Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection laws is:
Datenturm GmbH Schemmener Straße 14 51647 Gummersbach Germany
Phone: +49 2261 9913991
WhatsApp: +49 155 60917334
Email: [email protected]
2. General Information
We process personal data only to the extent necessary to provide a secure and functional website, process inquiries, initiate and perform contracts, provide customer accounts and support services, or fulfil legal obligations.
Personal data is any information relating to an identified or identifiable natural person.
The legal bases are in particular:
- Art. 6(1)(a) GDPR for consent,
- Art. 6(1)(b) GDPR for pre-contractual measures and contract performance,
- Art. 6(1)(c) GDPR for compliance with legal obligations,
- Art. 6(1)(f) GDPR for legitimate interests,
- Section 25 TDDDG for storing information on your terminal equipment or accessing information already stored there.
3. Provision of the Website and Server Log Files
When you access our website, the web server and upstream security and delivery systems automatically process technical information. This may include in particular:
- IP address,
- date and time of access,
- page or file accessed,
- amount of data transferred,
- referrer URL,
- browser type and version,
- operating system,
- HTTP status code,
- technical security and error events.
This processing serves the secure, stable and error-free provision of the website, the defense against attacks, and technical error analysis, based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the security and functionality of our online offering.
Regular server log files are generally deleted after 14 days at the latest. Longer storage only takes place if required to investigate a specific security incident or to assert, exercise or defend legal claims.
4. Hosting and Technical Service Providers
The website is operated on a Virtual Private Server administered by us. Hosting, infrastructure, maintenance, backup and IT security service providers may gain access to personal data insofar as this is necessary for the provision of their services.
Insofar as such service providers process personal data on our behalf, they are engaged on the basis of Art. 28 GDPR. We limit access to what is necessary and take appropriate technical and organizational protective measures.
5. Cloudflare
We use services provided by:
Cloudflare, Inc. 101 Townsend Street San Francisco, California 94107 USA
Cloudflare provides a globally distributed content delivery network as well as security, proxy and protection functions. This is used in particular for:
- fast and stable delivery of our website,
- protection against DDoS attacks and abusive access,
- detection of automated or malicious requests,
- securing our technical infrastructure.
This may involve processing of IP address, date and time, URL accessed, referrer, browser and device information, HTTP headers, and security-related log data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, high-performance and reliable provision of our online offering.
Cloudflare may also process data outside the European Union or the European Economic Area. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework. Where its requirements are met, the transfer takes place on the basis of the European Commission's adequacy decision pursuant to Art. 45 GDPR. In addition, Cloudflare provides for the European Commission's standard contractual clauses.
Further information:
https://www.cloudflare.com/privacypolicy/ https://www.cloudflare.com/cloudflare-customer-dpa/ https://www.dataprivacyframework.gov/participant/5666
6. Technically Necessary Cookies and Similar Technologies
6.1 PHPSESSID
Our website uses the technically necessary session cookie PHPSESSID. It serves in particular:
- session management,
- language selection,
- shopping cart management,
- protection of forms via CSRF tokens,
- login and management of customer accounts,
- display of short-term system messages.
The cookie does not contain plain-text passwords. It is generally deleted at the end of the browser session.
Storage or access takes place on the basis of Section 25(2) No. 2 TDDDG, insofar as this is strictly necessary for the expressly requested use of the website. Subsequent processing takes place, depending on the function, on the basis of Art. 6(1)(b) or (f) GDPR.
6.2 Consent Setting
We store your choice in the consent management system under the name dt_ck in your browser's local storage. Only the selected category, the version of the consent notice, and the time of selection are stored.
This storage serves to respect your choice and to be able to prove consent. The legal bases are Section 25(2) No. 2 TDDDG as well as Art. 6(1)(c) and (f) GDPR.
The setting is stored for a maximum of twelve months or deleted earlier if you change your choice via the "Privacy Settings" function or delete your browser data.
7. Consent Management
Services that are not technically necessary are only loaded after you have expressly given your consent beforehand. You can change or withdraw your consent at any time with effect for the future via the "Privacy Settings" link.
The lawfulness of processing carried out prior to withdrawal remains unaffected.
The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
8. Web Analytics with Self-Hosted Matomo
We use Matomo for statistical analysis of the use of our website. Matomo is operated by us on our own server environment under our control at analytics.neurog.eu.
Matomo is only loaded after your consent. We configure Matomo so that:
- no analytics cookies are set,
- IP addresses are truncated before storage,
- no data is transmitted to the Matomo manufacturer or other analytics services,
- raw data is automatically deleted after a defined short period.
This may involve processing of:
- truncated IP address,
- pages accessed,
- time and duration of the visit,
- referrer,
- browser, device and operating system information,
- screen resolution,
- interactions with links.
The legal bases are Art. 6(1)(a) GDPR and, insofar as access to information on your terminal equipment takes place, Section 25(1) TDDDG.
You can withdraw your consent at any time via "Privacy Settings".
9. Google Maps
A map from Google Maps may be embedded on our contact page. The provider is generally:
Google Ireland Limited Gordon House, Barrow Street Dublin 4 Ireland
The map is only loaded once you expressly consent via the placeholder. Before your consent, no connection to Google is established through the map integration.
After activation, IP address, browser and device information, referrer, location information and further usage data may in particular be transmitted to Google. If you are logged into a Google account, Google may associate the access with your account.
The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Google may also process data in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework. Where its requirements are met, the transfer takes place pursuant to Art. 45 GDPR. Standard contractual clauses may additionally be used.
Further information:
https://policies.google.com/privacy https://www.dataprivacyframework.gov/participant/5780
10. Fonts
The fonts used on this website are provided locally by our server. Therefore, no connection to Google Fonts or any other external font provider is established solely because of the display of the typeface.
11. Contacting Us by Email or Telephone
If you contact us by email or telephone, we process the data you provide to us. This may include in particular name, contact details, company, content of the inquiry, and other voluntarily provided information.
If your contact serves to initiate or perform a contract, Art. 6(1)(b) GDPR is the legal basis. For general business or organizational inquiries, processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in processing and responding to your inquiry.
The data is deleted once the inquiry has been conclusively processed and no statutory retention obligations, legitimate interests or possible legal claims stand in the way.
12. Contact Form
When using the contact form, the following data may in particular be processed:
- name,
- email address,
- phone number, if voluntarily provided,
- company, if provided,
- subject,
- message content,
- date and time,
- IP address,
- browser or user agent information,
- language setting.
Required fields are marked accordingly. The data is processed to handle and respond to your inquiry.
The legal basis is Art. 6(1)(b) GDPR if your inquiry is directed at a contract or pre-contractual measures. In other cases, processing takes place on the basis of Art. 6(1)(f) GDPR.
Non-contract-related contact inquiries are generally deleted no later than twelve months after final processing. If a contractual relationship arises from the inquiry, the statutory and contractual retention periods provided for this apply.
13. Quote, Shopping Cart and Server Inquiries
Our website allows you to select products or services and submit a non-binding inquiry. Submission via the website is not a chargeable order and does not directly result in a contract.
This may in particular involve processing of:
- name,
- company,
- email address,
- phone number,
- selected products and services,
- price and tariff information,
- project description and message,
- language,
- IP address and user agent,
- for server inquiries, additionally package, contract term, domain, DNS details, control panel, desired number of IPs, and technical notes.
Processing takes place to review your inquiry, prepare an individual quote, and carry out pre-contractual measures on the basis of Art. 6(1)(b) GDPR.
If no contract is concluded, the data is generally deleted no later than twelve months after the inquiry is closed, unless legal claims or statutory obligations prevent this. If a contract is concluded, the necessary contract and billing data is stored in accordance with the statutory retention periods.
14. Customer Account and Registration
When registering and using a customer account, we process in particular:
- name,
- email address,
- company,
- phone number,
- user or membership number,
- default avatar image,
- securely hashed password,
- registration and usage timestamps,
- contract, order, service and subscription data associated with the account.
Passwords are not stored in plain text.
Processing takes place to set up and manage the customer account and to initiate and perform contracts, on the basis of Art. 6(1)(b) GDPR.
The customer account is deleted once it is no longer needed and no statutory retention obligations, ongoing contracts, outstanding claims or legal claims stand in the way. Contract and billing data that must be retained by law is separated from the active customer account and stored in a blocked state until the respective period expires.
15. Customer Area, Services and Subscriptions
Depending on the contractual relationship, the customer area may in particular process and display the following data:
- orders and status information,
- booked services,
- server IP addresses,
- hostname and operating system,
- resources and server location,
- prices, terms and subscription data,
- internal, contract-related notes,
- support cases.
Processing takes place for contract performance and customer support pursuant to Art. 6(1)(b) GDPR.
16. Support Tickets
If you create or respond to a support ticket, we process in particular:
- user or customer assignment,
- category,
- subject,
- messages and replies,
- status,
- timestamps,
- names of the employees and users involved.
Processing takes place to perform the contract and handle support inquiries, on the basis of Art. 6(1)(b) GDPR. For general technical inquiries, processing may additionally be based on Art. 6(1)(f) GDPR.
Support cases are generally stored until the end of the contractual relationship and subsequently until the regular statute of limitations expires, unless earlier deletion is possible or statutory retention obligations prevent this.
17. Android Beta Registration
For registration for a closed Android beta, we process the name provided, the email address used for Google Play, and the time of registration.
Processing takes place to handle your beta request and to carry out pre-contractual measures or measures expressly requested by you, on the basis of Art. 6(1)(b) GDPR.
The data is generally deleted within six months after the end of the beta phase or after the registration has been conclusively processed, unless a subsequent contractual or usage relationship arises.
When accessing Google Play, you leave our website. Further processing is carried out by Google in accordance with its own privacy policy.
18. Domain Availability Check
Our website offers a technical domain availability check for certain extensions. The domain names entered are transmitted server-side to the respective responsible registry or its public RDAP system. Depending on the extension, this may in particular be:
- DENIC eG for
.de, - Verisign, Inc. for
.comand.net, - Public Interest Registry for
.org.
The domain name entered as well as, for technical reasons, the IP address of our server are transmitted. Your own IP address is not passed on to the registry as part of the RDAP request, but may be processed in our server and security logs.
Please do not enter personal or confidential information in the domain search.
Processing takes place to carry out the domain check you requested, on the basis of Art. 6(1)(b) GDPR, and for secure technical provision, on the basis of Art. 6(1)(f) GDPR.
For US-based registries, processing may take place in the USA. Insofar as the search term itself contains personal data, transmission takes place at your express initiative to carry out the requested check. We limit transmission to the domain name entered.
19. Sending Emails via Google Workspace
For the technical sending and receiving of business emails, in particular for contact, quote, order, beta and support processes, we use Google Workspace with Gmail or SMTP functions.
Depending on the specific contractual model, the contracting party may in particular be:
Google Cloud EMEA Limited 70 Sir John Rogerson's Quay Dublin 2 Ireland
Within the scope of service provision, other companies of the Google group and subcontractors, in particular Google LLC in the USA, may be involved.
This may in particular involve processing of:
- sender and recipient addresses,
- names and contact details,
- subject and message content,
- technical delivery and log data,
- IP address and timestamp,
- contract, order or support information.
The legal basis depends on the specific communication and is in particular Art. 6(1)(b), (c) or (f) GDPR.
Google LLC is certified under the EU-U.S. Data Privacy Framework. Where its requirements are met, the transfer takes place on the basis of Art. 45 GDPR. Standard contractual clauses of the European Commission may additionally apply.
Further information:
https://policies.google.com/privacy https://cloud.google.com/terms/data-processing-addendum https://www.dataprivacyframework.gov/participant/5780
20. Technical Email Logs
To monitor technical delivery, we store only the metadata required for this purpose, in particular recipient, message type, sending time and success status. Complete message content is not permanently stored in an additional technical mail log.
Technical delivery logs are generally deleted after 30 days at the latest, unless required to investigate a specific error or security incident or to defend legal claims.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the reliable and traceable delivery of business communications.
21. WhatsApp
Our website may contain a link for contacting us via WhatsApp. A connection to WhatsApp is only established once you click the link.
