GOpenCDR TLD operator agreement
The terms on which a TLD registry runs a TLD in the GOpenCDR root: delegation, the IANA rule, registration policy within the floors, abuse, data, fees, and how a delegation ends without stranding registrants.
This agreement
This agreement is between Gelhaus Solutions, as Tier 0 of GOpenCDR, and the organisation or person that operates a TLD in the GOpenCDR root, the TLD operator. It takes effect when both sides sign it for a named TLD. Publishing it here is not an offer: a TLD is delegated only under a signed copy of the version current at the time.
The GOpenCDR terms, the acceptable use policy and the governance charter bind the operator as they bind everyone else, and the general terms of service govern warranty, liability and law.
Delegation
- A TLD string is proposed, checked against every collision source and the reserved list, opened for public comment for 14 days, and decided by the council responsible under the charter.
- A decided string is delegated only once it passes the pre-delegation tests: signed with DNSSEC, with a DS record in the GOpenCDR root; no wildcards and no synthesised answers; reachable over IPv4 and IPv6, over TCP and with EDNS; no open recursion; and the same serial on every server.
- A delegation is a right to operate the TLD under this agreement. It is not ownership of the string. It belongs to the operator and cannot be transferred without Tier 0's consent in writing and the approval of the Operators Council.
Hosted or self-hosted
Hosted is the default. Gelhaus Solutions runs the TLD's registry on the GOpenCDR platform: the registry database, the portal, zone generation, signing with the TLD's own keys held in our key store, and authoritative service. The operator decides the TLD's policy and looks after its registrants and the first response to abuse.
Self-hosted is permitted after technical checks. The operator then runs its own registry and servers, meets the delegation baseline at all times, keeps its keys under controls no weaker than the DNSSEC practice statement describes, and accepts continuous conformance probing. A self-hosted TLD that falls below the baseline may be suspended from the root until it meets it again.
IANA always wins
The operator accepts, without any claim or compensation:
- that a name in its TLD which comes to exist in the IANA root is withdrawn everywhere within one hour of the IANA delegation and blocked for good;
- that if its string enters ICANN's application pipeline, the TLD goes into sunset within 7 days: registrations close, registrants are told, renewals are capped at the expected delegation date and migration tooling is offered. The window lasts until ICANN delegates the string, and the sunset is lifted if the application is withdrawn or rejected;
- that a TLD whose string also exists in the IANA root operates only as an additive TLD, holding only names IANA does not have, with IANA winning name by name, and only with the approval of two thirds of the Community Council and two thirds of the Operators Council.
Registration policy
- The operator sets its TLD's registration policy and publishes it. The policy may be stricter than GOpenCDR's floors and never looser: an account with a verified email address is the floor for registrant data, and the renewal periods in the GOpenCDR terms may be lengthened but not shortened.
- Any registrant data the policy collects beyond the floor is named in it, with its purpose and how long it is kept. For that data, the policy is the TLD's own privacy information.
- A TLD may limit who may register, may charge for names and may register by invitation only. The root takes no share of anything registrants pay.
- A change that restricts registrants is announced 30 days before it takes effect. A change that loosens takes effect at once.
- The Operators Council may amend a TLD's policy by two thirds on the topics the charter allows, with the operator recused.
Abuse
- The operator keeps an abuse contact reachable, and acts on every report passed to it within 48 hours, or 12 hours where phishing or malware is active.
- Where it does not, the root abuse desk acts on the name itself in a hosted TLD. For a self-hosted TLD, repeated failure to act is a breach of this agreement and can lead to the delegation being suspended.
- The operator gives registrants the reasons for any action it takes and offers the appeal the GOpenCDR terms describe.
- The operator acts on orders only where they come with valid legal process from a competent authority, and reports the requests it receives for the six-monthly transparency report.
Data protection
- For a hosted TLD, Gelhaus Solutions and the operator are joint controllers for registration data. The joint controller arrangement is part of this agreement and sets out who does what.
- For a self-hosted TLD, the operator is the controller for its registry data. Gelhaus Solutions processes only what the root needs: the TLD's DS records, its servers and its zone as published.
- Registration data is disclosed only under the registration data disclosure policy, or under a stricter policy of the TLD.
Continuity
Registrants must not be stranded when an operator leaves.
- Gelhaus Solutions holds the registry data of a hosted TLD. A self-hosted operator deposits a complete, encrypted export of its registry data with Gelhaus Solutions at least once a week, to be used only if the delegation ends without a successor.
- When a delegation ends, the TLD passes to a successor operator approved by the Operators Council. Where there is none, it is wound down in a sunset during which registrants are told and have at least six months to move their names.
Fees
- Community TLDs pay no fee, to apply or to be hosted.
- Brand and private TLDs pay a cost-recovery application fee, and a hosting fee where they are hosted, as stated in the offer signed with this agreement. Contention between applications for the same string is settled by the council's review of their merits, not by price.
Term and ending
- The agreement runs without a fixed term.
- The operator may end it with six months' notice. The TLD then passes to a successor or into sunset as described under "Continuity".
- Gelhaus Solutions may end it for a material breach not remedied within 30 days of notice, for repeated failure to act on abuse, or when the string is withdrawn or sunset under the IANA rule. It may suspend a delegation at once where the security or stability of the namespace, a court or an authority requires it.
- Ending the agreement does not end the registrants' rights before their names have been handed on or the sunset has run its course.
Everything else
No service level applies. Warranty and liability, including the cap for businesses, are as set out in the general terms of service. German law applies, and where the operator is a merchant, the courts at Gelhaus Solutions' registered seat have jurisdiction. A material change to this agreement is announced to the operator at least six weeks ahead, and the operator may object and end the agreement at the date the change would take effect.