Data Access, Export, and Portability Policy

1. Purpose and Scope

This Policy governs the conditions under which Ubilibet customers may request and receive a copy of the data associated with the services they have contracted, as well as, where applicable, transfer their exportable data and digital assets to another provider or to their own information and communications technology infrastructure.

Its purpose is to ensure a transparent, secure, proportionate, and traceable process, avoiding unjustified obstacles and facilitating service continuity during export or switching processes.

The inclusion of a service in this Policy does not, in itself, imply that such service qualifies as a data processing service for the purposes of the Data Act. The specific obligations set out in Chapter VI shall apply only where the relevant legal requirements are met; in all other cases, Ubilibet shall apply this Policy as a contractual or operational commitment, without prejudice to any applicable sector-specific regulations.

2. Scope of Application and Relationship with Other Regulations

This Policy applies to customers who have contracted the services listed in Section 4 and Annex I. It covers both standard export requests and exit or provider-switching processes.

This Policy shall be interpreted in accordance with:

  • Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data, in particular Articles 23 to 30 where the service qualifies as a data processing service;
  • Regulation (EU) 2016/679 and applicable legislation on the protection of personal data;
  • the contractual terms and conditions of the service, ICANN rules and the rules of the relevant registries, as well as any applicable sector-specific regulations;
  • the intellectual property rights, trade secrets, and security and confidentiality obligations of Ubilibet, the customer, and third parties.

Requests concerning an individual’s rights of access, rectification, erasure, objection, restriction of processing, or data portability shall be handled through Ubilibet’s specific data protection procedure. This Policy does not replace that procedure.

3. Definitions

Term Definition
Customer natural or legal person who contracts one or more Ubilibet services and is authorised to request an export or switching process.
Exportable Data input and output data, including metadata, generated directly or indirectly through the customer's use of the service and which can be transferred without including Ubilibet’s or third parties’ own assets or data that are protected or related to the internal security of the service.
Digital Assets elements in digital format over which the customer has an independent right of use and which may be necessary to effectively use their data or applications in another environment, including certain configurations and metadata.
Standard Export obtaining a copy of data without necessarily resulting in termination of the service or a change of provider.
Switching Provider process whereby the customer transfers a service, exportable data and, where applicable, digital assets to another provider or to their own infrastructure, or requests their deletion upon termination of the service.
Destination Provider provider or third party expressly authorised by the customer to receive or assist with the migration.
Temporary Export File copy prepared specifically for download, separate from data that remains in Ubilibet’s operational systems or backups.
Transitional Period period beginning once the notice period has ended and during which the service contract remains applicable while the switching process is carried out, including customer assistance, service continuity, and the secure transfer of the relevant data and assets.

4. Services Included

This Policy applies to the service categories listed below, subject to the specific scope and limitations set out in Annex I:

  • Customer account information and contractual and billing information.
  • Domain management and recovery, associated contacts, and DNS zones.
  • Digital certificates.
  • TMCH, DPML, AdultBlock, and GlobalBlock.
  • Monitoring, content monitoring, BrandIntel, BrandLock Web3, and AbuseShield.
  • Trademark services.
  • Email and Hosting services.

In each case, only the data and assets relating to the service actually contracted, which are under Ubilibet’s control and to which the customer has a right of access or use, will be exported.

5. Types of Requests

The customer must indicate the type of request:

  • Standard export: obtaining a copy of data without terminating the service.
  • Switching to another provider: transfer of exportable data and digital assets to the provider designated by the customer.
  • Switching to own infrastructure: transfer to local ICT infrastructure or infrastructure controlled by the customer.
  • Termination and deletion: termination of the service followed by deletion of exportable data and digital assets in accordance with the applicable time limits.
  • Partial or historical export: a copy limited to specific services, accounts, domains, periods, or categories of data.

6. Request Procedure

The request must be submitted by the account holder or an authorised person to Ubilibet’s Operations team by email at: soporte_clientes@ubilibet.com

The request must contain, at a minimum, the information specified in Annex II. Where the request concerns switching providers, the customer must identify the destination provider or their own infrastructure, provide the necessary contact details, and expressly authorise their involvement.

Once the request has been received, Ubilibet will process it internally. No additional documentation will be requested where identity and authorisation can be sufficiently verified using the information available in the account. Ubilibet may request additional information where necessary to prevent unauthorised access, fraud, representation disputes, or risks to third parties.

7. Verification, Authorisation and Security

Ubilibet will verify, in a proportionate manner, that the request has been submitted by the account holder or by a duly authorised person. As a general rule, verification will be carried out using the registered contact address and the available information relating to the account and the services concerned.

Where there are reasonable doubts regarding the identity of the requester, their authority to act, the scope of their authorisation, or where there is a risk of unauthorised access, Ubilibet may request only the additional information strictly necessary to complete the verification.

Where data is to be provided to a destination provider or another third party, the customer’s express authorisation and sufficient identification of the recipient will be required.

Ubilibet will retain sufficient evidence of the request and the verification procedures carried out and will maintain appropriate security measures throughout the preparation and delivery of the export.

8. Timeframes and Service Continuity

8.1 Standard Exports

For the purposes of this section, exports that form part of a process of switching to another provider or to the customer’s own infrastructure, subject to the framework set out in Section 8.2, shall not be considered standard exports.

  • Acknowledgement of receipt: within 24 business hours of receiving a complete request.
  • Delivery: without undue delay and, as a general rule, within 30 calendar days following validation of the request.
  • Operational target: where the volume and complexity allow, Ubilibet will endeavour to complete the export within 24 business hours. This target does not constitute a guaranteed service level unless expressly agreed otherwise.

8.2 Provider Switching Subject to the Data Act

Where Chapter VI of Regulation (EU) 2023/2854 applies, the switching process shall comply with the contractual terms and, at a minimum, with the following limits: The contract shall establish a maximum notice period for initiating the switching process, which may be shorter but shall in no case exceed two months;

  • following the notice period, the mandatory transitional period shall, as a general rule, not exceed 30 calendar days;
  • during the transitional period, Ubilibet shall provide reasonable assistance, maintain service continuity, inform the customer of known risks, and ensure a high level of security;
  • if the 30-day period is technically unfeasible, Ubilibet shall notify the customer and provide justification within 14 business days of the request, indicating an alternative period that shall not exceed seven months;
  • the customer shall have a minimum data retrieval period of 30 calendar days following the end of the transitional period, without prejudice to any longer period agreed between the parties.

The limits set out in this section reflect the legal framework applicable to the switching process and do not replace the specific technical and operational conditions, dependencies, or particularities of each service.

For standard exports and other requests not subject to the specific framework set out in Section 8.2, the operational timeframes may be adjusted where the request is incomplete, there is a legal or technical impediment, cooperation is required from the customer, the destination provider, registries, authorities, providers, or other third parties, or where security risks must be addressed. Ubilibet will inform the customer of the reason and, where possible, provide a revised estimated processing timeframe.

For switching processes subject to Chapter VI of the Data Act, situations involving technical unfeasibility shall be managed in accordance with the specific rules set out above, without prejudice to the necessary cooperation of the parties involved.

9. Delivery, Formats and Availability

The export will be delivered via a secure, individual link. The link may include measures such as an expiration date and a limit on the number of downloads. Depending on the nature and sensitivity of the information, Ubilibet will apply additional security measures that are technically available and proportionate to the risk.

The temporary export file will remain available for 60 calendar days from the date it is made available. At the customer’s request, and provided there is no security risk or deletion obligation, Ubilibet may renew the link or generate a new export.

Formats will be selected based on the service, interoperability, technical availability, and the purpose of the request. These may include, among others:

  • CSV, XLSX, or JSON for structured data;
  • PDF for documents, reports, or supporting records whose structure must be preserved;
  • TXT or BIND for DNS zones;
  • EML, MBOX, or other interoperable formats for email, where available; ZIP, TAR.GZ, SQL, or other commonly used formats for files, databases, and hosting assets; CRT, P7B, PEM, CER, or equivalent formats for certificates and certificate chains.

10.Costs

Data exports and mandatory switching activities governed by this Policy shall be provided free of charge to the customer.

Additional professional services requested by the customer that go beyond standard legal or contractual obligations may be quoted separately, such as customised transformations, specific development work, migration consulting, extraordinary data recovery, or on-site assistance. Any additional costs will be communicated to and agreed by the customer before the work begins.

11. Minimum Content and Metadata

Where necessary to interpret the information provided, the export will include the available and reasonably necessary metadata, either incorporated into the exported file itself or provided in accompanying documentation.
As contextual information for the export, Ubilibet will include, where applicable: the request date; the date on which the export was generated; the date format used, where relevant; and any contextual information necessary for the correct interpretation of the data.
Depending on the service, the format used, and the available technical capabilities, Ubilibet may include additional metadata relating to the originating account or service, the period covered, categories of information, data structure, incidents, omissions, or integrity verification mechanisms.
The above shall not limit the inclusion of other metadata that forms part of the exportable data where the Data Act applies.

