As of June 2026
Note on the authoritative language: This English text is a non-binding convenience translation. The legally binding and authoritative version is the German original (available at regfish.de/legal/acceptable-use). In the event of any discrepancy between this translation and the German version, or in the event of a dispute, the German version shall prevail.
§ 1 Scope, classification and definitions
(1) This Acceptable Use Policy (hereinafter the “AUP”) governs the permitted use of the services provided by regfish GmbH, Bleichstraße 8a, 35390 Gießen (hereinafter “regfish”). It covers in particular the registration, transfer and renewal of domains, DNS services (including DNSSEC, DynDNS, Hidden Primary and DNS automation), TLS/SSL and other certificates, e-mail services, web hosting and WordPress hosting, web forwarding, as well as the public application programming interface (API). Other services are covered insofar as they are offered.
(2) This AUP forms part of the contract between regfish and its customers (hereinafter uniformly referred to as the “customer”). It is incorporated by reference from the General Terms and Conditions (GTC, available at regfish.de/legal/terms) and gives concrete form to the duties of proper use established therein.
(3) In the relationship of the contractual documents to one another, the following order of precedence applies in the event of a conflict: individual agreement takes precedence over the data processing agreement (for matters of data protection, available at regfish.de/legal/dpa), which takes precedence over the additional terms and service description (available at regfish.de/legal/additional-terms), which take precedence over the service level agreement (available at regfish.de/legal/sla), which takes precedence over the GTC, which take precedence over this Acceptable Use Policy.
(4) This AUP directly binds the customer. If the customer enables other persons to use the services, in particular its employees, agents or end customers within the framework of a resale (reseller), the customer shall ensure that these persons comply with the requirements of this AUP. The customer is liable for the conduct of the persons attributable to it as for its own conduct. This AUP does not establish any direct contractual binding of the customer’s end customers vis-à -vis regfish.
(5) “Content” within the meaning of this AUP means all data, files, messages, domain names, DNS records, programs and other information that the customer stores, transmits, publishes, processes or disseminates via the services.
§ 2 Fundamental duty of lawful use
(1) The customer uses the services exclusively within the framework of the applicable laws, the contractual agreements and this AUP. The customer ensures that the services used by it and the content for which it is responsible do not infringe legal provisions, the rights of third parties, or the requirements of the respective competent registry or the issuing certification authority (Certificate Authority).
(2) The customer is solely responsible for the content and acts disseminated or made accessible via its services, accesses and access credentials. regfish does not carry out any general monitoring of stored or transmitted content without specific cause, nor is it obliged to do so.
(3) The customer keeps its master and contact data (in particular domain holder and contact details) up to date, complete and correct at all times. Incorrect or incomplete information may lead to the suspension or loss of a domain by the registry.
§ 3 Prohibited content and uses
(1) The storage, publication, transmission, dissemination or linking of unlawful or criminal content is prohibited. This includes in particular:
– content that depicts, advertises or makes accessible the sexual abuse or sexual exploitation of children or adolescents, as well as any form of depiction that contravenes the protection of minors or that is harmful to minors without effective age verification;
– content that constitutes incitement to hatred, glorification of violence, terrorist, extremist content, or content inciting criminal offences, as well as content prohibited under the German Criminal Code;
– insulting, defamatory, slanderous content or content that otherwise infringes the personality rights of third parties;
– content that infringes data protection law, in particular the unauthorised publication or processing of the personal data of third parties.
(2) The infringement of the rights of third parties is prohibited, in particular of copyright, trademark, patent, design, name, personality and other protective or ancillary copyright rights. This also includes the offering or dissemination of unlawfully reproduced works (such as films, music, software, e-books) and the circumvention of technical protection measures.
(3) Any fraudulent or deceptive use is prohibited, in particular:
– phishing, pharming and the pretence of another identity or authority (identity misuse, brand or authority spoofing);
– the dissemination, hosting or control of malware of any kind (viruses, worms, Trojans, ransomware, spyware, exploit kits) as well as command-and-control infrastructure for botnets;
– fraud schemes, pyramid schemes, unlawful gambling and the distribution of prohibited or licence-requiring goods without the required authorisation.
(4) Furthermore, uses that infringe the export control or sanctions provisions of the European Union, the United Nations or other competent bodies are prohibited.
§ 4 E-mail and anti-spam rules
(1) The sending of unsolicited advertising or bulk e-mails (spam) via the services is prohibited. The customer sends commercial or promotional e-mails only insofar as the consent of the recipients required for this purpose or a statutory authorisation is present; the requirements of section 7 of the German Act against Unfair Competition (UWG) and of the General Data Protection Regulation (GDPR) must be observed.
