Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCDR / GOpenCDR registrar agreement

GOpenCDR registrar agreement

The terms on which an accredited registrar connects to the GOpenCDR registry over EPP or the REST API, and what it owes the registrants it serves.

Last updated 27 September 2026 Auf Deutsch lesen →

On this page

  1. This agreement
  2. Access to the registry
  3. Registrants
  4. Abuse and requests from authorities
  5. Data protection
  6. Security
  7. Fees
  8. Suspension and ending
  9. Everything else

This agreement

This agreement is between Gelhaus Solutions, as the operator of the GOpenCDR registry platform, and a registrar accredited for one or more TLDs that Gelhaus Solutions hosts. Each TLD's operator grants the accreditation for its TLD and may add terms of its own for it. This agreement governs the connection to the platform and applies to every accreditation. It takes effect when both sides sign it, and publishing it here is not an offer.

Registrars are optional. Every registrant can register and manage names directly in the GOpenCDR portal.

Access to the registry

  • The registry offers EPP (RFC 5730 to 5734) over mutually authenticated TLS, with the secDNS, RGP, fee, change poll and secure authorisation information extensions, and the GOpenCDR REST API with the same operations.
  • Each registrar receives its own credentials, bound to the network addresses it names. Keep them secret. Tell us within 24 hours if they may be compromised; we may revoke them at once.
  • Stay within the published rate limits, send an idempotency key with every request that changes something, and honour a refusal with Retry-After rather than retrying around it.
  • Check availability only for registrations you have been asked to make. Do not harvest availability answers, sell them, or use them to register a name ahead of the person who asked for it.

Registrants

  • Every name is held by the registrant's own GOpenCDR account, and the registrar acts on it under its accreditation. A registrar does not hold its customers' names in an account of its own.
  • Before a registration, show the registrant the GOpenCDR terms, the acceptable use policy, the privacy notice and the TLD's own policy, record their acceptance and pass the version identifiers from the document archive with the registration.
  • The registry sends the yearly confirmation of a free name to the address of the account that holds it. Do not suppress, intercept or answer it on the registrant's behalf.
  • A registrant may move a name to another registrar, or to direct management in the portal, at any time. Provide the authorisation information on request within five days and free of charge, and apply no lock the registrant has not asked for, other than one imposed for a dispute or for abuse.
  • Free names stay free. You may charge for your own services, but never for a name the registry gives away, and you must say plainly which is which.

Abuse and requests from authorities

  • Keep an abuse contact reachable, and act on reports about names you manage within 48 hours, or 12 hours where phishing or malware is active. The TLD and the root may act on a name directly at any time.
  • Pass requests for registry data to Gelhaus Solutions, which decides them under the registration data disclosure policy. Disclose no registry data yourself beyond what that policy allows.

Data protection

You are the controller for your own customer relationship and publish your own privacy information for it. For the registration data you submit, Gelhaus Solutions and the TLD operator are joint controllers under the joint controller arrangement. Tell your customers so, and neither sell, lend nor reuse registry data for anything but managing their names.

Security

Keep the systems that hold your registry credentials patched and access to them limited and logged. Report a breach that affects registry credentials or registrant data within 24 hours, and cooperate in its investigation.

Fees

The root charges registrars nothing and takes no share of what registrants pay. Any fee for accreditation in a TLD is set in that TLD's terms.

Suspension and ending

  • We may suspend access at once where credentials are compromised, the interface is misused, or a breach threatens the registry or its registrants. A TLD operator may end its accreditation under its own terms.
  • Either side may end this agreement with 30 days' notice. We may end it for a material breach not remedied within 14 days of notice.
  • When it ends, registrants keep their names. They move to direct management or to another registrar, and you provide the authorisation information for every name you manage and help with the move.

Everything else

No service level applies. Warranty and liability, including the cap for businesses, are as set out in the general terms of service. German law applies, and the courts at Gelhaus Solutions' registered seat have jurisdiction. A material change to this agreement is announced at least six weeks ahead, and a registrar may object and end the agreement at the date the change would take effect.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform Billing
  • GOpenCDR

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany