Legal
Privacy Policy
This is a courtesy English translation. The German version is legally binding; in case of any discrepancy, the German text prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
–
Represented by:
Loading provider details …
The provider details could not be loaded right now. Please reload the page or contact us directly.
A data protection officer has not been appointed, as the legal requirements for this (§ 38 BDSG, German Federal Data Protection Act) are not met.
2. Principles of data processing
We process personal data on the following legal bases:
- Art. 6(1)(b) GDPR — performance of a contract and pre-contractual measures (registration, ordering, support)
- Art. 6(1)(c) GDPR — compliance with legal obligations (tax and commercial law, GoBD, Digital Services Act)
- Art. 6(1)(f) GDPR — legitimate interests (IT security, abuse prevention, operational stability)
3. Provision of the website and server log files
Every time you access our website and customer area, we automatically collect technical information: IP address, date and time, requested URL, HTTP status code, user agent and referrer. This processing serves to deliver the page, defend against attacks and investigate cases of misuse (Art. 6(1)(f) GDPR). These web server access logs are deleted after 30 days at the latest, unless a security-relevant incident requires longer retention. What our application itself logs is set out in section 11.
4. Registration and customer account
A customer account is required to use our server, game server and domain products. For this we process: username, email address, password (as a hash, never in plaintext), and — when ordering paid services — billing address and order data. The basis is Art. 6(1)(b) GDPR.
For login we additionally offer two-factor authentication (TOTP) and passkeys (WebAuthn). Passkey key material stays on your device or in your password manager; we only store the public key for verification, no third parties are involved.
5. Payment processing
We process balance top-ups through our payment service provider Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands. In doing so, we transmit to Mollie the amount, the chosen payment method and a payment reference containing your customer number; you enter your payment data (such as card or account details) directly on Mollie's page, and it does not reach us. The basis is Art. 6(1)(b) GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place. More information:mollie.com/en/privacy.
5a. Identity verification for payouts
If you ask us to pay out balance, we generally refund via the payment methods you used to top up — no additional data is collected in that case. Only if this is no longer possible and there are reasonable doubts as to whether the payout is going to the entitled person (for example because the stated account holder differs from the data you have on file) do we ask you for proof of identity.
The sole purpose is to avoid paying out your balance to an unauthorised person: we are only discharged from our obligation if we perform to the person actually entitled (§ 362 BGB, German Civil Code). The legal basis is Art. 6(1)(b) GDPR (fulfilment of the repayment claim) and Art. 6(1)(f) GDPR (legitimate interest in fraud prevention). We are not subject to a statutory identification obligation under the German Anti-Money Laundering Act (Geldwäschegesetz) — we are not among the obliged entities listed there.
For this we only need your name, address, date of birth and the validity of the document.Black out all other information, in particular the ID card number and serial number as well as the card access number; under § 20(2) of the German Identity Card Act (Personalausweisgesetz) we are not permitted to use these in any case. We delete the proof immediately after the check — it is not an accounting record; the payout itself is documented by the amount, date and bank transfer. We only record that and when a check took place.
6. Domain registration
When you order a domain, we transmit the holder and contact data required for registration (Whois data) to our domain registrar service provider (DomainRobot / InterNetX GmbH) as well as to the registry responsible for the chosen domain extension. These entities process the data as independent controllers in accordance with their own registration terms. The basis is Art. 6(1)(b) GDPR.
The registries operate public directory services (WHOIS or RDAP). Depending on the extension and your role as holder, your name, address, email address and telephone number may be publicly retrievable there; for .de, holder data is currently not displayed publicly but can be retrieved where there is a legitimate interest. The scope and duration are determined by the requirements of the respective registry and ICANN — we have no influence on this. The information is mandatory for registration; without it, a domain cannot be registered (Art. 6(1)(b) GDPR).
7. Bot and spam protection (Cloudflare Turnstile)
To protect login, registration and forms from automated abuse, we use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. This processes your IP address and browser characteristics to distinguish automated access from human use. The basis is Art. 6(1)(f) GDPR (protection against abuse). On the transfer to the US, see section 10a. More information:cloudflare.com/privacypolicy.
8. Email delivery
We send transactional and support emails (order confirmations, invoices, security notices, ticket replies) through our own mail infrastructure. We do not pass data on to external email marketing providers.
9. Server and hosting infrastructure
We operate the servers you book (KVM, game servers) on our own or leased infrastructure at locations in Germany and the Netherlands. You, as the customer, are responsible under data protection law for any content you store yourself on a booked server; we process this content solely to provide the hosting service.
