Privacy Policy
What we collect, why we hold it, how long we keep it, and what you can ask us to do with it.
my.socialmedia is a concept site published by PREMLEAD SAS as part of internet.best, and this is that site’s policy — the same document, covering these pages as a sub-site of it. The only personal data this mini-site collects is what you type into a form yourself: the waiting list at /start and the contact form. There are no hubs, no follower lists and no click analytics behind any of it, because .socialmedia is not delegated and no name is registered — the product this site describes is not running. The same policy on internet.Best.
Version 2.0 · last updated 18 August 2026 · replaces the version dated April 2026.
1. Purpose and scope
This policy explains how personal data is collected, used, shared, stored and protected in connection with the internet.Best website and its sub-sites and preview environments; the domains.Best registry services for the .Best top-level domain and any further top-level domains the group operates; the web.Best website-building platform; the ai.Best platform; and investor relations, press, careers, events and business development carried out under the internet.Best brand. Together these are the Services.
It is written to meet the transparency requirements of Articles 12, 13 and 14 of the GDPR and the French Loi Informatique et Libertés, and — where they apply — the UK GDPR, the Swiss FADP, the Australian Privacy Act 1988 (Cth) and US state privacy laws including the CCPA as amended by the CPRA.
It does not apply to third-party websites, registrars, resellers, payment providers or social platforms we link to but do not control; to websites published by our customers using web.Best, which are governed by those customers' own policies; or to personal data processed by ICANN, by accredited registrars, or by escrow agents in their own capacity as independent controllers.
2. Who is responsible for your data
The group operates through several legal entities, and they do not all process the same data. Naming one controller for everything would be inaccurate, so the allocation is set out below.
| Service | Controller | Registered address |
|---|---|---|
| .Best registry operations, registration data, registry abuse handling | THE BEST SAS (société par actions simplifiée) — RCS Créteil 839 725 553 · SIRET 839 725 553 00011 · VAT FR50 839 725 553, acting through its subsidiary BestTLD Pty Ltd, the ICANN-accredited registry operator | THE BEST SAS: 295 rue du Professeur Paul Milliez, 94500 Champigny-sur-Marne, France. BestTLD Pty Ltd (Australian proprietary company, limited by shares) — ACN 156 262 752 · ABN 47 156 262 752: Level 9, 1 Chifley Square, Sydney NSW 2000, Australia |
| internet.Best website, investor relations, press, careers, group marketing | PREMLEAD SAS (société par actions simplifiée) — RCS Créteil 799 482 120 · SIRET 799 482 120 00018 · VAT FR25 799 482 120 | 295 rue du Professeur Paul Milliez, 94500 Champigny-sur-Marne, France |
| web.Best and ai.Best platforms | PREMLEAD SAS — RCS Créteil 799 482 120 | 295 rue du Professeur Paul Milliez, 94500 Champigny-sur-Marne, France |
| my.socialmedia concept site, its waiting list and contact form | PREMLEAD SAS — RCS Créteil 799 482 120 | 295 rue du Professeur Paul Milliez, 94500 Champigny-sur-Marne, France |
Where two or more of these entities determine the purposes and means of a processing operation together, they act as joint controllers within the meaning of Article 26 GDPR. The essence of that arrangement is available on request, and whichever entity you contact will route your request to the correct controller.
2.1 How to contact us about privacy
- Privacy contact: privacy [at] internet.best
- Data Protection Officer: we have appointed a DPO — dpo [at] internet.best
- Postal: PREMLEAD SAS, 295 rue du Professeur Paul Milliez, 94500 Champigny-sur-Marne, France, attn. Privacy
- Contact form: the Contact page of this website
- EU representative: not applicable — the controllers are established in the European Union. Where BestTLD Pty Ltd processes personal data of individuals in the EEA, it does so under Article 3(2) GDPR and enquiries are handled through the French entities above.
3. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data.
- Controller — the entity that decides why and how personal data is processed.
- Processor — an entity that processes personal data on a controller's instructions.
- Registrant — the person or organisation holding a .Best domain registration.
- Registrar — an ICANN-accredited company through which a registrant registers a domain.
- RDDS / RDAP — the services through which domain registration data is published or disclosed.
- Registry Agreement — the agreement between ICANN and the registry operator governing the .Best TLD.
