This English translation is provided for convenience only. In case of any discrepancy, the German version shall prevail.
1. Privacy at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our Privacy Policy set out below this text.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section “Note on the Responsible Entity” in this Privacy Policy.
How do we collect your data?
Some of your data is collected because you provide it to us, for example data that you enter into a contact form.
Other data is collected automatically or after your consent when you visit the website, by our IT systems. This is mainly technical data (e.g., internet browser, operating system or time of the page visit). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure that the website is provided without errors. Other data may be used to analyze your user behavior. Where contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders or other requests for services.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and other questions on the topic of data protection.
Analytics Tools and Third-Party Tools
When you visit this website, your browsing behavior may be statistically evaluated. This is done primarily using so-called analytics programs.
Detailed information on these analytics programs can be found in the following Privacy Policy.
2. Hosting
Cloudflare
We use services of Cloudflare on our website. The provider is Cloudflare Germany GmbH, Rosenheimer Straße 143C, 81671 Munich, Germany.
Cloudflare provides a globally distributed content delivery network (CDN), DNS services and security features such as DDoS protection and a web application firewall. This allows the content of our website to be delivered faster and helps us better defend against attacks, abusive access and technical disruptions.
When our website is accessed, Cloudflare may in particular process IP addresses, access times, requested URLs, HTTP headers, device and browser information and other technical connection data. This processing is necessary to ensure the security, stability and performance of our website.
Cloudflare is used on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, fast and reliable provision of our online offering and in protection against attacks and abusive use.
Where Cloudflare uses cookies or comparable technologies that are technically necessary for the provision and security of the website, this is done on the basis of Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act). Where consent is required, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG; consent can be revoked at any time.
We have concluded a data processing agreement with Cloudflare. Further information on data processing by Cloudflare can be found in Cloudflare's privacy policy at: https://www.cloudflare.com/privacypolicy/.
We host the content of our website with the following provider:
External Hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses and other data generated via a website.
External hosting is carried out for the purpose of performing our contract with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Our host(s) will process your data only to the extent necessary to fulfill their performance obligations and will follow our instructions with regard to this data.
We use the following host(s):
TrafficPlex GmbH
Konsul-Smidt-Str. 90
28217 Bremen, Germany
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this Privacy Policy.
When you use this website, various personal data is collected. Personal data is data that can be used to personally identify you. This Privacy Policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet (e.g., when communicating by email) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Note on the Responsible Entity
The entity responsible for data processing on this website is:
Friedl & Friedl GbR
Represented by: Erik Friedl
Vetschauer Straße 19
01237 Dresden
Phone: +49 152 59511637
Email: [email protected]
The responsible entity is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses or the like).
Conclusion of Data Processing Agreements (DPA)
We offer all of our customers (regardless of whether they registered as a private or business customer) the option to conclude a data processing agreement (DPA) with us pursuant to Art. 28(3) GDPR. This is particularly necessary if you use our hosting services to process personal data of third parties.
The agreement is concluded conveniently and digitally, directly in your customer portal at: https://nexthosting.net/account/settings.
There you can individually select the categories of data that apply to your use (e.g., master data, communication data, log data) as well as the group of data subjects (e.g., your own customers or website visitors) and generate the agreement. After confirmation, the agreement is permanently stored in your customer account so that you can meet your obligations to provide evidence to the supervisory authorities.
Receivables Management and Debt Collection (paywise)
If receivables arising from the contractual relationship remain unpaid despite a reminder, we reserve the right to transmit the data required to collect the receivable (name, address, email address, contract and invoice data, and the amount of the receivable) to a debt collection service provider. Our partner for receivables management is: paywise GmbH, Bahnhofstr. 95, 82166 Gräfelfing. The data is disclosed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the effective enforcement of our lawful claims for payment. In the event of an assignment of the receivable, the legal basis is Art. 6(1)(b) GDPR.
Storage Period
Unless a more specific storage period is stated within this Privacy Policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will take place once these reasons no longer apply.
General Information on the Legal Bases for Data Processing on This Website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, where special categories of data pursuant to Art. 9(1) GDPR are processed. In the event of express consent to the transfer of personal data to third countries, data processing is also based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to the access to information on your end device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where this is required to fulfill a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6(1)(f) GDPR. The legal bases that apply in each individual case are explained in the following paragraphs of this Privacy Policy.
