DATA PROTECTION DECLARATION
EGhosting.de
Web hosting · Server · Domains · Software · Digital services
1. Accountable person
In charge of
The meaning of the General Data Protection Regulation (GDPR/AVG) is:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
E-mail: hello@eghosting.de
Website: https://eghosting.de
VAT identification number:
NL869888316B01
Subsequent
“eghosting.de”, “we” or “us”.
Unless otherwise
data protection officer, data protection requests can be sent directly to
the above e-mail address.
2. Scope and distribution of roles
2.1 These
Data protection declaration applies to the website eghosting.de, the customer account,
Ordering and support processes as well as the hosting, server,
Domain, software and digital services.
2.2 In the case of
Management of customer, contract, billing, support and security data
In principle, we act as responsible.
2.3 Processed into
Customer via a hosting or server service personal data of his own
User, visitor, employee or business partner, is in principle the
Customer and we are responsible – as far as the legal requirements are concerned
present – Processor. In this case, we close before the beginning of the
Processing an agreement on order processing in accordance with Article 28 GDPR.
This Privacy Policy does not replace such an agreement.
2.4 Is an external
Service providers are independently responsible for processing, apply
in addition to its data protection information.
3. Principles and legal bases
We process
personal data only if there is a legal basis for this. Y
after processing, we rely in particular on:
[if !supportLists]·[endif]Article 6(1)(a) GDPR: consent;
[if !supportLists]·[endif]Article 6(1)(b) GDPR: Contract performance or pre-contractual
measures;
[if !supportLists]·[endif]Article 6(1)(c) GDPR: fulfilment of legal obligations;
[if !supportLists]·[endif]Article 6(1)(f) GDPR: the protection of legitimate interests, provided that
the interests or fundamental rights of the data subject.
Beneficiaries
Interests can in particular be IT security, stability, abuse and
Fraud prevention, legal defense, improvement of our services and a
appropriate direct marketing to existing customers.
4. Visit of the website and server protocols
4.1 When calling the
Website can in particular IP address, date and time, accessed URL,
transmitted data volume, referrer URL, browser type, operating system,
device information and access status are processed.
4.2. Processing
is required to provide the Website, to prevent attacks and disruptions
detecting, analyzing errors and ensuring the security of systems
guarantee. The legal basis is Article 6 paragraph 1 letter f GDPR.
4.3
Security protocols are generally only stored as long as this
required for operation, fault analysis and security. In
security-related events may be affected protocols until
Final clarification and, where appropriate, legal proceedings
will become.
5. Encryption and security
5.1 The website
uses TLS encryption. An encrypted connection is regularly on
“https://” and the browser’s lock icon.
5.2 We meet under
consideration of risk, state of the art, implementation costs, type,
Extent and purpose of processing appropriate technical and organisational
Measures. For this purpose, access limits, encryption, logging,
backups, recovery procedures, security updates; and
Regular checks are required.
5.3 No procedure
It provides absolute security. Access data is confidential to the user
treatment; if abuse is suspected, they must be changed immediately and we are
to inform.
6. Cookies, local storage and consent management
6.1. We use
Cookies and similar technologies such as local storage, pixels or
device identifiers. For example, technically necessary technologies serve
registration, shopping cart, language settings, security, load distribution and
Storage of data protection settings.
6.2 Unconditionally
Required technologies do not regularly require consent. The
Processing of personal data is based on Article 6 as appropriate
Paragraph 1 letter b or f GDPR.
6.3 Analysis,
Marketing, personalization and tracking technologies are only available after
prior, voluntary consent activated, if no legal
Exception applies. The legal basis is Article 6 paragraph 1 letter a GDPR in
Connection with the applicable Dutch rules for access
on terminals, in particular the telecommunicatiewet.
6.4 Consent
can at any time with effect for the future via the available on the website
cookie or data protection settings can be revoked or changed.
Rejection must be as easy as consent. Not required
Technologies are not loaded before consent.
