As of June 2026
Note on the authoritative language: This English text is a non-binding convenience translation. The legally binding and authoritative version is the German original (available at regfish.de/legal/privacy). In the event of any discrepancy between this translation and the German version, or in the event of a dispute, the German version shall prevail.
The protection of your personal data is a central concern for us. In this privacy policy we inform you, pursuant to Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR), in detail and transparently about which personal data we collect, for which purposes and on which legal bases we process it, to whom we transfer it and which rights you are entitled to.
Where reference is made below to “customers” (Kundinnen und Kunden) or “customers”, all genders are meant. This policy applies to the website regfish.de, the associated services (customer account, ordering and administration interfaces) as well as to the services we provide.
1. Controller
(1) The controller within the meaning of the GDPR and other data protection provisions is:
regfish GmbH
BleichstraĂźe 8a
35390 GieĂźen
Germany
Represented by the managing directors Carsten MĂĽller and Andreas Mallek.
Telephone: 0641 / 49 888 530
E-mail: support@regfish.de
Website: regfish.de
Commercial register: Local Court (Amtsgericht) of GieĂźen, HRB 6589
VAT identification number: DE253460760
(2) Further mandatory information can be found in our imprint, available at regfish.de/legal/imprint.
2. Data Protection Officer
(1) We have appointed an external data protection officer. For questions regarding the collection, processing or use of your personal data as well as regarding the exercise of your rights, you can reach him at:
Rudolf Fiedler
c/o DPP Data Protection GmbH
Zum Gottschalkhof 2
60594 Frankfurt am Main
Telephone: +49 69 175366960
E-mail: datenschutz@regfish.de
(2) If you wish to contact our data protection officer directly with a data protection matter, please use the contact details above and mark your message with a note indicating that it is intended for the data protection officer.
3. General Information on the Legal Bases
(1) We process personal data only where there is a legal basis for doing so. In particular, the following legal bases may apply:
– Art. 6 (1) (a) GDPR, where we obtain your consent for a processing operation.
– Art. 6 (1) (b) GDPR, where the processing is necessary for the performance of a contract to which you are a party or in order to take steps prior to entering into a contract.
– Art. 6 (1) (c) GDPR, where the processing is necessary for compliance with a legal obligation to which we are subject (such as retention obligations under commercial and tax law).
– Art. 6 (1) (d) GDPR, where vital interests of the data subject or of another natural person require processing.
– Art. 6 (1) (f) GDPR, where the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party and your interests, fundamental rights and freedoms do not override those interests.
(2) For each processing operation described below, we name the respective applicable legal basis. Where we base a processing operation on Art. 6 (1) (f) GDPR, we state the respective legitimate interest.
(3) Insofar as access to information in your terminal equipment or the storage of information therein is concerned, the lawfulness is additionally governed by section 25 of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).
4. Provision of the Website and Server Log Files
(1) You can visit our website without actively providing any information about your person. However, when the website is accessed, access data transmitted by your browser is automatically stored in server log files, in particular:
– the IP address of the requesting device
– the date and time of access
– the page accessed or the file requested and the volume of data transferred
– the page from which you visit us (referrer)
– browser type and version as well as the operating system
(2) The IP address is an item of personal data. We process this data in order to deliver the website, to ensure its stability and security and to repel attacks. The legal basis is our legitimate interest in a secure and functional online presence (Art. 6 (1) (f) GDPR).
(3) Storage period: The server log files are stored for a maximum of 30 days and subsequently deleted or anonymised by truncating the IP address. A longer storage of individual log files takes place only where this is necessary to clarify or pursue a specific security-relevant incident (for example an attack); in this case, the log files concerned are retained until the incident has been conclusively clarified. This incident-related storage remains limited to the data necessary to clarify and pursue the specific incident and to the period necessary for this purpose; thereafter they are deleted or anonymised.
(4) The provision of the aforementioned data is technically necessary in order to display the website. Without this data, a connection cannot be established.
