Privacy Policy for nic.merck

Effective Date: April 23, 2026
Last Updated: April 23, 2026

Merck KGaA, Darmstadt, Germany, and Merck & Co, United States, (or its affiliate responsible for the .merck gTLD) (“Merck“, “we“, “us“, or “our“) operates the website nic.merck and manages the .merck generic Top-Level Domain (gTLD) as a branded registry.

We respect your privacy and are committed to protecting your personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), and relevant ICANN policies for gTLD registry operators.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit nic.merck, submit an abuse complaint, contact us, or otherwise interact with our services.

1. Information We Collect

We may collect the following categories of personal data:

a) Information you provide directly

  • When you submit an abuse complaint form: name, email address, details of the reported domain or abuse (including any supporting evidence or descriptions you provide).
  • When you contact us via email, contact form, or other means: name, email address, subject, and message content.
  • Any other information you voluntarily submit.

b) Automatically collected information

  • Technical data such as IP address, browser type and version, device information, operating system, and pages visited.
  • Usage data (e.g., date and time of access, referring website) collected via cookies or similar technologies. See our [Cookie Policy] (if you have one) or the Cookies section below.

c) Registration Data (if applicable)
As a gTLD registry operator, we may receive limited registration data (domain registration information) from accredited registrars in accordance with ICANN’s Registration Data Policy. Most personal data in WHOIS/RDDS is redacted for privacy. We do not directly collect registrant data from end users on this website.

2. How We Use Your Personal Data

We use the collected information for the following purposes:

  • To process and investigate abuse complaints submitted to our abuse contact point, as required by our Registry Agreement with ICANN and our anti-abuse policies.
  • To respond to your inquiries and provide customer support.
  • To improve our website, services, and security.
  • To comply with legal obligations, including ICANN contractual requirements, law enforcement requests, or court orders.
  • To protect the rights, property, or safety of our registry, users, or the public (e.g., mitigating DNS abuse such as phishing, malware, or spam).
  • For internal administrative and analytical purposes.

We rely on the following legal bases (where GDPR applies):

  • Performance of a contract or steps prior to entering a contract.
  • Legitimate interests (e.g., operating a secure registry and handling abuse reports).
  • Compliance with legal obligations.
  • Consent (where we obtain it, e.g., for certain marketing communications — you can withdraw consent at any time).

3. Sharing of Personal Data

We may share your personal data with:

  • Affiliates within the Merck Group.
  • Service providers and processors (e.g., hosting providers, email service providers, security vendors) who act on our behalf and are bound by data processing agreements.
  • Accredited registrars or other parties involved in resolving abuse complaints (only as necessary).
  • Law enforcement, regulatory authorities (including ICANN), or courts when required by law or to enforce our rights.
  • In the context of a merger, acquisition, or sale of assets (with appropriate safeguards).

We do not sell your personal data to third parties.

4. International Data Transfers

Merck entities are global organizations. Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including countries that may not offer the same level of data protection. Where required, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission or other lawful transfer mechanisms.

5. Data Retention

We retain your personal data only as long as necessary for the purposes outlined above or as required by law. Abuse complaint data is typically retained for a limited period (e.g., to allow for investigation and potential follow-up) and then securely deleted or anonymized, unless longer retention is mandated by legal or regulatory requirements.

6. Your Rights (GDPR / Applicable Data Protection Laws)

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Right to access, correct, or delete your data.
  • Right to restrict or object to processing.
  • Right to data portability.
  • Right to withdraw consent at any time (where processing is based on consent).

To exercise these rights, please contact us using the details in the “Contact Us” section below. We will respond within the timeframe required by law.

You also have the right to lodge a complaint with your local data protection supervisory authority.

7. Cookies and Similar Technologies

Our website may use cookies and similar tracking technologies to enhance functionality and analyze usage. You can manage your cookie preferences through your browser settings.

8. Security

We implement reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no internet transmission or electronic storage method is 100% secure.

9. Children’s Privacy

Our website is not intended for children under the age of 16. We do not knowingly collect personal data from children.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top will be revised accordingly. We encourage you to review this page periodically.

11. Contact Us

For any questions, requests, or to exercise your data protection rights, please contact us at:

Email: privacy@nic.merck or abuse@nic.merck
Postal Address: nic.merck C/O Hogan Lovells, 17, av. Matignon, Paris, Ile de France, 75008,France

You may also contact our Data Protection Officer if one is appointed.

Powered by DNS.Business

We develop core back-end registry systems, domain management software, registry migration services, new gTLD enablement, and value-added technology products that support the operation, growth, and optimization of domain ecosystems.