Back to the list
Choosing and pricing14 min

Who owns your domain, your code and your data

A company buys a website and gets nothing to show for it. How to check who holds the domain in five minutes, why paying for code does not make it yours, and what to do when you are already stuck.

Vít HofmanCustom websites and applications#Ownership#Contract#Choosing a supplier

A company buys a van and gets the registration document. It buys a building and it appears in the land registry. It buys a website and gets nothing at all. Usually it does not even know where to look.

Most of the time that does not matter. It matters in two moments: when you and your supplier part ways, and when the supplier stops existing. Both arrive without warning, and both get dealt with at the point where it is too late to add anything to a contract.

This article shows how to check where you stand in five minutes, what the contract needs to say for it to be fine, and what can be done when you are already stuck. You will not need a developer or a lawyer, at least not straight away.

Short answer

  • A domain belongs to whoever is recorded in the registry as the holder. Not whoever pays for it, and not whoever manages it.
  • You can check it in five minutes in the public registry of your domain's extension. Either the holder's name is right there, or you can at least see that the holder is somebody other than you.
  • Source code does not become yours simply because you paid for it. It has to be in the contract, otherwise you hold a licence to use it, not the work itself.
  • The data on the site (content, enquiries, customers) is always yours, but that is no help when you do not have a readable copy of your own.
  • Dependence on a supplier is rarely created on purpose. It is created by convenience, and nobody notices until something happens.

Three different things that get treated as one

When somebody in a company says „our website“, they usually mean three separate things that can belong to three different people. Most of the trouble starts with treating them as one.

What it isWho usually holds itWhat happens without it
The domain, that is the addressThe holder recorded in the registryYou lose the address and the company e-mail with it
Hosting, that is where the site runsWhoever holds the account with the providerThe site disappears overnight if somebody stops paying
The site itself, that is code and contentThe author, until a contract says otherwiseYou may not have it modified anywhere else
Operating data, that is enquiries and customersAlways you, as the data controllerYou own it and still cannot reach it
Each row can be lost on its own and each is fixed differently

The worst combination is not having none of them. It is having three out of four. A company with its own domain, its own hosting and its own data but no rights to the code can move the site and change nothing on it. A company with full rights to the code and no domain has a fine website at an address somebody else can switch off.

How to check who holds the domain in five minutes

Do this now, before you read the rest. For most extensions the registry is public and the answer comes back instantly.

  1. 1Open the public lookup for your domain's extension and enter the domain without www. For .cz domains that is nic.cz/whois.
  2. 2Find the line marked holder or registrant. That is the owner. Nobody else decides about the domain, not even whoever pays for it.
  3. 3Look at the line marked registrar. That is the company the domain is registered through, a reseller in effect. It can be changed without losing the domain.
  4. 4Check the expiry date. Domains renew every year or two, and a forgotten domain is released to anybody after a few weeks.
  5. 5If the holder is not your company, send the supplier one sentence: please transfer the domain to our company. Usually it is done within a week.

Holder, registrar and technical contact are not the same thing

This is where most of the mistakes happen, because all three roles sound alike and the supplier legitimately sits in one of them.

The holder is the owner. They decide where the domain goes, who may manage it and whether it gets renewed. This is where your company belongs, full stop.

The registrar is the company the domain is registered through. It is a commercial relationship like a phone contract: you can change it and the domain comes with you. For .cz domains the transfer is done with a password the current registrar issues on request.

The technical contact is the person who configures where the domain points. Your supplier can sit here, and it is practical, because otherwise you will be chasing them for every change.

So a healthy split is simple: you are the holder, the supplier is at most the technical contact. A supplier listed as holder is not the end of the world, but it is worth sorting out before you need it sorted out quickly.

The domain sits under the supplier's account and they pay for it. Once a year you get an invoice with a line saying „domain and hosting“ and you do not know which provider it is with.

The domain is registered to your company, you have access to the registrar account, and the supplier appears as the technical contact. The invoice names an actual provider.

The code: why paying for it is not enough

This tends to surprise business owners. With commissioned work, paying for it does not by itself mean you can do anything you like with the result. Without a clause in the contract you get the right to use the work for the purpose it was made for, not the right to hand it to somebody else and have it rebuilt.

In practice that means that once you part ways, the next developer formally cannot touch the site. It usually ends in an agreement, but negotiating that at the moment the site is down and the supplier is not answering is the worst possible time.

The fix is one sentence in the contract. It does not need to be complicated.

Three levels of dependence

Not every dependence on a supplier is a trap. The point is knowing which level you are at, because each one is fixed differently and costs differently.

LevelHow you recognise itWhat leaving costs
HealthyDomain yours, code released, ordinary technologyHanding over backups and credentials, so days
AwkwardYou have the code but only its author understands itBringing somebody else up to speed, so weeks
TrapDomain held elsewhere, or a closed platformA new website, so the whole price again
Leaving is measured in days, in weeks, or in a whole new website

The middle level is the most common one and nobody talks about it. You do have the code, but it is written in a way only the person who wrote it understands: no documentation, personal habits throughout, occasionally a library nobody maintains any more. Formally you are free; in practice you pay for somebody to spend a month learning a stranger's website.

It cannot be removed entirely, because somebody else's code is always somebody else's. It can be reduced by building on technology more than one person knows, and by handing over a description of how the thing fits together.

Code that exactly one person on earth understands is a liability. It makes no difference that it is formally yours

The most common and least visible level of dependence

The data is yours, and that is not enough

Enquiries, contacts, orders and site content are yours in data protection terms: you are the one who decides about them, even when they physically sit on somebody else's server. The law is on your side.