6.5 Concrete
Providers, purposes, data categories, storage periods and recipients are
Cookie overview of the consent manager currently shown.
Browser settings do not replace this transparent choice.
7. Contact, quote requests and support
7.1 Contact by
E-mail, form, telephone or ticket system we process in particular names,
Contact details, customer and contract numbers, content of the message, technical
Information, annexes and communication times.
7.2 Serves the request
a contract or pre-contractual measures, is legal basis Article 6
Paragraph 1 letter b GDPR. Otherwise, the processing is carried out on the basis of
our legitimate interest in a proper processing according to article
6 paragraph 1 letter f GDPR. Legally required documentation is based on
Article 6(1)(c) GDPR.
7.3 Support content
may contain sensitive information. Users should only transmit data,
which are necessary for processing and access data only about
provide for secure procedures.
7.4 Requests will be
deleted or anonymized after completion, unless they are
Contract performance, security, legal defence or legal storage
are needed.
8. Customer account and authentication
8.1 When equipped
and use of a customer account we process in particular name, address,
e-mail address, telephone number, login and security data, customer identifiers,
Orders, contracts, invoices, support processes and settings.
8.2 Legal basis
is Article 6 paragraph 1 letter b GDPR. Security protocols and measures
Account abuse shall be based in addition on Article 6(1)(f)
GDPR.
8.3 A customer account
may be terminated or its deletion requested. contractual,
Invoice, safety and demonstration data shall be kept independently of:
as far as legal obligations or legitimate reasons for immediate deletion
oppose it.
8.4 As far as an
multi-factor authentication is offered, we process the
Required key, token or device information exclusively for
Account security.
9. Registration by third parties
9.1 Will be on the
Website registration on: Googleor Meta/Facebook offered, is
In principle, a connection to the respective provider is only established if
the user selects this login type. Google+ is not used; and
Service has been discontinued.
9.2 Depending on the release
in particular, we receive a provider identifier, name, e-mail address and
if applicable, a profile picture. We only use the data that is required for registration
and account allocation are required. Legal basis for Article 6(1)
(b) GDPR; optional additional data will only be provided on the basis of
Consent according to Article 6 paragraph 1 letter a GDPR.
9.3 The user can
cancel the connection in the customer account and with the third party provider. This will make it
Our existing customer account is not automatically deleted. For processing
by the third party, its data protection notices apply.
10. Orders and execution of contracts
10.1 For orders
and contracts we process in particular identity and contact data,
billing and tax data, payment status, product and contract data,
IP address, time of order and required proof.
10.2 Legal bases
are Article 6 paragraph 1 letter b GDPR for contract performance and Article 6
Paragraph 1 letter c GDPR for tax, commercial, sanctions and other
legal obligations. Fraud and abuse investigations may be carried out under Article 6:
Paragraph 1 letter f GDPR.
10.3 Mandatory information
are marked as such. Without necessary information, an order can
where applicable, not completed or executed.
11. Hosting, server and e-mail services
11.1 To
Provision and assurance of the services we process depending on the product
in particular customer and contract identifiers, IP addresses, assignments of
resources, system and access protocols, traffic and usage metadata,
Configurations, fault data and support information.
11.2 Legal basis
is Article 6 paragraph 1 letter b GDPR. security, stability and
Abusive measures are additionally based on Article 6(1)(f)
GDPR and, as far as applicable, legal obligations according to article
6 paragraph 1 letter c GDPR.
11.3 Content that
Customers on their own hosting or server systems are stored by us
In principle, not evaluated for own purposes. Access only takes place,
as far as this is for the agreed administration, support, security,
security, misuse management or compliance with a lawful
arrangement is required.
11.4 At
Email services can provide technical metadata and automated
security information is processed to deliver messages and
Identify spam, malware and abuse. A substantive control
is only automated or event-related, as far as necessary and legal
Permitted.
