Version: June 14, 2026
Julian Dreyseitel, Daronlo-Hosting
Charlottenstraße 71, 45964 Gladbeck, Germany
Email: [email protected]
We process personal data only where required for operation, security, communication, and contract fulfilment, or where you have given consent. Legal bases include in particular Article 6(1)(a) GDPR (consent), (b) GDPR (contract and pre-contractual measures), (c) GDPR (legal obligations), and (f) GDPR (legitimate interests in secure and efficient operation).
The website, database, customer panel, and game servers are operated on rented infrastructure in Germany. Infrastructure and hosting services are provided in particular by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany.
When the website is accessed, IP address, date and time, requested URL, referrer, browser identifier, transferred data volume, and status code may be processed in server and security logs. The purpose is delivery, troubleshooting, defence against attacks, and platform stability. Legal basis is Article 6(1)(f) GDPR. Standard access and security logs are generally deleted no later than after 30 days; security-relevant entries may be retained longer until an incident is resolved.
When you register and use our services, we process in particular username, email address, password hash, verification status, login and security data, and the link to your Pterodactyl customer account. Plaintext passwords are not stored. Processing takes place for account and contract fulfilment under Article 6(1)(b) GDPR and for abuse prevention under Article 6(1)(f) GDPR.
For ordering and service operation, we process customer and order data, selected plan, price, term, server configuration, technical identifiers, payment status, and timestamps and versions of legal confirmations. Server content, worlds, plugins, mods, backups, and logs are processed on the hosting infrastructure to the extent required for service delivery.
In addition to backups available in the customer area, game server volumes are generally backed up once per day in encrypted form via Restic to an external Hetzner Storage Box. The provider is Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The purpose is restoration after technical failures and protection against data loss. Legal bases are Article 6(1)(b) and (f) GDPR. More information: Hetzner Privacy Policy.
Current technical backup retention includes up to 14 daily, 8 weekly, and 6 monthly restore points. Production data is deleted after the contract ends and the grace period expires. Encrypted copies may then remain until the automatic expiry of the relevant backup generation, generally for no longer than six months. After that, they are removed as part of the rotation process. Contract and billing documents remain stored according to statutory commercial and tax retention periods.
Payments are processed by Stripe. For customers in the EEA, the provider is generally Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Order number, amount, currency, service description, email and billing data, and technical payment data are transmitted to Stripe. Full card or bank details are not stored on our servers.
The legal basis is Article 6(1)(b) GDPR. Stripe also processes some data for fraud prevention and to meet its own legal obligations. More information: Stripe Privacy Policy.
Transactional, confirmation, and support emails are sent via mail servers operated by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. In particular, recipient address, name, subject, message content, and technical delivery data are processed. The legal basis is Article 6(1)(b) GDPR and, for security and operational messages, additionally Article 6(1)(f) GDPR.
For contact forms and individual server requests, we process the contact, content, and project data you provide, plus temporary technical request data to prevent abuse. The data is processed to handle the request under Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Non-contractual requests are generally deleted no later than 12 months after completion.
Spam protection is implemented locally via CSRF protection, rate limits, an invisible honeypot field, and a minimum completion time. Google reCAPTCHA is not used.
After your voluntary consent, we record page views and selected click events locally. Stored data includes timestamp, event type, accessed path, shortened referrer information, session identifier, internal user ID for logged-in users, and limited technical metadata. No IP address is stored in the analytics event log.
Legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. Analytics data is deleted automatically after 90 days. Consent can be withdrawn at any time via “Cookie settings” in the footer; withdrawal applies for the future.
We use technically necessary session cookies for login, security, cart, and order functions. Legal bases are Section 25(2) No. 2 TDDDG and Article 6(1)(b) or (f) GDPR. Session cookies generally expire when the browser is closed or the session ends.
Your privacy choice is stored in the browser’s local storage together with the selection, version, and timestamp. To meet our accountability obligations, we also store the choice, consent version, timestamp, a pseudonymised session ID, and for logged-in users the internal user ID. The IP address is not stored in this consent log. Proof records are deleted after three years. The browser entry remains until you delete it or a new consent version is required.
Fonts and Font Awesome icons are loaded from our own server. No connection to Google Fonts, Font Awesome, or an external CDN is established for this purpose.
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, may be used for DNS management and customer-configured server subdomains. DNS, IP, and connection data may be processed. Legal bases are Article 6(1)(b) and (f) GDPR. More information: Cloudflare Privacy Policy.
Discord links are simple external links. A connection to Discord is established only when you click them. If you voluntarily store a Discord webhook URL in the customer area, we store and use it to deliver the server notifications you requested. The URL can be removed at any time. Provider: Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands. More information: Discord Privacy Policy.
Data is disclosed only to parties that need it for the stated purposes, in particular hosting, email, payment, DNS, and support providers, as well as authorities where required by law. Required data processing agreements under Article 28 GDPR are concluded with processors.
Where providers may process data outside the EEA, transfers take place only on the basis of statutory safeguards, in particular adequacy decisions including the EU-US Data Privacy Framework or standard contractual clauses. Details can be found in the linked privacy notices of the providers.
We store data only as long as necessary for the respective purpose. After that, it is deleted or restricted. Mandatory statutory retention periods, especially for tax-relevant documents, may be six, eight, or ten years. Statutory limitation periods and legal defence needs may justify longer storage in individual cases.
Under the GDPR, you have rights of access, rectification, erasure, restriction, data portability, and objection. You may withdraw any consent at any time with effect for the future. Requests can be sent to [email protected].
You may also lodge a complaint with a data protection supervisory authority. The authority competent for the controller is in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia: www.ldi.nrw.de.
For registration, ordering, and contract performance, the data marked as required must be provided. Without this data, an account or hosting contract cannot be created or fulfilled. No solely automated decision-making with legal effect and no profiling takes place.
We update this policy if services, data flows, or the legal framework change. The version published on this page is authoritative.