4. The personal data we collect
| Category | Examples | When collected |
|---|---|---|
| Identification and contact | Name, email, telephone, postal address, company, job title, country | Account creation, contact form, newsletter, investor access request, press enquiry, event registration |
| Account and authentication | Username, hashed password, multi-factor settings, session identifiers, preferences | Registration and use of an account |
| Support and correspondence | Message content, attachments, ticket history, call notes | When you contact support, sales or the abuse desk |
| Abuse reports | Reporter identity where provided, description, evidence, URLs, log extracts | When abuse is reported to us or to a registrar |
| Identity verification | Government-issued identity document, company registration extract, proof of authority | Only where needed to verify entitlement — for example before releasing a domain placed on hold |
| Investor and business development | Firm name, professional contact details, role, correspondence, NDA status | Fundraising, partnership and registrar onboarding |
| Careers | CV, cover letter, employment history, references | Job applications |
| Payment-related | Billing name and address, VAT number, invoice history, payment token | Paid services. We do not store full card numbers; card processing is handled by our payment provider. |
4.1 Domain registration data
As operator of the .Best TLD we receive registration data from ICANN-accredited registrars: domain name; registrant, administrative, technical and billing contact details; name servers; registrar of record; creation, update and expiry dates; status codes; and DNSSEC data.
We do not collect this from you directly — it reaches us through your registrar, who is your contractual counterparty. Article 14 GDPR applies, and this section is the information notice for that purpose. We are contractually required to receive and retain it under the Registry Agreement, and we do not choose what is published: publication and redaction are governed by ICANN policy.
4.2 Platform content, technical data and third-party sources
web.Best — the content you upload or generate to build a website, and the settings of the sites you publish. ai.Best — the prompts, inputs, configurations and subscription information you submit, and metadata about the AI services you connect.
Technical data — IP address, approximate country-level location derived from it, user-agent, device and browser type, operating system, language; server and application logs, timestamps, requested and referring URLs, status codes, error traces; DNS query data in aggregate; audit trails of account actions; and security signals such as rate-limiting counters and blocked-request records.
We may also receive data from registrars and resellers, ICANN and its compliance function, our registry service provider, escrow agents, anti-abuse and threat-intelligence feeds, rights-holders and their agents, public company registers, B2B contact-data providers used for investor and partner outreach, and payment and anti-fraud providers.
We do not seek special categories of data under Article 9 GDPR, nor data relating to criminal convictions. Please do not include such data in free-text fields, support tickets or abuse reports unless it is strictly necessary. Where it reaches us unsolicited we delete it as soon as we reasonably can, unless retention is legally required.
5. Why we process your data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Operating the registry: accepting, modifying and deleting registrations, resolving domains, maintaining the registry database | Contract and legal obligation; legitimate interests in operating a stable TLD — Art. 6(1)(b), (c), (f) |
| Complying with ICANN consensus policies: RDDS/RDAP, escrow, reporting, UDRP and URS, Trademark Clearinghouse, compliance audits | Legal obligation and contractual necessity — Art. 6(1)(b), (c); legitimate interests where the obligation is contractual — Art. 6(1)(f) |
| Providing accounts and platform services | Performance of a contract — Art. 6(1)(b) |
| Billing, invoicing, accounting and tax records | Legal obligation — Art. 6(1)(c); contract — Art. 6(1)(b) |
| Security, abuse prevention, DNS-abuse mitigation, fraud detection, phishing and malware takedowns | Legitimate interests in protecting the TLD and its users — Art. 6(1)(f); legal obligations under the Registry Agreement |
| Verifying identity before a change, release or disclosure | Legitimate interests in preventing domain hijacking — Art. 6(1)(f); legal obligation where the request is a data subject request — Art. 6(1)(c) |
| Responding to enquiries, support requests and complaints | Contract or legitimate interests — Art. 6(1)(b), (f) |
| Marketing to businesses and professionals, always with an opt-out | Consent where required — Art. 6(1)(a); otherwise legitimate interests in B2B communication — Art. 6(1)(f) |
| Aggregate, server-side measurement of how the site is used | Legitimate interests — Art. 6(1)(f). We set no analytics cookies; see Section 8 |
| Investor relations, fundraising and corporate transactions | Legitimate interests — Art. 6(1)(f); contract where an NDA or subscription agreement is in place |
| Recruitment | Pre-contractual steps at the candidate's request — Art. 6(1)(b); consent for a talent pool — Art. 6(1)(a) |
| Establishing, exercising or defending legal claims; responding to lawful requests from authorities | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f); Art. 9(2)(f) where special-category data is unavoidably involved |
Where we rely on legitimate interests we have carried out a balancing test weighing our interest against your rights. You may request a summary of the relevant assessment, and you have the right to object.
6. Registry-specific processing: the ICANN framework
Operating a top-level domain means working inside a policy framework we do not set. Registration data is made available through RDAP in accordance with ICANN's registration data policies. Under the current framework the contact details of natural-person registrants are generally redacted from public output, with an anonymised or web-form contact channel published instead; registrants that are legal persons may have more data published. What our RDAP output publishes for .Best follows ICANN policy as implemented by CentralNic, our registry service provider.
Non-public registration data may be disclosed on request to third parties with a legitimate interest — law enforcement, rights-holders, security researchers, litigants — where disclosure is lawful and the requester's interest is not overridden by the registrant's rights. Requests are assessed case by case and each disclosure is logged. Requests can be submitted through our Contact page; the registrar of record may also be the appropriate point of contact.