9a. Technical access to your servers and deletion
You receive full administrator access (root) on booked servers. So that a server can be provided at all, we generate an initial password and store it in encrypted form; you can change it at any time. Beyond that, there is a technical possibility of accessing the server via the virtualisation layer (Proxmox/QEMU Guest Agent) — this is the case with every form of virtual hosting and cannot be switched off.
We use this access exclusively for provisioning, maintenance and troubleshooting, to defend against abuse, or on the basis of a legal obligation. Access by our staff is logged. We do not routinely look at the contents of your virtual machine in the process; anyone processing particularly sensitive data should additionally encrypt it themselves.
When a server ends, the virtual machine, the associated storage volumes and the backups on the storage system are deleted and the occupied storage area is released for reuse. The assignment of the server to your account that we keep is retained as an accounting record (§ 147 AO, German Fiscal Code), without technical access data.
Separately, we record which IP addresses your server had and from when to when. After a server ends, its IP addresses are passed on to other customers, but abuse reports and requests from authorities often concern a point in the past. Without this history we could not attribute them to the right contract, and the current holder of the same address would come under suspicion wrongly. We store only the address, the server, the customer account and the two points in time. The legal basis is Art. 6(1)(f) GDPR. We delete the entry one year after the address was released, even if you delete your customer account before then (Art. 17(3)(e) GDPR).
9b. Security notifications
For security-relevant events on your account — sign-in from a new device, password change, creation of an API key — we send you a notification stating the time and IP address of the event. This serves your own oversight and is based on Art. 6(1)(f) GDPR (security of processing, Art. 32 GDPR). The underlying log entries are subject to the period stated in section 11.
9c. Traffic measurement for your server
We measure the data volume transferred for every server. We record only the totals of inbound and outbound bytes per server and billing period, together with the time of measurement.For this purpose we do not analyse the contents, destinations or remote endpoints of your connections — the figures come from the hypervisor's counters, not from the traffic itself. For the detection of attacks originating from a server, see section 9d.
The measurement serves the performance of the hosting contract: it evidences your consumption against an agreed traffic quota and is the basis for any throttling. The legal basis is Art. 6(1)(b) GDPR. The measurement runs on our own infrastructure (section 9); no external service provider is involved.
Counters are reset at the start of each billing period. Records of when a traffic threshold was reached and what was done in response are deleted after 90 days.
Discord notifications (optional). In your server's settings you may store a Discord webhook address. If you do, we transmit your server's name, the measured consumption and any throttling to Discord (Discord Netherlands B.V., Amsterdam; parent company in the USA) when a traffic threshold is reached. This transfer happens solely because you bring it about yourself by storing the address — the legal basis is your consent under Art. 6(1)(a) GDPR. You can remove the address at any time, which ends the transfer going forward. Without a stored address, no transfer takes place.
9d. Detection of attacks originating from your server
To prevent attacks on third-party systems from originating from our servers, a monitoring program runs on every virtualisation node. Every 30 seconds it counts the packets and bytes each server sends and receives, and it evaluates the node's connection table: destination IP address, destination port, whether a connection was established and how many packets it carried; for requests sent to your server via UDP, also the sender address. We do not analyse the contents of your connections. The evaluation is automatic. Data is only stored when a pattern indicating an attack is detected — a denial-of-service (DoS) attack, the use of an open service on your server as an amplifier, a port scan, mass login attempts (brute force), bulk email sending or signs of crypto mining. In that case we store the measured values, the main target affected (IP address and port), the time period and the reasoning.
The purpose is the security of our network and the protection of third parties. The legal basis is Art. 6(1)(f) GDPR — preventing denial-of-service attacks is a recognised legitimate interest (Recital 49 GDPR) — and the enforcement of section 8 of our Terms (Art. 6(1)(b) GDPR). We process the IP addresses of attacked systems on the same basis.
Depending on the location, a detected attack may automatically lead to us blocking your server's outgoing traffic, disconnecting it from the network, stopping it or temporarily locking its management (section 8 of our Terms), and to us contacting you by email or opening a ticket about it in your customer account. Insofar as this constitutes an automated decision within the meaning of Art. 22 GDPR, it is necessary for the performance of the contract (Art. 22(2)(a) GDPR): it ends an ongoing attack before third parties suffer harm and the data centre disconnects our network. You are notified without undue delay with a statement of reasons, and you may at any time request that a member of staff reviews the block, express your point of view and contest the block (Art. 22(3) GDPR) — most easily via a support ticket.
Findings are deleted one year after the last detection; measurements without a finding are not stored. The evaluation runs on our own infrastructure; no external service provider is involved.
