Privacy Policy
As of 15.01.2026 · According to GDPR
1 Responsible
Responsible for data processing on this website is:
Data Protection Officer:
For questions regarding data protection, you can reach our Data Protection Officer at:
info@hablexhost.es
2 Overview of Processing
We process personal data only if necessary. The following overview summarizes the types of data processed and the purposes of their processing:
Types of Data
- • Inventory data (Name, Address)
- • Contact data (Email, Phone)
- • Contract data (Orders, Payments)
- • Usage data (Pages, Times)
- • Meta/Communication data (IP, Browser)
Purposes of Processing
- • Provision of contractual services
- • Customer service and support
- • Billing and payment processing
- • Security and Fraud Prevention
- • Website Optimization
3 Legal Bases
We process your data based on the following legal bases of the GDPR:
-
a
Consent (Art. 6 para. 1 lit. a GDPR)
If you have consented to the processing of your data (e.g., newsletter, cookies).
-
b
Contract Fulfillment (Art. 6 para. 1 lit. b GDPR)
If the processing is necessary for the fulfillment of a contract or pre-contractual measures.
-
c
Legal Obligation (Art. 6 para. 1 lit. c GDPR)
If we are subject to a legal obligation (e.g. retention obligations).
-
f
Legitimate interests (Art. 6 para. 1 lit. f GDPR)
If the processing is necessary for the protection of our legitimate interests (e.g. security, analytics).
4 Your rights as a data subject
According to GDPR, you have the following rights:
Right of access (Art. 15)
You can request information about your data stored with us.
Right to rectification (Art. 16)
You can request the correction of inaccurate data.
Right to erasure (Art. 17)
You can request the deletion of your data ("right to be forgotten").
Restriction (Art. 18)
You can request the restriction of processing.
Data portability (Art. 20)
You can obtain your data in a machine-readable format.
Right to object (Art. 21)
You can object to the processing of your data.
Right to complain: You have the right to lodge a complaint with a data protection authority regarding the processing of your data.
Withdrawal of consent: You can withdraw any consents given at any time with effect for the future.
5 Data processing when visiting the website
Server log files
Each time our website is accessed, our server automatically records the following data in so-called server log files:
- IP address of the requesting computer (anonymized after 7 days)
- Date and time of access
- Name and URL of the retrieved file
- Amount of data transferred
- Message about successful retrieval
- Browser and operating system used
- Referrer URL (previously visited page)
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interests in security and stability).
Storage duration: Log files are deleted after 30 days.
SSL/TLS Encryption
This website uses SSL/TLS encryption to protect data transmission (recognizable by "https://" and the lock symbol). This means that the data you transmit is not readable by third parties.
7 Customer account and orders
Registration
During registration, we collect the following data:
- First and last name
- Email address
- Password (stored encrypted)
- Optional: Company, Phone, Address
Orders
For orders, we additionally process:
- Billing address
- Payment information (via secure payment providers)
- Order history
- Communication regarding the order
Legal basis: Art. 6 para. 1 lit. b GDPR (Contract fulfillment).
Storage duration: Customer data is stored for the duration of the business relationship, and thereafter according to commercial and tax retention periods (usually 10 years).
8 Hosting services (data processing)
When using our hosting services (web hosting, VPS, server), the data you store there will be processed by us as part of a contract processing in accordance with Art. 28 GDPR.
Your role: You are the controller of the data you store.
Our role: We are the data processor and process the data only according to your instructions.
A data processing agreement (DPA) can be created at any time through your customer account or requested from us.
Server location
Our servers are located in Germany and the European Union. Your data does not leave the EU unless you explicitly choose a server outside the EU.
9 Payment service provider
For payment processing, we use external payment service providers:
Stripe
Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA
Privacy Notice: stripe.com/en/privacy
Stripe is certified under the EU-U.S. Data Privacy Framework.
PayPal
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
Privacy Notice: paypal.com/privacy
Note: We do not store complete credit card details. Payment data is processed directly by the payment service providers.
10 Support and Tickets
The following data is processed when using our support system:
- Name and email address
- Content of support inquiries
- Related service and order data
- Communication history
Legal basis: Art. 6 para. 1 lit. b GDPR (Contract fulfillment).
Storage duration: Support tickets are archived for 3 years after the end of the contract and then deleted.
11 AI-powered services
We use AI technologies to improve our services:
Support assistance
To support our support team, requests can be analyzed by AI systems to generate suitable solution suggestions. All AI-generated answers are reviewed by employees.
AI Assistant (Product)
If you use an AI assistant as a product, conversation data will be processed for the purpose of providing the function. For details, please refer to the product-specific privacy notices.
Third-Party AI
We use AI APIs from Groq, OpenAI, and Anthropic. These providers process data according to their own privacy policies. We minimize the personal data transmitted and do not use data for AI training.
12 Additional Third-Party Services
Content Delivery Network (CDN)
We use CDN services for fast loading times. This may involve transmitting your IP address to the CDN provider.
External Fonts
Fonts are loaded locally from our servers. No connection is made to Google Fonts or similar services.
E-Mail Delivery
We use SMTP servers with TLS encryption for e-mail delivery. Transactional e-mails are logged for quality purposes.
13 Security Measures
We take technical and organizational measures to protect your data:
14 Changes to this privacy policy
We reserve the right to adjust this privacy policy as needed to comply with changing laws or changes to the service.
The current version is always available on this page. In the event of significant changes, we will inform registered users by email.
Questions about data protection?
If you have questions about the processing of your data or the exercise of your rights, please contact us: