1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:
Exbil
Efe Bagri
Sankt-Gallen-Ring 189
90431 Nürnberg
Deutschland
Phone: +49 911 47766005
Email: [email protected]
2. General information
We take the protection of your personal data very seriously and treat it confidentially and in accordance with the statutory data protection regulations (GDPR, BDSG) and this privacy policy. Personal data is information by which you can be personally identified.
This privacy policy applies to all websites, platforms and services of the provider, in particular exbil.net, exbil.cloud, reselling.exbil.net and all subdomains, as well as to the hosting and IT services provided within the scope of the contractual relationship.
3. Collection and processing of personal data
3.1 Server log files
When you access our website, technically necessary data is stored in so-called server log files, which your browser automatically transmits to us:
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a technically error-free presentation and the security of our systems). The data is deleted after 30 days.
3.2 Contact form and email contact
For inquiries via the contact form or by email, your details (name, email address, content of the message) are stored to process the inquiry. The legal basis is Art. 6 (1) (b) GDPR (initiation of a contract) or Art. 6 (1) (f) GDPR (legitimate interest in processing inquiries). The data is deleted as soon as it is no longer required for the purpose for which it was collected, at the latest after 3 years.
3.3 Contract data
As part of the order and contract processing, we collect the following data:
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (legal obligations, e.g. retention obligations under commercial and tax law). The storage period is governed by the statutory retention periods (6 or 10 years).
3.4 Domain registration
When registering domains, your owner data (name, address, email address, telephone number) is first transmitted to our white-label registrar Realtime Register B.V. (Enschede, Netherlands) and from there forwarded to the responsible TLD registry (e.g. DENIC, Verisign, EURid). Depending on the TLD policy these data may be published in the public Whois directory — where available we enable a WHOIS privacy service on request. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (obligation towards the registries).
3.5 Customer account and SSO
A central Exbil account (single sign-on) is used to access our platforms (Cloud, Reselling, Docuware). We store your name, email address, password hash as well as login history and assigned permissions. The legal basis is Art. 6 (1) (b) GDPR. The data is deleted as soon as the account is permanently closed.
3.6 Applications
For applications submitted via our careers page, we process your application documents exclusively for the purpose of conducting the application procedure. The legal basis is § 26 BDSG in conjunction with Art. 88 GDPR. In the event of an unsuccessful application, the data is deleted 6 months after the procedure is completed, unless consent to longer storage has been given.
3.7 Cloud Services and Game Servers (Reselling)
Through our reselling platform (reselling.exbil.net) we offer Cloud Services and Game Servers. To operate these services we process the following data:
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in operational security and abuse prevention). Content is operated exclusively by us as a processor on your behalf — we do not decide on its purpose. At the end of the contract the data is deleted within 30 days; before that you may download a backup via the backup feature (right to data portability, Art. 20 GDPR).
3.8 Container Registries
Through our Container Registry product you can privately host your own Docker images. We process the following data:
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in security and quota enforcement). Image data is stored exclusively encrypted in German data centres. When you terminate your registry access, the namespace and all hosted images are irreversibly deleted (multiple overwrites) after a grace period of 14 days. During the grace period you can export all images via the panel.
4. Hosting and data center
Our services are hosted in certified data centers in Germany and the European Union. A transfer of personal data to third countries outside the EU/EEA only takes place if an adequate level of data protection within the meaning of Art. 44 et seq. GDPR is ensured (e.g. EU standard contractual clauses, adequacy decision).
Insofar as we act as a processor for you (e.g. when hosting your Cloud Services, Container Registries, website, databases or email mailboxes), we conclude a data processing agreement (DPA) with you in accordance with Art. 28 GDPR. A template is available on request at [email protected].
All platform services we offer (exbil.net, dash.exbil.net, reselling.exbil.net, Cloud Services, Container Registry, Mail mail, VPN) run exclusively on our own hardware that we administer ourselves. We do not use any third-party cloud hyperscaler. Concrete locations (current version of this policy):
5. Cookies
Our website uses exclusively technically necessary cookies (e.g. session cookie, CSRF token, theme setting, cookie consent storage). These are required for the operation of the website and are set on the basis of § 25 (2) no. 2 TTDSG – no consent is required for this.
Should we use non-essential cookies (functional, statistics, marketing) in the future, we will obtain your prior consent for this via our cookie banner in accordance with Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. You can revoke or adjust your consent at any time via the “Cookie settings” link in the footer.
We currently do not use any tracking, marketing or analytics cookies.
6. Recipients of personal data
Your data is passed on to third parties in the following cases:
Personal data is not passed on for advertising purposes or sold.
7. Sub-processors
To provide our services we use the following carefully selected sub-processors. With each of them we maintain a separate data processing agreement (DPA) under Art. 28 GDPR:
We provide a current list of our sub-processors to customers on request. Before engaging additional sub-processors we will notify you in advance and grant you a right to object (Art. 28 (2) GDPR).
8. Retention period
We only store personal data for as long as is necessary to fulfil the respective purposes or as required by statutory retention obligations. In particular, the following apply:
9. Your rights
You have the following rights with regard to the personal data concerning you:
To exercise your rights, you can contact us at any time at [email protected].
10. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data by us (Art. 77 GDPR). The competent supervisory authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach
Phone: +49 (0) 981 180093-0
Email: [email protected]
11. Data security
For transmission we use TLS encryption (typically TLS 1.3) with current cipher suites. Personal data is protected at rest by the following concrete measures: bcrypt-hashed credentials (no plaintext), AES-256-encrypted backups before transmission, filesystem-level encryption (fscrypt/LUKS) on our backend nodes, isolated network segments per customer workload, regular security updates of the host OS, and audit logs of all administrative access (90-day retention). We review our technical and organisational measures regularly and adapt them to the state of the art (Art. 32 GDPR).
12. Changes to this Privacy Policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements or in order to implement changes to our services. The new privacy policy will then apply to your next visit.
13. Authoritative Version
This privacy policy is provided in several languages. Only the German version is legally authoritative and binding. Translations are provided solely for ease of understanding.