6. Customer Account, Order and Contract Processing
(1) For the opening of a customer account as well as for the ordering and processing of our services, we process the data provided by you. These are in particular:
– inventory and master data (form of address, first and last name, where applicable company, address, country)
– contact data (e-mail address, telephone number and, where applicable, fax number)
– access data (username, password in encrypted form, two-factor authentication settings)
– contract, order and usage data (services ordered, terms, domains, certificates, configurations)
– in the case of business customers, additionally VAT identification number and register details
(2) The purpose of the processing is the establishment, performance and administration of the contractual relationship, including the customer account, order processing, provision of the services, invoicing, support and warranty. The legal basis is Art. 6 (1) (b) GDPR (contract and pre-contractual measures). Insofar as the processing serves to fulfil legal obligations, the legal basis is Art. 6 (1) (c) GDPR.
(3) In our input forms we have marked the mandatory fields that you must complete so that we can conclude and perform the desired contract. The provision of this data is necessary for the performance of the contract; without it we cannot render the service, in particular cannot register any domain and cannot have any certificate issued. The provision of further data is voluntary.
(4) Storage period: We store the contract and master data for the duration of the contractual relationship. After termination of the contract, the data is deleted as soon as it is no longer necessary for the purposes of the processing, but at the latest after expiry of the statutory limitation and retention periods (see Section 14). An inactive customer account without active services and without outstanding claims will be deleted or anonymised by us after expiry of 24 months from the last activity, insofar as no statutory retention obligation precludes this.
(5) If you order services for third parties or enter data of employees of your company, you warrant that you are authorised to transmit this data and that the processing is lawful within the meaning of Art. 6 GDPR. In this case you are responsible for informing the data subjects pursuant to Art. 13 and 14 GDPR.
7. Domain Registration, Domain Transfer and Disclosure to Registries
(1) In connection with the registration, renewal or transfer of domains, it is necessary for the performance of the contract to transmit personal data of the domain holder as well as of the administrative and technical contacts to the respective competent registry. Recipients are in particular DENIC eG (.de), EURid (.eu), nic.at (.at), Nominet (.uk) and other registries.
(2) The registries process the holder and contact data transmitted to them in order to administer the domain on the basis of their respective registration policies and statutory or contractual obligations. The registries decide independently on the purposes and means of this processing; to that extent they are controllers in their own right. There is no processing on behalf of the controller on our behalf in the case of domain registration. The legal basis for the transmission is the performance of the contract concluded with you (Art. 6 (1) (b) GDPR).
(2a) Insofar as we and a registry jointly determine the purposes and means with regard to individual processing steps of domain administration and thus joint controllership pursuant to Art. 26 GDPR exists, the following shall apply as the essence of the arrangement made: We collect the holder and contact data from you, check it for completeness and transmit it to the registry; the registry maintains the authoritative domain register, is responsible for its publication in accordance with its policies (see paragraph 3) as well as for the retention of the register data. Each party fulfils the information obligations incumbent upon it pursuant to Art. 13 and 14 GDPR. Irrespective of this, you may assert your data subject rights against any of the parties involved; the primary point of contact for matters concerning our processing is our data protection officer (Section 2). We will provide you with a summary of the respective applicable arrangement on request at datenschutz@regfish.de.
(3) Publication in public directories: Depending on the respective top-level domain and the policies of the registry, certain inventory and contact data may be retrievable via publicly accessible directory services (WHOIS or RDAP). Which data is published depends on the requirements of the respective registry. Insofar as publication takes place, it is based on the fulfilment of the registry requirements within the framework of the contract (Art. 6 (1) (b) GDPR) or on the registry’s own legal obligation.
(4) Origin of data from third parties (Art. 14 GDPR): Insofar as you, as the domain holder or as a reseller, provide data of third parties (for example of end customers or of administrative or technical contacts), we do not collect this data directly from the data subject but receive it from you. The categories of this data comprise name, address and contact data. We process it for the purpose of domain administration and disclosure to the registry on the basis of Art. 6 (1) (b) and (f) GDPR; our legitimate interest consists in the proper provision of the domain service.
(5) Transfer to third countries: Depending on the respective registry, the transmission may also take place to countries outside the European Union or the European Economic Area (third countries). Where there is no adequacy decision of the EU Commission for a third country, we base the transmission on the fact that it is necessary for the performance of the contract concluded with you or concluded in your interest (Art. 49 (1) (b) and (c) GDPR).
(6) Storage period: We store the data necessary for domain administration for the duration of the registration or of the contractual relationship; otherwise Section 14 applies.