We are required to deposit registry data with an independent escrow agent on a recurring basis, so registrations can be preserved and transferred if the registry ceases to operate. We provide ICANN with the periodic reports required by the Registry Agreement, and ICANN may request registration data in the course of compliance activity.
Registration data is used in rights-protection mechanisms including the UDRP, the URS, and Trademark Clearinghouse Sunrise and Claims services. Dispute-resolution providers, complainants and respondents receive registration data as part of those proceedings.
Where a domain is reported for phishing, malware, botnet command-and-control, pharming or spam used to deliver them, we investigate and may apply registry-level statuses including serverHold, or refer the matter to the registrar. Before restoring a suspended domain we require verification of the registrant's identity. That copy is used solely for verification, is never published, and is deleted once verification is complete and any applicable dispute period has passed.
Third parties may obtain access to the .Best zone file under ICANN's Centralized Zone Data Service. The zone file contains domain names and name-server information; it does not contain registrant contact details.
7. Automated processing, and when we act as a processor
We use automated rules and scoring to detect fraud, bots, abusive registrations and DNS abuse. These can flag an account, a payment or a domain for review. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing without human involvement. Where an automated system leads to a suspension, blocking or refusal, you may request human review, express your point of view and contest the outcome by writing to the privacy contact above.
For websites published by customers using web.Best, the customer is the controller of the personal data collected through their own site, and we act as their processor under an Article 28 data processing agreement. If you are a visitor to such a site and want to exercise your rights in relation to it, contact the site operator; if you cannot reach them, contact us and we will forward your request where we are lawfully able to.
8. Cookies
The public pages of this site set no cookies at all. The only cookies we set are three strictly necessary authentication cookies, and only after you sign in to a gated area — the investor pages, the data room or the internal dashboard. We use no analytics cookies, no advertising cookies and no third-party tracking tags, which is why you are not asked to accept anything.
Because these cookies are strictly necessary to deliver a service you have expressly requested, they are exempt from consent under Article 82 of the Loi Informatique et Libertés. Full detail — names, purposes, lifetimes and flags — is in our Cookie Policy. If we ever introduce non-essential cookies, they will be set only after consent collected through a banner where refusing is as easy as accepting, and this policy will be updated before that happens.
9. Who we share data with
We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.
Within the group, THE BEST SAS, PREMLEAD SAS and BestTLD Pty Ltd share data where necessary for administration, security, finance and the provision of the Services, under intra-group agreements.
Our registry service provider, CentralNic — part of Team Internet Group plc — operates the SRS, EPP, RDAP and DNS infrastructure on our behalf as a processor. ICANN-accredited registrars and resellers are your contractual counterparty for a registration and act as independent controllers for the data they collect from you. ICANN, escrow agents, dispute-resolution providers and rights-holders receive data as described in Section 6.
This site is hosted and served by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, which acts as our hosting and content-delivery processor. Payment and anti-fraud providers, banks and accountants receive data for billing, collections, statutory accounts and audit. Where you use ai.Best, the AI providers whose services you connect or which power a feature receive the inputs necessary to return a result.
Professional advisers, and — under confidentiality — prospective investors or acquirers, may receive data in the context of a financing or corporate transaction; if the business or part of it is transferred, personal data may transfer with it and you will be informed. Courts, regulators, law enforcement and tax authorities receive data where we are legally required to respond. We assess each request for validity and, where lawful, notify the individual concerned.
10. International transfers
Personal data is transferred outside the EEA in three situations: to Australia, where BestTLD Pty Ltd is established and which has no European Commission adequacy decision; to the United States, where certain infrastructure, escrow, AI and communications providers are established, and where ICANN itself is based; and to other countries where a registrar, dispute provider or vendor is established.
For transfers to countries without an adequacy decision we rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented by a transfer impact assessment and technical measures such as encryption in transit and at rest, pseudonymisation and access controls; on the EU–US Data Privacy Framework where the recipient is certified for the relevant data categories; and on Article 49 derogations in narrow cases, in particular transfers necessary to perform a contract with you or to establish, exercise or defend legal claims. Publication of registration data through RDDS is, by design, globally accessible.
A copy of the relevant transfer safeguards can be requested from the privacy contact above.
