Legal
Data Processing Agreement
under Art. 28(3) GDPR, part of the T&Cs (§ 12)
This is a courtesy English translation. The German version is legally binding; in case of any discrepancy, the German text prevails.
§ 1 Scope, contracting parties, conclusion
This agreement governs the processing of personal data by TryNxt (the "provider") on behalf of the customer. It applies to all services under the T&Csto the extent that the customer processes personal data of third parties on the booked servers. To that extent, the customer is the controller and the provider is the processor within the meaning of Art. 4(7) and (8) GDPR.
This agreement is incorporated via § 12 of the T&Cs and becomes part of the contract when the services are used for personal data of third parties, without any separate signature being required. Text form is sufficient (Art. 28(9) GDPR). The customer can retrieve, save and print this agreement at this address at any time.
This agreement does not cover the data the provider processes under its own responsibility to manage the customer account, for billing and for registering domains; theprivacy policy applies to those.
§ 2 Subject matter and duration
The subject matter of the processing is the provision of server infrastructure under § 2 of the T&Cs: virtual KVM servers and game servers, including booked add-on services (in particular backups via the backup function). The provider supplies compute, storage and network resources; which applications run on them and which data they process is determined solely by the customer, who has full administrator access to their servers. The provider does not process the content of the data.
The duration corresponds to the term of the respective service. The obligations under this agreement continue beyond that until the customer's data has been deleted in accordance with § 10.
§ 3 Nature and purpose of processing, type of data, data subjects
Nature of processing: storing the data on the virtual machines' disks, transmitting it within the provider's network, backing it up as part of the backup function used by the customer, and deleting it in accordance with § 10.
Purpose of processing: provision of the hosting services booked by the customer.
Type of personal data: all personal data the customer stores on or processes with the booked servers. Depending on the customer's application, this may include master, contact, contract, usage and communication data; special categories of personal data (Art. 9 GDPR) are not excluded.
Categories of data subjects: all persons whose data the customer processes on the booked servers, such as the customer's customers, prospects, users, employees and business partners.
The provider does not take note of the content of this data and therefore cannot determine its nature and scope itself. Before processing, the customer checks whether the measures described in Annex 1 are sufficient for their data; in particular, the customer encrypts particularly sensitive data within their servers themselves.
§ 4 Instructions
The provider processes the data only on documented instructions from the customer. The instructions are conclusively set out in the T&Cs, this agreement and the settings the customer makes in the customer area or via the application programming interface. The customer gives further instructions in text form to the contact address stated in the provider details. Instructions that go beyond the booked scope of services require a separate agreement.
The virtualisation layer technically allows access to the customer's servers. The provider uses this access exclusively for provisioning, maintenance and troubleshooting and to prevent abuse under § 8 of the T&Cs; in doing so, it does not routinely look at the content of the servers.
Where the provider is required to process data by Union or Member State law, it informs the customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
If the provider considers that an instruction infringes the GDPR or other Union or Member State data protection provisions, it informs the customer without undue delay (Art. 28(3) subparagraph 2 GDPR). It may suspend the execution of the instruction until the customer confirms or changes it.
Data is transferred to a third country or an international organisation only on documented instructions from the customer and in compliance with Art. 44 et seq. GDPR, unless the provider is required to do so by Union or Member State law; paragraph 3 then applies accordingly. The engagement of a subprocessor listed in § 7 that is established in or processes data in a third country also counts as an instruction, provided the list states the transfer mechanism.
§ 5 Confidentiality
The provider ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after their engagement ends.
§ 6 Security of processing
The provider takes the technical and organisational measures required under Art. 32 GDPR. They are described in Annex 1, including the measures that are currently not implemented.
The measures are subject to technical progress. The provider may replace them with equivalent or more effective measures; the level of protection set out in Annex 1 must not be reduced. Material changes are documented in Annex 1.
The customer is responsible for security within their servers — operating system, applications, credentials, firewall settings, encryption and their own data backups.
