Controller
Everworkx
Bernd Linder
Afrastrasse 34
86660 Tapfheim
Germany
and
Everworkx
Bernd Linder
Afrastrasse 34
86660 Tapfheim
Germany
and
Markus Kunkel
Wilhelm-Leibl-Weg 16
97422 Schweinfurt
Germany
contact@everworkx.com
Data processed on this website
Website delivery and security
The server processes IP address, time, requested resource, referrer, browser and operating system data to deliver the website, detect abuse and ensure technical security. The legal basis is the legitimate interest in secure operation.
Customer account and orders
Account, contact, billing and contract data are processed to create and manage the account, prepare and perform orders, activate services, issue invoices and meet legal retention duties.
Service usage and API keys
Usage records, technical identifiers, API keys, request volumes and service status are processed to authenticate access, meter usage, prevent abuse and bill chargeable services.
Contact form and email
Submitted name, email address, company, subject and message are processed to answer the request and, where applicable, prepare a contract.
Domain search
The requested domain name and extensions are transmitted to the Everworkx domain service and, where necessary, public RDAP services to check availability. Search requests are rate-limited and protected against abuse.
Cookies and sessions
Only technically necessary session cookies are used for login, cart, security tokens and language context. No advertising or analytics cookies are currently used.
Recipients and external resources
Data is disclosed only where required for hosting, domain availability and registration, technical delivery, payment or legal obligations. Bootstrap and Bootstrap Icons are currently loaded through jsDelivr; the visitor IP address is therefore transmitted to the CDN provider. No data is sold.
Storage periods
Data is retained for as long as needed for the stated purpose, an active account or contract, defence of claims and statutory commercial or tax retention periods. Security logs are deleted when no longer required for operational protection.
Rights of data subjects
Subject to the statutory requirements, you may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interests. You may withdraw consent for the future and lodge a complaint with a data protection supervisory authority. Requests can be sent to contact@everworkx.com.
Customer content and data processing
When customers process third-party personal data through hosting, servers, storage, DNS or API services, the customer generally remains the controller. Everworkx acts as a processor only where the requirements of Article 28 GDPR are met and a data processing agreement has been concluded. Customers must ensure a lawful basis, transparency and appropriate permissions for uploaded or transmitted data.
Security, access and incident handling
Technical and organizational measures include encrypted transmission, access controls, password hashing, limited administrative permissions, security logging, rate limits and backups where contractually included. Credentials and API keys must be kept confidential. Suspected compromise should be reported immediately.
International transfers and service providers
Where a provider outside the EEA is used, transfers take place only where a lawful transfer mechanism applies, such as an adequacy decision or standard contractual clauses. The currently embedded jsDelivr resources may involve delivery from international infrastructure. Payment providers will be added to this notice before their productive use.
Required and optional data
Account, billing and contract data marked as required are needed to provide the requested service. Without them, an account or order cannot be completed. Optional profile and contact fields may be left blank. No solely automated decision with legal or similarly significant effect currently takes place.