12. Domains
12.1 For
Submit registration, management, renewal and transfer of domains
we provide necessary data to registrars, registrars and technical
service providers. Name, organisation, address, e-mail address,
Telephone number, domain name, registration data and technical contact details
belongs.
12.2 Legal basis
is Article 6 paragraph 1 letter b GDPR. by law or by binding
Assignment rules for given checks shall be based, where applicable, on Article 6(6)
1 letter c GDPR or our legitimate interest in a
proper registration in accordance with Article 6(1)(f) GDPR.
12.3 What data
appear publicly in registration services, depends on the specifications
the respective registry, registrar and applicable law. We
do not publish any additional data without a legal basis.
13. Digital products, software and licensing
13.1 For downloads,
We process software and licenses in particular customer and contract identifier,
Product, license key, activation data, permitted device or
Installation identifier, version and update information and technical
Error data.
13.2 Processing
serves provision, activation, license checking, updates, protection against abuse
and support. Legal bases are Article 6(1)(b) and, for
appropriate abuse and security measures, letter f GDPR.
13.3 Telemetry or
Analysis data not required for contract performance or security
are processed only on a separately communicated legal basis
and, if necessary, only after consent.
14. Payment processing
14.1 Depending on the
Checkout of actually offered and selected payment method we send
Required identity, contact, order, invoice, amount, currency
and transaction data to the respective payment service provider. Complete
In principle, card or bank access data is provided immediately to
Payment service providers, as far as the checkout is correspondingly integrated
is.
14.2 Possible
Payment service providers are:
[if !supportLists]·[endif]PayPal (Europe) S.à r.l. et Cie, S.C.A.,
Luxembourg;
[if !supportLists]·[endif]Stripe Payments Europe, Limited, Ireland;
[if !supportLists]·[endif]Mollie BV, Netherlands;
[if !supportLists]·[endif]Klarna Bank AB (publ), SwedenIf Klarna payment methods are offered
will become.
14.3 Legal basis
for the transmission for payment processing, Article 6(1)(b)
GDPR. Legal audit and storage obligations are based on Article 6
Paragraph 1 letter c GDPR. Fraud prevention may be referred to in Article 6(1):
letter f GDPR.
14.4
Payment service providers may act as independent responsible identity,
conduct fraud or credit checks. details, legal bases,
Recipients and data subject rights result from the checkout linked
Data protection notices of the selected provider.
14.5 One
Payment method that requires a credit check is identified as such
made. An exclusively automated decision with legal or
similar significant effect by us takes place only under the conditions of
Article 22 GDPR.
15. Accounting, taxation and enforcement
15.1 Invoicing,
Payment, contract and tax data are processed for accounting,
VAT, OSS and proof obligations. The legal basis is
Article 6(1)(c) GDPR.
15.2 Required
Data can be sent to tax consultants, auditors, banks,
payment service providers, financial authorities, courts, legal advisers or
debt collection service providers are transmitted, as far as this is required by law
or is necessary for the enforcement or defence of claims.
The legal basis is Article 6 (1) letters c and f GDPR.
15.3 Dutch
Basic accounting documents are generally kept for seven years.
For data covered by special tax regulations such as OSS, a
storage of ten years is required.
16. Newsletter and direct advertising
16.1 Newsletter
are generally only sent after voluntary consent. Notification
we regularly use a double opt-in procedure and store
Email address, time, IP address and proof of confirmation. Legal basis
is Article 6 paragraph 1 letter a GDPR; proof of consent is based
in addition to Article 6 paragraph 1 letter c or f GDPR.
16.2 Consent
can be revoked at any time via the unsubscribe link or by message to us
will become. The legality of the processing until the revocation remains unaffected.
16.3 If
legally permissible, we can send existing customers via email about our own similar
inform services. This can be objected to free of charge at any time.
Telephone advertising to consumers has been done since 1. July 2026 only with
prior consent, unless there is a legal exception.
