Legal information
Privacy policy
Last updated: 3 October 2026
This document is a translation provided for convenience. Only the French version is legally binding.
This policy explains what personal data NODYNA collects when you use the nodyna.com website and its services, for what reasons, how long it is kept and how to exercise your rights. It has been drawn up in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and French Law No. 78-17 of 6 January 1978, known as the “Informatique et Libertés” Act (French Data Protection Act).
In short: we only collect what is necessary to provide our services, we do not sell your data, and we use neither advertising nor audience measurement tools.
1. Data controller
The controller of the processing described in this policy is 2BWEB (Entreprise individuelle), which operates the NODYNA brand (hereinafter “NODYNA” or “we”).
For any question about your personal data, or to exercise your rights, write to us at contact@nodyna.com.
2. Data collected
We only collect the data necessary for the purposes described in this policy, directly from you or when you use the website:
- Customer account: surname, first name, email address and password (stored only in hashed form); if you provide them, telephone number, postal address, company name and intra-Community VAT number.
- Orders and billing: services ordered and their configuration (system, location, hostname), amounts, payment method used, invoices, Stripe payment and subscription references; for a bank transfer, the information shown on the transfer order (name of the payer, reference).
- Your services: technical information about your services (assigned IP addresses, access credentials, activation and expiry dates).
- Technical data: IP address and browser used (user agent) when you log in, security logs (logins, sensitive actions on your account) and the history of the service emails sent to you.
- Correspondence: messages sent via the contact form (name, email, company, subject, message and IP address) or via support tickets.
- Offers on premium domains: name, email, telephone (optional), amount offered, message and IP address.
- Domain names: identity and contact details of the holder required by the registry (name, organisation, postal address, email, telephone), passed on to registries and registrars. Depending on the rules of each registry, some of this data may be published in WHOIS or RDAP directories; your personal contact details are masked there whenever the registry allows it.
Some of this information is essential: without it, we cannot create your account, process your order or respond to your request. Our services are reserved for adults.
This policy does not cover the data you host on your own servers: you are the controller of that data, and NODYNA acts as a processor for it, under the conditions laid down in the general terms and conditions of sale.
3. Purposes and legal bases
Each of our processing operations is based on one of the legal bases provided for in Article 6 of the GDPR.
Performance of the contract and pre-contractual measures (Article 6(1)(b))
- creating and managing your customer account;
- processing your orders and payments, and activating, managing and renewing your services;
- registering, renewing and transferring your domain names with registries and registrars;
- selling or leasing premium domains, and processing your purchase offers;
- technical support and replies to your messages;
- sending service emails: order confirmation, service activation, billing, security, due dates.
Compliance with our legal obligations (Article 6(1)(c))
- issuing and keeping invoices and accounting records;
- handling reports of illegal content and responding to requests from authorised authorities.
Legitimate interest (Article 6(1)(f))
- security of the website, our infrastructure and your account: login logs, detection of suspicious access, abuse prevention;
- fraud prevention, in particular payment fraud;
- handling complaints, debt recovery and disputes;
- responding to contact requests from people who are not customers.
Consent
None of our processing is currently based on your consent: we use neither advertising cookies nor audience measurement tools, and we do not send you any direct marketing. Should we one day wish to send you a newsletter or commercial offers, we would first obtain your consent, which you could withdraw at any time.
Your data is never sold or rented out, and is not used for advertising purposes. No decision producing legal effects concerning you is taken solely on the basis of automated processing.
4. Retention periods
Your data is kept for no longer than is strictly necessary for the purposes pursued:
- Customer account: for the entire duration of the contractual relationship, then 3 years from the end of the last service or, for an account without any service, from its last activity.
- Invoices and accounting records: 10 years from the end of the financial year concerned (Article L123-22 of the French Commercial Code [Code de commerce]).
- Login and security logs: 12 months.
- Contact messages, support tickets and offers on premium domains: 3 years from the last exchange.
- Domain name registration data: for the duration of the registration, then in accordance with the rules of the registries and registrars.
At the end of these periods, the data is deleted or anonymised. It may be kept longer where required by law, or archived with restricted access for the establishment, exercise or defence of our legal claims, for the applicable limitation period.
