Skip to content

Note: Studio commissions are accepted selectively right now — our focus is on the hosting lines.

All legal documents

Legal

Privacy Policy

Last updated: 10 August 2026

This Privacy Policy informs you in accordance with Art. 13 and 14 GDPR as well as the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG) about the processing of personal data when you visit our websites, use the customer portal and use our hosting, server, domain, e-mail, gameserver and studio services.

1. Controller

Nobody Workz – Michael Gloe & Lukas Eberle GbR Bahnhofstraße 1, 92521 Schwarzenfeld, Bavaria, Germany E-mail: support@nobodyworkz.eu

A data protection officer has not been appointed because the requirements of Art. 37 GDPR and Sec. 38 BDSG are not met. Please direct data protection requests to the address above.

2. General, server log data

When you access our services, our infrastructure processes data that is technically required (e.g. IP address, date/time, requested resource, HTTP status, transferred data volume, referrer, user agent). Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in provision, security and stability). Log files are generally deleted after a short period (typically up to 30 days) unless they are needed longer to investigate concrete abuse or due to legal obligations.

3. Customer account and contract data

For the conclusion, performance and processing of contracts, we process inventory, contract, billing and usage data (e.g. name, contact details, address, VAT/tax identifiers where applicable, ordered services, payments, invoices, login/session data, 2FA secrets, password hashes). Legal basis: Art. 6 (1) (b) GDPR (contract) and (f) GDPR (security of accounts). Retention in accordance with German commercial and tax law (esp. Sec. 147 AO, 257 HGB; generally 6–10 years).

4. Authentication (login, 2FA, passkeys, OAuth, magic link)

For sign-in we offer password login, two-factor authentication (TOTP + backup codes), passkeys / WebAuthn (FIDO2) as well as, optionally, Discord OAuth login and magic-link sign-in by e-mail. We process the corresponding credentials, device and key identifiers (for passkeys, only public keys – no biometric data) and, in the case of OAuth, the profile data you have authorised (in particular Discord user ID, display name, optionally avatar, optionally e-mail address). Legal basis: Art. 6 (1) (b) and (f) GDPR. With Discord login, data is imported from the relevant platform (Art. 14 GDPR); Discord''s privacy statements apply in addition.

5. Processors, recipients and third-country notes

To provide our services we use the carefully selected providers listed below and have, where required, concluded data processing agreements pursuant to Art. 28 GDPR. For transfers outside the EU/EEA we rely – where applicable – on an adequacy decision by the EU Commission (in particular the EU-U.S. Data Privacy Framework for certified U.S. providers) or on appropriate safeguards pursuant to Art. 46 GDPR (in particular EU Standard Contractual Clauses/SCC supplemented by additional measures).

EU processors (no third country, Art. 28 GDPR):

  • 24fire GmbH (Germany) – provision of the virtualised server infrastructure (VPS, dedicated, gameserver hosts) in the NTT Frankfurt 1 (DE) and SkyLink Eygelshoven (NL) data centres. Purpose: provision of the booked services. Legal basis: Art. 6 (1) (b) and (f) GDPR.
  • INWX (InterNetworX Ltd. & Co. KG, Germany) – domain registrar; transmission of owner/tech/admin contacts to the respective registry (e.g. DENIC eG for .de). Legal basis: Art. 6 (1) (b) and (c) GDPR.
  • Plesk International GmbH (Switzerland/EU) – managed web hosting control panel for web hosting plans. Purpose: web hosting, mailboxes, databases. Legal basis: Art. 6 (1) (b) GDPR.
  • Plesk mail server (self-operated on a 24fire server, Germany) – e-mail server platform based on Postfix, Dovecot and Roundcube (IMAP/SMTP/webmail, DKIM/SPF/DMARC). Legal basis: Art. 6 (1) (b) GDPR. Incoming messages are analysed automatically for spam and viruses; quarantined messages are accessible exclusively to the respective mailbox owner and are not read by the provider's staff. Telecommunications secrecy (Sec. 3 TDDDG, Sec. 88 TKG, Sec. 206 StGB) is preserved.
  • Pelican Panel (self-operated on a 24fire VM, Germany) – gameserver management panel (live console, SFTP). Legal basis: Art. 6 (1) (b) GDPR.

