Our legal framework for compliance with the EU GDPR, CCPA, and legitimate interest access to WHOIS datasets.
Effective Date: January 1, 2026 | Standard Contractual Clauses Version 2.4
This Data Processing Agreement ("DPA") supplements the SpiralBig Terms of Service and applies to enterprise customers subject to the European Union General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK Data Protection Act 2018 ("UK GDPR"), or the Swiss Federal Act on Data Protection ("FADP").
Following the implementation of ICANN's Temporary Specification for gTLD Registration Data, top-level domain registries and accredited domain registrars routinely redact personal contact information (such as registrant personal names, home street addresses, and individual personal telephone numbers) from public WHOIS and RDAP directory outputs.
SpiralBig strictly adheres to registry redaction flags. Where domain data contains corporate contact details, organizational legal entity names, corporate email addresses, or privacy proxy addresses, such business contact data is compiled pursuant to Recital 49 of the GDPR, which recognizes the processing of personal data to the extent strictly necessary and proportionate for network and information security by computer emergency response teams (CERTs), cybersecurity providers, and security risk management teams as a legitimate interest.
SpiralBig maintains robust technical and administrative safeguards to ensure high levels of security:
Where customer data originating from the European Economic Area is transferred to infrastructure outside the EEA, such transfers are governed by the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor and Module 1: Controller-to-Controller as applicable), ensuring equivalent levels of data protection under Chapter V of the GDPR.
If a data subject contacts SpiralBig regarding domain records or personal account information, SpiralBig will verify the request and take appropriate action in accordance with Articles 15 through 22 of the GDPR. For queries regarding WHOIS record amendments or privacy proxy opt-outs, domain owners may also contact their domain registrar directly to trigger automated zone updates.
SpiralBig Global Data Protection Desk
Email: dpo@spiralbig.com
Telephone: +91 96037 81602