16.4 After de-registration
the e-mail address can be stored in a block list for further
to prevent advertising. The blocked list is not used for other purposes.
17. Comments and Public Content
17.1 If a
Comment function is offered, we process the selected name,
Comment, time, email address and IP address. Posted content
and the displayed name is publicly available.
17.2 Processing
serves to provide the function, moderation, defense against abuse and
Legal defence. The legal basis is Article 6 paragraph
1 letter b or f GDPR.
17.3 Unlawful,
Abusive or in violation of the rules of use contributions can be examined,
restricted or deleted. Unpublished contact details will be
only if necessary and on a legal basis.
18. Analysis, advertising and social media
18.1 As far as Google Ads, Google AdSense,
Conversion tracking, meta/Facebook pixels, social plugins or similar
Services They will be used only after they have
Required consent activated. The old appeal to a mere
legitimate interest for personalized tracking is not used.
18.2 Depending on the
Service may include IP address, device and browser data, cookie or
advertising identifiers, pages visited, interactions, referrers, purchases and
Conversion events processed and with existing accounts of the provider
are linked.
18.3 Legal basis
is Article 6 paragraph 1 letter a GDPR. Consent can be given at any time via
the data protection settings are revoked. Specific providers, data,
Purposes, recipients and terms are listed in the consent manager.
18.4
Transfer social media links that only lead to external pages
Basically only when clicking on data to the provider. Embedded plugins,
Feeds or buttons with premature data transfer are only sent to
Consent loaded.
19 Google reCAPTCHA or abuse protection
19.1 If Google
reCAPTCHA is used to distinguish human input from
automated misuse, in particular IP address, device and browser data,
Interactions and technical identifiers transmitted to Google.
19.2 Because of the
possible access to the terminal and further processing by Google
In principle, the service shall only be provided with the consent referred to in Article 6(1):
letter a GDPR loaded, unless a
Legally consent-free, strictly necessary security configuration
is proven.
19.3 As
A more data protection-friendly alternative can be local or European
protection mechanisms are used. The service actually used is in
Designate consent managers.
20. Maps and External Content
20.1 If Google
Maps, videos, fonts, status pages or other external content
can be integrated, already during loading a connection to the respective
Providers are created. External content that is not technically necessary,
only after consent according to Article 6 paragraph 1 letter a GDPR
loaded.
20.2 Alternative
static placeholders or two-click solutions can be used. The
Users can actively unlock the content and are previously informed about providers and
possible data transmission informed.
21. Recipients and processors
21.1 Received data
only positions that they need for the respective task. This may include:
Employees, affiliates, data centres, infrastructure and
cloud providers, support and communications services, domain registrars,
payment service providers, accounting, tax and legal services,
security providers and authorities.
21.2
Processors shall be carefully selected, contractually in accordance with Article 28
GDPR and only used according to documented instructions.
Independent controllers receive data only with existing
Legal basis.
21.3 We sell
no personal data.
22. Transmissions outside the EEA
22.1 As far as data on
beneficiaries outside the European Economic Area;
This is only done under the conditions of Articles 44 to 49 GDPR.
22.2 For recipients in
a country with an adequacy decision, we base the transmission on
this Decision. For certified US companies, this can be done by the EU-US Data
The privacy framework.
22.3 Missing
adequacy decision, we use in particular the current
Standard contractual clauses of the European Commission and consider necessary
additional protective measures. In exceptional cases, a legal exception may be
in accordance with Article 49 GDPR.
22.4 The former
EU-US Privacy Shield is no longer used as a legal basis.
23. Storage time
23.1 We store
personal data only for as long as they are for the respective purpose
required or legal obligations, security interests or
request the assertion, exercise or defence of legal claims.