Third-country or mixed processors (with safeguard):

  • Cloudflare, Inc. (USA; also Cloudflare Germany GmbH) – DDoS protection, CDN, bot and abuse protection (Turnstile), DNS resolution. Purpose: protection and delivery. Legal basis: Art. 6 (1) (f) GDPR. Safeguard: EU-U.S. Data Privacy Framework (certified) + EU Standard Contractual Clauses (SCC).
  • Stripe Payments Europe, Ltd. (Ireland; group company Stripe, Inc., USA) – card payments, wallet top-up, subscriptions. Legal basis: Art. 6 (1) (b) GDPR. Safeguard for U.S. transfer: EU-U.S. Data Privacy Framework + SCC. Stripe acts as an independent controller for the actual payment processing.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) – PayPal payments. Legal basis: Art. 6 (1) (b) GDPR. PayPal acts as an independent controller for the payment processing.
  • Discord, Inc. (USA) – community server, OAuth login, bot integration for ticket mirroring, news embeds and owner notifications. Legal basis: Art. 6 (1) (a) (login linking) or (f) GDPR. Safeguard: EU-U.S. Data Privacy Framework.
  • Tebex Limited (United Kingdom) – platform for the sale of digital studio assets (webstore, checkout, license management). Legal basis: Art. 6 (1) (b) GDPR. Safeguard: EU Commission UK adequacy decision and SCC.
  • Sentry (Functional Software, Inc., USA; eu.sentry.io – EU/Frankfurt region) – optional error tracking for admin/portal stability. Legal basis: Art. 6 (1) (f) GDPR. Safeguard: EU hosting of telemetry; EU-U.S. Data Privacy Framework + SCC for any group access.
  • Supabase, Inc. (USA; data hosted in the eu-west-1 region, Ireland) – platform database for customer accounts, orders, tickets and documents. Legal basis: Art. 6 (1) (b) and (f) GDPR. Safeguard: EU hosting of content data; for any support/group access from the U.S. EU Standard Contractual Clauses (SCC) and EU-U.S. Data Privacy Framework.
  • Google Ireland Ltd. (Ireland; Google LLC, USA) – reach measurement via Google Analytics 4 with IP anonymisation and Consent Mode v2. Only with explicit consent (Art. 6 (1) (a) GDPR in conjunction with Sec. 25 (1) TDDDG). Safeguard: EU-U.S. Data Privacy Framework + SCC.

A current, complete list of sub-processors in the context of hosted processing of customer content is additionally provided in our Data Processing Agreement (DPA).

6. Payment data

For paid orders, the data required for processing (e.g. name, billing address, order and amount data) is processed and transmitted to the selected payment service provider (Stripe or PayPal). Legal basis: Art. 6 (1) (b) GDPR. We do not store complete payment instrument data (e.g. card numbers).

7. Domain registration (WHOIS, data transfer)

When registering or managing domains, we transmit the required owner, administrative and technical contact data to our registrar (INWX) and through it to the responsible registry or ICANN-accredited bodies. This is required for contract performance and for compliance with the allocation rules (Art. 6 (1) (b) and (c) GDPR). Depending on the domain ending, parts of this data may be stored in public or non-public directories (e.g. WHOIS/RDAP) and processed in accordance with the rules of DENIC, ICANN and/or the respective registry.

8. Contact, tickets, support

If you contact us by e-mail, via the contact form or via the ticket/support function, we process the data you provide and technical metadata (in particular IP address for spam/abuse prevention). Legal basis: Art. 6 (1) (b) GDPR (contract/pre-contractual) or (f) GDPR (security, evidence). The contact form is protected by Cloudflare Turnstile against automated abuse. Support conversations may be linked to our Discord-based ticket mirror to the extent necessary for processing.

