Privacy Notice for Websitevisitors and Customers

Drei wellenförmige Linien in Blau- und Türkistönen.

1. Introduction

The controller within the meaning of Art. 4 No. 7 GDPR (hereinafter "we", "us/our") takes appropriate measures to enable the best possible protection of your privacy and the security of your personal data. These privacy notices describe how we collect, use, store and disclose your personal data when you visit our websites, use our products and services or interact with us.

In the context of providing our products and services, we also act as a processor within the meaning of Art. 4 No. 8 GDPR. The data processing that we perform as a processor when providing our products and services is available in our data processing agreement.

 

2. Information and Contact Details of the Controller

The Controller is:

IONOS SE

Elgendorfer Str. 57

56410 Montabaur

Germany

E-Mail: datenschutz@ionos.de

 

You can reach our Data Protection Officer at:

IONOS SE

The Data Protection Officer

Elgendorfer Straße 57

56410 Montabaur

Germany

E-Mail: datenschutz@ionos.de

 

3. What Data We Process

We may process various types of personal data about you, including:

  • Identity data: Name, username, title.
  • Contact data/Inventory data: Contract data such as billing address, delivery address, e-mail address, telephone numbers.
  • Financial data: Payment data, bank account details.
  • Transaction data: Details of payments to and from you as well as details of products and services you have purchased from us.
  • Technical data: IP address, browser type and version, operating system, device information.
  • Profile data: Username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
  • Usage data: Information about how you use our website, products and services.
  • Marketing and communications data: Your preferences in receiving marketing communications from us and your communication preferences.

 

4. How We Process Your Data

We process your data in various ways, including:

  • Direct interactions: You provide us with your data when you create an account, order products or services, fill in forms, visit our website, contact us or provide feedback.
  • Automated technologies or interactions: We collect data about your devices, browsing actions and patterns when you use our website through cookies and similar technologies.
  • Third parties or publicly available sources: We may receive personal data about you from various third parties and public sources (e.g. through business partners or web crawling). 

 

5. How We Use Your Data

We use your personal data for the following purposes:

We process your personal data to fulfill our contractual obligations and ensure smooth use of our offers. This includes, among other things, the collection of inventory data, payment information and usage data. This data is used to manage your orders, provide technical support and continuously improve our services and, if necessary, adopt your changes in the customer area. 

If you intend to become our business partner, we generally process your contact information, company data and contract-specific information. We use this information to manage participation in our programs, for contract fulfillment, to facilitate communication and to optimize cooperation.

We process your personal data such as your name, your contact details and payment information for this purpose. This data is necessary to process your orders, to make the payment process secure and to guarantee you smooth purchase processing. In addition, we also use this data to provide you with invoices. 

We process your personal data such as name, contact details and the communication history as well as the content of your inquiry to customer support. This information is necessary to process your request efficiently and to guarantee the desired support. 

To manage and authenticate your account, we process personal data such as your name, your e-mail address and login information. This data is necessary to secure access to your account, verify your identity and enable you to use our services in a personalized way. 

To improve and personalize our website, we process data such as usage behavior, IP addresses and cookies. This information helps us to optimize the functionality of our website, adapt content to your interests and offer you a personal user experience. You can find further information in our Cookie Policy under point 14. 

To send you marketing communications or for telephone advertising, we process your inventory data and your usage data. We use this information to inform you about our products, services and offers that may be of interest to you. Further information on our marketing activities can be found in particular under point 6. 

We process your contact details, such as your e-mail address or postal address. This data is used to ensure that you receive important information about your contracts and our services. For example, we send you information about the function and use of your products, contract extensions or price adjustments. 

We process your personal data in order to comply with legal obligations, in particular to fulfill tax, accounting and recording obligations as well as to comply with regulations to combat money laundering and terrorism financing and, if necessary, also due to official orders in connection with the relevant telecommunications laws. In addition, in certain cases we are also obliged to investigate complaints about customer pages due to the Digital Services Act (DSA). 

We process your personal data, such as contact details and contract information. This data is necessary to comply with our contractual obligations, ensure contract performance and, in the event of payment defaults, enforce our claims. 

To prevent fraud and payment defaults, we process certain personal data, including transaction and payment information. This data processing helps us to detect suspicious activities, minimize risks and ensure financial security for both you and us. We check whether there are indications of abusive use of our web service or fraud attempts using the end device you use when you order online. In addition, your device data is compared with data on devices from which fraudulent acts have been carried out in the past or where there was a corresponding suspicion. As a rule, IONOS employees or a service provider also check the results manually at the relevant point.

For business intelligence analysis, we process data to gain insights that help us optimize our business processes and make strategic decisions. We use aggregated and anonymized data whenever possible to identify trends and improve the efficiency of our services.

To improve our products and services, we process information such as feedback, usage data and market analysis. This data helps us to optimize our offers, develop new functions and continuously improve your customer experience.

We process your personal data for the implementation of free product tests. We use your registration data, such as name, your contact details and other login information, to enable you to access the product test and to send you advertising for the same or similar products via e-mail.

