Privacy Policy

26 sectionsapprox. 26 min read
Contents

As of June 2026

Note on the authoritative language: This English text is a non-binding convenience translation. The legally binding and authoritative version is the German original (available at regfish.de/legal/privacy). In the event of any discrepancy between this translation and the German version, or in the event of a dispute, the German version shall prevail. The protection of your personal data is a central concern for us. In this privacy policy we inform you, pursuant to Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR), in detail and transparently about which personal data we collect, for which purposes and on which legal bases we process it, to whom we transfer it and which rights you are entitled to. Where reference is made below to “customers” (Kundinnen und Kunden) or “customers”, all genders are meant. This policy applies to the website regfish.de, the associated services (customer account, ordering and administration interfaces) as well as to the services we provide.

1. Controller

(1) The controller within the meaning of the GDPR and other data protection provisions is: regfish GmbH BleichstraĂźe 8a 35390 GieĂźen Germany Represented by the managing directors Carsten MĂĽller and Andreas Mallek. Telephone: 0641 / 49 888 530 E-mail: support@regfish.de Website: regfish.de Commercial register: Local Court (Amtsgericht) of GieĂźen, HRB 6589 VAT identification number: DE253460760 (2) Further mandatory information can be found in our imprint, available at regfish.de/legal/imprint.

2. Data Protection Officer

(1) We have appointed an external data protection officer. For questions regarding the collection, processing or use of your personal data as well as regarding the exercise of your rights, you can reach him at: Rudolf Fiedler c/o DPP Data Protection GmbH Zum Gottschalkhof 2 60594 Frankfurt am Main Telephone: +49 69 175366960 E-mail: datenschutz@regfish.de (2) If you wish to contact our data protection officer directly with a data protection matter, please use the contact details above and mark your message with a note indicating that it is intended for the data protection officer.

4. Provision of the Website and Server Log Files

(1) You can visit our website without actively providing any information about your person. However, when the website is accessed, access data transmitted by your browser is automatically stored in server log files, in particular: – the IP address of the requesting device – the date and time of access – the page accessed or the file requested and the volume of data transferred – the page from which you visit us (referrer) – browser type and version as well as the operating system (2) The IP address is an item of personal data. We process this data in order to deliver the website, to ensure its stability and security and to repel attacks. The legal basis is our legitimate interest in a secure and functional online presence (Art. 6 (1) (f) GDPR). (3) Storage period: The server log files are stored for a maximum of 30 days and subsequently deleted or anonymised by truncating the IP address. A longer storage of individual log files takes place only where this is necessary to clarify or pursue a specific security-relevant incident (for example an attack); in this case, the log files concerned are retained until the incident has been conclusively clarified. This incident-related storage remains limited to the data necessary to clarify and pursue the specific incident and to the period necessary for this purpose; thereafter they are deleted or anonymised. (4) The provision of the aforementioned data is technically necessary in order to display the website. Without this data, a connection cannot be established.

5. Cookies and Comparable Technologies

(1) On our website we use so-called cookies. Cookies are small files that are stored on your terminal equipment and that store certain settings and data for exchange with our system via your browser. Your browser allows restrictive settings and the deletion of cookies; this may impair the functionality of our offering. (2) Session cookies are deleted again after you close your browser. Other cookies remain on your terminal equipment for a limited period. (3) We use exclusively technically necessary cookies and comparable storage techniques that are strictly necessary in order to provide the service expressly requested by you. For these, no consent is required pursuant to section 25 (2) no. 2 TDDDG. In particular, these are: – session cookies (for example “sid”, “sfsid”) to maintain your session and your login. Storage period: for the duration of the session. – a cookie to protect against cross-site request forgery (CSRF). Storage period: for the duration of the session. – a cookie to store your language selection (locale) so that the website is displayed in the language chosen by you. Storage period: up to twelve months. – the contents of your shopping cart, which are stored for the duration of the session. (4) Insofar as the further processing of the data collected via technically necessary cookies serves to carry out the service requested by you, we base it on Art. 6 (1) (b) GDPR and otherwise on our legitimate interest in a functional and secure offering (Art. 6 (1) (f) GDPR). (5) We do not use any marketing or tracking cookies and do not create any cross-device usage profiles. Optional third-party services are loaded only after an active action on your part (see Section 13). For this reason, we do not use a cookie banner. We take into account a valid signal of a recognised consent management service under the Consent Management Regulation (Einwilligungsverwaltungsverordnung), insofar as such a signal is present.

6. Customer Account, Order and Contract Processing

(1) For the opening of a customer account as well as for the ordering and processing of our services, we process the data provided by you. These are in particular: – inventory and master data (form of address, first and last name, where applicable company, address, country) – contact data (e-mail address, telephone number and, where applicable, fax number) – access data (username, password in encrypted form, two-factor authentication settings) – contract, order and usage data (services ordered, terms, domains, certificates, configurations) – in the case of business customers, additionally VAT identification number and register details (2) The purpose of the processing is the establishment, performance and administration of the contractual relationship, including the customer account, order processing, provision of the services, invoicing, support and warranty. The legal basis is Art. 6 (1) (b) GDPR (contract and pre-contractual measures). Insofar as the processing serves to fulfil legal obligations, the legal basis is Art. 6 (1) (c) GDPR. (3) In our input forms we have marked the mandatory fields that you must complete so that we can conclude and perform the desired contract. The provision of this data is necessary for the performance of the contract; without it we cannot render the service, in particular cannot register any domain and cannot have any certificate issued. The provision of further data is voluntary. (4) Storage period: We store the contract and master data for the duration of the contractual relationship. After termination of the contract, the data is deleted as soon as it is no longer necessary for the purposes of the processing, but at the latest after expiry of the statutory limitation and retention periods (see Section 14). An inactive customer account without active services and without outstanding claims will be deleted or anonymised by us after expiry of 24 months from the last activity, insofar as no statutory retention obligation precludes this. (5) If you order services for third parties or enter data of employees of your company, you warrant that you are authorised to transmit this data and that the processing is lawful within the meaning of Art. 6 GDPR. In this case you are responsible for informing the data subjects pursuant to Art. 13 and 14 GDPR.

7. Domain Registration, Domain Transfer and Disclosure to Registries

(1) In connection with the registration, renewal or transfer of domains, it is necessary for the performance of the contract to transmit personal data of the domain holder as well as of the administrative and technical contacts to the respective competent registry. Recipients are in particular DENIC eG (.de), EURid (.eu), nic.at (.at), Nominet (.uk) and other registries. (2) The registries process the holder and contact data transmitted to them in order to administer the domain on the basis of their respective registration policies and statutory or contractual obligations. The registries decide independently on the purposes and means of this processing; to that extent they are controllers in their own right. There is no processing on behalf of the controller on our behalf in the case of domain registration. The legal basis for the transmission is the performance of the contract concluded with you (Art. 6 (1) (b) GDPR). (2a) Insofar as we and a registry jointly determine the purposes and means with regard to individual processing steps of domain administration and thus joint controllership pursuant to Art. 26 GDPR exists, the following shall apply as the essence of the arrangement made: We collect the holder and contact data from you, check it for completeness and transmit it to the registry; the registry maintains the authoritative domain register, is responsible for its publication in accordance with its policies (see paragraph 3) as well as for the retention of the register data. Each party fulfils the information obligations incumbent upon it pursuant to Art. 13 and 14 GDPR. Irrespective of this, you may assert your data subject rights against any of the parties involved; the primary point of contact for matters concerning our processing is our data protection officer (Section 2). We will provide you with a summary of the respective applicable arrangement on request at datenschutz@regfish.de. (3) Publication in public directories: Depending on the respective top-level domain and the policies of the registry, certain inventory and contact data may be retrievable via publicly accessible directory services (WHOIS or RDAP). Which data is published depends on the requirements of the respective registry. Insofar as publication takes place, it is based on the fulfilment of the registry requirements within the framework of the contract (Art. 6 (1) (b) GDPR) or on the registry’s own legal obligation. (4) Origin of data from third parties (Art. 14 GDPR): Insofar as you, as the domain holder or as a reseller, provide data of third parties (for example of end customers or of administrative or technical contacts), we do not collect this data directly from the data subject but receive it from you. The categories of this data comprise name, address and contact data. We process it for the purpose of domain administration and disclosure to the registry on the basis of Art. 6 (1) (b) and (f) GDPR; our legitimate interest consists in the proper provision of the domain service. (5) Transfer to third countries: Depending on the respective registry, the transmission may also take place to countries outside the European Union or the European Economic Area (third countries). Where there is no adequacy decision of the EU Commission for a third country, we base the transmission on the fact that it is necessary for the performance of the contract concluded with you or concluded in your interest (Art. 49 (1) (b) and (c) GDPR). (6) Storage period: We store the data necessary for domain administration for the duration of the registration or of the contractual relationship; otherwise Section 14 applies.