The provider for users in the European Economic Area is generally:
WhatsApp Ireland Limited Merrion Road Dublin 4, D04 X2K5 Ireland
When using WhatsApp, phone number, profile and contact data, communication content, metadata and technical device information may in particular be processed. Processing outside the EU or EEA cannot be ruled out.
Only use WhatsApp if you agree to processing by WhatsApp. Alternatively, you can contact us by email or phone.
Further information:
https://www.whatsapp.com/legal/privacy-policy-eea
22. External Links to Google Play and Google Search
Our website contains links to Google Play and Google Search. Data is only transmitted to Google through these links once you click them. From that point on, Google processes the data under its own responsibility.
Further information:
https://policies.google.com/privacy
23. Recipients and Categories of Recipients
Within our company, only those persons who need it to perform their duties have access to personal data.
In addition, data may be transmitted, to the extent necessary, to the following categories of recipients:
- hosting, infrastructure and backup service providers,
- CDN and IT security service providers,
- email and communication service providers,
- technical maintenance and support service providers,
- tax advisors, accounting and payment processing, where necessary,
- lawyers and other professional advisors,
- registries and technical domain services,
- authorities and courts, where there is a legal obligation.
24. Third-Country Transfers
Personal data is only transferred outside the European Union or the European Economic Area in compliance with Art. 44 et seq. GDPR.
Possible transfer bases include in particular:
- an adequacy decision of the European Commission,
- a valid certification under the EU-U.S. Data Privacy Framework,
- standard contractual clauses of the European Commission,
- other appropriate safeguards,
- exceptionally, a statutory exception under Art. 49 GDPR.
25. Storage Period
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations.
In particular, the following criteria generally apply:
- server log files: 14 days at most,
- technical email metadata: 30 days at most,
- non-contract-related contact and quote inquiries: twelve months at most after conclusion,
- beta registrations: generally six months at most after the end or processing,
- customer accounts: for the duration of active use and subsequently until open contractual and legal questions are clarified,
- support data: for the term of the contract and subsequently generally until the regular statute of limitations expires,
- contract, commercial and tax records: in accordance with the applicable statutory period, typically six, eight or ten years,
- backups: according to a documented rotation and deletion concept.
Data may be stored for longer if required to assert, exercise or defend legal claims or due to a statutory retention prohibition.
26. Obligation to Provide Data
The provision of personal data is generally neither required by law nor by contract.
However, certain information is required to process an inquiry, prepare a quote, set up a customer account, or conclude and perform a contract. Without this information, we may not be able to provide the desired service, or only partially.
Required fields are marked accordingly.
27. Security of Processing
We take appropriate technical and organizational measures to protect personal data. These include in particular encrypted connections, access and authorization concepts, logging of security-relevant events, data backups, update and deletion procedures, and measures against unauthorized access.
Complete security of data transmission over the internet cannot be technically guaranteed.
28. No Automated Decision-Making
No decision based exclusively on automated processing, including profiling within the meaning of Art. 22 GDPR, takes place via this website.
The AI products presented on the website are product information. No website visitor data is currently transmitted to a generative AI provider via the Datenturm website.
29. Rights of Data Subjects
Within the scope of the statutory requirements, you have in particular the following rights:
- access pursuant to Art. 15 GDPR,
- rectification pursuant to Art. 16 GDPR,
- erasure pursuant to Art. 17 GDPR,
- restriction of processing pursuant to Art. 18 GDPR,
- data portability pursuant to Art. 20 GDPR,
- objection pursuant to Art. 21 GDPR,
- withdrawal of consent pursuant to Art. 7(3) GDPR,
- lodging a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.
To exercise your rights, please contact:
In case of reasonable doubts about your identity, we may request additional information to verify your identity.
30. Right to Object
Insofar as we process personal data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object at any time for reasons arising from your particular situation.
We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
31. Right to Lodge a Complaint
You may lodge a complaint with a data protection supervisory authority. For companies based in North Rhine-Westphalia, the responsible authority is in particular:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia Kavalleriestraße 2–4 40213 Düsseldorf Germany
Phone: +49 211 38424-0 Email: [email protected] Website: https://www.ldi.nrw.de/
32. Currency and Changes
We adapt this privacy policy whenever statutory requirements, the services used, or technical processes change.
Last updated: 15 July 2026