9. Cookies, local storage, reach measurement, notifications

  • Technically necessary storage (local storage / cookies): login/session token, cookie consent state (nbw-consent-v1), language setting, theme choice, shopping cart, security token. Legal basis: Sec. 25 (2) TDDDG (strictly necessary) in conjunction with Art. 6 (1) (b)/(f) GDPR. No consent required.
  • Reach measurement with Google Analytics 4: only with explicit consent via the cookie banner (Sec. 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR). We use Google Consent Mode v2 (default: no analytics storage) and IP anonymisation. Consent can be withdrawn at any time with effect for the future via the cookie settings.
  • Web push notifications: only with explicit consent in the browser (Art. 6 (1) (a) GDPR); deactivatable at any time via browser and portal settings. The processing covers the push endpoint provided by the browser and the associated cryptographic keys.

For details about all cookies and storage mechanisms used, including name, provider, purpose and retention, see our Cookie Policy.

10. Map embedding (two-click solution)

On the contact page we initially display a locally hosted preview image. Only after your explicit activation (two-click solution, Art. 6 (1) (a) GDPR) is an interactive map by an external provider (e.g. OpenStreetMap, Google Maps, Apple Maps) embedded; in that case the IP address and access data may be transmitted to the map provider.

11. Transfer to third countries

Personal data is only transferred to countries outside the EU/EEA where this is required for contract performance or where you have given explicit consent. Such transfers are based on an adequacy decision by the EU Commission (e.g. EU-U.S. Data Privacy Framework for certified U.S. providers, UK adequacy for Tebex) or appropriate safeguards pursuant to Art. 46 GDPR (in particular EU Standard Contractual Clauses/SCC supplemented by additional technical and organisational measures). A copy of the safeguards is available on request.

A named overview of U.S.-based recipients and their respective safeguards is provided in section 5.

12. Retention period

We process personal data only for as long as required for the respective purposes:

  • server/service logs: typically up to 30 days,
  • audit trail of privileged actions (insert-only): owner-configurable retention plan, no longer than legal obligations require,
  • account/profile data: for the duration of the customer relationship plus grace and limitation periods,
  • contract, invoice and tax-relevant documents: 6–10 years (Sec. 147 AO, 257 HGB),
  • consent-based data (e.g. analytics, newsletter): until withdrawal,
  • tickets/support conversations: as long as required for processing and warranty claims, typically up to 3 years after closure,
  • web push subscriptions: until withdrawal or automatic invalidation by the browser.

13. Processing on behalf of customers (hosted content)

To the extent customers store their own content with personal data of third parties on our infrastructure (e.g. website, e-mail or gameserver data of their own users), customers are controllers and we are processors. The basis is the Data Processing Agreement (DPA) pursuant to Art. 28 GDPR, which applies in this constellation.

14. Your rights

You have the right to

  • access (Art. 15 GDPR),
  • rectification of incorrect data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR; "right to be forgotten"),
  • restriction of processing (Art. 18 GDPR),
  • data portability in a machine-readable format (Art. 20 GDPR),
  • object to processing (Art. 21 GDPR), in particular against processing based on legitimate interest.

You can withdraw any consent at any time with effect for the future. In the customer portal you can additionally export your data yourself (full data export as a ZIP with all associated CSVs) and request the deletion of your account.

15. Right to lodge a complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de. You can also contact the authority of your habitual residence.

16. Automated decision-making and profiling (Art. 22 GDPR)

We do not make decisions with legal effect or similarly significant impact that are based solely on automated processing. In operations we use the following automated procedures, which do not constitute profiling within the meaning of Art. 22 GDPR and are, in all relevant cases, subject to human review:

  • Auto-refund cron: if automated provisioning of a paid service fails, an automatic refund of the paid amount is triggered after a grace period.
  • Maintenance-mode cron: owner-planned maintenance windows are activated/deactivated on a schedule and display a non-personal banner in the customer portal.
  • Auto-provisioning / pool autoscale: technical provisioning of booked resources happens automatically; no assessment of the customer''s person occurs.
  • Anti-raid and anti-spam mechanisms (Discord bot, contact form Turnstile): protection against abuse patterns; no personal assessment beyond the purpose of abuse protection.

You may challenge automated measures and request a manual review at any time via support@nobodyworkz.eu.

17. Transport encryption

Our services are available over TLS/SSL encryption; you can recognise an active encryption by the padlock icon in your browser.

18. Changes

We adapt this Privacy Policy where legal or functional changes make this necessary. The version published on this page applies. Earlier versions are available on request.