Last updated: August 2026
This Privacy Policy explains how IronCloud PC (“IronCloud”, “we”, “us”) collects, uses, stores, and protects personal data when you use:
- the marketing website ironcloud.gr; and
- the domain registrar portal icresolve.com (ICResolve by IronCloud; formerly my.ironcloud.gr).
Processing is carried out in accordance with the GDPR (Regulation (EU) 2016/679) and applicable Greek law. See also our Cookie Policy and GDPR Policy.
1. Data controller
IronCloud PC
Leoforos Eleftherias 11, Alimos 17455, Greece
GEMI: 117557101000 · AFM: 800346977
Privacy: [email protected]
Support: [email protected] / [email protected]
Phone: +30 210 2202 667
Supervisory authority: Hellenic Data Protection Authority (HDPA) — www.dpa.gr.
2. Marketing site (ironcloud.gr)
2.1 Data we collect
- Contact forms: name, email, phone (optional), message.
- Newsletter: email address, processed via Mailchimp when you subscribe.
- Analytics: Google Analytics only after you accept non-essential cookies via the cookie banner.
- Language preference:
lang cookie (essential).
- Google reCAPTCHA / Maps: loaded only after cookie consent, where used (e.g. contact form spam protection, map on the contact page).
2.2 Purposes
- Respond to inquiries and pre-contractual requests.
- Send newsletters where you have consented.
- Measure site usage (analytics) only with consent.
- Remember language preference and protect forms (CSRF / session).
3. Registrar portal (icresolve.com)
ICResolve by IronCloud provides domain registration and related services through https://icresolve.com. The categories below describe data typically processed to provide those services.
3.1 Account
- Email, username, password hash, signup IP address, and record of terms acceptance.
- Optional Google OAuth (scopes: openid, email, profile) — we receive email, name, and Google subject identifier (
sub).
3.2 Profile and security
- Phone number (where provided).
- Multi-factor authentication: TOTP secret and/or email one-time codes.
3.3 Billing profiles
- Individual or company: name, company name, legal form, AFM/VAT, tax office, GEMI (where applicable), address, billing email/phone, invoice vs receipt preference.
- AFM verification may be performed via AADE-related services (e.g. mytimologisi / myData integration for Greek invoicing).
3.4 Domain contacts (ICCONTACTS)
- Name, organisation, email, phone, postal address, AFM (where required).
- For .gr / .ελ domains, registrant data is transmitted to FORTH-ICS as required for the EETT registrant database.
3.5 KYC documents (restricted TLDs)
Where a TLD requires identity verification, supporting documents are stored as encrypted AES-256-GCM BLOBs in our database.
3.6 Orders and payments
- Payment processing via Stripe (and legacy Viva where applicable).
- Invoice PDFs stored in our systems; Greek e-invoicing via mytimologisi → myData where required.
3.7 SSL certificates
- Let’s Encrypt for automated certificates.
- Commercial certificates via The SSL Store — contact/organisation data shared as needed to issue the certificate.
3.8 Support and account closure
- Support tickets and related correspondence.
- Account closure is handled manually via a support ticket (not an automated self-service erasure flow).
3.9 Security and operational logs
- Login attempts and related security events.
- Append-only audit log of significant account/admin actions.
- Redacted EPP/API operational logs.
3.10 Transient tokens
- Email verification tokens: typically 24 hours.
- Password reset tokens: typically 2 hours.
- MFA email codes: typically 10 minutes.
3.11 Cookies and local storage (portal)
- icregPortal — essential session cookie (HttpOnly; Secure when configured; SameSite=Lax).
- icTheme (localStorage) — UI theme preference only; not used for advertising.
The registrar portal does not set marketing/analytics cookies of the type used on ironcloud.gr.
4. Legal bases
- Art. 6(1)(b) GDPR — performance of a contract or steps prior to entering a contract (accounts, domain registration, billing, support).
- Art. 6(1)(c) GDPR — legal obligation (EETT/registry rules, tax and invoicing obligations).
- Art. 6(1)(f) GDPR — legitimate interests in security, fraud prevention, abuse detection, and service integrity (balanced against your rights).
- Art. 6(1)(a) GDPR — consent, where applicable (newsletter, non-essential analytics/cookies, optional Google OAuth where consent is the applicable basis).
5. Processors and recipients
Depending on the service used, personal data may be processed by or shared with:
- FORTH-ICS (Greece) — .gr / .ελ registry operations
- Cloudflare Registrar (United States) — certain TLD registrations; privacy/redaction mode where offered
- Stripe — payments
- Viva — legacy payments
- mytimologisi / AADE (Greece) — electronic invoicing / myData
- The SSL Store — commercial SSL certificates
- Let’s Encrypt — certificate issuance
- Google — OAuth, Analytics, reCAPTCHA, Maps (as configured)
- Mailchimp — newsletter
- Our SMTP / email delivery provider
Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs), where required.
6. Retention
| Category | Typical retention |
| Contact form emails (marketing site) | Up to 24 months |
| Newsletter | Until you unsubscribe |
| Analytics (if enabled) | Per Google Analytics (typically ~14 months) |
| Registrar account | While active, plus a reasonable period after closure for security and dispute handling |
| Domain / registrant data | Registration term plus periods required by EETT / registry / law |
| Invoices and billing records | Minimum 5 years (Greek tax rules) |
| Audit / security logs | Typically 2–7 years, depending on log type and legal needs |
| KYC documents | Verification period plus any legal/registry retention |
Some registrar, registry, and tax data cannot be erased while legal or contractual obligations apply, even if you request erasure or account closure.
7. Your rights
Under the GDPR you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent.
- Access / rectification: many profile and billing fields can be updated via self-service on the registrar portal.
- Erasure: account closure and erasure requests are handled manually via a support ticket or by emailing [email protected]. Erasure is not automated. Registry and tax retention may prevent full deletion.
- Portability: request via [email protected]. There is currently no automated data export.
- Complaint: you may lodge a complaint with the Hellenic DPA (www.dpa.gr).
We do not operate an automated DSAR / export / erasure portal. Requests are handled by our team within the timeframes required by law.
8. WHOIS and public directory data
Public WHOIS / directory lookups offered through our portal are GDPR-redacted where applicable. Registries may still require registrant data to be held and, in some cases, disclosed under registry rules or lawful requests. For TLDs handled via Cloudflare Registrar, privacy/redaction mode is used where available. Providing accurate registrant data remains a condition of registration.
9. Children
Our services are not directed at children. We do not knowingly collect personal data from children for marketing or registrar services.
10. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated through the website or portal.
Related documents: Cookie Policy · GDPR Policy · Terms of Service · Registrar portal: icresolve.com.