5. Recipients and processors
Your data is accessible only to authorised NODYNA personnel. It is disclosed only to the following recipients, to the extent necessary for them:
- OVHcloud (OVH SAS, Roubaix, France): hosting of the website and its databases, in France;
- Stripe (Stripe Payments Europe, Ltd., Ireland): card payments and subscription management. Your bank card details are entered directly on Stripe's secure page and never pass through our servers. For certain processing, such as fraud prevention, Stripe acts as an independent controller;
- Domain name registries and registrars (for example AFNIC for .fr or EURid for .eu, and our partner registrars): registration, renewal and transfer of your domain names;
- Server infrastructure providers: OVHcloud (France) and Hetzner Online GmbH (Germany, data centres in Germany and Finland), depending on the location chosen when ordering, for the delivery and operation of your servers;
- Administrative or judicial authorities, only where required by law.
Our processors are contractually bound to process your data only on our instructions and to guarantee its security and confidentiality (Article 28 of the GDPR).
6. Transfers outside the European Union
Your data is hosted within the European Union. However, some recipients may process it outside the Union:
- Stripe may process certain data in the United States. These transfers are governed by the EU–US Data Privacy Framework, which Stripe, Inc. has joined, and by the standard contractual clauses adopted by the European Commission;
- for certain extensions (for example .dev, .io or .ai), the registry is established outside the European Union, and the same may apply to some partner registrars. The transfer of your data is then necessary for the performance of the registration contract you have requested (Article 49(1)(b) of the GDPR).
7. Cookies
The website only uses cookies that are strictly necessary for it to function. In accordance with Article 82 of the French Data Protection Act, they do not require your consent: this is why no cookie banner is shown to you.
| Cookie | Purpose | Duration |
|---|---|---|
| ndy_session | Keeps you logged in to the customer area. Contains a random session identifier, deleted when you log out. | 30 days |
| ndy_cart | Keeps the contents of your cart between visits. Its contents are signed to prevent any tampering. | 30 days |
| ndy_locale | Remembers the language in which you browse the website. | 1 year |
These cookies are specific to nodyna.com and cannot be accessed by page scripts; they do not allow any tracking of your browsing on other websites. No advertising, audience measurement or social media cookies are used.
When you pay by card, you are redirected to Stripe's payment page, which may set its own cookies, necessary for payment and fraud prevention; these are governed by Stripe's privacy policy.
You can delete or block cookies in your browser settings; logging in to the customer area and the cart will then no longer work.
8. Security
We implement appropriate technical and organisational measures to protect your data:
- HTTPS encryption of all exchanges with the website;
- account passwords hashed with the scrypt algorithm: we can neither read nor recover them;
- server passwords and domain name transfer codes encrypted with AES-256-GCM; passwords are never sent by email;
- sessions protected by random tokens, which we only store in hashed form;
- access to data limited to authorised persons, and logging of sensitive actions.
In the event of a data breach, we would notify the CNIL (the French data protection authority) where required by law and, if the breach presented a high risk to your rights and freedoms, we would inform you as soon as possible (Articles 33 and 34 of the GDPR).
9. Your rights
You have the following rights over your personal data:
- Access: to know whether we process your data and to obtain a copy of it.
- Rectification: to have inaccurate or incomplete data corrected; most of it can be changed directly from your customer area.
- Erasure: to have your data deleted, except for data we are required to keep, such as invoices.
- Restriction: to have the use of your data temporarily frozen, for example while its accuracy is being checked.
- Objection: to object, on grounds relating to your particular situation, to processing based on our legitimate interest.
- Portability: to receive the data you have provided to us in a structured, commonly used format, or to have it transmitted to another organisation.
- Post-mortem instructions: to set instructions regarding what happens to your data after your death (Article 85 of the French Data Protection Act).
To exercise these rights, write to contact@nodyna.com, preferably from the address associated with your account. If we have reasonable doubts about your identity, we may ask you for additional information. Exercising your rights is free of charge.
We will reply within one month of receiving your request. This period may be extended by two months owing to the complexity or number of requests; we would then inform you within the first month.
10. Complaints to the CNIL
If you believe that the processing of your data does not comply with the regulations, you may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), the French data protection authority, at www.cnil.fr, or with the supervisory authority of the European Union Member State in which you reside. Feel free to write to us first: we will do our best to respond to your request.
11. Changes to this policy
We may update this policy to reflect changes in our services or in the regulations. The date of the last update appears at the top of this page; in the event of a significant change, we will inform you by email or by a message on the website.