Privacy Policy

Your Privacy Matters - Comprehensive Data Protection for .coliving Domain Services

Last Revised: September 29, 2025

GDPR Compliant US Privacy Laws Swiss FADP

Welcome to .coliving Privacy Protection

Welcome to the .coliving website, operated by .coliving™, located at P.O. Box 310121, New Braunfels, Texas 78131, and powered by Freename AG, Samstagernstrasse 41, Wollerau, Switzerland ("We," "Us," "Our").

We're committed to protecting your privacy when you use our Platform to register and manage .coliving Web3 domain names. This Privacy Policy explains how we collect, use, and protect your personal data.

Compliance Notice: This policy complies with the Swiss Federal Act on Data Protection (FADP), US privacy laws, and where applicable, the EU General Data Protection Regulation (GDPR) and UK GDPR.

1. Who We Are

Primary Data Controller

.coliving

P.O. Box 310121

New Braunfels, Texas 78131

Technology Partner

Freename AG

Samstagernstrasse 41

Wollerau, Switzerland

Shared Responsibility: If we share responsibility for your data with others, we'll let you know in accordance with applicable data protection laws.

2. What Data We Collect and Why

Types of Data We Collect

We collect only the personal data needed to provide and improve our .coliving domain services, such as:

Contact Information

  • • Name and email address
  • • Physical address
  • • Phone number

When you sign up or buy a .coliving™ domain

Account Information

  • • Username and password
  • • Wallet details
  • • Domain preferences

For managing your domain account

Usage Data

  • • Browser and device info
  • • IP address
  • • Pages visited

Analytics and security monitoring

Content Data

  • • Contact form messages
  • • Support requests
  • • Communication preferences

Customer service and support

Location Data

  • • General location
  • • Country/region
  • • Time zone

Based on your IP address

Why We Collect Your Data

Register and manage your .coliving domain
Process payments and royalties
Send you important updates (e.g., renewal reminders)
Improve our Platform's security and user experience
Comply with legal requirements (e.g., Registry policies)
Web 3.0 typography with on anstract futuristic tech wireframe background. Metaverse, future decentralized internet and new creative economy concept. 3D illustration

How We Get Your Data

From You

When you sign up, buy a domain, or contact us via email, forms, or social media.

Automatically

Through cookies, server logs, or analytics when you use our Platform.

From Others

From third parties (e.g., Registries) or public sources, if legally allowed.

3. Legal Basis for Using Your Data

We process your data based on the following legal foundations under US and international law:

Your Consent

When you provide explicit consent (US state laws, GDPR) for marketing, cookies, or optional services.

Business Necessity/Contract

To provide .coliving domain services, process payments, and fulfill our contractual obligations to you.

Legal Compliance

To meet US federal/state requirements, domain registry obligations, tax laws, and anti-money laundering regulations.

Legitimate Business Interests

For fraud prevention, security, customer service, and business operations, balanced against your privacy rights under applicable US and international laws.

4. How Long We Keep Your Data

Data Retention Policy

We keep your data only as long as needed for the purpose (e.g., managing your domain) or as required by law.

When no longer needed, we delete or anonymize it in accordance with our data retention schedule and applicable legal requirements.

5. Sharing Your Data

We may share your data with the following parties, always with appropriate safeguards:

Service Providers

Trusted partners who help us run the Platform:

  • • Web hosting services
  • • Payment processors (Stripe, Coinbase Commerce)
  • • Email services
  • • Analytics providers

Registries

To register Web2 domains, your data may go to:

  • • Registries like Nominet or Verisign
  • • WHOIS database (public)
  • • Domain management systems

Legal Authorities

When required by law or to protect our rights:

  • • Court orders
  • • Law enforcement requests
  • • Regulatory compliance

International Data Transfers

US-Based Operations: As a Texas-based entity, our primary data processing occurs within the United States under US privacy law protections.

International Partners: Some partners are in Switzerland, the UK, or the European Economic Area (EEA). We ensure appropriate safeguards through:

  • • Standard Contractual Clauses (SCCs) approved by US and EU authorities
  • • Adequacy decisions where available
  • • US-EU Data Privacy Framework compliance
  • • Swiss-US Data Privacy Framework protections
  • • Binding Corporate Rules for enterprise partners

Your Rights: International transfers don't diminish your privacy rights under applicable US state laws or international regulations.

6. Your Data Protection Rights

Your Rights Under US, Swiss, UK, and EU Laws

You have comprehensive rights under applicable data protection laws, including US state privacy laws (California CCPA/CPRA, Texas, Virginia, Colorado), Swiss FADP, and where applicable, GDPR/UK GDPR:

Access & Know

See what personal data we have about you and how we use it (US/GDPR right)

Correction

Fix inaccurate personal information (Universal right)

Deletion

Request deletion of your personal data (California "Right to Delete" & GDPR)

Opt-Out of Sale

Opt out of personal data "sales" or sharing (California CCPA/CPRA)

Portability

Get your data in a usable format (GDPR & some US state laws)

Non-Discrimination

No discrimination for exercising privacy rights (US state laws)

Limit Use & Disclosure

Limit use of sensitive personal information (California CPRA)

Authorized Agent

Designate someone to exercise rights on your behalf (US laws)

Exercise Your Rights

To exercise these rights under US or international law, contact us at:

Verification Required: We may need to verify your identity before processing requests to protect your privacy.

Regulatory Authorities

You can also contact relevant authorities:

California: California Attorney General's Office

Texas: Texas Attorney General's Office

UK: Information Commissioner's Office (ICO)

Switzerland: Federal Data Protection Commissioner (FDPIC)

EU: Your local data protection authority

7. Data Security

Strong Security Measures

We implement comprehensive security measures following US federal standards (NIST Cybersecurity Framework) and international best practices to protect your data from unauthorized access, disclosure, alteration, or destruction.

Technical Safeguards (US NIST Standards)

  • • HTTPS/TLS 1.3 encryption
  • • SOC 2 compliant data centers
  • • Multi-factor authentication
  • • Regular security updates and patches
  • • Intrusion detection and monitoring
  • • Data encryption at rest and in transit

Administrative Safeguards (US Compliance)

  • • Background checks for personnel
  • • Regular security training and awareness
  • • Incident response procedures (NIST guidelines)
  • • Data minimization and retention policies
  • • Third-party security assessments
  • • Business continuity planning

Security Limitations: While we implement industry-leading security measures, no online system is 100% secure. Internet communications may be subject to monitoring by government authorities under applicable US federal and state laws, which is beyond our control.

Web 3.0 typography with on anstract futuristic tech wireframe background. Metaverse, future decentralized internet and new creative economy concept. 3D illustration

8. Cookies and Tracking

Cookies

We use cookies (small data files stored in your browser) to enhance your experience and improve our services:

Essential Cookies

Make our Platform work properly:

  • • Session cookies for login
  • • Security tokens
  • • User preferences

Analytics Cookies

Help us understand usage:

  • • Google Analytics
  • • Page view tracking
  • • Performance metrics

Marketing Cookies

Show relevant content:

  • • Personalized ads
  • • Campaign tracking
  • • Social media pixels

Cookie Control: You can manage cookies in your browser settings or opt out via tools like YourAdChoices or Network Advertising Initiative.

Server Logs

We collect data like your IP address, browser type, and pages visited to improve security and performance. This data is stored in server logs and used for system administration and security monitoring.

Google Analytics

We use Google Analytics to understand how you use our Platform. Your IP address is anonymized before analysis.

Opt Out: You can opt out using Google's browser add-on or by adjusting your cookie preferences.

Email Marketing

We use ActiveCampaign to store data (e.g., name, email) and send newsletters. It tracks which links you click to offer relevant content.

Unsubscribe: You can opt out of newsletters anytime using the unsubscribe link in emails.

9. Third-Party Services

We use trusted third-party services to run our Platform, each with their own privacy practices:

WordPress.com

Website infrastructure by Automattic Inc.

Stripe

Secure payment processing

Coinbase Commerce

Cryptocurrency payments

YouTube

Embedded video content

Third-Party Privacy: These providers may use cookies or collect your IP address to deliver services. We ensure they follow data protection rules. Check their privacy policies for details (Stripe, Coinbase Commerce, Automattic, Google).

US Legal Framework & Governing Law

Governing Law & Jurisdiction

Primary Jurisdiction: This Privacy Policy and all data processing activities are governed by the laws of the State of Texas and the United States of America.

