How we deal with your data in 3 steps
We only collect data which is necessary to carry out our activities: registration and publication services for domain names, nothing more.
Data use and data sharing
Under no circumstances will Registro.br share your data with third parties for commercial and/or advertising purposes. Our only source of income is the annual subscription you pay for registering the .br domain, or for using the allocated numbering resources.
The ownership data, contact email addresses and technical information of .br domain names are available for public consultation on an individual basis. In the case of registration by individuals, ownership comprises their name and national registry number with the Federal Revenue Service (CPF - individual taxpayer's identification number). For companies, besides the above information (with the CNPJ - corporate taxpayer's identification number - replacing the CPF), the telephone number and physical address are also disclosed.
August 06, 2018
All the information provided by users when they register and that is collected when they access and use the site will be exclusively used by Registro.br and added to its database to operationalize the provision of its services, i.e. the registration and consultation of information relating to
1. Personal data collected:
1.1. The personal information provided by the user at the time of registering for .br domain name registration, or simply creating a user (ID), which includes in addition to the registration data the necessary data for payment processing by means of a bank slip, credit card or other financial transaction mechanisms;
1.2. Internet protocol (IP) addresses, logical ports and browser characteristics;
1.3. Information may be automatically collected when the user accesses the Registro.br site by way of tools such as cookies, which is a small text sent to the user's browser;
1.4. In accordance with Brazilian legislation, in particular with Law No. 12,965/14, internet application access logs are collected (i.e., every time that the Registro.br website is accessed, including the users registered themselves).
2. Other data collected:
2.1. DNS queries to registered domains, including subdomains that are informed by those requesting delegation information for the purposes of problem diagnosis, the preparation of statistical analyses, security analyses, fraud prevention and scientific and technological research activities.
2.2. Website traffic data for problem diagnosis activities, the preparation of statistical or security analyses arising from the provision of DNS services involving several autonomous systems;
3. Data treatment:
3.1. The collected data are used for diagnosing problems, preparing statistical and security analyses and fighting fraud with the purpose of guaranteeing and improving the information registration and consultation activities of .br domain names.
3.2. The data collected for payment purposes that relate to credit cards, bank slips and other financial transaction mechanisms follow the practices adopted by the respective operators and financial institutions, in line with the permissions provided for in current legislation and related to banking confidentiality.
3.3. The data collected by way of cookies are used for the purposes of:
3.3.1. User authentication on the Registro.br website, in particular for identifying them in future accesses (logins);
3.3.2. Avoiding the fraudulent use of credentials and protecting user data from unauthorized third parties.
3.4. Information about the browser characteristics of the users serves to guarantee their compatibility with the Registro.br website and thus the use of all its functionalities.
3.5. Registro.br partially publishes the data collected in a public service directory ("Directory") for purposes of consultation on the ownership, contact information and technical information of domain names in .br:
3.5.1. Legal Entities have their name, physical address, e-mail addresses, telephone numbers and the national registration number with the Federal Revenue Service (CNPJ) published. Other data are not disclosed;
3.5.2. Individuals (natural persons) have their name, e-mail address and the national registration number with the Internal Revenue Service (CPF) published. Other data collected are not disclosed.
4. Data sharing
4.1. Under no circumstances will the data collected be shared with third parties for commercial and/or advertising purposes.
4.2. The data collected can be shared with third parties for improving performance in the resolution and operation of the DNS system. In these cases the shared data will not directly identify an user.
4.3. IP address data, browser characteristics and means of payment may be shared with banking institutions for the processing of financial operations and for combating fraud.
4.4. Strictly for the procedures specified in Law No. 12,965/14 and Decree No. 8771/16, user registration data may be supplied to the competent authorities without a court order.
5. Warehousing and information security standards
5.1. Registro.br offers the .br domains' registration service through encrypted channels that adopt forward secrecy, a technique that guarantees that even if a private key is compromised past communication will not be, neither by signed certificate.
5.2. The traffic relating to data that are consulted on the
5.2.1. Registro.br offers the optional resource of the Domain Name System with a Security/DNSSEC Extension at no additional cost, which ensures by way of encryption that traffic is not tampered with.
5.3. As a standard of information security prescribed in Brazilian law (Decree No. 8771/16), Registro.br, using authentication mechanisms, maintains strict control over access to its users' data. It also creates an inventory to ensure the individualization of the person responsible for the access.
5.4.1. In such cases there is no individualization of a person or a group of users, nor of the interval between consultations relating to a particular domain name.
6. Data erasure
6.1. User information is maintained while it is linked to active services. If a user's account no longer has any services or credits, is not updated and has not been accessed for more than 90 days, the data will no longer be available in the Directory.
6.2. In accordance with the applicable legislation or compliance with a court order, Registro.br may maintain certain user data for a period of not less than 6 (six) months, even after their exclusion has been requested.
7. General provisions
7.3. If the user does not agree with the tenor of this policy, it should not use the services and/or the Registro.br website.