To enable you to receive optimal support in the context of suitable product selection, we offer free product presentations in the form of webinars or product demos. To conduct the webinars and product demos, we process your registration data such as name, your contact details and other login information. This data is necessary to enable you to access our events. 

For troubleshooting in our products and services, we process relevant data such as technical logs, error messages and usage data. This data is necessary to quickly identify and resolve technical problems in order to ensure you smooth use of our offers.

We process your personal data for registration and participation in raffles. Further information on data processing within the scope of the raffle can generally be found in the respective terms and conditions of participation for the raffle.

In the context of the use and training of AI, we process data to provide you with AI applications and to improve the performance and efficiency of our AI applications. This applies to applications in the areas of products and services, fraud prevention, customer support and marketing. We usually process aggregated data for this purpose. However, if we process personal data, corresponding deletion routines have been implemented. 

To record and store telephone conversations for quality and evidence purposes, we process call data in order to improve service quality and, if necessary, to maintain communication evidence.

To screen against sanctions lists, we process your personal data to ensure that we comply with our legal obligations and conduct business in accordance with international regulations. This screening serves to identify potential risks and ensure compliance with trade restrictions. 

In the context of web crawling activities, we collect public data from the Internet to analyze trends, improve our services and conduct market research. In doing so, we take care to only process publicly available information in order to comply with data protection regulations. 

Within the corporate group, data may be exchanged with affiliated companies of IONOS Group SE or United Internet AG in order to create synergies and, in particular, to optimize administrative processes, web presences and services/products. 

We also process your personal data if you visit our presences within social media. This includes, in particular, the information you provide yourself.

6. Data Processing For Marketing Purposes

We use your personal data for marketing purposes in order to send you individualized offers and information about our products and services. In doing so, we are guided by our legitimate interests in strengthening our customer relationships and continuously improving our services and products. We also use machine learning to calculate individual product recommendations. Machine learning serves the purpose of directing advertising to our customers efficiently and in a targeted manner. The basis for the calculations is the respective usage behavior of the customers within our websites and, if applicable, also the websites of the affiliated companies of IONOS Group SE. In this regard, we have a predominant legitimate interest in optimizing business processes or making products more appealing through the use of machine learning. However, to protect your data, we have anonymized all personal data as far as possible or implemented corresponding deletion routines.

In order to deliver targeted advertising in the form of ads on portals of our marketing partners or our affiliated companies, we also use services such as Meta Custom Audiences, LinkedIn Matched Audiences, TikTok Custom Audiences, Reddit Custom Audiences and Google Customer Match. We transmit inventory data (e-mail address, telephone number, zip code, country) to our marketing partners. However, the data is not sent in plain text, but is hashed in advance using the SHA 256 algorithm and then transmitted. The marketing partner then compares this with its own identical data in order to then display targeted, personalized advertising in the form of ads on the portals of the respective marketing partner or our affiliated companies.

Type of data:
  • Inventory data (e.g. contract data such as e-mail address, telephone number)
  • Information about your interactions with our services (e.g. pages visited, products purchased)
  • Demographic data (e.g. age, gender)
  • Your preferences and interests
  • Usage data (data generated when using websites, services and products, including analysis of click behavior)
Purposes of use:
  • Sending newsletters and promotional e-mails
  • Display of personalized advertisements on our websites and on other platforms
  • Conducting customer surveys and market research
  • Analysis of customer behavior data to improve our products and services
  • Telephone contact for promotional purposes
  • Use and training of AI
  • Data transfer between affiliated companies
Legal basis:

The legal basis for the processing of your personal data for marketing purposes is our legitimate interest and the consent you have given for selected data processing operations.

Right to object:

You have the right to object to the processing of your personal data for marketing purposes at any time. As a customer, you can change your settings for receiving newsletters, telephone contact and promotional e-mails at any time via your customer area (Control Panel) or assert your objection at: datenschutz@ionos.de .

 

7. Legal Bases For Processing

We process your personal data on the following legal bases:

  • Contract fulfillment: The processing is necessary for the fulfillment of a contract with you or for the implementation of pre-contractual measures.
  • Consent: You have given your consent to the processing of your personal data for specific purposes.
  • Legitimate interests: The processing is necessary for our legitimate interests, provided that your interests or fundamental rights and freedoms do not prevail. Legitimate interests that we pursue are in particular: Financial interests, direct marketing, fraud prevention, AI use and training, data transfer to affiliated companies, improvement of technical infrastructure, improvement of our products/services and web presences, cost savings and process optimization.
  • Legal obligation: The processing is necessary to fulfill a legal obligation to which we are subject.

 

8. Disclosure of Your Data

We may disclose your personal data to the following categories of recipients if necessary:

Your data could also be passed on to technology providers who provide various technical services for the support and optimization of the online offer. This category includes, among others, providers of cookies and other tracking technologies, anti-fraud software such as reCAPTCHA, Friendly CAPTCHA and fraud detection tools such as Crif and ThreatMetrix, as well as companies that operate social media platforms, including Facebook Ireland Ltd., Twitter Inc., Google LLC, LinkedIn Ireland Unlimited Company and Xing New Work SE.

