Interpreting General Data Protection Regulation Principles (GDPR)

The General Data Protection Regulation (GDPR) is a set of rules that governs how companies collect, use, and protect personal data for people in the European Union. Hover extends the same data protections to all customers, no matter where they're located. This article breaks down GDPR's core concepts in plain language and explains what they mean for you as a Hover customer.

What is GDPR?

GDPR lays out standards for how companies handle the personal data customers entrust to them, and it went into effect on May 25, 2018. At its core, GDPR can be simplified into three concepts: consent and control, transparency, and the right to be forgotten.

Consent and control

Businesses that collect or process personal data must get explicit, informed consent to do so and explain why the information is needed. Only the minimum amount of data necessary should be collected, and it can't be used for anything beyond what was originally agreed — putting you in control of how your information is used from the start.

Transparency

If a security breach exposes personal information, GDPR requires that anyone affected be notified as soon as possible. The notice must explain what happened, what's being done about it, and what affected individuals should do to protect themselves.

The right to be forgotten

You have the right to revoke consent you previously gave for your data to be used. When you do, the provider must erase your records — with some exceptions, since certain services can't be provided without personal information, and some data must be retained for legal or public-interest reasons.

The seven GDPR principles

Seven principles sit at the heart of how Tucows (Hover's parent company) approaches personal data:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

Tucows extends these principles to all customers, regardless of location. Hover never sells your personal information and doesn't share it beyond what's needed to provide the service you've signed up for.

We keep two commitments in mind as we apply these principles:

  1. Operating within the legal requirements set by GDPR.
  2. Keeping domain purchases and management as simple and seamless as possible for you.

What counts as personal data

Personal data is any information that can be traced back to and used to identify a specific person. Combining multiple pieces of information can also add up to personal data, even if no single piece identifies someone on its own.

Personal data

Not personal data

Basic information such as first and last name, home address, phone number

Company registration number or VAT ID

A unique email address, such as first.last@email.com

A general company email address, such as info@email.com

Location data, such as IP addresses

Anonymized (redacted) data

Order numbers

Credit card numbers

Our terms of service explain how Hover handles your information and complies with GDPR standards. Hover support cannot view your personal information — including your name and account email address — without first verifying your account (see Verifying Your Identity With Hover Support).

Data processed to fulfill our service contract with you is kept for the lifetime of the service, plus up to seven years afterward.

Next steps

  • Review your account's security settings: see Hover security standards for an overview of the protections available to you.
  • Manage your domain's public visibility: see Domain WHOIS privacy to control what information is published about your domain.

Questions? Contact Hover Support.

How helpful was this article?

Thanks for your feedback!

Do you still need help? If so please submit a request here.