11. How long we keep data
| Data | Retention |
|---|---|
| Domain registration data | For the life of the registration, plus the period required by ICANN policy and applicable law after expiry, deletion or transfer |
| Escrow deposits | As set out in the escrow agreement |
| Account data | For the life of the account, plus 12 months after closure, then deleted or anonymised |
| Platform content | For the life of the subscription, plus a 30-day recovery grace period, then deleted |
| Billing, invoices and accounting records | 10 years from the close of the financial year (French Commercial Code, art. L123-22) |
| Support tickets and correspondence | 3 years from the last contact |
| Abuse case files and evidence | 3 years from closure, or longer where litigation is reasonably foreseeable |
| Identity verification documents | Deleted once verification is complete, and in any event within 3 months, unless retained for an ongoing dispute |
| Security and access logs | 12 months |
| Authentication cookies | 7 days from sign-in |
| Marketing contact data | 3 years from your last contact, or until you unsubscribe |
| Unsuccessful job applications | 2 years from the last contact, per CNIL recommendation |
| Prospect and investor records | 3 years from the last meaningful contact |
Where data must be kept for legal, accounting or evidentiary reasons after it is no longer needed operationally, it is moved to restricted archive access rather than left in active use.
12. Your rights
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erase your data, where one of the grounds in Article 17 GDPR applies.
- Restrict processing in the circumstances set out in Article 18 GDPR.
- Portability — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
- Object to processing based on legitimate interests on grounds relating to your situation, and object at any time, without justification, to direct marketing.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Not be subject to a solely automated decision producing legal or similarly significant effects.
- Give instructions as to the fate of your personal data after your death, under Article 85 of the Loi Informatique et Libertés.
- Lodge a complaint with a supervisory authority.
12.1 Limits specific to a registry
Some rights are constrained by our obligations as a registry operator. We generally cannot unilaterally amend or delete registration data received from a registrar — requests to correct or delete it should go to your registrar, who transmits the change to us. We cannot erase registration data we are contractually or legally required to retain, escrow or report. And erasing registration data may not be possible without terminating the registration itself, which would affect your rights in the domain. Where we cannot action a request we will tell you why and, where possible, point you to the party who can.
To exercise a right, write to the privacy contact above indicating the right and the Service concerned. We may ask for information reasonably necessary to confirm your identity — a safeguard for you, and we ask only for what is proportionate. We respond within one month, extendable by two further months for complex or numerous requests, in which case we tell you within the first month. Exercising your rights is free; we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
12.2 Supervisory authorities
- France — Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr
- United Kingdom — Information Commissioner's Office, ico.org.uk
- Switzerland — Federal Data Protection and Information Commissioner, edoeb.admin.ch
- Australia — Office of the Australian Information Commissioner, oaic.gov.au
- You may also complain to the authority of your habitual residence or place of work.
13. Rights in other jurisdictions
California. Residents may request disclosure of the categories and specific pieces of personal information collected, the sources, the business purpose and the categories of third parties it is disclosed to; may request deletion or correction; may limit the use of sensitive personal information; and may not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined by the CPRA — we run no advertising or analytics tags of any kind. Requests may be made through the contacts above, including by an authorised agent.
Australia. BestTLD Pty Ltd handles personal information in accordance with the Australian Privacy Principles. You may complain to us first; if you are not satisfied, you may complain to the OAIC.
Switzerland and the United Kingdom. The rights in Section 12 apply equivalently under the FADP and the UK GDPR.
14. Security
- Encryption in transit (TLS) and at rest for data stores holding personal data.
- Role-based access control, least-privilege provisioning and multi-factor authentication for administrative access.
- Registry-grade operational controls, including registry lock options, EPP authorisation codes and change verification for domain operations.
- Segregation of production, staging and preview environments.
- Logging, monitoring, alerting and DDoS mitigation.
- Backups and tested restoration, with business-continuity and disaster-recovery planning consistent with our Registry Agreement obligations.
- Vendor due diligence and written data processing agreements with processors.
- Confidentiality obligations and privacy training for staff.
- Vulnerability management and patching.
No system is perfectly secure. We do not guarantee absolute security, and you are responsible for keeping your credentials confidential and for enabling the security features we make available.
Where a personal data breach is likely to result in a risk to your rights and freedoms we notify the competent supervisory authority within 72 hours of becoming aware of it under Article 33 GDPR, and notify affected individuals without undue delay where the risk is high under Article 34. Security vulnerabilities can be reported through our Security page.
15. Children, marketing and changes
The Services are intended for businesses and professionals and are not directed at children. We do not knowingly collect personal data from children under 15, the age of digital consent in France. If you believe a child has provided us with personal data, contact us and we will delete it.
You can unsubscribe from marketing email using the link in the message or by writing to us. Operational messages — expiry notices, security alerts, policy changes, invoices, registry notifications — are part of the Service and cannot be opted out of while you hold an account or a domain.
We may update this policy to reflect changes in the Services, in ICANN policy or in the law. The version number and date at the top indicate the current version. Where a change is material — a new purpose, a new category of recipient, a change of controller — we notify account holders before it takes effect, and where the change requires consent we ask for it. Previous versions are available on request.
Something here unclear, wrong, or a right you want to exercise? Write to us — naming the section helps.