Privacy Policy
We are pleased about your visit to our website hostyon.com and your interest in our company and our offers.
Despite careful content control, we assume no liability for external links to third-party content, as we have not initiated the transmission of this information, have not selected or modified the information itself, and have not selected the recipients of the transmitted information.
The protection of your personal data during its collection, processing, and use on the occasion of your visit to our website is an important concern for us and takes place within the framework of legal regulations, about which you can inform yourself, for example, at www.bfdi.bund.de.
In the following, we explain which information we collect during your visit to our websites and how it is used:
1. Collection and Storage of Personal Data as well as the Nature and Purpose of Their Use
a) When visiting the website
Each time a customer (or other visitor) accesses our website, information is automatically sent to the server of our website by the internet browser used on your end device (computer, laptop, tablet, smartphone, etc.).
This information is temporarily stored in a so-called log file.
The following data is collected without your intervention and stored until automated deletion:
- IP address of the requesting computer (and, if applicable, in anonymized or pseudonymized form),
- Name of the retrieved file and amount of data transferred, as well as the date and time of retrieval,
- Notification of successful retrieval,
- Requesting domain (referrer URL),
- Description of the type of internet browser used and the operating system of your end device, as well as the name of your access provider.
Our legitimate interest pursuant to Art. 6(1)(f) GDPR for collecting the data is based on the following purposes:
- Ensuring a smooth connection establishment and comfortable use of the website,
- Evaluating system security and stability, as well as
- For further administrative purposes to ensure secure server operation.
Under no circumstances do we use the collected data for the purpose of drawing conclusions about your person.
b) When using our contact or registration form
For questions of any kind, we offer you the opportunity to contact us using a form provided on the website.
In doing so, at least a valid email address and your name are required so that we know who the inquiry comes from and can answer it.
Further information can be provided voluntarily.
Data processing for the purpose of contacting us is carried out in accordance with Art. 6(1)(a) GDPR on the basis of your voluntarily given consent or – insofar as it concerns pre-contractual inquiries – in accordance with Art. 6(1)(b) GDPR.
The personal data collected by us for the use of the contact form will be deleted after your request has been settled, provided that no statutory retention obligations prevent this.
Cloudflare Turnstile
To protect your inquiries via our internet forms, we use the Cloudflare Turnstile service. Turnstile is a privacy-friendly alternative to traditional CAPTCHAs that automatically checks whether access is made by a human or by automated programs (bots).
Turnstile performs invisible checks in the background to enable a better user experience. The verification serves exclusively to ensure the security of our website and to prevent abusive, automated access. For this purpose, Turnstile evaluates technical information (including IP address, user-agent header, TLS fingerprints, and web browser data).
The processing of this data is based on our legitimate interests pursuant to Art. 6(1)(f) GDPR, namely the protection of our website from automated attacks, spam, and abuse. The recipient of the data is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Since Cloudflare is based in the USA, a transfer of personal data to the USA may take place. Cloudflare ensures an adequate level of data protection via the EU Commission's Standard Contractual Clauses as well as through its certification under the EU-US Data Privacy Framework. Further information can be found in the Cloudflare Turnstile Privacy Policy.
c) Upon entering into a contractual relationship / Registering as a user
When creating a customer account or entering into a contractual relationship on our platform, we process the following personal and company-related data:
- Data for identification and contacting (e.g., name of the contact person, email address, phone number),
- Company data (company name, legal form, business address, VAT identification number or tax number),
- Information on your chosen payment method and billing details.
The strictly mentioned data are processed for the establishment, implementation, and execution of the contractual relationship. The legal basis for this processing is Art. 6(1)(b) GDPR. Insofar as we are legally obliged to collect data (e.g., tax evidence), the processing is based on Art. 6(1)(c) GDPR.
The data will be stored for the duration of the contract term and blocked for further use after termination. After expiry of the statutory commercial and tax retention periods (according to HGB and AO; usually 6 to 10 years), this data will be permanently deleted.
d) Use of payment service providers
To process payments, we work together with external payment service providers. We pass your order data to the payment service provider you selected within the scope of payment processing strictly for this purpose. The legal basis for the transfer and processing of data is Art. 6(1)(b) GDPR (performance of a contract).
Google Pay
When using Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland), your encrypted order data is transmitted to Google. The transaction is carried out via a tokenized numerical value, so we do not receive direct credit card or bank details. Google privacy information: Google Pay Privacy Notice.
Apple Pay
When using Apple Pay (Apple Distribution International, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland), payment data is transmitted encrypted to Apple. Apple does not store any data that can be assigned to your person. Apple privacy information: Apple Pay Support.