Recipients of Personal Data
In the course of our business activities, we work with various external parties. In some cases, this also requires the transmission of personal data to these external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the disclosure of data. When using processors, we only disclose our customers' personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke any consent you have already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
Access, Rectification and Erasure
Within the framework of the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to rectification or erasure of this data. You can contact us at any time regarding this and other questions on the topic of personal data.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
- If you contest the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you can request the restriction of data processing instead of erasure.
- If we no longer need your personal data, but you need it for the exercise, defense or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data – apart from being stored – may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.
If SSL/TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Disclosure of Data for Domain Registrations
When registering domains, we transmit the required data (e.g., name, address, email) to the respective registries (e.g., DENIC for .de domains). This is absolutely necessary for the performance of the contract (Art. 6(1)(b) GDPR).
4. Data Collection on This Website
Registration on This Website (Customer Portal)
You can register on our website to use our hosting services. We distinguish between registration as a private customer (B2C) and as a business customer (B2B).
Scope of data processing: The data you enter into the input form during registration is transmitted to us and stored. Depending on the customer type you choose, we collect:
-
For private customers: name, address, email address and, where applicable, telephone number.
-
For business customers: in addition to the data above: company name, legal form, authorized representatives and the VAT identification number (VAT ID).
Purpose of processing: Registration serves to open a customer account through which contracts can be concluded, managed and invoiced. The business data of B2B customers is also collected to verify business status and for correct tax treatment (in particular for intra-Community supplies and services).
Legal basis: The data is processed on the basis of Art. 6(1)(b) GDPR for the performance of a contract or for the implementation of pre-contractual measures.
Storage period: The data collected during registration is stored by us for as long as you are registered on our website. Statutory retention periods (e.g., 10 years for invoice data under the German Fiscal Code (AO) and Commercial Code (HGB)) remain unaffected.
Orders, Fraud Prevention and Risk Assessment (FraudLabs Pro)
To prevent payment defaults, abusive orders and fraud, we use FraudLabs Pro. The provider is Hexasoft Development Sdn. Bhd., 70-3-30A D'Piazza Mall, Jalan Mahsuri, 11950 Bayan Baru, Pulau Pinang, Malaysia.
As part of the check, order, contact, device, connection and transaction data in particular may be processed. This includes in particular name, email address, telephone number, billing and delivery address, IP address, device information or device fingerprint, order value, payment information, transaction characteristics and risk-related check results.
The processing is carried out for the purpose of fraud prevention, detection of abuse, risk assessment of orders and avoidance of payment defaults. The legal basis is Art. 6(1)(f) GDPR. Where the processing is necessary for the decision on the conclusion or performance of a contract, it is additionally based on Art. 6(1)(b) GDPR.
A check is carried out in particular for orders with an increased risk and – where technically configured in our checkout – for orders with a value of €50.00 or more.
We reserve the right, based on the result of the check, to subject orders to an extended review, to put them on hold or to release them only subject to additional verification measures.
Further information on data processing by FraudLabs Pro can be found in the provider's privacy policy at https://www.fraudlabspro.com/privacy-policy.
Cookies
Our websites use so-called “cookies”. Cookies are small data packets and do not cause any damage to your end device. They are stored on your end device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are deleted automatically at the end of your visit. Persistent cookies remain stored on your end device until you delete them yourself or until they are deleted automatically by your web browser.
Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g., the cart function or the display of videos). Other cookies may be used to evaluate user behavior or for advertising purposes.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g., for the cart function) or to optimize the website (e.g., cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing takes place exclusively on the basis of this consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies on a case-by-case basis, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when you close the browser. If cookies are disabled, the functionality of this website may be limited.
You can find out which cookies and services are used on this website in this Privacy Policy.
Contact Form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to its storage or the purpose for the data storage no longer applies (e.g., after your inquiry has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Inquiries by Email, Telephone or Fax
If you contact us by email, telephone or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be revoked at any time.
The data you send to us via contact requests will remain with us until you request its deletion, revoke your consent to its storage or the purpose for the data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Comment Function on This Website
For the comment function on this site, in addition to your comment, information on the time the comment was created, your email address and, if you do not post anonymously, the username you have chosen will be stored.