Practice is another matter. When the supplier holds the database and you part ways badly, you can be entirely right and still not have your data. So this is not solved by law, it is solved by a backup.

A simple rule: once a quarter, ask for an export of what is in the site. Enquiries and contacts in a spreadsheet, page content as a database backup. You do not need to be able to do anything with it, you just need to have it. If the supplier refuses, you have just learned something important.

What to do when you are already stuck

The usual case: the domain is held by a former supplier who is not answering. The procedure is dull and it works.

  1. 1Find out from the registry who the registrar is. That is the company you will be dealing with, not the supplier.
  2. 2Send the holder a written transfer request with a deadline. E-mail is fine, but send it from a company address and name the domain clearly.
  3. 3If nothing comes back within two weeks, go to the registrar and show that the domain carries your company name and that you use it. Registrars know these cases.
  4. 4In parallel, make sure the domain does not lapse. Find the expiry date and watch it. A lapsed domain is a worse problem than a domain in somebody else's name.
  5. 5Only if none of that works does it go to a dispute under the registry's rules. That takes months and a lawyer, which is why it is the last step.

When dependence is perfectly fine

If the article left you thinking every dependence is a mistake, it would be useless. Most companies depend on somebody, and it is cheaper than the alternative.

When you buy a shop on a hosted platform, you are buying a service. The code is not yours, it runs on somebody else's infrastructure and you cannot take it with you. In return you never deal with updates, backups or security. That is an honest trade and for plenty of companies the right one. What matters is knowing that is the deal, rather than assuming you will move it elsewhere one day.

It is equally fine for a supplier to hold the technical contact on the domain, manage the hosting and have their own logins to the site. That is not dependence, it is a division of labour. The difference is whether you have the same things too.

How we handle it

Our price list puts it in one line: the data is yours and you can take the site elsewhere at any time. Here is what stands behind it.

  • The domain is registered to your company from day one. We appear on it at most as the technical contact, so you do not have to be involved in every change.
  • We hand over the whole codebase, history included, with a description of how it fits together. The contract says that once paid for, you may do anything with it, including having somebody else modify it.
  • A backup of the database and files is yours whenever you ask, not only when the relationship ends.
  • You hold your own credentials and we hold ours. There is no account you cannot get into.

And the honest other side: a custom site can move, but whoever takes it over has to know the technology it stands on. That is why we build on things more people than the two of us know, rather than on an invention of our own. Zero dependence does not exist; what exists is dependence you can get out of in a week rather than by paying for a whole new site.

Related articleTwenty questions to ask before signing, each with the good answer and the warning sign. Four of them are exactly about what this article covers

Frequently asked questions

Who owns my website's domain?

Whoever is recorded in the registry as the holder, sometimes called the registrant. That is not necessarily whoever pays for the domain, nor whoever manages it. For .cz domains you can check in five minutes at nic.cz/whois: enter the domain without www and look for the holder line.

How do I find out who a domain is registered to?

Through the public registry lookup for that extension, or the whois command. The output shows the holder, the registrar and the expiry date. For private individuals the holder details are often hidden; in that case ask the registrar for a statement. The holder is entitled to one, so not getting it is itself an answer.

Do I own the source code if I paid for it?

Not automatically. Without a clause in the contract you get the right to use the work for the purpose it was made for, not the right to have somebody else modify it. The contract should say that on payment the economic rights pass to you, including the right to modification by a third party.

What is vendor lock-in on a website?

Dependence on a single supplier that you cannot leave cheaply. It comes about in three ways: a domain held by the supplier, missing rights to the code, and a site built on a closed platform. The first two can be fixed with a sentence in the contract; the third only with a new site.

My supplier holds the domain and will not answer. What now?

First find out from the registry who the registrar is, because that is who you will be dealing with. Send a written transfer request with a deadline. If nothing comes back, go to the registrar and show that the domain carries your company name. Watch the expiry date while you do: a lapsed domain is a worse problem than one in somebody else's name.

Is it wrong for a supplier to have access to my site?

No, that is a division of labour. What is wrong is when only one side has it. The healthy split is that you are the domain holder and hold your own logins and a backup, and the supplier holds their own so they can work.

Summary

  • Domain, hosting, code and data are four separate things. Each can be lost on its own and each is fixed differently.
  • You can check the domain holder in five minutes. Do it before you need to.
  • The holder is the owner, the registrar is the reseller, the technical contact is the administrator. A supplier belongs in the third role, not the first.
  • Code is not yours because you paid for it. Without a clause in the contract you may use the site, not have it rebuilt elsewhere.
  • The data is yours by law, which is no help when you do not hold a copy. Ask for an export once a quarter.
  • Depending on a closed platform is an honest trade as long as you know about it. The problem is dependence nobody mentioned.

Not sure where you stand

Send us your website address. We will look up who the domain is registered to, where the site runs and what follows from that, and send it back to you in plain language. It takes both of us a few minutes and we want nothing for it.

Discussion

No email needed and you are not signed up to anything.

Nobody has written anything yet. You can be first.

Once a month

What is changing in websites and marketing, and what actually works

At most one email a month. Findings from practice, numbers we measured ourselves, and the things that did not work.

  • At most one email a month
  • One click to unsubscribe
  • We never pass the address on or sell it

Notes from the field

Once you confirm, we send the ten things you can check on your own site in an hour.

What do you do

Pick one. It decides what we send you and what we spare you.

Tell us what you need to solve

We reply within one working day. The first consultation is free and commits you to nothing. Write even if you are not sure what you want yet.

Start a project