(2) The following applies to the building and maintenance of distribution lists:
– newsletters and comparable mailings are carried out exclusively after a demonstrable confirmed consent (double opt-in); the customer keeps the proof of consent on file;
– every promotional message contains a functioning, free-of-charge means of unsubscribing or objecting, as well as correct sender and provider details;
– the customer carries out appropriate list hygiene, removes undeliverable addresses (bounce management) and takes account of unsubscriptions without undue delay.
(3) The following are prohibited in particular:
– the falsification or concealment of sender details, headers or the transmission path, as well as so-called spoofing;
– the collection of e-mail addresses by automated extraction (harvesting) or the unauthorised acquisition of address lists;
– the operation or use of an open mail relay (open relay) or an open proxy that enables unauthorised third parties to send mail.
(4) regfish is entitled to use technical protective measures against spam and misuse, including appropriate limitations of sending volumes and rates. Where there is reasonable suspicion of misuse, regfish may provisionally throttle or suspend the sending of e-mail.
§ 5 Network and resource misuse, fair use
(1) The services may be used only to an extent that does not impair the operation, stability and security of the infrastructure of regfish and of third parties. Excessive, disproportionate or improper use of computing, storage, network or other resources is prohibited (fair use).
(2) Specific limit values and examples for the permitted use (such as storage and data volume, number of mailboxes or DNS zones, request and sending rates) are set out in the respective service description and the additional terms (available at regfish.de/legal/additional-terms). Insofar as no expressly agreed fixed limit values apply to a service, the permitted use is measured by the average needs typical for the respective tariff among comparable customers; the authoritative factors here are objective indications such as the repeated and significant exceedance of these needs over an extended period.
(3) In the event of a significant and sustained exceedance, regfish proceeds in a graduated and proportionate manner: regfish first calls upon the customer to adjust its use and points out the exceedance to it, offers it a higher-grade service package where appropriate, and only thereafter limits the use appropriately. A limitation is communicated to the customer with reasonable advance notice, unless an immediate measure is necessary to avert a specific danger to the operation, stability or security of the infrastructure.
(4) Prohibited in particular is the use of the web hosting, mail and web forwarding services for:
– the operation of Tor exit nodes, open anonymisation or proxy services;
– the operation of streaming servers, download or mirror archives, file-hosting or file-sharing services (including torrent trackers and FTP mirrors), insofar as this has not been expressly agreed;
– the mining of cryptocurrencies as well as other computing- or network-intensive background processes without an express agreement.
(5) These restrictions apply to the shared hosting environment. They do not apply insofar as expressly deviating conditions have been agreed for a service (such as a dedicated server or colocation service); such services are provided exclusively insofar as they are offered.
§ 6 Security and integrity
(1) Any act that is liable to impair the security, availability or integrity of the services, of the infrastructure of regfish or of the systems of third parties is prohibited. This includes in particular:
– unauthorised intrusion or the attempt to intrude into third-party systems, networks or data (hacking) as well as the exploitation of security vulnerabilities;
– the scanning of networks or systems, for example by means of port or vulnerability scans, without express authorisation;
– overload attacks (denial-of-service, distributed-denial-of-service) as well as the initiation, amplification or forwarding of such attacks;
– the interception, eavesdropping or manipulation of third-party data traffic, as well as the falsification of network or sender identifiers;
– the circumvention, defeating or disruption of authentication, accounting, quota or security mechanisms.
(2) The customer protects its access credentials, keys and API tokens against unauthorised access, keeps its applications and content at an appropriate security level and remedies identified vulnerabilities without undue delay. The customer reports any suspicion of misuse of its accesses to regfish without undue delay.
(3) Controlled security investigations of the customer’s own services (such as penetration tests) are permitted only after prior coordination with regfish in text form and within the coordinated scope.
§ 7 DNS and domain misuse
(1) The abusive use of domains and DNS services is prohibited, in particular:
– the registration or use of domains with the intention of infringing trademark, name or other distinctive sign rights of third parties or of unfairly profiting from them (cybersquatting, typosquatting);
– the use of domains or DNS records for the control of malware or botnets, for phishing, for fraudulent purposes or for fast-flux and comparable concealment techniques;
– the intentional provision of false holder or contact data, or the concealment of the true holder or contact data, vis-à -vis regfish or the registry.
(2) The customer observes the respective applicable allocation and use conditions of the competent registry (in particular DENIC eG, EURid, nic.at and Nominet). Allocation, suspension and deletion decisions of the registry remain unaffected.