Storage of the IP Address
Our comment function stores the IP addresses of the users who write comments. As we do not review comments on this website before they are published, we need this data in order to be able to take action against the author in the event of legal violations such as insults or propaganda.
Subscribing to Comments
As a user of the site, you can subscribe to comments after logging in. You will receive a confirmation email to verify that you are the owner of the email address provided. You can unsubscribe from this function at any time via a link in the info emails. In this case, the data entered as part of subscribing to comments will be deleted; however, if you have transmitted this data to us for other purposes and elsewhere (e.g., newsletter subscription), it will remain with us.
Storage Period of the Comments
The comments and the associated data are stored and remain on this website until the commented content has been completely deleted or the comments have to be deleted for legal reasons (e.g., offensive comments).
Legal Basis
The comments are stored on the basis of your consent (Art. 6(1)(a) GDPR). You can revoke any consent you have given at any time. An informal notification by email to us is sufficient for this purpose. The lawfulness of the data processing operations already carried out remains unaffected by the revocation.
5. Social Media
This website includes functions of the Instagram service. These functions are offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your end device and the Instagram server. As a result, Instagram receives information about your visit to this website.
If you are logged in to your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. Please note that, as the provider of these pages, we do not receive any knowledge of the content of the transmitted data or of how it is used by Instagram.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website by means of the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook or Instagram. The processing carried out by Facebook or Instagram after the forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. You can find the text of the agreement at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook or Instagram tool and for the implementation of the tool on our website in a manner that is safe under data protection law. Facebook is responsible for the data security of the Facebook and Instagram products. You can assert data subject rights (e.g., requests for information) regarding the data processed by Facebook or Instagram directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
The data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de- de.facebook.com/help/566994660333381.
Further information can be found in Instagram's privacy policy: https://privacycenter.instagram.com/policy/.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
Discord (Support Server, Community and Gaming Area)
We operate official Discord servers, in particular the “Nexthosting” server, through which customers can receive support, as well as further community and gaming servers operated by us.
If you contact us via Discord, join one of our Discord servers or use functions there such as tickets, direct messages, voice channels or community areas, we process the data that you voluntarily provide in this context. This may include in particular your Discord username, your Discord ID, server and role information, communication content, uploaded files and other information you provide.
The processing is carried out to handle support requests, to communicate with prospective customers and customers, for community and server management, for moderation and to ensure IT and operational security. The legal basis is Art. 6(1)(b) GDPR, insofar as the communication serves to initiate or perform a contract, and otherwise Art. 6(1)(f) GDPR.
Please note that Discord also processes your personal data under its own responsibility under data protection law. Further information can be found in Discord's privacy policy at https://discord.com/privacy.
Where our website merely contains an external link or an invitation to Discord, data is generally only transmitted to Discord once you actively click on this link or actually use Discord.
6. Analytics Tools and Advertising
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses so-called “cookies”. These are text files that are stored on your computer and that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
IP anonymization: We have activated the IP anonymization function on this website. As a result, your IP address is truncated by Google within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA.
Legal basis: The storage of Google Analytics cookies and the use of this analytics tool are based on Art. 6(1)(a) GDPR. Consent can be revoked at any time.
Objection to data collection: You can prevent the collection of your data by Google Analytics by clicking the following link. An opt-out cookie will be set, which prevents the collection of your data during future visits to this website: Disable Google Analytics.
More information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Google Ads and Google Ads Conversion Tracking
We use Google Ads. In this context, we may use Google Ads conversion tracking and, where activated, other measurement and remarketing functions from Google.
If you reach our website via a Google ad, Google may store or read a recognition technology on your end device, or measurement signals may be processed, in order to measure the success of our advertising campaigns. In particular, it may be tracked whether you have visited certain pages or performed certain actions (e.g., registration, order or contact request).
This service is used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be revoked at any time.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Further information on how Google processes data from websites that use Google services can be found at https://policies.google.com/technologies/partner-sites?hl=de and in Google's privacy policy at https://policies.google.com/privacy?hl=de.
Trustpilot
We use the review platform Trustpilot on our website. The provider is Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark.
