minor has provided
personal data, we will delete it immediately. Parents/guardians should contact
us at privacy@[domain] if they believe their child has provided data.


§ 12 AUTOMATED DECISION-MAKING AND PROFILING

12.1 Fraud Detection
We use automated systems to detect fraudulent transactions and suspicious
activity. This may result in account suspension or transaction rejection. You
have the right to contest such decisions and request human review.

12.2 Domain Recommendations
We may use algorithms to recommend domains based on your browsing history.
This does not produce legal effects and can be disabled in account settings.

12.3 Pricing Algorithms
Domain valuations may use automated assessment tools. Final pricing is
determined by sellers and market dynamics, not solely by automated systems.


§ 13 THIRD-PARTY LINKS

Our Platform may contain links to external websites (e.g., domain registrars,
DNS providers). We are not responsible for the privacy practices of third-party
sites. Please review their privacy policies before providing personal data.


§ 14 MARKETING COMMUNICATIONS

14.1 Transactional Emails (No opt-out)
- Account verification and password resets
- Bid notifications and sale confirmations
- Payment receipts and invoices
- Escrow status updates
- Important platform announcements

14.2 Marketing Emails (Opt-in/Opt-out)
- New feature announcements
- Domain listing tips and best practices
- Platform news and updates

You can unsubscribe from marketing emails via the link in each email or by
updating your account preferences. Transactional emails cannot be disabled as
they are essential to the service.


§ 15 CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect changes in our practices or legal
requirements. Material changes will be notified via:
- Email notification to registered users
- Prominent notice on the Platform homepage
- Pop-up notification upon next login

The "Last Updated" date at the top of this document indicates when the policy
was last revised. Continued use of the Platform after changes constitutes
acceptance of the updated policy.


§ 16 CONTACT INFORMATION

For questions, concerns, or to exercise your rights regarding data protection:

Data Protection Contact:
Email: info@noramedia.de
Postal Address: NoraMedia, Leipziger Str. 33a, 36037 Fulda, Germany

We aim to respond to all inquiries within 30 days as required by GDPR.


§ 17 APPLICABLE LAW

This Privacy Policy is governed by the laws of the Federal Republic of Germany
and the European Union's General Data Protection Regulation (GDPR).

Jurisdiction: [Your Jurisdiction, e.g., Berlin, Germany]


================================================================================
IMPORTANT NOTICES
================================================================================

1. GDPR COMPLIANCE: This policy complies with Regulation (EU) 2016/679 (GDPR)
and the German Federal Data Protection Act (BDSG).

2. LEGAL BASIS: All data processing activities have a valid legal basis under
Art. 6 GDPR (consent, contract, legal obligation, legitimate interest).

3. DATA MINIMIZATION: We collect only data necessary for providing our services
(Art. 5(1)(c) GDPR).

4. TRANSPARENCY: This policy provides clear information about all processing
activities as required by Art. 13/14 GDPR.

5. USER RIGHTS: All GDPR rights (access, rectification, erasure, portability,
objection) are fully implemented.

6. DPO REQUIREMENT: If your company processes data on a large scale, you must
appoint a Data Protection Officer (Art. 37 GDPR).

7. COOKIE CONSENT: Obtain explicit consent for non-essential cookies via a
GDPR-compliant Cookie Consent Banner.

8. DATA BREACH: Implement procedures to detect, report, and investigate data
breaches within 72 hours (Art. 33 GDPR).

9. PLACEHOLDERS: Replace all bracketed placeholders [Company Name], [domain],
[Address], etc. before publication.

10. LEGAL REVIEW: Have this policy reviewed by a data protection lawyer or
specialist before making it legally binding.


================================================================================
END OF PRIVACY POLICY
================================================================================