12. Exclusions and Limitations

The following shall be excluded from the export, solely to the extent necessary and without being used to unjustifiably prevent or delay the process:

  • algorithms, models, code, tools, methodologies, internal documentation, and other proprietary assets of Ubilibet or third parties that are protected by intellectual property rights or constitute trade secrets;
  • internal data relating to the operation of the service where disclosure could compromise its security, integrity, resilience, or that of other customers;
  • passwords, tokens, authentication seeds, internal credentials, non-exportable private keys, and other security elements whose disclosure is neither necessary nor secure;
  • third-party data or documents where the customer is not entitled to receive them or their disclosure is prohibited by applicable law;
  • information that is not under Ubilibet’s control and whose retrieval requires a separate procedure involving registries, authorities, providers, or third parties;
  • data deleted in accordance with applicable retention periods or that is not available in active systems and standard backups;
  • information whose extraction would require the development of new technologies or services not otherwise provided for, unless specifically agreed.

The exclusions shall not apply to input or output data, reports, results, configurations, or digital assets belonging to the customer or made available to them, unless a specific and duly justified legal, contractual, or security-related limitation applies.

13. Data Protection, Confidentiality and Third Parties

Where the export contains personal data, Ubilibet will act in accordance with its applicable role for each service and will implement data minimisation, access control, confidentiality, and security measures. The presence of third-party personal data will not automatically prevent the export where Ubilibet processes such data on behalf of the customer and the disclosure is made in response to a valid and documented instruction.
The customer will be responsible for ensuring that their request, receipt, and subsequent use of the data have a valid legal basis and respect the rights of third parties. The destination provider must be subject to appropriate confidentiality, security, and data protection obligations.
Where trade secrets or confidential information are involved, Ubilibet may adopt proportionate measures to preserve their confidentiality, including restricting access, partial disclosure, encryption, or entering into specific confidentiality commitments, provided that such measures do not prevent the customer from exercising their legally recognised rights.

14. Deletion and Retention

The deletion of the temporary export file does not constitute the deletion of data stored in the service systems. These actions will be managed separately.

  • The temporary export file will be deleted at the end of its availability period.
  • Where the customer requests termination or switching and the process has been successfully completed, Ubilibet will delete the exportable data and digital assets generated directly by or relating directly to the customer after the applicable data retrieval period.
  • Data may be retained where required by law, necessary for the establishment, exercise, or defence of legal claims, subject to a valid instruction from the customer, or during a technical backup overwrite period.
  • Any residual retention in backups will be limited, protected, and will not be used for ordinary purposes.

15. Contractual, Technical and International Information

The specific conditions governing provider switching, the comprehensive categories of exportable data and assets, exclusions, timeframes, termination and, where applicable, additional costs must be set out in the contract or in contractual documentation incorporated by reference.

Ubilibet will maintain up-to-date technical information on data structures and formats, applicable standards, available interfaces, and known limitations. It will also provide the required information regarding the jurisdiction applicable to the infrastructure used and the measures adopted to prevent unlawful international access to or transfers of non-personal data by authorities of third countries.

For domains, certificates, trademarks, and services provided through registries, authorities, or third-party providers, the process will also be subject to their technical and procedural rules, which may require additional validations or procedures.

16. Policy Updates and Contact

Ubilibet will review this Policy at least annually and whenever there are significant changes to the services, formats, infrastructure, or applicable regulations. Any enquiries or requests relating to this Policy may be addressed to: soporte_clientes@ubilibet.com

Annex I.

Categories of Exportable Data and Assets by Service

The following list must be validated by the relevant technical and product teams. Data will be included where it relates to the contracted service, is under Ubilibet’s control, and the customer is entitled to receive it. The expression “where applicable” avoids committing to the delivery of elements that do not exist, are not part of the product, or depend on third parties.

A. Customer Account Information

Exportable Data and Assets:

  • Account and customer identification information.
  • Contact details and associated addresses.
  • Authorised users, roles, and permissions configured by the customer.
  • Service and communication preferences.

Expected Formats: CSV, XLSX, JSON, or PDF, depending on the nature of the information.

B. Contractual and Billing Information

Exportable Data and Assets:

  • Contracted services and associated financial terms.
  • Issued invoices and billing contact details.
  • Quotes, proposals, or cost estimates, where available.
  • Activation, renewal, modification, and termination dates.
  • Automatic renewal status and renewal period.

Expected Formats: CSV, XLSX, JSON, or PDF.