Trustpilot widgets (Trustboxes)
We embed so-called Trustboxes on our website to display the customer reviews we have collected. When you visit a page of our website that contains such a Trustbox, your browser establishes a direct connection to Trustpilot's servers. Among other things, your IP address and device- and browser-specific information are transmitted to Trustpilot. These widgets are used on the basis of our legitimate interest in the transparent presentation of our customers' opinions and in building trust in our services (Art. 6(1)(f) GDPR). Where corresponding consent (e.g., via a cookie banner) has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG; consent can be revoked at any time.
Review invitations
If you have given us your express consent pursuant to Art. 6(1)(a) GDPR during or after your order, we transmit your email address, your name and a reference number (e.g., order or customer number) to Trustpilot so that they can send you a review invitation by email. You can revoke this consent at any time with effect for the future by contacting us or by using the unsubscribe link in Trustpilot's review invitation.
Further information on how your data is handled can be found in Trustpilot's privacy policy at: https://de.legal.trustpilot.com/for-reviewers/end-user-privacy-terms.
ProvenExpert
We use a review seal or widget from ProvenExpert on our website. The provider is Expert Systems AG, Quedlinburger Straße 1, 10589 Berlin, Germany.
The ProvenExpert widget is used to display customer reviews and trust indicators about our company on our website. When you visit a page on which the widget is embedded, your browser may establish a connection to ProvenExpert's servers. In particular, technical data such as your IP address, date and time of the visit, the page visited, referrer URL, browser type and version, operating system and other technical connection data may be transmitted to ProvenExpert.
ProvenExpert is embedded on the basis of our legitimate interest in the transparent presentation of customer reviews, in building trust among prospective customers and customers, and in optimizing our online offering (Art. 6(1)(f) GDPR).
Where ProvenExpert uses cookies or comparable technologies that are not technically necessary, processing takes place exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be revoked at any time via the cookie settings.
If you actively submit a review via ProvenExpert or interact with the ProvenExpert profile, ProvenExpert processes the data you provide in the process under its own responsibility under data protection law. Further information on data processing by ProvenExpert can be found in ProvenExpert's privacy policy at: https://www.provenexpert.com/de-de/datenschutzbestimmungen/.
WP Statistics
This website uses the analytics tool WP Statistics to statistically evaluate visitor accesses. The provider is Veronalabs, Tatari 64, 10134, Tallinn, Estonia (https://veronalabs.com).
WP Statistics allows us to analyze the use of our website. In doing so, WP Statistics collects, among other things, log files (IP address, referrer, browsers used, origin of the user, search engine used) and actions that website visitors have taken on the site (e.g., clicks and views).
The data collected with WP Statistics is stored exclusively on our own server.
This analytics tool is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the anonymized analysis of user behavior in order to optimize both our web offering and our advertising. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
IP Anonymization
We use WP Statistics with anonymized IP addresses. Your IP address is truncated so that it can no longer be directly attributed to you.
7. Plugins and Tools
Google Fonts (Local Hosting)
To ensure a uniform display of fonts, this site uses so-called Google Fonts, which are provided by Google. The Google Fonts are installed locally. No connection to Google servers is established in the process.
Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Font Awesome (Local Hosting)
To ensure a uniform display of fonts, this site uses Font Awesome. Font Awesome is installed locally. No connection to Fonticons, Inc. servers is established in the process.
Further information on Font Awesome can be found in the Font Awesome privacy policy at: https://fontawesome.com/privacy.
MyFonts
This site uses MyFonts. These are fonts that are loaded into your browser when you visit our website in order to ensure a uniform typeface in the display of the website. The provider is Monotype Imaging Holdings Inc., 600 Unicorn Park Drive, Woburn, Massachusetts 01801, USA.
To verify compliance with the license terms and the number of monthly page views, MyFonts transmits your IP address together with the URL of our website and our contract data to its servers in the USA. According to Monotype, your IP address is anonymized immediately after transmission so that it can no longer be linked to an individual (anonymization).
For details, please refer to Monotype's privacy policy at https://www.monotype.com/de/rechtshinweise/datensc hutzrichtlinie/datenschutzrichtlinie-zum-tracking-von-webschriften.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6347.
Google Maps
This site uses the map service Google Maps. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to embed map material on our website.