Amazon Pay
When selecting Amazon Pay, your payment and order data will be transmitted to Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg. Amazon privacy information: Amazon Pay Privacy Policy.
Stripe
For credit card and other online payment methods, we use Stripe (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland or Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA). Data processing is carried out for contract performance (Art. 6(1)(b) GDPR). Insofar as data is transferred to the US parent company, the level of data protection is secured via Standard Contractual Clauses as well as the EU-US Data Privacy Framework. Stripe privacy policy: Stripe Privacy.
PayPal
When paying via PayPal, the processing takes place via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal reserves the right to obtain a credit report on the basis of legitimate interests for certain payment methods (e.g., invoice). PayPal privacy principles: PayPal Privacy Statement.
Mollie
For the aggregation and handling of payments, we use the service of Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands. Mollie processes IP addresses, browser data, and payment details exclusively to process the transaction. Mollie privacy policy: Mollie Privacy.
e) When registering for our newsletter / Receiving system and transaction emails
Insofar as you have expressly consented to receive our newsletter pursuant to Art. 6(1)(a) GDPR, we will use your email address to regularly send you promotional information. Unsubscribing is possible at any time via the link at the end of each newsletter or by email to the contact details mentioned in the Legal Notice (Impressum).
Furthermore, we process your email address for sending technically and contractually necessary transactional emails (e.g., registration confirmations, invoices, system notifications, or server alerts). The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract).
Brevo
For sending and analyzing our newsletter as well as certain customer communications, we use the Brevo service (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany). Brevo collects technical data (e.g., IP address, browser type) and uses tracking pixels to evaluate whether and when emails are opened or links are clicked. This serves to optimize our offer. Processing for marketing purposes is based on your consent (Art. 6(1)(a) GDPR). We have concluded a data processing agreement with Brevo pursuant to Art. 28 GDPR. Brevo privacy policy: Brevo Privacy Policy.
Mailjet
For sending transactional emails, system notifications, and contract-relevant information, we use the Mailjet service (Mailjet SAS, 13–13 bis, rue de l’Aubrac, 75012 Paris, France). Mailjet collects technical information (e.g., time of retrieval, IP address, browser type, and operating system) and enables statistical evaluations of delivery rates and clicks to ensure the technical reliability of email delivery. The processing is carried out for contract performance or implementation of pre-contractual measures (Art. 6(1)(b) GDPR) as well as to protect our legitimate interests in a secure and high-performance email delivery system (Art. 6(1)(f) GDPR). We have concluded a data processing agreement with Mailjet in accordance with Art. 28 GDPR. Mailjet privacy policy: Mailjet Privacy Policy.
2. Disclosure of Personal Data
A transfer of your data to third parties for purposes other than those listed below does not take place.
We only share your data with third parties if:
- You have given your express consent pursuant to (Art. 6(1)(a) GDPR),
- This is necessary for the processing of contractual relationships with you (Art. 6(1)(b) GDPR),
- There is a legal obligation for disclosure (Art. 6(1)(c) GDPR), or
- The disclosure is necessary for the establishment, exercise, or defense of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data (Art. 6(1)(f) GDPR).
In these cases, the scope of the transmitted data is limited to the minimum required.
Our data processing takes place primarily within the Federal Republic of Germany and the European Union (EU). Insofar as we work together with third-party providers who process data outside the EU or the European Economic Area (EEA), we ensure the required level of data protection through legally provided safeguards (such as the EU Standard Contractual Clauses or adequacy decisions like the EU-US Data Privacy Framework). All third-party providers used are listed in this privacy policy.
3. Data Subject Rights
Upon request, we will gladly inform you whether and which personal data relating to your person are stored (Art. 15 GDPR), in particular regarding the processing purposes, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if they were not collected from us, and the existence of automated decision-making including profiling.
You also have the right to have any incorrectly collected personal data rectified or incomplete data completed (Art. 16 GDPR).
Furthermore, you have the right to demand that we restrict the processing of your data, provided that the legal prerequisites for this are met (Art. 18 GDPR).
You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format or to request transmission to another controller (Art. 20 GDPR).
In addition, you have the right to be forgotten, i.e., you can demand that we erase your personal data, provided that the legal prerequisites for this are met (Art. 17 GDPR).
Regardless of this, your personal data will be automatically deleted by us if the purpose of the data collection has ceased to apply or the data processing has been unlawful.
Pursuant to Art. 7(3) GDPR, you have the right to withdraw your once-given consent to us at any time. As a result, we may no longer continue the data processing based on this consent for the future.
You also have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(f) GDPR (balancing of interests) (Art. 21 GDPR).
