Data Privacy Statement

Thank you very much for your interest in our company and in our website. The protection of your personal data and your privacy are very important to us. In this privacy statement, we would like to inform you about how we handle your personal data. The party responsible for data processing is

DENIC eG
Theodor-Stern-Kai 1
60596 Frankfurt am Main
GERMANY
Phone: +49 69 27 235 0
Fax: +49 69 27 235 238
E-Mail: info[at]denic[dot]de

You can contact our Data Protection Officer at privacy[at]denic[dot]de.

When you make use of one of DENIC eG's offerings, e.g. visit our website or use the tools we provide there, we will process your personal data. We process your data in strict confidence and only for the purpose we tell you when we collect the data. The processing of your data will always be in keeping with the standards of the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other applicable data protection provisions.

1. Provision of the Website

Whenever you visit our Internet offering at vchecked.de or retrieve a file, a range of data referring to this action is temporarily stored and processed in a log file. The following data is processed:

  • IP address
  • Date and time of your access (time stamp)
  • Details of the access request and destination address (protocol version, HTTP method, referrer, user-agent string)
  • Name of the file that has been accessed and amount of data transmitted (requested URL incl. query string, size in bytes)
  • Message whether the request was successful (HTTP status code)
  • Website from which the request is made
  • Browser type or app used
  • Operating system and the interface it uses
  • Language and version of browser software
  • Session IDs

When processing this data, we will not draw conclusions about your person. Neither a personal evaluation nor an evaluation of the data for marketing or profiling purposes will take place. The legal basis for data processing in this context is Article 6(1) (f) of the GDPR. The processing of this data is technically inevitable in order to make our website available and to guarantee stability and security of our systems. It is not possible to use our website without such processing of data, so you cannot object to this processing. Your data will be deleted after seven days.

2. Use of Cookies

We use cookies on our website. Cookies are stored on your computer and from there transmitted to our website. A cookie comprises a characteristic string of characters that allows your web browser to be uniquely identified when you return to our website.

We differentiate between essential cookies (item 2.1) and cookies for usage analysis (item 2.2).

You can configure the processing of cookies in your browser yourself. By changing the settings in your browser, you can deactivate or restrict the transmission of cookies. Cookies that have been stored may be deleted at any time. This can also be done in an automated way. If cookies are deactivated for our website, it may no longer be possible to use all functions to their full extent. You find more detailed information on the website of your respective browser provider:

Google Chrome https://support.google.com/accounts/answer/61416?hl=en
Mozilla Firefox https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox#w_clear-cookies-for-any-website
Safari https://support.apple.com/en-hk/guide/safari/sfri11471/mac
Internet Explorer https://support.microsoft.com/en-us/windows/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Opera https://help.opera.com/en/latest/web-preferences/

2.1. Essential Cookies

Essential cookies are technically necessary for the proper functioning of our website. Some of these cookies ensure the technical stability of our website and enable functionalities that are relevant to security. Moreover, essential cookies are mandatory for certain functions. It is not possible to use our website without such processing of data. Essential cookies do not contain personal data, i.e. no IP addresses or other information is collected that would allow tracking. Below you find a list of the essential cookies we use:

Cookie Purpose Deletion Deadline
BIGipServer* Session Cookie End of session

The legal basis for personal data processing with essential cookies is Article 6(1) (f) of the GDPR. By using technically necessary cookies we want to make the use of our website easier for you. Some functions of our website will not work without cookies. For these functions, it is necessary that your browser will be recognised when you revisit our website after visiting other websites. The purposes pursued with the aforementioned constitute our legitimate interest. We do not use your user data collected through our technically necessary cookies to create a user profile.

2.2. Cookies for Usage Analysis

Usage analysis cookies enable us to analyse in which way you use our website. With the help of these cookies we can test the effectiveness of our website and identify errors. Moreover, the cookies provide information that help us to optimise our services and that is useful for web analyses. We use the cookies listed below for usage analysis:

Cookie Supplier Purpose Deletion Deadline
_pk_ref Matomo To store the attribution information of the referrer that was originally used to visit the website 6 months
_pk_id Matomo Is used to store some details about the user, such as the unique visitor ID 13 months
_pk_ses Matomo Short-lived cookies used to temporarily store data for the visit. 30 minutes
_pk_cvar Matomo Short-lived cookies used to temporarily store data for the visit. 30 minutes

The legal basis for personal data processing with usage analysis cookies is your declaration of consent according to Article 6(1) (a) of the GDPR.