10. Cookies and local storage
We use one cookie and a few entries in your browser's local storage (LocalStorage). All of them are technically necessary or store a setting you made yourself; no consent is required for them (§ 25(2) No. 2 TDDDG).
| Name | Purpose | Legal basis |
|---|---|---|
refresh-token | Sign-in/session in the customer area (httpOnly) | § 25(2) No. 2 TDDDG |
trynxt.cookie-consent | Remembers that you have seen the notice on your first visit (LocalStorage) | § 25(2) No. 2 TDDDG |
trynxt.cart | Identifier of your shopping cart, also without signing in (LocalStorage) | § 25(2) No. 2 TDDDG |
trynxt.theme, trynxt.locale, trynxt.a11y | Display, language and accessibility settings you chose (LocalStorage) | § 25(2) No. 2 TDDDG |
cf-turnstile | Bot protection on login/registration (see section 7) | Art. 6(1)(f) GDPR |
We do not use any cookies or storage entries beyond those listed above. There are no analytics, reach-measurement or marketing services. Because all storage is technically necessary (§ 25(2) No. 2 TDDDG, German Telecommunications Digital Services Data Protection Act), no consent is required for it; the notice on your first visit serves solely to inform you. Should we use reach measurement in the future, we will obtain your consent for it beforehand and add it to the table above.
10a. Transfers to third countries
Our servers and the services we use to process your data are located in the European Union as a rule. A transfer to a country outside the EU and the EEA only occurs where we use a service whose provider is established in a third country. Currently this concerns onlyCloudflare, Inc. (USA) for bot protection (section 7).
Cloudflare is certified under the EU-US Data Privacy Framework. That transfer is therefore covered by an adequacy decision of the European Commission of 10 July 2023 (Art. 45(1) GDPR); alongside an adequacy decision, no additional safeguard is required. In addition, and in case the certification lapses or the decision is annulled, we have agreed the European Commission's Standard Contractual Clauses with Cloudflare (Implementing Decision (EU) 2021/914) — Art. 46(2)(c) GDPR.
Which further providers we use, in which country they process, and what any third-country transfer is based on, can be found at any time in the list of subprocessors in thedata processing agreement; it is kept up to date.
11. Retention periods
We retain invoices and accounting records for 10 years (§ 147 AO / GoBD), business correspondence including the sent-email archive for 6 years (§ 257 HGB, German Commercial Code). We also retain logs of interventions by our staff (changes to accounts, bookings, permissions and settings) for 10 years so that changes to accounting-relevant data remain traceable (§ 146(4) AO), and delete them automatically afterwards.
Irrespective of these periods, we delete additional personal information earlier as soon as its purpose has been fulfilled (Art. 5(1)(e) GDPR):
- IP addresses and device identifiers in log and booking data areautomatically deleted after 90 days. This also applies to the IP address recorded with an order or payment: the record itself is retained for ten years, the IP address is not.
- Application logs and the action logs of your servers (start, stop, reinstallation and the like) are deleted after 90 days, change logs for domains, system events, findings of the attack detection (section 9d) and messages in the customer area after one year, the history of IP assignments (section 9a) one year after the address was released.
- The security log of your account (sign-ins, password and two-factor changes, see section 9b) and the records of the notice on your first visit are deleted after three years — the period in which claims arising from unauthorised access can be asserted (§ 195 BGB). The IP address and device identifier in them are removed after 90 days already.
- Closed support tickets are deleted as soon as the regular limitation period has expired — three years from the end of the year of the last processing (§ 195 in conjunction with § 199(1) BGB). Open tickets are not deleted automatically.
- When you delete your customer account, we remove or anonymise your personal data immediately, including the ticket texts you wrote. Only the data subject to a statutory retention obligation is retained, and the history of IP assignments (section 9a) until its period expires.
12. Your rights
Under the GDPR you have the following rights:
- Access to the personal data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR), unless a retention obligation applies
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of a given consent with effect for the future
You can correct your contact details and your email address yourself in the customer area under Account. We change your username for you on request by email.
A direct export tool for your account data is available in the customer area under Account → Privacy; it provides your master, order, invoice and log data as a JSON file. You can also delete your account yourself there.
You exercise all other rights — in particular restriction of processing under Art. 18 GDPR and objection under Art. 21 GDPR — informally by email; we implement them manually and reply to you within one month (Art. 12(3) GDPR). This also applies to the deletion of a suspended account: a suspension prevents login and thus self-deletion — your right to erasure remains unaffected; simply write to us.
On request, in addition to the copy of your data, you will receive the information under Art. 15(1) GDPR in text form: purposes of processing, categories of data, recipients, envisaged storage period and the source of the data.
For all of this you can reach us at:
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. Generally, this is the authority in your habitual place of residence or the authority responsible for us:
Note: Provider address and supervisory authority are still placeholders — please complete them in the admin panel under company settings.