If you wish to make use of your right of withdrawal or objection, an email is sufficient to: info@hostyon.com
In the event of violations of data protection regulations, you have the option to lodge a complaint with a competent supervisory authority pursuant to Art. 77 GDPR. The competent supervisory authority includes, among others, the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), accessible at https://www.datenschutz.rlp.de.
4. Duration of Data Storage
The collected data will be stored by us for as long as is necessary for the execution of the contracts entered into with us, as long as statutory (especially commercial and tax) retention periods prescribe this, or until you have effectively exercised your right to erasure.
5. Cookies and Tracking Technologies
We use cookies on our website. These are small text files that your browser automatically creates and that are stored on your end device when you visit our website. Information is stored in the cookie that arises in connection with the specific end device used. However, this does not mean that we gain direct knowledge of your identity.
Cookies are divided into technically necessary and technically non-necessary cookies:
a) Technically necessary cookies
Technically necessary cookies are strictly required for the operation of our website and to provide basic functions. For example, they ensure that your shopping cart or your login status is maintained during the session. These cookies are usually deleted automatically after leaving our website or closing the browser (session cookies).
The legal basis for the use of these cookies is our legitimate interest pursuant to Art. 6(1)(f) GDPR in providing a technically error-free and optimized website as well as Section 25(2)(2) TDDDG.
b) Technically non-necessary cookies (Subject to consent)
Insofar as you have declared your express consent via our cookie consent banner, we use technically non-necessary cookies to statistically evaluate the use of the website, analyze user behavior, and optimize marketing measures. The exact functionality, storage duration, and possible third-party recipients of the data can be found directly in the settings of our consent banner.
The legal basis for this is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with future effect via the cookie settings on our website.
6. JavaScript and Technical Optimizations
To provide interactive functions and to optimize the visual presentation, our website uses JavaScript. If you deactivate the execution of JavaScript in your browser for security reasons, some functions of our platform may not be available to you or may only be available to a limited extent.
ShortPixel (Image Optimization)
To optimize loading times and efficiently deliver compressed image media, we use the ShortPixel service provided by ID SCOUT SRL, 2 Transilvaniei St., Apt. 19, Bucharest 1, Romania. When a page is called up, your browser loads the required images into the browser cache. For this purpose, your browser connects to the servers of ShortPixel, whereby your IP address is transmitted to ShortPixel. Processing is carried out on the basis of our legitimate interest in a performant and loading-time-optimized presentation of our online offer (Art. 6(1)(f) GDPR). Further information can be found in the ShortPixel Privacy Policy.
7. Online Marketing and Analysis Measures
The web analysis and marketing measures listed below and used by us are executed, provided they are third-party tools, exclusively on the basis of your prior, express consent pursuant to Art. 6(1)(a) GDPR.
a) Google Tools (Google Ireland Limited)
We use various services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Google Analytics 4 (GA4)
Insofar as you have given your consent, we use Google Analytics 4, a web analytics service. GA4 records interactions from you on our website on an event basis. By default, full IP addresses are not logged or stored; IP addresses are automatically shortened and anonymized (so-called IP masking) within member states of the EU or the EEA before being transmitted to servers in the USA. The data is automatically deleted with a retention period of 14 months. You can prevent collection by installing the Google Analytics Opt-out Browser Add-on.
Google Tag Manager
We use the Google Tag Manager. This tool serves exclusively to integrate and trigger other website tags via a central interface. The Tag Manager itself does not set cookies or collect personal data, but it triggers other tags that in turn may collect data.
Google Ads & Conversion Tracking
We use Google Ads Conversion Tracking to measure the success of our advertising campaigns. If you reach our website via a Google ad, a cookie is set, which expires after 30 days and does not serve personal identification. The information is used purely for statistical evaluations for us as the campaign operator.
Google Workspace
For our business email communication and office organization, we use Google Workspace. The processing of your data (e.g., email address, message content) within the scope of mail traffic is carried out to implement pre-contractual measures or for contract performance pursuant to Art. 6(1)(b) GDPR. We have concluded a data processing agreement with Google, including EU Standard Contractual Clauses.
b) Matomo (Self-hosted / Privacy-friendly Analysis)
For statistical analysis and optimization of our offer, we use the open-source software Matomo. The data processing takes place exclusively on our own, secured servers. IP addresses are anonymized immediately before storage. No data is transmitted to third parties. The processing is based on our legitimate interest in the anonymous statistical reach measurement to optimize our web offer pursuant to Art. 6(1)(f) GDPR. Insofar as we operate Matomo using cookies, this is only done after your prior consent.
c) Facebook Pixel and Custom Audiences
Insofar as you have consented, we use the Facebook Pixel of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This enables Meta to identify visitors to our website across devices in order to place targeted advertisements in the Meta network (Facebook, Instagram). Data transfers to the USA are secured via the EU-US Data Privacy Framework. Further information can be found in the Meta Privacy Policy.