To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission. When Google Maps is activated, Google may use Google Fonts for the purpose of a uniform display of fonts. When you access Google Maps, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly.
Google Maps is used in the interest of an appealing presentation of our online offerings and to make the locations stated on the website easy to find. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
The data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. You can find details here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
More information on how user data is handled can be found in Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is intended to check whether data entry on this website (e.g., in a contact form) is made by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, time spent on the website by the visitor or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The data is stored and analyzed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated spying and from spam. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Further information on Google reCAPTCHA can be found in the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
hCaptcha
We use hCaptcha (hereinafter “hCaptcha”) on this website. The provider is Intuition Machines, Inc., 2211 Selig Drive, Los Angeles, CA 90026, USA (hereinafter “IMI”).
hCaptcha is intended to check whether data entry on this website (e.g., in a contact form) is made by a human or by an automated program. To do this, hCaptcha analyzes the behavior of the website visitor based on various characteristics.
This analysis starts automatically as soon as the website visitor enters a website with hCaptcha enabled. For the analysis, hCaptcha evaluates various information (e.g., IP address, time spent on the website by the visitor or mouse movements made by the user). The data collected during the analysis is forwarded to IMI. If hCaptcha is used in “invisible mode”, the analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The data is stored and analyzed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated spying and from spam. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
The data processing is based on Standard Contractual Clauses, which are contained in IMI's data processing addendum to its general terms and conditions and in the data processing agreements.
Further information on hCaptcha can be found in the privacy policy and terms of use at the following links: https://www.hcaptcha.com/privacy and https://hcaptcha.com/terms.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6388.
8. Payment Service Providers
SOFORT / Sofortüberweisung
On our website, we offer payment via SOFORT or Sofortüberweisung, where available. This payment method is provided via Klarna. The provider is Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden.
If you select payment via SOFORT, the payment, order and contact data required for payment processing is transmitted to Klarna. This may include in particular name, address, email address, IP address, order data, payment amount, bank information and other data required for payment processing.
The data is transmitted for the purpose of carrying out the payment transaction and is therefore based on Art. 6(1)(b) GDPR. Where Klarna processes data for fraud prevention, detection of abuse, security or to comply with legal obligations, this is done on the basis of the respectively applicable statutory legal basis.
Further information on data processing by Klarna and SOFORT can be found in Klarna's privacy policy at: https://www.klarna.com/de/datenschutz/.
Google Pay
On our website, we offer payment via Google Pay, where available. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
If you select payment via Google Pay, the payment, order and transaction data required for this purpose is processed for payment processing. The actual payment processing is carried out via Google Pay and the respective integrated payment service provider, e.g., Stripe, Mollie or another payment provider.
When using Google Pay, information about your stored payment method, the transaction, your device and technical connection data may in particular be processed.
The data processing is carried out to perform the payment transaction and is therefore based on Art. 6(1)(b) GDPR. Where processing additionally takes place for fraud prevention, security or prevention of abuse, it is based on Art. 6(1)(f) GDPR.
Further information on data processing by Google Pay or Google Payments can be found in the Google Payments privacy notice at: https://payments.google.com/legaldocument?family=0.privacynotice&hl=de and in Google's privacy policy at: https://policies.google.com/privacy?hl=de.
Apple Pay
On our website, we offer payment via Apple Pay, where available. The provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
If you select payment via Apple Pay, the payment, order and transaction data required for this purpose is processed for payment processing. The actual payment processing is carried out via Apple Pay and the respective integrated payment service provider, e.g., Stripe, Mollie or another payment provider.
Apple Pay uses security and tokenization procedures to process payments as securely as possible. In particular, information about your device, your stored payment method, the transaction and technical data may be processed.
The data processing is carried out to perform the payment transaction and is therefore based on Art. 6(1)(b) GDPR. Where processing additionally takes place for fraud prevention, security or prevention of abuse, it is based on Art. 6(1)(f) GDPR.
Further information on data processing by Apple Pay can be found at: https://www.apple.com/de/legal/privacy/data/de/apple-pay/ and in Apple's privacy policy at: https://www.apple.com/legal/privacy/de-ww/.