(3) For TLS/SSL and other certificates, the customer observes the requirements of the issuing certification authority and the Baseline Requirements of the CA/Browser Forum. In particular, the customer makes no incorrect statements in the issuance process, does not misuse issued certificates, and reports a compromise or the suspicion of key misuse without undue delay, so that a suspension (revocation) can take place.
§ 8 Reporting channels, abuse reports and point of contact (Digital Services Act)
(1) regfish provides intermediary services within the meaning of Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act, hereinafter the “DSA”). The provisions below implement the requirements applicable thereto. regfish is not subject to any general obligations to monitor without specific cause (section 10 of the German Digital Services Act [DDG]; Art. 8 DSA).
(2) Infringements of this AUP, unlawful content or other misuse may be reported at any time. Please address reports to abuse@regfish.de or to the general contact support@regfish.de, regfish GmbH, BleichstraĂźe 8a, 35390 GieĂźen, telephone 0641 / 49 888 530.
(3) regfish provides an electronic notice-and-action mechanism in accordance with Article 16 DSA. A report of allegedly unlawful content should contain the following information so that regfish can establish the unlawfulness:
– a sufficiently substantiated explanation of the reasons why the content is considered to be unlawful;
– a clear indication of the exact electronic location of the information, in particular the domain concerned, the exact URL or the IP address, and, where necessary, further information enabling the identification of the content;
– the name and the e-mail address of the reporting person or entity, except in the case of reports relating to certain criminal offences against sexual self-determination;
– a statement that the reporting person or entity holds a good-faith belief that the information is accurate and complete.
(4) Complete reports pursuant to paragraph 3 that enable the establishment of unlawfulness without a detailed legal examination give rise to regfish’s knowledge within the meaning of section 10 DDG. regfish confirms to the reporting person the receipt of their report without undue delay, processes the report in a timely, diligent, non-arbitrary and objective manner, and notifies the reporting person of its decision together with information on the available redress mechanisms.
(5) regfish designates as its single point of contact for direct communication with authorities, the Commission and the Digital Services Coordinator competent under the DDG (Art. 11 DSA), and as its point of contact for electronic communication with users (Art. 12 DSA), the following body: regfish GmbH, Digital Services Point of Contact, BleichstraĂźe 8a, 35390 GieĂźen, e-mail dsa@regfish.de. Communication with this point of contact is possible in the German and the English language.
(6) regfish examines incoming reports and, insofar as necessary, initiates appropriate measures in accordance with § 9. Information on the current operating status of the services is available at status.regfish.de.
§ 9 Notice-and-takedown, suspension, escalation and consequences
(1) If regfish becomes aware of a sufficient suspicion of an infringement of this AUP or of unlawful content, regfish may call upon the customer to submit a statement and to remedy the infringement within a reasonable period. In the case of imminent danger (danger in default), in the case of serious infringements or where there is a legal obligation, regfish may also act without prior notice. Before taking adverse measures, regfish gives the customer the opportunity to submit a statement where possible, insofar as this does not jeopardise the purpose of the measure or an immediate measure is required.
(2) regfish is entitled, depending on the severity and urgency of the infringement, to take the following measures in a graduated manner:
– notice and a call to remedy;
– temporary suspension or rendering inaccessible of the affected content, domains, DNS records, mailboxes or accesses where there is a reasonable suspicion of an infringement;
– permanent removal, deletion or permanent suspension of the affected content, domains, DNS records, mailboxes or accesses only in the case of an established or manifest infringement, or in the case of an infringement established by an authority or a court, or insofar as a legal, administrative or judicial obligation, or a binding requirement of a registry or a certification authority, requires this;
– throttling or temporary suspension of the affected service;
– in the case of serious or repeated infringements, the extraordinary termination of the contract for good cause.
(3) regfish selects the measure in accordance with the principle of proportionality and limits it, where possible, to the affected content or service.
(4) Where regfish restricts the provision, visibility or accessibility of content vis-Ă -vis the customer as a user, suspends or terminates a service, or terminates the contract on account of unlawful content or an infringement of this AUP, regfish notifies the affected customer of the decision together with a clear and specific statement of reasons (statement of reasons pursuant to Article 17 DSA). The statement of reasons contains in particular information as to whether the measure removes, renders inaccessible, demotes or otherwise affects the content and what territorial and temporal scope it has, the underlying facts and circumstances, where applicable a reference to the use of automated means, the contractual or legal basis relied upon, as well as information on the redress mechanisms available to the customer pursuant to paragraphs 5 and 6. The statement of reasons is omitted only insofar as the measure is based solely on an order of an authority or a court and that body requires otherwise, or insofar as the measure is not one for which a statement of reasons is required.