d) Solid Affiliate (Partner Program Tracking)
We use the Solid Affiliate tool for the technical handling of our affiliate program. If a user reaches us via the referral link of one of our distribution partners (affiliates) and books a hosting package, the system records the referring ID as well as the time of the click in order to correctly assign the referral commission incurred. No permanent profiling or merging with other profile data takes place. Processing is carried out for contract performance and billing of the affiliate relationship pursuant to Art. 6(1)(b) GDPR.
f) Cloudflare
To protect our website, we use the Cloudflare service of the provider Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Cloudflare operates a Content Delivery Network (CDN) and provides protection functions for the website (Web Application Firewall).
For this purpose, the data transfer between the requesting browser and our server is decrypted by Cloudflare in order to prevent attacks such as so-called Distributed Denial of Service (DDoS) attacks on our software.
The legal basis is the protection of legitimate interests, namely the prevention of attacks on our website pursuant to Art. 6(1)(f) GDPR.
Further information on Cloudflare's privacy regulations can be found here: www.cloudflare.com/privacypolicy.
8. Google Maps Services
We use the API services of Google Maps (e.g., Google Maps, Directions, Distance, Geocoding, and Geolocation) of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) on our website.
The use of these services takes place exclusively on the basis of your prior, express consent pursuant to Art. 6(1)(a) GDPR as well as Section 25(1) TDDDG. Without your consent via our consent banner, no data will be transmitted to Google and the interactive maps will remain blocked.
In the event of consent, your browser establishes a direct connection to Google's servers. Among other things, your IP address and location data are processed. The parent company Google LLC is certified under the EU-US Data Privacy Framework, ensuring an adequate level of data protection. Further information can be found in the Google Maps Terms of Service as well as in the Google Privacy Policy.
9. Use of YouTube (Enhanced Privacy Mode)
We embed videos from the YouTube platform on our website. The operator of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
The embedding takes place exclusively on the basis of your prior consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. We use the **"enhanced privacy mode"** provided by YouTube. This ensures that YouTube only transmits data about your user behavior to its servers and sets cookies when you start playing the video with an active click.
When playing, a connection to Google's network is established, whereby your IP address is transmitted and Google learns that you are visiting our site. If you are logged into your Google or YouTube account at the same time, Google can assign this usage behavior directly to your personal profile. You can prevent this by logging out of your Google accounts before playing the video. Google LLC is certified under the EU-US Data Privacy Framework. Further details can be found in the Google Privacy Policy.
10. Social Networks (Simple Links)
We do **not** use active social media plugins on our website that already silently transmit data to social network operators when the page loads. Instead, we exclusively use static, simple links to our official company profiles. Data transmission to the respective networks therefore only takes place if and when you actively click on the corresponding link.
If you call up the linked profiles, the operators of these networks often process personal data (e.g., IP address, user behavior) also on servers outside the European Union and use these profiles for market research and advertising purposes. We have no influence on this data processing. To assert your data subject rights (e.g., request for information), it is most effective to contact the respective providers directly, as only they have full access to the user data.
We link to the following social networks on our website:
- Meta (Facebook / Instagram): Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Privacy Policy: www.facebook.com/about/privacy/
- X (formerly Twitter): X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Privacy Policy: twitter.com/en/privacy
- LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Privacy Policy: www.linkedin.com/legal/privacy-policy
- Pinterest: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. Privacy Policy: policy.pinterest.com/en/privacy-policy
- XING: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany. Privacy Policy: privacy.xing.com/en/privacy-policy
- WhatsApp: WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Privacy Policy: www.whatsapp.com/legal/#privacy-policy
- TikTok: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. Privacy Policy: www.tiktok.com/legal/privacy-policy
11. Data Security
Within the website visit, we use the widespread SSL/TLS procedure in connection with the highest encryption level supported by your browser. In addition, we use suitable technical and organizational security measures (TOM) to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or against unauthorized access by third parties. Our security measures are continuously revised in line with technological developments.
When contacting us by unencrypted email, complete data security on the transmission path cannot be guaranteed by us. For confidential information, we therefore recommend using the postal service or end-to-end encrypted communication channels.
12. Timeliness and Amendment of This Privacy Policy
This privacy policy is currently valid and has the status: June 2026.
Due to the further development of our website and offers or due to changed statutory or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed and printed out at any time on the website at https://hostyon.com/en/privacy-policy/.
13. Name and Contact Details of the Data Controller
This data protection information applies to data processing by the controller pursuant to Art. 4(7) GDPR:
Micha Cassola
Am Kiesweg 26
66955 Pirmasens
Email: info@hostyon.com