Data protection, data security and the responsible handling of personal data are important to Altavis GmbH (“Altavis, hostclick”, “we”, “us”).
1.Personal data that we collect and process to make our website available
You can visit our website and obtain information about our services without telling us who you are. However, we do collect technical data when you visit our website. This is necessary to make our website available.
As with every connection to a web server, the server on which we host the website and applications automatically logs and stores certain technical data. This data includes the IP address and operating system of your device, the date and time of use, the website from which you are visiting us and the type of browser you are using to access our website. To the extent that we process personal data, we do this based on our interest to make the website available, offer you the best possible user experience and guarantee the security and stability of our systems.
Our website uses fonts by Google LLC “Google” (Google Fonts). To integrate Google Fonts into the website, your browser establishes a connection to the Google server. In doing so, the IP address of your device is transmitted to Google. Google logs records of font queries and protects this data from unauthorized access. Google analyzes aggregated data to optimize Google Fonts and identify which websites use Google Fonts. For more information on Google Fonts, see: https://fonts.google.com. For information on how Google handles personal data, see: https://policies.google.com/privacy?hl=en
2.Personal data that we collect and process to provide services
If you use registration, order or contact forms on our website or call to inquire about our offerings and services, we collect your contact data and other contractually relevant personal data. We collect and process this personal data for the purpose of providing services and information about our services.
To answer your inquiries, we regularly require your first name, last name, e-mail address, phone number and hostclick customer number. For entering into and performing contracts relating to the utilization of billable services (web hosting, domain and additional services), we need additional information, in particular your date of birth, the payment method of your choice as well as (for domain services) information required by the regulator, in particular, the owner of the domain and the recipient of the invoice.
We process the contact and transaction data to enter into a contract with you, perform the contract or communicate with you about our offers and services. We also process this personal data based on our interest to answer your inquiries as well as possible, provide and develop our services in accordance with the contract or optimize your user experience. Based on our interest to inform you of new developments as well as services and offers by hostclick, we also send you corresponding commercial information (e.g. via a newsletter). However, you can opt out of receiving such information at any time.
3. Personal data that we store and provide on your behalf
We collect and process on your behalf (personal) data, which you store yourself if you use our hosting services. This processing consists of the storing, provision, transfer and deletion of data in accordance with our contractual agreements with you.
When we provide hosting services (including additional services such as Sitebuilder, Office 365, Hosted Exchange, G Suite), we store personal data and other data which you choose to store on the infrastructure we use to provide our services as well as personal data relating to persons to whom you grant access to your website or applications. This includes, in particular, personal data that is usually collected when calling up or executing websites and applications (log data, e.g. the IP address and operating system of the user’s device as well as the browser’s date and time of access). Furthermore, this includes the data entered by users as well as the personalized usage data collected by you.
To the extent that we process personal data we, as the processor, do so in accordance with our contractual obligations towards you. You remain responsible for the legality of processing of the personal and other data stored by you, including the permissibility of contracted or subcontracted processing.
We provide the “Office 365, Hosted Exchange and G Suite” services in cooperation with our partner Sherweb Inc. (“Sherweb”). The data collected via Sherweb is stored on a Sherweb server in Canada. Sherweb has undertaken to comply with suitable guarantees for data protection and data security.
Cookies are text files that are downloaded onto your computer or mobile device when you visit a website or use an application. Some of them (session cookies) are required to enable you to use certain functions such as navigation between the different areas of the website or access to the control panel.
You can disable the storing of cookies in your web browser. You can also delete cookies that have already been saved at any time. Please note, however, that some functions of the website or our applications might be restricted or unavailable if you disable cookies.
5. Data that we collect and process to analyze and improve the use of our website
We use Google Analytics to evaluate the use of our website and receive information for improving our services.
Google Analytics is a service by Google. We use it only with activated IP anonymization. This means that your IP address is truncated in Switzerland, the EU or the EEA. Only in exceptional cases will your full IP address be transmitted to a Google server in the USA and truncated there. You can prevent Google Analytics from using your data by downloading and installing a browser add-on for disabling Google Analytics (https://tools.google.com/dlpage/gaoptout?hl=en). For more information on data protection and your options in relation to Google Analytics, see: https://support.google.com/analytics/answer/6004245?hl=en.
6. Data that we collect and process to target potential customers
Our website uses Google Tag Manager to generate tags for our website and applications. These tags enable us to tailor marketing measures for our services to potential customers (re-targeting).
7. How we process and protect personal data; how long we store it
We take appropriate technical and organizational measures in the interest of confidentiality, integrity and contractual availability of personal data. In accordance with our risk assessment, we implement admission controls in particular, but also access controls as well as procedures for regular checking, assessment and evaluation of the measures.
We store personal data only to the extent and for the duration required to fulfill the purpose for which the personal data was collected, we have a legitimate interest in storing the data or are required to do so by law.
8. To whom we forward your personal data
To perform the contract, to pursue our legitimate interests or comply with statutory requirements, it might be necessary to forward your personal data to the following categories of recipients: registries, registration partners, Escrow-Agents, SSL providers, Service Partner, or courts and authorities.
When providing domain name services, it is necessary for contract processing and for legal reasons that we pass on (personal) data to our domain registration partner Key-Systems GmbH, St. Ingbert, Germany (“Key-Systems”). The latter will transmit the data to the responsible registries and make it accessible via a Whois service. Depending on the respective top-level domain, this can include: name and complete address of domain name owner; if necessary (for legal entities or partnerships) the names of the natural persons appointed to represent the company, the complete address (incl. e-mail) of the billing and administrative contact as well as the technical contact, the data of the registration of the relevant domain name and the most recent amendment to this registration as well as the IP address of the activated DNS server. If you are utilizing our “Data protection for domains” services, the WHOIS entry contains in part or in full information about the corresponding service instead of the respective personal data and your contact data is not passed on to the registries.
As an ICANN-accredited registrar, Key-Systems is obliged to deposit domain holder data in trust. This is done in accordance with ICANN regulations. For this purpose, your personal data is passed on to the escrow agents used by Key-Systems.
To provide SSL services, we have to inform the SSL provider of the respective domain and your contact data in order to perform the contract.
To carry out credit checks or debt collections we may forward your personal data to credit reporting agencies or debt collection agencies to the extent required for this purpose and as described above.
To the extent that courts or authorities request and we are legally required, we will pass on your personal data to them or other third parties.
If data has to be passed on to organizations in countries without adequate data protection, we comply with the provisions of the FADP (or, where applicable, the GDPR) in relation to international data transfer (e.g. by choosing service providers who are subject to the U.S.-Swiss Privacy Shield or by integrating accepted standard contract clauses for data transfer).
9. Your rights in relation to your personal data
The Swiss Federal Act on Data Protection (FADP) and any other applicable data protection laws (including, where applicable, the GDPR) grant you rights in relation to personal data which we collect and process.
You have the right to be provided with information about what personal data of yours we process. You have the right to correct your personal data and to restrict processing thereof. You also have the right to deletion of your personal data and a right to object to the processing of personal data. To the extent that the GDPR applies and we carry out processing for performance of a contract or based on your consent, you also have the right to receive a copy of the personal data for transfer to a third party. Irrespective of this, you can use the Client Area to make copies of the websites or applications we have stored for you at any time.
Please note that exceptions or restrictions apply to these rights. In particular, we might have to process and forward your personal data in order to perform a contract with you, pursue our own legitimate interests such as the assertion, exercise or defense of legal claims or to comply with statutory requirements. To the extent legally permissible, in particular in order to safeguard the rights and freedoms of persons concerned and protect our legitimate interests (e.g. nondisclosure and security interest as well as consideration of our business resources and opportunities) we can therefore also reject your data protection-related requests, e.g. information or deletion requests, or only partially comply with your requests. However, you do have the right to lodge a complaint with a competent supervisory authority.
If you would like to exercise your data subject rights as the user of a website or application of one of our customers, please address these directly to the respective operator of the website or application. We are only the order processor in relation to these. The customer responsible for processing must uphold the data subject rights.
10. How to contact us
Controller (or, depending on the context, order processor):
Altavis GmbH, Haerdlenstrasse 20, PO Box, 8302 Kloten, Switzerland.
You can contact us via the contact form by clicking the link below:
If you would like to exercise your data subject rights in accordance with the data protection law applicable to us or have general questions about data protection at hostclick, please contact firstname.lastname@example.org.
Kloten, May 2018