Legal
Privacy Policy
Airfree Clouds Pty Ltd (ACN: 000 000 000) — Effective 1 July 2025
1. Overview
Airfree Clouds Pty Ltd (“Airfree Clouds”, “we”, “us”, or “our”) is an authorised licensee of Airfree Services Pty Ltd and operates the domain registration, business email, and workspace platform available at airfreeclouds.com. We are committed to processing personal data lawfully, fairly, and transparently.
We do not sell personal data, run advertising networks, or share your information with third parties for marketing purposes. This policy explains what we collect, why we collect it, how long we keep it, and what rights you have over it.
If you are located in the European Economic Area or the United Kingdom, Airfree Clouds is the data controller for the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR respectively.
2. Data we collect
2.1 Account data
When you create an account we collect your full name, email address, a hashed password, and your preferred language and time zone. If you add two-factor authentication we store only the encrypted TOTP seed — we never store recovery codes or backup numbers in plaintext.
2.2 Domain registration data
ICANN policy requires us to collect registrant contact information (name, postal address, telephone number, email address) for every domain registration. This data is submitted to the relevant registry operator. Where WHOIS privacy is active, proxy contact details replace your personal details in public WHOIS databases; your underlying registrant data is retained internally and disclosed only as required by ICANN dispute-resolution procedures.
2.3 Payment data
We use Stripe, Inc. as our payment processor. Airfree Clouds never stores full card numbers, CVV codes, or bank account details. When you pay, your card details are submitted directly to Stripe's PCI-DSS-compliant vault. We retain only the last four digits of the card, expiry month and year, card brand, and the Stripe payment method token to facilitate renewals and refunds.
2.4 Usage and log data
Our servers automatically record IP addresses, browser user-agent strings, HTTP request paths, response status codes, and timestamps. These logs are used solely for security monitoring, abuse prevention, and diagnosing platform issues. We self-host our analytics and do not transmit raw log data to third parties.
3. How we use your data
- Providing, operating, and improving the Airfree Clouds platform
- Processing domain registrations and transfers with registry operators
- Billing, invoicing, and fraud prevention
- Sending transactional emails (renewal reminders, security alerts, receipts)
- Responding to support requests and account queries
- Meeting legal obligations including ICANN policy, tax law, and court orders
- Detecting and preventing abuse, spam, phishing, and other policy violations
We do not use personal data to train machine-learning models, build advertising profiles, or infer sensitive characteristics about individuals.
4. Legal basis under GDPR (Article 6)
| Processing activity | Lawful basis |
|---|---|
| Account creation and management | Art. 6(1)(b) — performance of a contract |
| Domain registration data submitted to registries | Art. 6(1)(c) — compliance with a legal obligation (ICANN) |
| Payment processing | Art. 6(1)(b) — performance of a contract |
| Security logging and fraud detection | Art. 6(1)(f) — legitimate interests |
| Transactional email (renewal, security alerts) | Art. 6(1)(b) — performance of a contract |
| Marketing email (product updates, promotions) | Art. 6(1)(a) — consent (opt-in only) |
| Compliance with tax and court orders | Art. 6(1)(c) — compliance with a legal obligation |
5. Data sharing
We share personal data with a small number of third parties, strictly as necessary:
- Registry operators and ICANN-accredited bodies: registrant contact data is transmitted to the relevant top-level domain registry (for example, Verisign for .com, AFILIAS for .info) as required by ICANN policy. These operators act as independent data controllers.
- Stripe, Inc.: payment card data is processed directly by Stripe under their Privacy Policy and PCI-DSS compliance program. We do not share additional personal data with Stripe beyond what is required to process a transaction.
- Legal disclosure: we may disclose personal data where required by applicable law, a valid court order, or as required by ICANN's Registration Data Request Policy.
We do not share personal data with advertising networks, data brokers, analytics platforms, or any third party for commercial gain.
6. Data residency
By default, personal data for all customers is stored within the European Union (Frankfurt, Germany). Customers who select Australian billing addresses or explicitly opt for AU hosting during sign-up have their data stored in Australia (Sydney, New South Wales).
When data is transferred outside your selected region — for example, when registry operators process domain registration data — we rely on the EU Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms approved under applicable data protection law.
7. Retention periods
| Data category | Retention period |
|---|---|
| Account profile data | Duration of the account, plus 30 days after deletion request |
| Domain registrant data (active domain) | Duration of the registration plus any applicable ICANN escrow period |
| Domain registrant data (expired / transferred domain) | 2 years post-expiry, as required by ICANN consensus policy |
| Payment records and invoices | 7 years (Australian tax law requirement) |
| Server access logs | 90 days, then automatically deleted |
| Support tickets | 3 years from ticket closure |
| Marketing consent records | Until consent is withdrawn, plus 3 years |
8. Your rights under GDPR (Articles 15–22)
If you are located in the EEA or UK, you have the following rights regarding your personal data:
- Access (Art. 15): request a copy of the personal data we hold about you and information about how we process it.
- Rectification (Art. 16): ask us to correct inaccurate or incomplete personal data.
- Erasure (Art. 17): request deletion of your personal data where there is no compelling reason for us to continue processing it. Note that domain registrant data may be subject to mandatory ICANN retention obligations.
- Restriction of processing (Art. 18): ask us to restrict processing of your data in certain circumstances, for example while a complaint is investigated.
- Data portability (Art. 20): receive your personal data in a structured, machine-readable format and transmit it to another controller.
- Objection (Art. 21): object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Automated decision-making (Art. 22): we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, email privacy@airfreeclouds.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (in the EU: your national DPA; in the UK: the ICO).
9. Cookies
Airfree Clouds uses session cookies and strictly functional cookies only. We do not deploy tracking pixels, third-party advertising cookies, or behavioural analytics cookies. Our analytics are self-hosted and do not involve transmission of personal data to external analytics vendors. For a full list of cookies we set, see our Cookie Policy.
10. Contact and Data Protection Officer
For privacy enquiries, data subject requests, or to raise a concern, contact our Data Protection Officer:
Data Protection OfficerAirfree Clouds Pty Ltd
privacy@airfreeclouds.com
Changes to this policy will be published on this page with an updated effective date. Material changes will also be communicated by email to registered account holders at least 30 days before taking effect.