Stripe
Among other options, we offer payment via Stripe on this website. The providers for the European Economic Area are Stripe Payments Europe, Limited and – where regulated payment services are concerned – Stripe Technology Europe, Limited, each based in Dublin, Ireland.
If you select payment via Stripe, the payment, order and contact data you enter is transmitted to Stripe. Your data is transmitted to Stripe on the basis of Art. 6(1)(b) GDPR (performance of a contract).
Stripe may also process personal data to the extent necessary for fraud prevention, risk minimization, compliance with legal obligations, payment processing and the provision and security of the Stripe services.
Further information can be found in Stripe's privacy policy at https://stripe.com/privacy and in the Privacy Center at https://stripe.com/legal/privacy-center.
Mollie
Among other options, we offer payment via Mollie on this website. The provider is Mollie B.V., the Netherlands.
If you select payment via Mollie, the payment, order and contact data you enter is transmitted to Mollie. Your data is transmitted to Mollie on the basis of Art. 6(1)(b) GDPR (performance of a contract).
Mollie processes personal data in particular for payment processing, to comply with legal obligations, to ensure the security and integrity of the financial sector, and for fraud prevention and detection of abuse.
Further information can be found in Mollie's privacy policy at https://www.mollie.com/legal/privacy.
PayPal
Among other options, we offer payment via PayPal on this website. The provider of this payment service is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
If you select payment via PayPal, the payment data you enter is transmitted to PayPal. Your data is transmitted to PayPal on the basis of Art. 6(1)(b) GDPR (performance of a contract). For the payment methods credit card via PayPal, direct debit via PayPal or – if offered – “Pay Later”, PayPal reserves the right to carry out a credit check. PayPal uses the result of the credit check regarding the statistical probability of payment default for the purpose of deciding whether to provide the respective payment method.
The credit report may contain probability values (so-called score values). Where score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical method. The calculation of the score values includes, among other things but not exclusively, address data. For details on data protection at PayPal, please refer to the PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Klarna
We offer payment using Klarna's services on our website. The provider is Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter “Klarna”).
Klarna offers various payment options (e.g., installment purchase, purchase on invoice or Sofortüberweisung). If you choose to pay with Klarna, Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna payment services. For details, please refer to Klarna's cookie notice: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
The data is transmitted to Klarna on the basis of Art. 6(1)(b) GDPR (performance of a contract) and on the basis of our legitimate interest in providing secure and diverse payment methods (Art. 6(1)(f) GDPR). When you select a Klarna payment service that involves credit risk for Klarna (e.g., purchase on invoice), Klarna may carry out an identity and credit check. For details on this and on how your data is handled, please refer to Klarna's privacy policy: https://www.klarna.com/de/datenschutz/.
Source: https://www.e-recht24.de
9. Features in the Customer Portal and the Game Server Panel
Usage Monitoring, Crash Detection and Notifications
For each game server, we record technical measurements at short intervals (state, usage of CPU, memory and storage space, number of players, map, version). These are used for the history charts in the game server panel, for notices about permanently high usage and for detecting crashes. We store measurements in fine resolution for 48 hours, hourly values for 35 days and events (for example a detected crash) for 30 days. If you wish, we notify you of a crash by email or via a Discord webhook stored by you. The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and our legitimate interest in stable operation (Art. 6(1)(f) GDPR).
Public Presentation of Your Server (Status Banner, Server Page, Community List)
If you switch on one of these features, we publish the information about your server that you release for this purpose: name of the server, game, address, state, number of players and slots, map and version, as well as the texts, tags, colors and links entered by you and your logo. We do not publish the names of individual players. We review entries for the community list and uploaded logos before publication; entered texts pass through an automatic word filter. The processing is carried out to provide the feature you have chosen (Art. 6(1)(b) GDPR). You can switch off each feature at any time in the game server panel; the publication then ends. When the contract ends, we delete the entries and logos.
Server pages are delivered at an address of the domain nexthosting.app. When a page is accessed, we process the connection data required for delivery (in particular IP address, time, address accessed) as when our website is accessed. Fonts are hosted on our servers. If the operator of a server page has embedded content from other providers (Google Docs, YouTube, Discord, Twitch), it is only loaded when you click on it; only then is data (in particular your IP address) transmitted to the respective provider. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). For providers based in the USA, data may be transferred to the USA.