§ 7 Subprocessors
The customer grants the provider general authorisation to engage other processors (subprocessors). The subprocessors currently engaged are set out in the following list and are deemed approved.
| Company | Location | Purpose | Third country |
|---|---|---|---|
| Loading … | |||
The provider informs the customer in text form in advance of any intended addition or replacement of a subprocessor (Art. 28(2) sentence 2 GDPR). The customer may object to the change in text form within 14 days of receiving the information on legitimate data protection grounds. If the provider cannot remedy the objection, the customer is entitled to terminate the affected services as of the date the change takes effect; § 10 of the T&Cs applies accordingly to the paid but no longer provided part of the term.
The provider imposes on each subprocessor, by contract, the same data protection obligations as set out in this agreement, in particular sufficient guarantees to implement appropriate technical and organisational measures (Art. 28(4) GDPR). Where a subprocessor fails to fulfil its data protection obligations, the provider remains liable to the customer for the performance of that subprocessor's obligations.
Services the provider uses as purely ancillary services with no intended access to the customer's data, such as telecommunications and transport services, do not constitute subprocessing.
§ 8 Assistance with data subject rights
The customer can fulfil the rights of data subjects under Chapter III GDPR (in particular access, rectification, erasure, restriction and data portability) themselves using their administrator access. Where the customer requires the provider's cooperation for this, the provider assists the customer, taking into account the nature of the processing, by appropriate technical and organisational measures, insofar as this is possible.
If a data subject contacts the provider with a request that evidently concerns data on the customer's servers, the provider forwards it to the customer without undue delay. It does not respond to the request itself unless instructed by the customer.
§ 9 Assistance with obligations under Art. 32 to 36 GDPR
Taking into account the nature of processing and the information available to it, the provider assists the customer in ensuring compliance with the obligations under Art. 32 to 36 GDPR.
If the provider becomes aware of a personal data breach that affects or may affect the customer's servers or the data processed on them, it notifies the customer without undue delay (Art. 33(2) GDPR) by email to the address stored in the customer account. The notification contains, as far as known, the information under Art. 33(3) GDPR: the nature of the breach, the categories of data concerned and approximate number of records concerned, the likely consequences, and the measures taken or proposed. Information not yet available is provided subsequently without undue further delay.
The provider takes the containment measures available to it without undue delay and documents them. Notifying the supervisory authority and communicating the breach to data subjects under Art. 33 and 34 GDPR is the customer's responsibility; the provider makes the information it holds available to the customer for this purpose.
For a data protection impact assessment and a prior consultation of the supervisory authority (Art. 35, 36 GDPR), the provider makes the information it holds available to the customer on request, in particular on the measures in Annex 1 and on the subprocessors.
§ 10 Deletion and return after the end of the service
Throughout the entire term, the customer has full access to their servers and can download their data themselves at any time. Data is returned in this way; it is the customer's responsibility to back up their data before the service ends. The provider does not hand over the data separately.
After a service ends, the provider deletes the virtual machine, its disks and the backups created via the backup function on its storage system:
- If the service ends when the paid term expires, the server is first stopped and deleted afterseven days. Within this period, the customer can recover it by renewing (§ 6 of the T&Cs).
- If the service ends early at the customer's express request, in particular by withdrawal or deletion of the customer account, this period does not apply; the server is deleted without undue delay.
Deletion is carried out by removing the virtual disks and releasing the storage area for reuse; no overwriting or cryptographic erasure takes place (Annex 1). Afterwards, the provider can no longer restore the data. Only the assignment of the server to the customer account is retained as an accounting record (§ 147 German Fiscal Code, AO), without content, technical credentials or IP addresses. The provider is not required by Union or Member State law to store the data processed on the servers.
On request, the provider confirms the deletion to the customer in text form.
§ 11 Evidence and audits
The provider makes available to the customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. This is based on this agreement with Annex 1 and the list of subprocessors; the provider answers further questions on request in text form.
If this information is not sufficient in an individual case, the provider allows for and contributes to audits, including inspections, conducted by the customer or an auditor mandated by the customer who is bound to confidentiality. An inspection must be announced in text form with reasonable notice, as a rule at least two weeks, and takes place during normal business hours without disrupting operations. Data of other customers and the provider's trade and business secrets remain protected; an auditor who is in a competitive relationship with the provider may be rejected. Access to data centres is governed by the rules of their respective operator.
Each party bears its own costs arising from an audit. The powers of the supervisory authorities remain unaffected.
§ 12 Customer obligations
The customer is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. If the customer detects errors or irregularities in the provider's processing, they inform the provider without undue delay.