This includes partners who support the implementation of digital marketing strategies, the analysis of user data and target group analysis. Examples include Google Analytics for web analysis, HubSpot for CRM and marketing automation services, and other specialized marketing partners such as Meta, LinkedIn and Reddit.

In order to be able to offer a comprehensive range of services, data is also passed on within the framework of partnerships for product development and for marketing purposes. Partners such as Salesforce for CRM solutions, OpenAI for AI-supported services or Atlassian for status information services fall into this category. In addition, we also use payment processors such as PayPal, domain registration points, debt collection companies and service providers in the area of customer service. 

In accordance with legal obligations, data may be passed on to state institutions, judicial authorities or other official bodies, both to comply with legal requirements and to protect the rights of the company.

Within the corporate group, data may be exchanged with affiliated companies of IONOS Group SE or United Internet AG in order to optimize administrative processes and services. 

9. International Data Transfer

We may transfer your personal data to countries outside the European Union (EU) and the European Economic Area (EEA). In such cases, we will ensure that appropriate safeguards are taken to protect your data within the framework of legal requirements, unless you have given us your consent for the data transfer in an individual case.

 

10. Data Security

We have taken appropriate security measures to protect your personal data from loss, misuse, unauthorized access, disclosure, alteration or destruction.

 

11. Storage Period

In principle, we only store your personal data for as long as is necessary for the purposes mentioned in these privacy notices or as we are obliged or entitled to do due to legal retention periods. For example, we store your personal data for the duration of a contract concluded with you. If, on the other hand, data processing is based on the legal basis of consent or a legitimate interest, we usually store your data until the point at which you grant your revocation or objection. 

 

Further information on individual case-related retention periods can be found listed as examples below.

Contract data: Stored for the duration of the contractual relationship and beyond, provided that legal storage obligations (e.g. 10 years due to tax and commercial law provisions) exist.

Invoicing data: Until the termination of the contract and beyond, in order to comply with legal obligations (up to 10 years).

Chat and communication data/call recordings: Chat or conversation histories are stored for 90 days. If a chat or telephone call leads to a contract conclusion, the relevant part is stored for the contract duration + necessary legal period (up to 10 years).

Raffles: Data processed in the context of raffles is usually deleted after the raffle has ended, provided that no further retention periods exist or the participant has agreed to further use of the data. 

Information requests: If data subjects assert their right to information against us, we store the data for the duration until full information is provided and beyond that for up to 3 years. 

Contact forms/Contact points: Data processed in the context of inquiries via contact forms or contact points is usually stored until the inquiry has been completely processed, provided that no further legal retention periods exist. 

Analysis and tracking data: Data used to improve services is usually stored for a short time, e.g. for the duration of the cookie lifetime.

Security and fraud prevention data: Usually stored for up to 6 months. However, longer storage periods are possible for specific purposes. 

Friendly Captcha and reCAPTCHA data: Stored until the purpose (security check) is achieved.

Marketing data: Usually stored until objection. 

AI-based data: Usually this is aggregated data. If a personal reference cannot be excluded, the data is kept until the purpose is achieved and then deleted.

Marketing and newsletter data: Stored until revocation of consent or fulfillment of the purpose.

Rating and survey data: Until termination of the contract or fulfillment of the purpose, such as at the latest 24 months after a survey for its improvement.

Google Analytics and similar tracking services: Limited in time by cookie settings or until revocation occurs.

Comments in blogs: Comments remain until the blog is deleted or the comment is classified as legally questionable.

Webinars and demos/product tests: Data is stored until the webinar/demo or product test is conducted and, if necessary, used for follow-up communication.

Cloud data and IT services: Storage until deletion by the user or at the end of the contract.

CDN and web services: Data is stored until the termination of the service or by user deletion request.

Logfiles and temporary memory data: Often between a few days and a maximum of 60-90 days, depending on specific security or operational needs.

12. Automated Decision-Making/Profiling

No automated decision-making within the meaning of Art. 22 GDPR, including profiling, takes place that has legal effects on you or significantly affects you, unless this is legally permissible. 

 

13. Your Rights

You have the following rights regarding your personal data:

  • Right to information: You have the right to receive information about your stored data.
  • Right to rectification: You have the right to have incorrect data corrected.
  • Right to erasure: You have the right to request the deletion of your data.
  • Right to restriction of processing: You have the right to restrict the processing of your data.
  • Right to data portability: You have the right to receive your data in a portable format.
  • Right to object: You have the right to object to the processing of your data.
  • Right to withdraw consent: You have the right to withdraw consent once given at any time.
  • Right to lodge a complaint with a supervisory authority: You also have the right to lodge a complaint with a competent data protection supervisory authority at any time.

To exercise your rights, please use the contact details provided in point 2. As a customer, you also have the option at any time to view or change the data processing concerning you in the customer area (Control Panel).

 

14. Cookies and Similar Technologies

We use cookies and similar technologies to improve and personalize your experience on our website and to display interest-based advertising to you. You can find further information in our Cookie Policy

 

15. Changes to these Privacy Notices

We may update these privacy notices from time to time. The current version will be published on this website.