23.2 Typical
Criteria are duration of the contract, statutory limitation period, security relevance and
legal retention periods. In particular, in principle:
[if !supportLists]·[endif]Customer account:
until deletion or termination of the contract, then only
required residual data;
[if !supportLists]·[endif]contractual,
Invoicing and accounting data: regularly seven years, for relevant
OSS data 10 years;
[if !supportLists]·[endif]Evidence of consent
and blocked lists: as long as the proof or prevention
unwanted advertising is necessary;
[if !supportLists]·[endif]Support
and communication data: pending completion and beyond, if for
contract, security or legal rights required;
[if !supportLists]·[endif]Security protocols:
only for a period appropriate to the risk, in the case of incidents up to
final processing;
[if !supportLists]·[endif]Cookie
and tracking data: according to the term specified in the consent manager.
23.3 After the removal of the
For the purpose, data is deleted, anonymized or – with existing
Storage obligations – blocked for other uses.
24. Rights of data subjects
Data subjects
in accordance with the statutory requirements in particular have the following
Rights:
[if !supportLists]·[endif]Information
pursuant to Article 15 GDPR;
[if !supportLists]·[endif]Correction
pursuant to Article 16 GDPR;
[if !supportLists]·[endif]Deletion
pursuant to Article 17 GDPR;
[if !supportLists]·[endif]Restrictions
processing pursuant to Article 18 GDPR;
[if !supportLists]·[endif]Information
of recipients pursuant to Article 19 GDPR;
[if !supportLists]·[endif]Data portability
pursuant to Article 20 GDPR;
[if !supportLists]·[endif]Objection
pursuant to Article 21 GDPR;
[if !supportLists]·[endif]Revocation
consent with effect for the future in accordance with Article 7(3) GDPR;
[if !supportLists]·[endif]Protection
before exclusively automated decisions under Article 22 GDPR;
[if !supportLists]·[endif]Complaint
a data protection supervisory authority in accordance with Article 77 GDPR.
Requests may be made to: hello@eghosting.de directed.
In order to avoid unauthorized information, we may
Require identification. We generally answer questions within
one month; This time limit may apply in the case of complex or numerous applications after the
legal requirements are extended.
25. Right of appeal
shall be:
Personal data based on Article 6(1)(e) or (f)
GDPR may be processed by the data subject for reasons arising from his
a special situation, submit an objection at any time. We process
the affected data then no longer, unless we can
legitimate grounds which demonstrate the interests, rights and freedoms of
the data subject predominates, or the processing serves to assert,
Exercise or defence of legal claims.
Against the
Processing for direct marketing can be objected at any time without justification
will become. After the objection, the data will no longer be used for direct marketing
used.
26. Right of appeal and competent supervision
Data subjects
in particular to those for our Dutch headquarters
Apply the competent supervisory authority:
Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ The Hague
Netherlands
Website: https://autoriteitpersoonsgegevens.nl/
A complaint shall be:
also at the supervisory authority of the place of usual residence, workplace
or location of the alleged infringement. We ask that we first
provide an opportunity for direct clarification; This is not a condition for
a complaint.
27. Minors
Ours
Paid services are not provided without the necessary consent
to minors. Will Consent-Based Services Become Directly a Child
offered, we observe the applicable age and consent requirements.
If we obtain knowledge of unauthorized data of minors,
deleted or obtained the necessary consent.
28. Automated decisions
We meet
in principle not exclusively automated decisions that
have legal effect on a person or similarly
significant adverse effects. Where a payment service provider has a payment method:
automatically checks, if necessary acts on its own
Accountability and informs separately about logic, meaning and rights.
29 Obligation to provide data
The provision of
Personal data is required by law or contract to the extent
for identity verification, ordering, invoice, payment, domain registration,
provision of services or safety measures is required. Without mandatory information
We may not be able to conclude or fulfil the respective contract.
Voluntary information shall be marked accordingly.
30. Changes to this data protection declaration
We fit these
Data protection declaration if our procedures, used providers or
change the legal situation. The current version is on eghosting.de
retrievable. In the event of significant changes, we shall provide appropriate information,
for example on the website, in the customer account or by e-mail.
Status: 27.08.2026