C. General Service Inventory

Exportable Data and Assets:

  • Service type and name.
  • Asset identifier: domain, Common Name, trademark, or other identifier.
  • Expiration date and renewal period.
  • Billing contact and automatic renewal status.
  • Operational status and associated additional services.

Expected Formats: CSV, XLSX, or JSON.

D. Domain Management

Exportable Data and Assets:

  • Domain name, status, and expiration date.
  • Registrant, registrant organisation, and administrative, technical, and billing contacts.
  • DNS servers, DNSSEC status, and associated services, including Registry Lock, Local Presence, Local Representative, and DNS zone, where applicable.
  • Transfer data, including the AuthInfo/EPP code where applicable, technically available, and subject to successful completion of security validations and compliance with registry rules.
  • History of operations and changes visible to the customer, where available.

Expected Formats: CSV, XLSX, JSON, TXT, or PDF.

Specific Conditions or Limitations: Domain transfers will also be governed by the rules of ICANN, the relevant registry, and the applicable registrar. Certain codes or data will only be provided as part of the specific transfer procedure.

E. Contacts Associated with Domains

Exportable Data and Assets:

  • Domain name and contact type.
  • First and last name, organisation, and tax identification number, where applicable.
  • Postal address, telephone number, and email address.
  • Registration or modification dates, where available.

Expected Formats: CSV, XLSX, or JSON.

Specific Conditions or Limitations: Disclosure will be subject to registry privacy rules and to the customer having a valid legal basis for receiving and using third-party personal data.

F. DNS and DNS Zones

Exportable Data and Assets:

  • Zone name and primary DNS server.
  • Hostmaster email address.
  • SOA values: serial, refresh, retry, expire, and minimum TTL, where applicable.
  • Complete set of records: type, origin, name, value, TTL, priority, port, and weight, as applicable to each record.
  • Exportable DNSSEC data, including DS records or equivalent information, where applicable.
  • Complete zone file and metadata necessary for its interpretation.

Expected Formats: TXT/BIND, CSV, or JSON.

Specific Conditions or Limitations: Private keys or internal credentials will not be exported where their disclosure could compromise security. The DNSSEC key policy will be determined by the technical model in use.

G. Digital Certificates

Exportable Data and Assets:

  • Common Name and included Subject Alternative Names.
  • Certificate file and available certificate chain.
  • Issue, expiration, and revalidation dates, where applicable.
  • CSR or request information where it is under Ubilibet’s control and is exportable.

Expected Formats: CRT, P7B, PEM, CER, TXT, or equivalent formats.

Specific Conditions or Limitations: Ubilibet does not generate, store, or manage the private keys associated with certificates and, therefore, such keys do not form part of the exportable data or assets and cannot be provided by Ubilibet.

H. TMCH

Exportable Data and Assets:
  • Service type, protected trademark, and expiration date.
  • Renewal period, registration number, holder, jurisdiction, and classes.
  • Variants, verified labels, and documentation provided by the customer, where available.
  • Notifications, statuses, and results provided by the provider or the TMCH.
Expected Formats: CSV, XLSX, JSON, or PDF.

I. DPML, AdultBlock and GlobalBlock

Exportable Data and Assets:

  • Service type and protected trademark.
  • Expiration date, renewal period, and holder.
  • Protected variants or strings and covered extensions, where available.
  • Status, exceptions, unblocks, and results communicated to the customer.

Expected Formats: CSV, XLSX, JSON, or PDF.

Specific Conditions or Limitations: Data availability will depend on the information provided by the blocking service provider.

J. Monitoring and Content Monitoring

Exportable Data and Assets:

  • Service type, protected trademark or term, and configuration created by the customer.
  • Expiration date and renewal period.
  • Generated reports, generation date, and delivery date.
  • Alerts, results, evidence, and historical records made available to the customer.
  • Review or management status of each result, where available.

Expected Formats: CSV, XLSX, JSON, or PDF.

Specific Conditions or Limitations: Algorithms, scoring models, undisclosed internal rules, and proprietary methodologies will not be included; however, results and reports provided to the customer will be included.

K. BrandIntel

Exportable Data and Assets:

  • Service type, protected trademark, and holder contact details.
  • Expiration date and renewal period.
  • Configurations and criteria defined by the customer.
  • Reports, alerts, results, evidence, and historical records provided to the customer.
  • Classifications or scores displayed to the customer, together with the information necessary to interpret them, where available.

Expected Formats: CSV, XLSX, JSON, or PDF.

Specific Conditions or Limitations: Analysis models, internal weightings, and proprietary methodologies will remain excluded unless they form part of the contractual documentation provided to the customer.