Discord Status and Notifications via Discord
If you store the address of a Discord webhook in the game server panel, we send the information you have chosen (name of the server, state, number of players, map, version, and for notifications the occasion) to this webhook. The recipient is Discord (Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands; the processing may also be carried out by Discord Inc. in the USA). The transmission takes place at your instigation to provide the feature (Art. 6(1)(b) GDPR). It ends as soon as you remove the webhook or switch off the feature.
“Report a Problem” with Diagnosis
If you report a problem in the game server panel, we create a support ticket in your name and attach an automatically generated diagnosis: information about the server (plan limits, state, start command and start variables), events and history of the monitoring and – unless you deselect it – the last lines of the server console and, for Minecraft, the end of the log file and the latest crash report. Access credentials in these texts are automatically made unrecognizable. Console and log lines may contain names and IP addresses of players. We use the diagnosis exclusively to process your request (Art. 6(1)(b) GDPR) and store it together with the ticket.
Boost
If you book a boost, we process the booking details (server, strength, period, price, payment route) for performance and billing (Art. 6(1)(b) GDPR) and send you the associated emails (confirmation, invoice and, for recurring boosts, reminders before the next occurrence). We retain invoice data within the statutory retention periods (Art. 6(1)(c) GDPR).
Pausing a Server (Keeping the Server Data)
If you pause a server, we pack the data stored on the server and keep it in a separate storage until the server is resumed or the contract ends. This data may contain personal data that you or your players have stored on the server (for example player names, save games, log files). For keeping the data, we use a storage service provider with data centers in the European Union as a processor. When the server is resumed, we transfer the data back and delete the package in storage; when the contract ends, we delete it permanently. We also store when you agreed to the terms for pausing, the size of the data and the times of pausing and resuming for billing purposes. The legal basis is Art. 6(1)(b) GDPR.
Templates and One-Click Setups
If you start a template, your server loads the required software from the sources of the respective providers (for example Modrinth, GeyserMC). The retrieval originates from our infrastructure; your own IP address is not transmitted to these sources. We log who started which template and when in order to be able to trace changes to the server (Art. 6(1)(b) and (f) GDPR).
Dedicated IP Address and Nexthosting Schutz
If you book a dedicated IP address for a game server, we filter the traffic to this address on the host system of your game server and provide you with the interface “Nexthosting Schutz”. In doing so we process connection data of the senders that want to reach your address: IP address, port addressed, time, and number and size of the packets. We do not evaluate the contents of the connections.
In detail we store: measurements per minute without IP addresses (30 days); for each attack its beginning, end, volumes and the addresses of the busiest senders (up to two months); per hour and country of origin the number of new connections and of refused packets without IP addresses (30 days) and, to count different senders per day, a non-reversible short value (8 days); on the host system the addresses of senders that were connected to your server for a longer time, in order to let them through with priority during an attack (“regular players”, 30 days after the last connection), and the addresses of automatically blocked senders for the duration of the block; also the entries of your block list and allow list until you remove them. We determine the country of origin with a database stored on our systems (IP Geolocation by DB-IP); IP addresses are not transmitted to third parties for this purpose.
If you report an attack to us, we create a support request with an evaluation that also contains the addresses of the busiest senders. If you set up notifications to a Discord channel, we transmit the server name, the address and key figures of the attack to the address you have given at Discord (Discord Inc., USA); we store the address you have given in encrypted form. If you invite co-managers, we store their customer number and show you their first name. We log changes that our staff make to the protection of an address.
The legal bases are Art. 6(1)(b) GDPR (contract with you) and Art. 6(1)(f) GDPR; our legitimate interest is the security of our systems and networks and of our customers’ servers. To the extent that we process the data of the visitors of your server on your behalf, you are responsible for this processing; the basis is then the data processing agreement, which you can conclude in your customer account. If you give the dedicated IP address back or your contract ends, we delete the data of the protection of this address after 60 days at the latest.
Log of Rejected Orders
If an order is rejected because the selected payment method is not available to you, we log the time, customer number, payment method and amount in order to be able to detect misuse and errors (Art. 6(1)(f) GDPR). Payment data such as account or card numbers is not stored in the process.
Other legal documents