8. TLS/SSL and Other Certificates, Disclosure to Certification Authorities (CAs)

(1) When ordering TLS/SSL, S/MIME, code-signing or similar certificates, it is necessary for the performance of the contract to transmit the application data (for example the data from the certificate signing request, the CSR, as well as organisation and contact data) to the respective certification authority (Certificate Authority, CA). The CAs used are in particular DigiCert, Sectigo, GeoTrust, Thawte and RapidSSL. (2) The CA issues the certificate in accordance with the Baseline Requirements of the CA/Browser Forum in its own data protection responsibility; to that extent there is no processing on behalf of the controller. In the issuance of certificates, a direct contractual relationship regularly arises between the certificate holder and the CA. The legal basis for the transmission is the performance of the contract (Art. 6 (1) (b) GDPR). (3) For certain types of certificate (in particular for TLS certificates), details from the issued certificate are entered into publicly viewable directories, namely into the Certificate Transparency logs maintained in accordance with the requirements of the CA/Browser Forum. We have no influence over this; the publication is part of the CA’s issuance procedure. (4) Transfer to third countries: Insofar as a CA transmits data to a third country, Section 7 (5) applies accordingly (Art. 49 (1) (b) and (c) GDPR or adequacy decision). (5) Storage period: We store data for the administration of the certificate for the term of the certificate and of the contractual relationship; otherwise Section 14 applies.

9. Hosting, E-mail, DNS and API Services for Business Customers (Processing on Behalf of the Controller)

(1) Insofar as we provide for you web hosting or WordPress hosting, e-mail services (mailboxes and forwarders), DNS services (DNS hosting, DNSSEC, DynDNS, Hidden Primary, DNS automation) or the public API and in doing so process personal data that you or your end users enter into our systems, we process this data on your instructions and on your behalf. To that extent there is processing on behalf of the controller pursuant to Art. 28 GDPR; the controller for this content data is you. (2) For these services we conclude a data processing agreement with business customers. The relevant provisions, including the technical and organisational measures and the sub-processors used, are set out in the data processing agreement, available at regfish.de/legal/dpa. A current overview of the sub-processors used by us is, insofar as provided, available for retrieval at regfish.de/legal/subprocessors. (3) Resellers: If you pass on services obtained from us to your own customers, you remain our direct contractual partner and become the controller vis-Ă -vis your end customers. In this constellation we are your processor; the chain of responsibility is reflected in the data processing agreement. (4) We operate the hosting and mail infrastructure on our own systems. Otherwise, we process the content data stored on your behalf exclusively in accordance with your instructions and for the duration of the respective contract; details on deletion and return are governed by the data processing agreement.

11. Support and Communication

(1) If you contact us (for example by e-mail, via contact forms, by telephone or via the support chat), we process the data communicated by you in order to process and respond to your enquiry. (2) The legal basis is Art. 6 (1) (b) GDPR, insofar as your enquiry serves the performance or initiation of a contract, and otherwise our legitimate interest in processing enquiries (Art. 6 (1) (f) GDPR). (3) Storage period: We store the communication history until the respective enquiry has been conclusively processed and no further queries are to be expected, but for a maximum of 24 months after the last contact. Insofar as the history is part of a contractual relationship or is subject to statutory retention obligations, the periods under Section 14 apply. On the integration of the support chat, see Section 13.

12. Data Security

(1) We take technical and organisational measures pursuant to Art. 32 GDPR in order to protect your data against loss, destruction, unauthorised access, alteration and unauthorised disclosure. The transmission via our website takes place in encrypted form (TLS). Your payment data is transmitted in encrypted form to our payment service provider when you store a payment method. (2) We continue to develop our security measures in line with technological developments. Please always treat your access data as confidential and close the browser window when you have ended your communication with us, in particular when sharing a device.

13. Services Used and Recipients

(1) To provide our website and services, we use the services named below. Insofar as these act as processors for us, we have concluded data processing agreements with them pursuant to Art. 28 GDPR.

Payment Processing (Stripe)

(2) For the processing of payments by SEPA direct debit and credit card, we use Stripe (Stripe Payments Europe, Ltd., Ireland). During the payment process, the data required for this is transmitted to Stripe. The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR) as well as the setting of strictly necessary cookies for fraud prevention (section 25 (2) no. 2 TDDDG). Insofar as Stripe transmits data to the USA, this transmission is safeguarded by the EU-US Data Privacy Framework (Art. 45 GDPR) or by standard contractual clauses (Art. 46 GDPR).

Support Chat (Intercom)

(3) For live support we use Intercom (Intercom R&D Unlimited Company, Ireland, with processing also by Intercom, Inc., USA). The chat is not loaded automatically. The Intercom script is loaded by your browser only when you actively open the chat via the chat button. Before that, no connection to Intercom takes place and no cookies are set by Intercom. Upon opening the chat, data (for example your IP address, browser information as well as your chat entries) is transmitted to Intercom and may in the process also be transmitted to the USA. The legal basis for loading the third-party content and the associated access to information in your terminal equipment is your consent declared through the active opening (section 25 (1) TDDDG, Art. 6 (1) (a) GDPR). For the subsequent substantive processing of your chat enquiry, the legal basis is the performance or initiation of a contract (Art. 6 (1) (b) GDPR), and otherwise our legitimate interest in processing enquiries (Art. 6 (1) (f) GDPR). Insofar as a transmission to the USA takes place, we base this on the EU-US Data Privacy Framework (Art. 45 GDPR), provided that the recipient is certified, and additionally on standard contractual clauses (Art. 46 (2) (c) GDPR).

Customer Relationship Management and Support (Datargo)

(4) For customer relationship management (CRM) as well as the support and chat function we use Datargo (Datargo GmbH, Frankfurt am Main, Germany); Datargo will in future replace the previous support and chat solution (Intercom); until then, both remain in use. The integration takes place using the click-to-load method: the service is loaded only when you actively call it up. Before that, no connection to Datargo takes place. Processing takes place within the European Union; no transfer to third countries takes place. The legal basis for loading the third-party content and the associated access to information in your terminal equipment is your consent declared through the active calling up (section 25 (1) TDDDG, Art. 6 (1) (a) GDPR); for the subsequent substantive processing of your enquiry, the legal basis is the performance or initiation of a contract (Art. 6 (1) (b) GDPR), and otherwise our legitimate interest in processing enquiries and in customer care (Art. 6 (1) (f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place.

Spam and Bot Protection (Cloudflare Turnstile)

(5) To protect our registration and form functions against automated and abusive access, we use Cloudflare Turnstile (Cloudflare, Inc., USA). The service is strictly necessary for the secure provision of the respective function and is loaded when the protected forms are accessed; in the process, technical information (in particular the IP address and details of the browser as well as a token) is transmitted to Cloudflare in order to check whether the request originates from a human. The legal basis is our legitimate interest in repelling abuse and in the security of our services (Art. 6 (1) (f) GDPR); access to the information in the terminal equipment necessary for the function is exempt from consent pursuant to section 25 (2) no. 2 TDDDG, since it is strictly necessary. Insofar as a transmission to the USA takes place, this is safeguarded by the EU-US Data Privacy Framework (Art. 45 GDPR) or by standard contractual clauses (Art. 46 GDPR). (6) Reach measurement and web analytics: We do not use any web analytics or tracking services such as Google Analytics. We do not create any usage profiles and do not transmit any data to third parties for analysis or advertising purposes. (7) Other recipients: We pass on personal data to carefully selected service providers whom we engage within the framework of the performance of the order (for example registries and certification authorities; see Sections 7 and 8). Insofar as we are legally obliged to do so, we also make personal data available to authorities and courts (Art. 6 (1) (c) GDPR). (8) A copy of the respective safeguards for transfers to third countries (for example the standard contractual clauses) can be requested at datenschutz@regfish.de.

14. Storage Period and Deletion

(1) We process and store personal data only for as long as is necessary to achieve the respective processing purpose. If the purpose ceases to apply or a statutory retention period expires, the data concerned is deleted or anonymised, unless its further storage is necessary for the conclusion or performance of a contract. (2) Insofar as no differing period is specified for the individual processing operations, the following criteria and periods apply: – Server log files: a maximum of 30 days, in the event of a security incident until clarification (Section 4). – Language selection cookie (locale): up to twelve months; other technically necessary cookies: for the duration of the session (Section 5). – Contract and master data: for the duration of the contractual relationship; inactive customer accounts without active services for a maximum of 24 months from the last activity (Section 6). – Communication and chat history: until conclusive processing, for a maximum of 24 months after the last contact (Section 11). – Invoicing, accounting and other tax-relevant data: on account of retention obligations under commercial and tax law (in particular section 257 of the German Commercial Code (HGB), section 147 of the German Fiscal Code (Abgabenordnung, AO), section 14b of the German Value Added Tax Act (Umsatzsteuergesetz, UStG)). The legal basis for this storage is Art. 6 (1) (c) GDPR. The period is eight years for accounting vouchers and otherwise up to ten years, in each case calculated from the end of the calendar year in which the voucher arose. – Records of consent: until withdrawal and subsequently for the period during which their storage is necessary to demonstrate lawfulness. (3) In addition, storage may take place for as long as claims can be asserted against us (statutory limitation periods, regularly three years pursuant to section 195 BGB, in special cases longer).

15. Newsletter and Advertising E-mails

(1) If you subscribe to our newsletter, we use the e-mail address provided by you in order to send you information about our products and offers. The subscription takes place by means of the double opt-in procedure: we first send you a confirmation e-mail and send the newsletter only after your confirmation. The legal basis is your consent (Art. 6 (1) (a) GDPR). (2) As an existing customer, you may, where applicable, receive from us notices regarding our own similar products and services as well as reminders of expiring domains or certificates by e-mail. The legal basis for this is our legitimate interest in direct marketing vis-à-vis existing customers (Art. 6 (1) (f) GDPR in conjunction with section 7 (3) of the German Act against Unfair Competition (UWG)). We send such e-mail advertising only under the following conditions, which must be met cumulatively: – We obtained your e-mail address from you in connection with the sale of goods or a service. – We use the address exclusively for direct marketing of our own similar goods or services. – You have not objected to the use. – We point out to you, already at the time of collection of the e-mail address as well as in each individual advertising e-mail, clearly and unambiguously, that you may object to the use at any time without any costs arising other than the transmission costs at the basic rates. (3) You can object to the receipt of advertising e-mails as well as the newsletter at any time, or unsubscribe from them, via the unsubscribe link in each e-mail or by message to datenschutz@regfish.de. No costs arise for you for this other than the transmission costs at the basic rates. (4) Transactional and service communications that are necessary for the performance of the contract (for example order confirmations, invoices, technical and security-relevant notices, expiry notifications) are not advertising and are sent independently of any advertising objection; the legal basis is Art. 6 (1) (b) and (c) GDPR.

16. Transfers to Third Countries

(1) Insofar as we transmit personal data to a country outside the European Union or the European Economic Area (third country), this takes place only under the conditions of Art. 44 et seq. GDPR. We base such transmissions on: – an adequacy decision of the EU Commission (Art. 45 GDPR), in particular the EU-US Data Privacy Framework for correspondingly certified recipients in the USA as well as, insofar as in force, the adequacy decision for the United Kingdom, – standard contractual clauses of the EU Commission (Art. 46 (2) (c) GDPR) with, where applicable, supplementary protective measures, insofar as no adequacy decision applies, or – the derogations under Art. 49 GDPR, in particular the necessity for the performance of the contract (Art. 49 (1) (b) and (c) GDPR), for example in the case of transmission to registries and certification authorities in third countries. (2) A copy of the agreed safeguards can be requested at datenschutz@regfish.de.

17. Automated Decisions in Individual Cases

(1) A decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR) does not take place. The AI-assisted domain search (Section 10) generates merely non-binding suggestions and does not take any decision concerning you.

18. Your Rights as a Data Subject

(1) Subject to the statutory requirements, you have the following rights: – right of access (Art. 15 GDPR) – right to rectification (Art. 16 GDPR) – right to erasure (Art. 17 GDPR) – right to restriction of processing (Art. 18 GDPR) – right to notification (Art. 19 GDPR) – right to data portability (Art. 20 GDPR) – right to withdraw a granted consent at any time with effect for the future (Art. 7 (3) GDPR); the lawfulness of the processing carried out up to the withdrawal remains unaffected (2) To exercise your rights, please contact datenschutz@regfish.de or the contact details named in Section 1. In order to process your request and for identification purposes, we process your personal data; the legal basis is Art. 6 (1) (c) GDPR.

Right to Object pursuant to Art. 21 GDPR

(3) You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based thereon. If you object, we will no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. (4) Where your personal data is processed for the purposes of direct marketing, you have the right to object at any time to this processing; this also applies to profiling connected with such direct marketing. If you object to processing for direct marketing purposes, your data will no longer be processed for these purposes.

19. Right to Lodge a Complaint with a Supervisory Authority

(1) Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. (2) The supervisory authority competent for us is: Der Hessische Beauftragte fĂĽr Datenschutz und Informationsfreiheit (The Hessian Commissioner for Data Protection and Freedom of Information) Postfach 3163 65021 Wiesbaden Telephone: +49 611 1408-0 E-mail: poststelle@datenschutz.hessen.de Website: datenschutz.hessen.de

20. Currency and Amendment of this Privacy Policy

(1) This privacy policy has the status of June 2026. Due to the further development of our website and offerings or on account of changed statutory or regulatory requirements, it may become necessary to adapt this privacy policy. The respective current version is available at regfish.de/legal/privacy.