8. TLS/SSL and Other Certificates, Disclosure to Certification Authorities (CAs)
(1) When ordering TLS/SSL, S/MIME, code-signing or similar certificates, it is necessary for the performance of the contract to transmit the application data (for example the data from the certificate signing request, the CSR, as well as organisation and contact data) to the respective certification authority (Certificate Authority, CA). The CAs used are in particular DigiCert, Sectigo, GeoTrust, Thawte and RapidSSL.
(2) The CA issues the certificate in accordance with the Baseline Requirements of the CA/Browser Forum in its own data protection responsibility; to that extent there is no processing on behalf of the controller. In the issuance of certificates, a direct contractual relationship regularly arises between the certificate holder and the CA. The legal basis for the transmission is the performance of the contract (Art. 6 (1) (b) GDPR).
(3) For certain types of certificate (in particular for TLS certificates), details from the issued certificate are entered into publicly viewable directories, namely into the Certificate Transparency logs maintained in accordance with the requirements of the CA/Browser Forum. We have no influence over this; the publication is part of the CA’s issuance procedure.
(4) Transfer to third countries: Insofar as a CA transmits data to a third country, Section 7 (5) applies accordingly (Art. 49 (1) (b) and (c) GDPR or adequacy decision).
(5) Storage period: We store data for the administration of the certificate for the term of the certificate and of the contractual relationship; otherwise Section 14 applies.
9. Hosting, E-mail, DNS and API Services for Business Customers (Processing on Behalf of the Controller)
(1) Insofar as we provide for you web hosting or WordPress hosting, e-mail services (mailboxes and forwarders), DNS services (DNS hosting, DNSSEC, DynDNS, Hidden Primary, DNS automation) or the public API and in doing so process personal data that you or your end users enter into our systems, we process this data on your instructions and on your behalf. To that extent there is processing on behalf of the controller pursuant to Art. 28 GDPR; the controller for this content data is you.
(2) For these services we conclude a data processing agreement with business customers. The relevant provisions, including the technical and organisational measures and the sub-processors used, are set out in the data processing agreement, available at regfish.de/legal/dpa. A current overview of the sub-processors used by us is, insofar as provided, available for retrieval at regfish.de/legal/subprocessors.
(3) Resellers: If you pass on services obtained from us to your own customers, you remain our direct contractual partner and become the controller vis-Ă -vis your end customers. In this constellation we are your processor; the chain of responsibility is reflected in the data processing agreement.
(4) We operate the hosting and mail infrastructure on our own systems. Otherwise, we process the content data stored on your behalf exclusively in accordance with your instructions and for the duration of the respective contract; details on deletion and return are governed by the data processing agreement.
10. AI-Assisted Domain Search
(1) To support the search for suitable domains, we offer an AI-assisted suggestion function. If you enter a search term, we process it in order to display domain suggestions to you.
(2) The processing of the search terms takes place exclusively on our own infrastructure within the European Union (self-operated servers with a locally executed AI model). The search terms are not transmitted to any third parties or to any third countries.
(3) The legal basis for the provision of the search function and the associated processing is our legitimate interest in a convenient and high-performance domain search (Art. 6 (1) (f) GDPR) as well as, insofar as the search serves the initiation of a contract, Art. 6 (1) (b) GDPR.
(4) Storage period: Search terms are processed only for the duration of the generation of the suggestions and are not stored for profiling or advertising purposes.
11. Support and Communication
(1) If you contact us (for example by e-mail, via contact forms, by telephone or via the support chat), we process the data communicated by you in order to process and respond to your enquiry.
(2) The legal basis is Art. 6 (1) (b) GDPR, insofar as your enquiry serves the performance or initiation of a contract, and otherwise our legitimate interest in processing enquiries (Art. 6 (1) (f) GDPR).
(3) Storage period: We store the communication history until the respective enquiry has been conclusively processed and no further queries are to be expected, but for a maximum of 24 months after the last contact. Insofar as the history is part of a contractual relationship or is subject to statutory retention obligations, the periods under Section 14 apply. On the integration of the support chat, see Section 13.