(5) Against a decision pursuant to paragraph 4, as well as against the decision not to act upon an abuse report, the affected customer or the reporting person may make use of an internal complaint-handling procedure within six months (Article 20 DSA). The complaint is to be addressed to the point of contact pursuant to § 8 paragraph 5 (dsa@regfish.de). regfish processes complaints in a timely, diligent, non-arbitrary and objective manner, reverses a measure without undue delay insofar as the complaint proves to be well-founded, and informs the complainant of the outcome. Decisions are not taken solely on the basis of automated procedures.
(6) Independently of the internal complaint-handling procedure, the customer is free, for the settlement of disputes concerning measures pursuant to paragraph 4, to call upon an out-of-court dispute settlement body certified pursuant to Article 21 DSA; the decision of such a body is not binding on the parties. The customer’s right to bring proceedings before the courts, as well as other redress mechanisms, remain unaffected. The customer obtains information on the respective competent certified dispute settlement body via the point of contact pursuant to § 8 paragraph 5.
(7) Insofar as regfish is obliged by law, by an authority or by a court to provide information, to suspend or to remove, or insofar as requirements of a registry or a certification authority require this, regfish implements these. The obligation to report certain content to the competent bodies remains unaffected.
(8) Insofar as a measure pursuant to this section was actually justified, the outages or impairments arising therefrom do not give rise to any claims of the customer against regfish. Where a measure was not justified, or not justified to its full extent, regfish is liable in accordance with the liability provision in § 14 of the GTC. The mandatory liability of regfish for damage arising from injury to life, body or health, for damage arising from intent and gross negligence, under the German Product Liability Act (Produkthaftungsgesetz), and to the extent of an expressly assumed guarantee, remains unaffected in any event. Any remuneration claims of regfish for the contractual period remain unaffected in the case of justified measures in accordance with the GTC.
§ 10 Indemnification
(1) The customer indemnifies regfish against all claims of third parties which they assert against regfish on account of an infringement of this AUP, on account of unlawful content, or on account of an unlawful use of the services by the customer or by the persons attributable to it, insofar as the customer is responsible for the underlying legal infringement. The indemnification covers the necessary and reasonable costs of legal defence (in particular the judicial and extrajudicial costs of an appropriate legal pursuit); any flat-rate or internal expenditure going beyond this is not reimbursed.
(2) The burden of proof that the customer is responsible for the legal infringement lies with regfish. As against consumers, the indemnification is limited to the legally permissible extent; the statutory allocation of liability and burden of proof is not altered to their detriment.
(3) The customer informs regfish without undue delay if third parties assert such claims, and supports regfish in its legal defence to the extent of its possibilities. regfish will not make any acknowledgement and will not conclude any settlement without the consent of the customer, insofar as this cannot reasonably be required of the customer.
§ 11 Amendments to this Acceptable Use Policy
(1) regfish may amend this AUP for an objective reason, in particular in the event of changes in the legal situation or in the case law of the highest courts, in the event of changed requirements of registries or certification authorities, in the event of new or changed technical or security-related requirements, as well as upon the introduction of new services. An amendment is made only insofar as it does not shift the balance of performance and consideration to the detriment of the customer.
(2) Amendments are communicated to the customer in text form with a period of at least six weeks before they take effect. The customer is entitled to terminate the contract extraordinarily as at the time the amendment takes effect. This right and the significance of the amendment are pointed out separately in the notification.
(3) Amendments concern exclusively subordinate provisions of this AUP regarding permitted use; the relationship of performance and consideration as well as the essential principal performance obligations are not covered by an amendment pursuant to this section. An amended version becomes effective as against the customer if the customer expressly consents to it, or continues to use the services after it takes effect and has not objected to the amendment up to that point. If the customer does not terminate and does not object, this does not constitute an express declaration; a binding effect arises solely in accordance with the foregoing sentences. Mere silence on the part of the customer does not constitute consent to the amendment.
§ 12 Final provisions
(1) Should a provision of this AUP be or become wholly or partially invalid or unenforceable, the validity of the remaining provisions remains unaffected. The statutory provision takes the place of the invalid or unenforceable provision.
(2) Insofar as this AUP refers to “customers” or “customer”, persons of any gender are meant. This AUP supplements the GTC; in all other respects, the provisions set out therein, in particular those on applicable law and place of jurisdiction, apply accordingly.


