Hosting Privacy Policy

Last updated:

This policy describes what happens to personal data arising under a hosting or managed services contract with us.

It does not cover simply visiting this website - the Privacy Policy governs that.

1. Controller

The controller within the meaning of the GDPR is the German company named in the Imprint. A message to the address given there is sufficient for data protection enquiries.

No data protection officer has been designated. The conditions of § 38 BDSG are not met.

2. Two roles, and why the distinction matters

Under a hosting contract we process personal data in two different capacities. Which one applies determines who decides about the data and whom you address with your rights.

We are the controllerWe are the processor
What it coversour business relationship with you: contract and account data, billing, support, operational logs of our own systemsthe personal data you store or process on the systems we operate - for example the data of your own customers, staff or users
Who decideswe do, within the limits of contract and lawyou do. We process this data solely on your instructions
Basisthis policy, sections 3 to 8the data processing agreement concluded with you under Art. 28 GDPR
Where to send data subject requeststo us (section 10)to you as the controller; we assist you under Art. 28(3)(e) and (f) GDPR

Sections 3 to 8 describe the first role only. What happens to the data on your systems is governed by the data processing agreement, not by this policy - there, you determine the purposes.

3. Contract and account data

To enter into and perform the contract we process:

  • company name and legal form
  • name of the authorised representative or contact person
  • postal address
  • VAT identification number, where applicable
  • email address and telephone number
  • the technical details needed to deliver the service - such as domains, IP ranges and fault contacts

The purpose is the establishment, performance and settlement of the contractual relationship. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for retention required by commercial and tax law.

4. Billing

We bill in two ways: by invoice followed by bank transfer, or through Stripe. No direct debit is collected.

When paying through Stripe you enter your payment details directly with Stripe. No card data reaches us - we receive only confirmation of payment and the details needed to allocate it.

The purpose is settlement of payment. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for retention of the records.

We retain invoices and the associated records for the periods required by commercial and tax law (section 8).

For accounts in the European Economic Area the contracting party is Stripe Payments Europe, Limited, Dublin, Ireland. In the course of settlement, data may be transferred to Stripe, LLC in the United States.

The United States does not offer a level of data protection equivalent to European law; in particular, authorities may under certain conditions access data without a remedy meeting European standards being available. The transfer relies on the safeguards agreed by Stripe - standard contractual clauses and participation in the EU-US Data Privacy Framework.

This transfer concerns billing only. Personal data you process on the systems we operate is not affected; section 2 and the data processing agreement govern it, and it does not leave the European Union.

5. Operating the services

Operating the systems we provide produces technical data that may relate to an identifiable person:

  • Operational and security logs of the host systems - for example time, source IP address and type of access for administrative logins
  • Monitoring data on availability and load
  • Backups of the systems we operate

The purpose is to deliver the contractually owed service, maintain operations and defend against attacks. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for attack defence.

Where these logs and backups contain data that you process on your systems, we act as a processor in that respect (section 2) - a backup of your server contains what is on it.

Customer systems run in two locations, both in Germany:

LocationOperator of the facilityWho operates the systems on it
our own premisesourselvesourselves
dedicated servers at Hetzner Online GmbHHetznerourselves

At both locations the systems are operated solely by us; Hetzner provides premises, power, connectivity and the hardware.

For availability monitoring we currently use Hyperping (Hyperping SAS, Paris, France; processing predominantly in Frankfurt am Main, Germany). Transmitted are the addresses of the systems to be checked and the measurement results. This service is being replaced by a solution we operate ourselves; the recipient falls away with that changeover.

The processing is based on the data processing agreement published by the provider, as amended from time to time.

6. Support

We handle enquiries about faults and change requests in our ticket system (Zammad). Your contact details, the content of your enquiry and the course of its handling are stored there.

The ticket system runs on a virtual server operated by us at Webdock ApS in the European Union; a data processing agreement is in place with the provider.

The purpose is to handle your request and to keep the business relationship traceable. The legal basis is Art. 6(1)(b) GDPR.

Handling a request may require access to your systems. This is done to perform the contract and, where data for which you are responsible is involved, solely on your instructions under the data processing agreement.

7. Access to your data at our end

Contract, billing and operational data is accessed by the managing director alone. No other persons are involved; there is no support department to which access is delegated, and no service provider holds administrative access to the systems.

This is not a limitation we regret but the single most effective safeguard in this document: the circle of those with access is as small as it can be.

8. Retention

WhatHow long
Contract and account datafor the duration of the contractual relationship
Invoices and records relevant for tax purposesfor the statutory retention periods, as a rule up to ten years (§ 147 AO, § 257 HGB)
Operational and security logs30 days. Longer only where they relate to a specific security incident, and then only until it is closed
Backupson a fixed generation plan: 13 daily, 8 weekly, 11 monthly and 3 yearly states. A backup leaves the set once its generation expires
Ticket systemdeleted once the matter is finally handled, at the latest after 24 months; longer only where commercial or tax retention obligations apply

What backups mean for erasure, and why it is stated here: If you request erasure of specific data, we remove it from the live systems. Individual items cannot technically be extracted from backups already taken - they disappear once the backup in question expires under the generation plan. Until then they are not processed further, only retained. For the yearly states this can take up to three years.

At the end of the contract we delete or return the data we process for you as a processor, at your choice; the data processing agreement sets out the details. This does not affect the data in sections 3 and 4 where statutory retention obligations apply.

After the contract ends, the systems remain unchanged for 30 days and can be restored at your request during that period. They are deleted thereafter. Backups expire under the generation plan set out above.

9. Recipients and sub-processors

RecipientFor whatRole
Webdock ApS, Denmarkvirtual server on which the ticket system runsprocessor
Hetzner Online GmbH, Germanydedicated servers running customer systemssub-processor; data processing agreement in place
Stripe Payments Europe, Limited (Ireland), with transfer to Stripe, LLC (USA)card payment processingprocessor
Hyperping SAS, Franceavailability monitoring; falls away with the move to our own solutionprocessor

No data is passed on for advertising purposes, and no data is sold.

Disclosure to public authorities takes place only where we are legally obliged to do so.

Changes to sub-processors are notified to you in advance in accordance with the data processing agreement so that you can object (Art. 28(2) GDPR).

You receive the data processing agreement together with the annex on technical and organisational measures as part of the contract; we also provide it beforehand on request.

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where processing is based on a legitimate interest, you have the right to object to it (Art. 21 GDPR).

An informal message to the address given in the Imprint is sufficient.

If a data subject whose data you process on your systems approaches us, we are not the right addressee - you are. We forward such requests to you and assist you in responding (Art. 28(3)(e) GDPR).

11. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority, in particular the authority of your habitual residence or the one responsible for us.

The authority responsible for us is that of the state in which we are established - following the Mannheim register court, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

12. Changes

This policy is amended when the processing described here changes. The version published here, bearing the date given above, is the applicable one.