Matomo

Our website uses Matomo, a web analysing service of InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. With Matomo, we analyse the use of our website and of individual functions and services, with the aim to optimise our website. Matomo uses cookies, which allow us to analyse your way of using our website (including your IP address).

We have activated the "Anonymise Visitor's IP addresses" function on our website. This means that your IP addresses are processed in a shortened form so that a reference to a person can be ruled out.

The legal basis for data processing in this context is Article 6(1) (a) of the GDPR.

Right to Object

You have the right to withdraw your consent at any time with effect for the future without giving reasons. If you do not agree with your data being transmitted to Matomo when you use our website in the future, you can opt for fully deactivating Matomo in your browser settings (see item 2 above). If you choose that option, it may no longer be possible to fully use all functions of our website.

For further information about the terms and conditions of use and data protection of Matomo please go to https://matomo.org/privacy-policy/.

You are not obliged to make available your personal data. There are neither legal nor contractual terms that require the provision of your personal data nor is that data necessary to enter into a contract. However, if you do not provide that data it might not be possible for you to use our website at all or to its full extent.

3. Contacting Us

There are various possibilities to get into contact with us.

3.1. Scope of Data Processing

You can contact us via the contact details (e-mail, post, phone) provided on our website. If you do so, we will process your personal data transmitted to us (e.g. e-mail address, postal address, phone number, information revealed in the text of the communication).

3.2. Legal Basis

If you contact us in the context of an existing contract or prior to entering into a contract, the legal basis is Article 6(1) (b) of the GDPR. In all other cases, the legal basis for processing your data is Article 6(1) (f) of the GDPR. It is our legitimate interest to process your contact inquiry.

3.3. Purpose of Data Processing and Categories of Recipients

The purpose of the data processing is the handling of your contact request. Your data is processed exclusively for this purpose. If you contact the DENICdirect customer service directly, your data will be transferred to and processed by DENIC Services GmbH & Co. KG, Heinrich-Hertz-Straße 6, 64295 Darmstadt, Germany. The DENIC Services GmbH Co. KG also is obliged to comply with the applicable data protection regulations; in particular, the DENIC Services GmbH Co. KG is only allowed to process the data for the fulfilment of its tasks on our behalf and only in accordance with our instructions.

3.4. Duration of Storage of Your Personal Data

After your contact request has been processed completely, we will restrict your data for further processing. Your data will be deleted once the statutory retention periods under fiscal and commercial law have expired. Pursuant to Section 147 of the German Fiscal Code, the retention period is ten full years for accounting records and, pursuant to Section 257 of the German Commercial Code, six full years for business documents.

You are not obliged to make available your personal data when you submit a contact request. There are neither legal nor contractual terms that require the provision of your personal data nor is that data necessary to enter into a contract. However, if you do not provide that data we will not be able to enter into contact with you.

4. DENIC vChecked Verification

The vChecked seal confirms that the identity of the holder of a .de domain has been verified by DENIC as an independent third party and that the person who was checked actually exists. To verify the identity of the holder of a .de domain, the holder data are verified in multi-step process that involves several authorities. Once the authentication has been confirmed you have access to the vChecked Customer Portal (CSP) and can download the seal and integrate it into your website.

4.1. Scope of Data Processing for vChecked Verifiation

You can initiate a vChecked request via the registrar that is responsible for your domain. The registrar will then submit your request to DENIC. We process the following (personal) data in the context of a vChecked request:

  • First and last name
  • Residential address, street and house number, postal code, place of residence, country
  • Company address, street and house number, postal code, place of residence, country
  • Date of birth, place of birth
  • E-mail address
  • Phone number, mobile number (optional)
  • Domain

4.2. Legal Basis

The legal basis for data processing in this context is Article 6(1) (b) of the GDPR. The processing of your personal data is necessary for carrying out the verification.

4.3. Purpose of Data Processing and Categories of Recipients

The purpose of the data processing is the implementation and administration of your verify request. Your data is processed exclusively for this purpose. For the purpose of the verification, we pass on your data within the framework of the request processing to DENIC Services GmbH & Co. KG, Heinrich-Hertz-Straße 6, 64295 Darmstadt, Germany. DENIC Services GmbH & Co. KG, will support us in the proper processing of your request. Additionally, for the purpose of verification, your data is passed on for checking to the following companies:

  • Palturai GmbH, Reifenberger Straße 1, D‐65719 Hofheim (in case of legal persons)
  • Abis GmbH, Lyoner Str. 20, D-60528 Frankfurt am Main
  • Schufa Holding AG, Kormoranweg 5, D-65201 Wiesbaden (in case of natural persons)

For the purpose of carrying out the identity check, your data is passed on to the following companies:

  • AUTHDATA GmbH, Julius-Reiber-Str.15a, D-64293 Darmstadt
  • Identity Trust Management AG, Lierenfelderstr. 51, D-40231 Düsseldorf.

These companies, too, are obliged to comply with all applicable data protection regulations; in particular, they are only allowed to process the data for the fulfilment of their tasks on our behalf and only in accordance with our instructions.

4.4. Duration of Storage of Your Personal Data

Your personal data will be deleted upon expiration of two complete years, as soon as the verification becomes invalid (e.g. due to domain deletion, change of domain holder, change of the authorised signatory).

5. Rights of the Data Subject

If we process your personal data, you are a data subject within the meaning of Article 4(1) of the GDPR, which gives you the following rights vis-à-vis DENIC:

  • Right of Access (Art. 15 GDPR)
  • Right to Rectification (Art. 16 GDPR)
  • Right to Erasure (Art. 17 GDPR)  Right to Restriction of Processing (Art. 18 GDPR)
  • Notification Obligation (Art. 19 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Object (Art. 21 GDPR)
  • Right to revoke your declaration of consent under data protection law (Art. 7(3) GDPR). You have the right to withdraw your consent vis-à-vis DENIC at any time, for instance by e-mail to privacy[at]denic[dot]de. The withdrawal of consent shall not affect the lawfulness of data processing based on your consent before its withdrawal.

Right to Object (Art. 21 GDPR)

Pursuant to Article 21 of the GDPR, you are entitled to object, for reasons relating to your particular situation, at any time to the processing of your personal data which is based on Article 6(1) (e) or (f) of the GDPR, including profiling based on these provisions. In this case, DENIC will no longer process your personal data, unless DENIC demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing is necessary to assert, exercise or defend any legal claims.

If you want to exercise one of these rights, please contact our Data Protection Officer at privacy[at]denic[dot]de.

We would like to point out that in certain cases we may ask you to provide additional information in order to verify your identity. This enables us to ensure that information is not disclosed to unauthorised persons, e.g. when you exercise your right of access.

Pursuant to Article 77 GDPR, you also have the right to complain to a data protection supervisory authority if you believe that we are not processing your personal data in a lawful way. The competent authority for DENIC is the data protection supervisory authority of Hesse. The contact details are: Hessischer Beauftragter für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany, e-mail: poststelle[at]datenschutz[dot]hessen[dot]de.

Automated decision making does not take place on our website.

6. Security

DENIC has technical and organisational safety measures in place to protect your personal data from accidental or intentional manipulation, loss, destruction or access by unauthorised persons. We continuously improve our security measures in line with technological evolution.

7. Responsibility for External Content

Our website contains links that lead to Internet pages of external providers. We have no influence on such providers and cannot ensure that they comply with the applicable data protection regulations. If you believe that linked external sites violate applicable law or have other inappropriate content, please let us know. We will check on it and remove the external link, if appropriate. We cannot be held responsible for the content and availability of linked external web pages.

8. Validity of the Data Privacy Statement

Further development of our website or the implementation of new technologies may render amendments to this data privacy statement necessary. We reserve the right to change this privacy statement at any time with effect for the future. The relevant version of this statement is always the version that is available at the time you visit our website.

Last amended: October 2021