L. BrandLock Web3

Exportable Data and Assets:
  • Service type, protected trademark or asset, and holder contact details.
  • Expiration date and renewal period.
  • Names, addresses, or Web3 assets associated with the service.
  • Configurations made by the customer.
  • Alerts, reports, results, and historical records made available to the customer.

Expected Formats: CSV, XLSX, JSON, or PDF.

M. AbuseShield

Exportable Data and Assets:

  • Service type, protected asset, and holder contact details.
  • Expiration date and renewal period.
  • Incidents, tickets, dates, statuses, actions taken, and closures.
  • Evidence provided by the customer and communications delivered to the customer.
  • Reports and results associated with the service.

Expected Formats: CSV, XLSX, JSON, PDF, or original evidence files, where applicable.

Specific Conditions or Limitations: Data relating to complainants, researchers, or third parties may be excluded where its disclosure would be unlawful or could compromise an investigation, security, or the rights of third parties.

N. Trademark Services

Exportable Data and Assets:

  • Service type, sign or trademark concerned, and holder details.
  • Applications, file numbers, jurisdictions, classes, and statuses.
  • Documentation provided by the customer and official documents included in the case file.
  • Communications, filed submissions, decisions, and supporting documents available to the customer.
  • Relevant dates, renewals, expiration dates, and actions taken.

Expected Formats: PDF, DOCX, CSV, XLSX, JSON, or available original formats.

Specific Conditions or Limitations: Internal notes, legal strategy, privileged communications, or third-party information that the customer is not entitled to receive may be excluded.

O. Domain Recovery

Exportable Data and Assets:

  • Domain concerned and type of recovery requested.
  • Opening and closing dates, status, and outcome.
  • Documentation and evidence provided by the customer.
  • Communications, submissions, and decisions made available to the customer.
  • Milestones and actions recorded in the case file.

Expected Formats: PDF, DOCX, CSV, XLSX, JSON, or available original formats.

Specific Conditions or Limitations: Internal notes, legal strategy, and confidential third-party information that must not be disclosed are excluded.

P. Email

Exportable Data and Assets:

  • Service type, associated domain, expiration date, and renewal period.
  • Quota or disk space, number of mailboxes, aliases, mailing lists, and forwarding addresses.
  • Mailbox content, folders, and folder structure, where Ubilibet hosts or stores the content and it is technically exportable.
  • Contacts and calendars, where they form part of the service and are available.
  • Customer-created configurations, rules, filters, and exportable access settings.
  • Metadata required for migration and, where available, logs accessible to the customer.

Expected Formats: EML, MBOX, CSV, JSON, ICS, VCF, or other available interoperable formats.

Specific Conditions or Limitations: Current passwords, hashes, tokens, authentication seeds, and internal credentials will not be exported. Migration may require the creation of new credentials with the destination provider.

Q. Hosting

Exportable Data and Assets:

  • Service type, contracted plan, associated domain, expiration date, renewal period, and allocated storage space.
  • Files and content hosted by the customer.
  • Databases and database dumps in a commonly used format.
  • Configurations created by the customer and digital assets over which the customer has an independent right of use.
  • Accounts, users, permissions, and exportable settings required for migration.
  • Logs accessible to the customer and backups where they form part of the contracted service and are technically exportable.
  • Metadata and documentation required to interpret the structure of the export.

Expected Formats: ZIP, TAR.GZ, SQL, CSV, JSON, XML, TXT, or other commonly used formats.

Specific Conditions or Limitations: Licences, software, components, system images, tools, or proprietary configurations belonging to Ubilibet or third parties will not be exported where the customer does not have an independent right of use. Internal backups will not be provided unless this is included in the product or specifically agreed.

Annex II. Minimum Information Required for the Request

To facilitate the processing of the request, it should include:
  • Customer’s name or company name.
  • Account identifier and registered contact address.
  • Name, position, and contact details of the requester.
  • Evidence of representation or authorisation where this is not recorded in the account.
  • Type of request: standard export, switching to another provider, switching to own infrastructure, or termination and deletion.
  • Services, domains, trademarks, mailboxes, hosting services, or assets concerned.
  • Data categories and requested time period.
  • Preferred format and purpose of the export.
  • Target date or migration window.
  • Contact details of the destination provider or authorised third party, where applicable.
  • Need for additional assistance, specific transformation, or technical coordination.
  • Confirmation that the requester is entitled to receive and use the data, including any third-party data that may be contained in the export.

Scroll to Top