Hosting Privacy Policy
Last updated:
This policy describes what happens to personal data arising under a hosting or managed services contract with us.
It does not cover simply visiting this website - the Privacy Policy governs that.
1. Controller
The controller within the meaning of the GDPR is the German company named in the Imprint. A message to the address given there is sufficient for data protection enquiries.
No data protection officer has been designated. The conditions of § 38 BDSG are not met.
2. Two roles, and why the distinction matters
Under a hosting contract we process personal data in two different capacities. Which one applies determines who decides about the data and whom you address with your rights.
| We are the controller | We are the processor | |
|---|---|---|
| What it covers | our business relationship with you: contract and account data, billing, support, operational logs of our own systems | the personal data you store or process on the systems we operate - for example the data of your own customers, staff or users |
| Who decides | we do, within the limits of contract and law | you do. We process this data solely on your instructions |
| Basis | this policy, sections 3 to 8 | the data processing agreement concluded with you under Art. 28 GDPR |
| Where to send data subject requests | to us (section 10) | to you as the controller; we assist you under Art. 28(3)(e) and (f) GDPR |
Sections 3 to 8 describe the first role only. What happens to the data on your systems is governed by the data processing agreement, not by this policy - there, you determine the purposes.
3. Contract and account data
To enter into and perform the contract we process:
- company name and legal form
- name of the authorised representative or contact person
- postal address
- VAT identification number, where applicable
- email address and telephone number
- the technical details needed to deliver the service - such as domains, IP ranges and fault contacts
The purpose is the establishment, performance and settlement of the contractual relationship. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for retention required by commercial and tax law.
4. Billing
We bill in two ways: by invoice followed by bank transfer, or through Stripe. No direct debit is collected.
When paying through Stripe you enter your payment details directly with Stripe. No card data reaches us - we receive only confirmation of payment and the details needed to allocate it.
The purpose is settlement of payment. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for retention of the records.
We retain invoices and the associated records for the periods required by commercial and tax law (section 8).
For accounts in the European Economic Area the contracting party is Stripe Payments Europe, Limited, Dublin, Ireland. In the course of settlement, data may be transferred to Stripe, LLC in the United States.
The United States does not offer a level of data protection equivalent to European law; in particular, authorities may under certain conditions access data without a remedy meeting European standards being available. The transfer relies on the safeguards agreed by Stripe - standard contractual clauses and participation in the EU-US Data Privacy Framework.
This transfer concerns billing only. Personal data you process on the systems we operate is not affected; section 2 and the data processing agreement govern it, and it does not leave the European Union.
5. Operating the services
Operating the systems we provide produces technical data that may relate to an identifiable person:
- Operational and security logs of the host systems - for example time, source IP address and type of access for administrative logins
- Monitoring data on availability and load
- Backups of the systems we operate
The purpose is to deliver the contractually owed service, maintain operations and defend against attacks. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for attack defence.
Where these logs and backups contain data that you process on your systems, we act as a processor in that respect (section 2) - a backup of your server contains what is on it.
Customer systems run in two locations, both in Germany:
| Location | Operator of the facility | Who operates the systems on it |
|---|---|---|
| our own premises | ourselves | ourselves |
| dedicated servers at Hetzner Online GmbH | Hetzner | ourselves |
At both locations the systems are operated solely by us; Hetzner provides premises, power, connectivity and the hardware.
For availability monitoring we currently use Hyperping (Hyperping SAS, Paris, France; processing predominantly in Frankfurt am Main, Germany). Transmitted are the addresses of the systems to be checked and the measurement results. This service is being replaced by a solution we operate ourselves; the recipient falls away with that changeover.
The processing is based on the data processing agreement published by the provider, as amended from time to time.
6. Support
We handle enquiries about faults and change requests in our ticket system (Zammad). Your contact details, the content of your enquiry and the course of its handling are stored there.
The ticket system runs on a virtual server operated by us at Webdock ApS in the European Union; a data processing agreement is in place with the provider.
The purpose is to handle your request and to keep the business relationship traceable. The legal basis is Art. 6(1)(b) GDPR.
Handling a request may require access to your systems. This is done to perform the contract and, where data for which you are responsible is involved, solely on your instructions under the data processing agreement.
7. Access to your data at our end
Contract, billing and operational data is accessed by the managing director alone. No other persons are involved; there is no support department to which access is delegated, and no service provider holds administrative access to the systems.
This is not a limitation we regret but the single most effective safeguard in this document: the circle of those with access is as small as it can be.
8. Retention
| What | How long |
|---|---|
| Contract and account data | for the duration of the contractual relationship |
| Invoices and records relevant for tax purposes | for the statutory retention periods, as a rule up to ten years (§ 147 AO, § 257 HGB) |
| Operational and security logs | 30 days. Longer only where they relate to a specific security incident, and then only until it is closed |
| Backups | on a fixed generation plan: 13 daily, 8 weekly, 11 monthly and 3 yearly states. A backup leaves the set once its generation expires |
| Ticket system | deleted once the matter is finally handled, at the latest after 24 months; longer only where commercial or tax retention obligations apply |
What backups mean for erasure, and why it is stated here: If you request erasure of specific data, we remove it from the live systems. Individual items cannot technically be extracted from backups already taken - they disappear once the backup in question expires under the generation plan. Until then they are not processed further, only retained. For the yearly states this can take up to three years.
At the end of the contract we delete or return the data we process for you as a processor, at your choice; the data processing agreement sets out the details. This does not affect the data in sections 3 and 4 where statutory retention obligations apply.
After the contract ends, the systems remain unchanged for 30 days and can be restored at your request during that period. They are deleted thereafter. Backups expire under the generation plan set out above.
9. Recipients and sub-processors
| Recipient | For what | Role |
|---|---|---|
| Webdock ApS, Denmark | virtual server on which the ticket system runs | processor |
| Hetzner Online GmbH, Germany | dedicated servers running customer systems | sub-processor; data processing agreement in place |
| Stripe Payments Europe, Limited (Ireland), with transfer to Stripe, LLC (USA) | card payment processing | processor |
| Hyperping SAS, France | availability monitoring; falls away with the move to our own solution | processor |
No data is passed on for advertising purposes, and no data is sold.
Disclosure to public authorities takes place only where we are legally obliged to do so.
Changes to sub-processors are notified to you in advance in accordance with the data processing agreement so that you can object (Art. 28(2) GDPR).
You receive the data processing agreement together with the annex on technical and organisational measures as part of the contract; we also provide it beforehand on request.
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where processing is based on a legitimate interest, you have the right to object to it (Art. 21 GDPR).
An informal message to the address given in the Imprint is sufficient.
If a data subject whose data you process on your systems approaches us, we are not the right addressee - you are. We forward such requests to you and assist you in responding (Art. 28(3)(e) GDPR).
11. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority, in particular the authority of your habitual residence or the one responsible for us.
The authority responsible for us is that of the state in which we are established - following the Mannheim register court, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
12. Changes
This policy is amended when the processing described here changes. The version published here, bearing the date given above, is the applicable one.