12. Data Security
(1) We take technical and organisational measures pursuant to Art. 32 GDPR in order to protect your data against loss, destruction, unauthorised access, alteration and unauthorised disclosure. The transmission via our website takes place in encrypted form (TLS). Your payment data is transmitted in encrypted form to our payment service provider when you store a payment method.
(2) We continue to develop our security measures in line with technological developments. Please always treat your access data as confidential and close the browser window when you have ended your communication with us, in particular when sharing a device.
13. Services Used and Recipients
(1) To provide our website and services, we use the services named below. Insofar as these act as processors for us, we have concluded data processing agreements with them pursuant to Art. 28 GDPR.
Payment Processing (Stripe)
(2) For the processing of payments by SEPA direct debit and credit card, we use Stripe (Stripe Payments Europe, Ltd., Ireland). During the payment process, the data required for this is transmitted to Stripe. The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR) as well as the setting of strictly necessary cookies for fraud prevention (section 25 (2) no. 2 TDDDG). Insofar as Stripe transmits data to the USA, this transmission is safeguarded by the EU-US Data Privacy Framework (Art. 45 GDPR) or by standard contractual clauses (Art. 46 GDPR).
Support Chat (Intercom)
(3) For live support we use Intercom (Intercom R&D Unlimited Company, Ireland, with processing also by Intercom, Inc., USA). The chat is not loaded automatically. The Intercom script is loaded by your browser only when you actively open the chat via the chat button. Before that, no connection to Intercom takes place and no cookies are set by Intercom. Upon opening the chat, data (for example your IP address, browser information as well as your chat entries) is transmitted to Intercom and may in the process also be transmitted to the USA. The legal basis for loading the third-party content and the associated access to information in your terminal equipment is your consent declared through the active opening (section 25 (1) TDDDG, Art. 6 (1) (a) GDPR). For the subsequent substantive processing of your chat enquiry, the legal basis is the performance or initiation of a contract (Art. 6 (1) (b) GDPR), and otherwise our legitimate interest in processing enquiries (Art. 6 (1) (f) GDPR). Insofar as a transmission to the USA takes place, we base this on the EU-US Data Privacy Framework (Art. 45 GDPR), provided that the recipient is certified, and additionally on standard contractual clauses (Art. 46 (2) (c) GDPR).
Customer Relationship Management and Support (Datargo)
(4) For customer relationship management (CRM) as well as the support and chat function we use Datargo (Datargo GmbH, Frankfurt am Main, Germany); Datargo will in future replace the previous support and chat solution (Intercom); until then, both remain in use. The integration takes place using the click-to-load method: the service is loaded only when you actively call it up. Before that, no connection to Datargo takes place. Processing takes place within the European Union; no transfer to third countries takes place. The legal basis for loading the third-party content and the associated access to information in your terminal equipment is your consent declared through the active calling up (section 25 (1) TDDDG, Art. 6 (1) (a) GDPR); for the subsequent substantive processing of your enquiry, the legal basis is the performance or initiation of a contract (Art. 6 (1) (b) GDPR), and otherwise our legitimate interest in processing enquiries and in customer care (Art. 6 (1) (f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place.
Spam and Bot Protection (Cloudflare Turnstile)
(5) To protect our registration and form functions against automated and abusive access, we use Cloudflare Turnstile (Cloudflare, Inc., USA). The service is strictly necessary for the secure provision of the respective function and is loaded when the protected forms are accessed; in the process, technical information (in particular the IP address and details of the browser as well as a token) is transmitted to Cloudflare in order to check whether the request originates from a human. The legal basis is our legitimate interest in repelling abuse and in the security of our services (Art. 6 (1) (f) GDPR); access to the information in the terminal equipment necessary for the function is exempt from consent pursuant to section 25 (2) no. 2 TDDDG, since it is strictly necessary. Insofar as a transmission to the USA takes place, this is safeguarded by the EU-US Data Privacy Framework (Art. 45 GDPR) or by standard contractual clauses (Art. 46 GDPR).
(6) Reach measurement and web analytics: We do not use any web analytics or tracking services such as Google Analytics. We do not create any usage profiles and do not transmit any data to third parties for analysis or advertising purposes.
(7) Other recipients: We pass on personal data to carefully selected service providers whom we engage within the framework of the performance of the order (for example registries and certification authorities; see Sections 7 and 8). Insofar as we are legally obliged to do so, we also make personal data available to authorities and courts (Art. 6 (1) (c) GDPR).
