1. Controller
The controller responsible for data processing on https://mathlabspace.de is:
- mathlabspace GmbH
- Friedrichstraße 123, 10117 Berlin, Germany
- Email: privacy@mathlabspace.de
- Phone: +49 30 12345678
2. Data Protection Officer
You can contact our Data Protection Officer at dpo@mathlabspace.de or by post marked “Data Protection Officer” at the company address above.
3. Scope of this policy
This privacy policy explains which personal data we collect when you visit mathlabspace.de, create an account, register or transfer domains, use DNS and related products, contact support, or otherwise interact with our services. It also describes the purposes, legal bases, retention, recipients, international transfers, and your rights under the GDPR.
4. Key definitions
Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data, such as collection, storage, use, disclosure, or deletion. Special categories of data (Art. 9 GDPR) are not intentionally collected for standard registrar services.
5. Categories of personal data
Depending on how you use mathlabspace, we may process:
- Identity and contact data: name, organization, postal address, email, phone
- Account data: username, hashed password, authentication factors, preferences
- Domain & registry data: domain names, nameservers, WHOIS/RDAP contacts, auth/EPP codes metadata, transfer history
- Billing data: invoice details, payment method tokens (processed by payment providers), tax IDs where required
- Technical data: IP address, browser type, device identifiers, timestamps, log files, approximate location derived from IP
- Support data: tickets, chat transcripts, call notes, attachments you upload
- Marketing preferences: newsletter opt-in/out, cookie consent choices
- Security data: login events, risk signals, abuse reports
6. Purposes and legal bases
We process personal data only where a GDPR legal basis applies:
- Art. 6(1)(b) GDPR – contract performance: account creation, domain registration/renewal/transfer, DNS management, billing, support needed to deliver services
- Art. 6(1)(c) GDPR – legal obligation: tax, accounting, registry/ICANN/DENIC identification requirements, responding to lawful requests
- Art. 6(1)(f) GDPR – legitimate interests: securing systems, preventing fraud/abuse, improving reliability, limited B2B communications (with opt-out)
- Art. 6(1)(a) GDPR – consent: non-essential cookies, certain analytics/marketing, optional newsletters (withdrawable at any time)
7. Domain registration and WHOIS / RDAP
To register a domain we must collect registrant data required by the relevant registry and publish or disclose data where registry policy or law requires it. For many TLDs, personal contact details may be redacted in public WHOIS/RDAP while remaining available to the registry, escrow providers, and for legitimate disclosure requests. Enabling WHOIS privacy (where offered) does not remove our need to store accurate ownership data.
- .de domains follow DENIC rules and applicable German requirements
- Inaccurate registrant data may lead to suspension or deletion under registry policy
- You must keep contact data up to date in your portfolio
8. Cookies and similar technologies
We use necessary cookies for security (including CSRF protection), session continuity, and load balancing. Optional analytics or marketing cookies are used only with consent. Details are described in our Cookie Policy. You can change preferences at any time via Cookie Preferences.
9. Recipients and processors
We may share personal data with:
- Domain registries and registry operators (e.g. DENIC for .de)
- Payment processors and banks for charging and refunds
- Hosting, email, and cloud infrastructure providers under Art. 28 GDPR contracts
- Customer support tooling providers
- Professional advisers (legal, tax, auditors) under confidentiality
- Authorities, courts, or rights holders where legally required or to establish/defend legal claims
- Escrow or data escrow agents required by registry/accreditation rules
10. International transfers
Where processors are located outside the EEA/UK, we implement appropriate safeguards such as EU Standard Contractual Clauses (SCCs), adequacy decisions, and supplementary measures where needed. You may request information about relevant transfer mechanisms via dpo@mathlabspace.de.
11. Retention
We retain personal data only as long as necessary for the purposes collected, including:
- Account and domain ownership records: for the life of the customer relationship plus periods required by registry/escrow rules
- Invoices and tax records: typically 10 years under German commercial and tax law (HGB/AO)
- Support tickets: generally up to 3 years after closure unless needed longer for disputes
- Security logs: typically 90–365 days, longer if investigating incidents
- Marketing consents and cookie logs: for the duration of consent plus evidence retention
12. Security measures
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), access controls, least-privilege administration, logging/monitoring, staff confidentiality obligations, and vulnerability management. No method of transmission or storage is 100% secure; please use strong unique passwords and enable two-factor authentication.
13. Your rights under the GDPR
Subject to legal conditions, you have the right to access, rectification, erasure, restriction, data portability, and objection (including to processing based on legitimate interests and to direct marketing). Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing. See our GDPR Rights page for how to exercise these rights.
14. Right to lodge a complaint
You may lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. For Berlin, this is typically: Berliner Beauftragte für Datenschutz und Informationsfreiheit (https://www.datenschutz-berlin.de/).
15. Children
Our services are directed to adults and businesses. We do not knowingly collect personal data from children under 16. If you believe a child provided data, contact privacy@mathlabspace.de and we will take appropriate steps.
16. Changes to this policy
We may update this privacy policy to reflect legal, technical, or business changes. The “Last updated” date at the top of the legal page will change accordingly. Material changes affecting your rights may be announced via the website or email where appropriate.
Questions about this document?
Contact legal@mathlabspace.de or privacy@mathlabspace.de. For account help use help@mathlabspace.de.