Court Jurisdiction: Any disputes relating to privacy or data protection shall be subject to the exclusive jurisdiction of the state and federal courts located in Comal County, Texas.

Regulatory Oversight: We operate under the oversight of applicable US federal agencies (FTC, CFPB) and Texas state authorities.

US Privacy Law Compliance

Federal Laws: COPPA, CAN-SPAM Act, Gramm-Leach-Bliley Act (where applicable)

State Laws: California CCPA/CPRA, Texas Identity Theft Enforcement and Protection Act, Virginia CDPA, Colorado CPA

Sectoral Laws: HIPAA (if applicable), FERPA (if applicable), financial privacy regulations

International Compliance: Swiss FADP, GDPR (for EU data subjects), UK GDPR

Enforcement Framework

US Enforcement: Federal Trade Commission (FTC), Consumer Financial Protection Bureau (CFPB), State Attorneys General

Private Rights of Action: Available under applicable state privacy laws (California, Texas, etc.)

Penalties: Civil penalties, injunctive relief, damages as provided under applicable US and state laws

Constitutional Framework

Fourth Amendment: Protection against unreasonable searches and seizures

Due Process: Fifth and Fourteenth Amendment protections for data processing

Commerce Clause: Interstate commerce regulation framework

First Amendment: Free speech protections for domain name content

Legal Supremacy and Conflict Resolution

US Law Priority: Where conflicts exist between US and international privacy laws, US federal and Texas state law shall take precedence for US-based operations and data subjects.

International Compliance: We maintain compliance with applicable international laws (GDPR, Swiss FADP) for relevant data subjects while ensuring primary compliance with US legal requirements.

Regulatory Cooperation: We cooperate with US and international regulatory authorities within the bounds of applicable law and constitutional protections.

Web 3.0 typography with on anstract futuristic tech wireframe background. Metaverse, future decentralized internet and new creative economy concept. 3D illustration

10. Notifications and Emails

Email Communications

We may send you emails or messages (e.g., newsletters, renewal reminders) to your registered email address. These may include tracking pixels to see if you open them or click links, helping us improve our communications.

Optional Communications

  • • Marketing newsletters
  • • Product updates
  • • Educational content

You can unsubscribe anytime

Essential Communications

  • • Account security alerts
  • • Domain renewal notices
  • • Service updates

Required for account security

11. Social Media

Social Media Interactions

We're active on social media platforms to share updates about .coliving domains. If you interact with us there, your data may be processed by those platforms, which may be outside the UK/EEA.

Platform Privacy: Check the privacy policies of social media platforms (Facebook, Twitter, LinkedIn, etc.) for details on how they handle your data.

12. WHOIS Data

Public Domain Registration Data

For Web2 domains linked to your .coliving domain, your name and contact details may appear in the public WHOIS database, unless specific protections apply.

Data Protection Options

  • .uk domains: Non-business registrants have data redacted by default
  • WHOIS Privacy Service: Available for eligible domains (uses proxy details)

Data Retention

  • We still keep your true data for legal and Registry purposes
  • May share it if required by law or court order

13. Updates to This Policy

Policy Updates

We may update this Privacy Policy to reflect changes in our services or laws. We'll post updates on our Platform and notify you via email when material changes occur.

Continued Use: Continued use of the Platform after updates means you accept the updated policy.

Bits and byte, virtual reality, digital, data transfer. Abstract, futuristic, computer network, technology, software, binary code, exchanging. 3D illustration

Contact Us About Privacy

Primary Data Controller

.coliving
P.O. Box 310121
New Braunfels, Texas 78131

[email protected]

Technology Partner

Freename AG
Samstagernstrasse 41
Wollerau, Switzerland

[email protected]

Data Protection Inquiries

For any questions about how we handle your personal data, to exercise your privacy rights, or to report privacy concerns, please contact us using the information above. We're committed to responding to your privacy inquiries promptly and transparently.

Why Choose .coliving Domains?

A .coliving domain is a secure, modern way to build your digital presence for coliving communities or businesses. Your privacy is protected with industry-leading security measures.

Privacy-first Web3 domain registration

Last Revised: September 29, 2025

GDPR Compliant US Privacy Laws Swiss FADP

This Privacy Policy constitutes our commitment to protecting your personal data in accordance with the highest international standards. By using our Platform, you acknowledge that you have read and understood our privacy practices.