§ 13 Liability, precedence, final provisions
Liability towards data subjects is governed by Art. 82 GDPR; between the customer and the provider, Art. 82(4) and (5) GDPR apply. Otherwise, liability is governed by § 9 of the T&Cs, unless Art. 82 GDPR provides otherwise.
In the event of conflicts between this agreement and the T&Cs, the provisions of this agreement take precedence in matters of data protection.
§ 11 of the T&Cs applies accordingly to amendments of this agreement; changes of subprocessors are governed by § 7. Otherwise, § 12 of the T&Cs applies.
Annex 1 Technical and organisational measures (Art. 32 GDPR)
This annex describes the measures actually implemented. Where a measure is missing, this is expressly stated. The customer takes measures within their servers themselves (§ 6).
1. Confidentiality
Physical access control.
- The provider does not operate its own server rooms. Physical access lies with the respective data centre operator; its access controls apply.
System access control.
- Passwords for the customer area and administration are stored using bcrypt (cost factor 12).
- Sessions are based on 256-bit random tokens that are stored only as SHA-256 hashes and replaced on each renewal; access tokens are signed and valid for 15 minutes.
- Two-factor authentication (TOTP, passkeys) is available to all accounts and mandatory for staff with the support or administrator role.
- Login attempts are limited per IP address; after repeated failed attempts, the account is locked.
- Access to the application programming interface uses personal keys with per-server permissions that expire after one year at the latest.
- Requests to the administration interfaces are checked for permitted origin (CORS allowlist, CSRF protection).
- A server's initial password is stored encrypted and can be changed by the customer at any time; displaying the password is logged.
Data access control.
- Staff permissions follow a role model that is defined in the program code and cannot be changed at runtime.
- Staff with the support role can see customer data only after entering a support PIN provided by the customer, and only for a limited time.
- Particularly sensitive administrative operations require renewed confirmation with the second factor.
- Technical access to customer servers via the virtualisation layer is limited to the purposes stated in § 4.
Separation control.
- Each customer server is a separate virtual machine with its own disk.
- Each server receives its own IPv6 /64 network; this prevents the use of other customers' addresses.
- Database queries in the customer area are restricted to the requesting account; authorisation is checked server-side.
Encryption and pseudonymisation.
- All interfaces are accessible only via HTTPS; emails are sent with enforced STARTTLS and certificate validation.
- Stored secrets (including initial server passwords and credentials for third-party systems) are stored encrypted.
- IP addresses and device identifiers in logs are automatically deleted after 90 days.
- Not implemented: encryption of the database at rest, and encryption or cryptographic erasure of customer server disks. The customer should encrypt particularly sensitive data within their servers themselves.
2. Integrity
- Database access takes place exclusively via parameterised queries.
- Administrative changes are logged with the state before and after the change and the acting person.
- Accounting and log data are protected by database triggers against deletion and subsequent modification; only clearing anonymisation fields after the retention period is permitted.
- Data is disclosed to authorities only on a documented order and such disclosures are logged separately.
3. Availability and resilience
- The administration database is backed up automatically; backups are retained for 30 days.
- Customer servers are backed up only as part of the backup function and its booked scope; this does not replace the customer's own data backup (§ 2 of the T&Cs).
- Expired servers remain recoverable for seven days (§ 10).
- Background services are monitored; repeated failures trigger a notification.
- Public endpoints are protected by rate limits, and forms without login additionally by bot protection.
- Not implemented: a documented and tested recovery procedure with targets for recovery time and data loss; regular restore tests do not take place.
4. Procedures for regular review
- A record of processing activities and a data breach notification process are in place and are updated when the system changes.
- Subprocessors are kept in a list; changes to it are logged.
- Security, logic and legal reviews are carried out with review records; automated tests safeguard data-protection-relevant processes on every change.
- Customer accounts are deleted via a single routine, regardless of who triggers the deletion.
5. Open items
- Encryption of the database at rest: not implemented.
- Cryptographic erasure of server disks: not implemented; the storage area is released without overwriting.
- Tested recovery procedure: backups exist, restore tests not set up.
- Checking passwords against lists of compromised passwords: not implemented.
- Default firewall settings for customer servers: not documented; the customer configures the firewall within the server.