(8) A copy of the respective safeguards for transfers to third countries (for example the standard contractual clauses) can be requested at datenschutz@regfish.de.
14. Storage Period and Deletion
(1) We process and store personal data only for as long as is necessary to achieve the respective processing purpose. If the purpose ceases to apply or a statutory retention period expires, the data concerned is deleted or anonymised, unless its further storage is necessary for the conclusion or performance of a contract.
(2) Insofar as no differing period is specified for the individual processing operations, the following criteria and periods apply:
– Server log files: a maximum of 30 days, in the event of a security incident until clarification (Section 4).
– Language selection cookie (locale): up to twelve months; other technically necessary cookies: for the duration of the session (Section 5).
– Contract and master data: for the duration of the contractual relationship; inactive customer accounts without active services for a maximum of 24 months from the last activity (Section 6).
– Communication and chat history: until conclusive processing, for a maximum of 24 months after the last contact (Section 11).
– Invoicing, accounting and other tax-relevant data: on account of retention obligations under commercial and tax law (in particular section 257 of the German Commercial Code (HGB), section 147 of the German Fiscal Code (Abgabenordnung, AO), section 14b of the German Value Added Tax Act (Umsatzsteuergesetz, UStG)). The legal basis for this storage is Art. 6 (1) (c) GDPR. The period is eight years for accounting vouchers and otherwise up to ten years, in each case calculated from the end of the calendar year in which the voucher arose.
– Records of consent: until withdrawal and subsequently for the period during which their storage is necessary to demonstrate lawfulness.
(3) In addition, storage may take place for as long as claims can be asserted against us (statutory limitation periods, regularly three years pursuant to section 195 BGB, in special cases longer).
16. Transfers to Third Countries
(1) Insofar as we transmit personal data to a country outside the European Union or the European Economic Area (third country), this takes place only under the conditions of Art. 44 et seq. GDPR. We base such transmissions on:
– an adequacy decision of the EU Commission (Art. 45 GDPR), in particular the EU-US Data Privacy Framework for correspondingly certified recipients in the USA as well as, insofar as in force, the adequacy decision for the United Kingdom,
– standard contractual clauses of the EU Commission (Art. 46 (2) (c) GDPR) with, where applicable, supplementary protective measures, insofar as no adequacy decision applies, or
– the derogations under Art. 49 GDPR, in particular the necessity for the performance of the contract (Art. 49 (1) (b) and (c) GDPR), for example in the case of transmission to registries and certification authorities in third countries.
(2) A copy of the agreed safeguards can be requested at datenschutz@regfish.de.
17. Automated Decisions in Individual Cases
(1) A decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR) does not take place. The AI-assisted domain search (Section 10) generates merely non-binding suggestions and does not take any decision concerning you.
18. Your Rights as a Data Subject
(1) Subject to the statutory requirements, you have the following rights:
– right of access (Art. 15 GDPR)
– right to rectification (Art. 16 GDPR)
– right to erasure (Art. 17 GDPR)
– right to restriction of processing (Art. 18 GDPR)
– right to notification (Art. 19 GDPR)
– right to data portability (Art. 20 GDPR)
– right to withdraw a granted consent at any time with effect for the future (Art. 7 (3) GDPR); the lawfulness of the processing carried out up to the withdrawal remains unaffected
(2) To exercise your rights, please contact datenschutz@regfish.de or the contact details named in Section 1. In order to process your request and for identification purposes, we process your personal data; the legal basis is Art. 6 (1) (c) GDPR.
Right to Object pursuant to Art. 21 GDPR
(3) You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based thereon. If you object, we will no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
(4) Where your personal data is processed for the purposes of direct marketing, you have the right to object at any time to this processing; this also applies to profiling connected with such direct marketing. If you object to processing for direct marketing purposes, your data will no longer be processed for these purposes.
20. Currency and Amendment of this Privacy Policy
(1) This privacy policy has the status of June 2026. Due to the further development of our website and offerings or on account of changed statutory or regulatory requirements, it may become necessary to adapt this privacy policy. The respective current version is available at regfish.de/legal/privacy.


