This policy explains what personal data we process when you use webXtrend, why we
process it, how long we keep it and which rights you have under the General Data Protection
Regulation (GDPR).
This is a translation for your convenience. The
German version is the legally authoritative text; in the
event of any discrepancy, the German wording prevails.
Last updated: 9 September 2026
1. Controller
The controller responsible for the processing described here is:
We are not required to appoint a data protection officer under
Sec. 38 of the German Federal Data Protection Act (BDSG). For any question about
this policy, please write to the address above.
2. Scope
This policy applies to the website webxtrend.com,
including the customer area you reach there after signing in, and to the customer
API at api.webxtrend.com. It does not apply to third-party websites
you reach through links or through data shown in our search results.
webXtrend is a domain intelligence service. The data we publish
about domains (DNS records, redirects, reverse-IP neighbours, linked social
media accounts and crawled start pages) is collected from public sources such
as the public DNS system and publicly reachable websites. Where such information
relates to an identifiable natural person, Section 11 of this policy applies.
3. Visiting our website (server log files)
Each time a page is requested, our web server automatically records:
— your IP address
— date and time of the request
— the requested URL and the HTTP status code
— the amount of data transferred
— the referring URL, if your browser sends one
— browser type, version and operating system (user agent)
Purpose: delivering the website, ensuring stability and
security, and investigating attacks or abuse.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest
is the secure and reliable operation of the service.
Retention: 14 days, then automatic deletion by log
rotation. Longer only where a specific incident is being investigated.
4. Domain searches
When you run a search, we log the search term, the time of the request,
how long it took, a summary of the result and the IP address the request came from.
The search term is a domain name; the IP address is personal data.
Purpose: detecting and preventing automated abuse and
scraping, enforcing usage limits, and capacity planning.
Legal basis: Art. 6(1)(f) GDPR.
Retention: 90 days.
We do not build usage profiles from these records, and we do not
link them to your account unless we are investigating a specific case of abuse.
5. Cookies
We use only cookies that are strictly necessary to provide the service
you requested. We do not use analytics, advertising, retargeting or social
media cookies, and we do not track you across websites. This is why you do
not see a cookie banner.
Name
Purpose
Lifetime
session
Keeps you signed in to your account. Contains a random identifier,
no personal data. Set to HttpOnly and, over HTTPS, Secure.
Until the browser is closed
Legal basis: Sec. 25(2) No. 2 TDDDG (strictly necessary
cookies, no consent required) in conjunction with Art. 6(1)(b) and (f) GDPR.
Some interface components store display preferences in your browser's
local storage: the colour scheme you picked for the dashboard
(wx-dash-theme) and the sorting and page length of result tables. That
information stays on your device and is never transmitted to us.
6. Customer account
To register an account we process: email address, password, and
(where you provide them) company name, contact name, street, postal code, city
and country. We also store your email notification preferences and, until your
address is confirmed, a one-time confirmation code.
Passwords are never stored in plain text. They are hashed with
bcrypt and cannot be read by us.
Purpose: creating and administering your account,
authentication, and providing the service you subscribed to.
Legal basis: Art. 6(1)(b) GDPR (performance of a
contract or pre-contractual steps).
Retention: for as long as your account exists. After
deletion of the account, data is erased unless we must keep it to meet statutory
retention obligations (see Section 8).
When you sign in, we store a random session identifier together
with your user ID and the time of your last activity, so that the session can be
validated and expired. Sessions are removed when you log out.
To stop passwords from being guessed, we count failed
sign-in attempts. We store a checksum of the email address that was entered, the
IP address the attempt came from and the time. We do not store the address itself,
only a value that cannot be reversed, and a successful sign-in deletes the entries
straight away.
Purpose: preventing automated sign-in attempts.
Legal basis: Art. 6(1)(f) GDPR.
Retention: 24 hours.
7. API access and downloads
If you use the customer API, we store your API token and a daily count
of the calls made with it, in order to enforce the query limit of your plan and to
bill correctly.
When you download a purchased data export, we record which user
downloaded which file, when, over which channel, how many bytes were transferred,
the IP address and the browser user agent.
Purpose: enforcing plan limits, and proving that
purchased data was actually delivered, for instance if a payment is charged
back on the claim that nothing was received.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR
(our legitimate interest in evidence for claims and defence against chargebacks).
Retention: delivery records for 3 years from the end of
the year of delivery, matching the statutory limitation period; usage counters for
as long as needed for billing.
8. Orders, payment and invoices
Payments are processed by Stripe Payments Europe, Ltd.,
The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland.
Card numbers and other payment credentials are entered directly on
Stripe's payment page. We never receive or store them. What we
transmit to Stripe is your email address, your name or company name, your billing
address, the order number and the product purchased. Stripe returns the payment
status, the billing address you confirmed, and its own customer, session and
invoice identifiers, which we store alongside your order.
We also keep a technical log of the payment communication,
including the requests and responses exchanged with Stripe and the IP address of
incoming Stripe webhook notifications. This technical log is kept for 3 years and
serves solely to trace payment problems and defend against claims; it is separate
from the accounting records described below.
Stripe may transfer data to Stripe, Inc. in the United States.
Such transfers are covered by the European Commission's standard contractual
clauses and by Stripe's certification under the EU–U.S. Data Privacy
Framework. Stripe processes payment data as an independent controller for its own
fraud prevention and regulatory obligations; see Stripe's own privacy policy at
stripe.com/privacy.
Purpose: processing your order, taking payment,
issuing invoices, managing subscriptions and handling refunds or disputes.
Legal basis: Art. 6(1)(b) GDPR for performing the
contract, and Art. 6(1)(c) GDPR for the statutory bookkeeping obligations that
follow from it.
Retention: invoices, orders and the underlying booking
records are kept for eight to ten years as required by Sec. 147 of the German Fiscal
Code (AO) and Sec. 257 of the German Commercial Code (HGB). During that period the
data is retained and no longer used for any other purpose.
9. Emails we send
Service emails: address confirmation, password
resets, sign-in notifications, warnings when you approach your query limit, invoices
and notices about incidents affecting the service. These are part of the contract
and cannot be switched off individually where they are legally or contractually
required. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.
Newsletter: only if you have explicitly
opted in and then confirmed that subscription. Legal basis: Art. 6(1)(a) GDPR and
Sec. 7(2) No. 3 of the German Act against Unfair Competition (UWG).
We use the double opt-in procedure. After you subscribe we send a
single mail to the address you gave us, containing a confirmation link. The address
goes on the list only once you open that link; without confirmation we send no
newsletter to it.
What we store for this: your email address, the time
of the subscription, the IP address and browser identification used, the wording of
the consent shown to you at the time, and the time and IP address of the
confirmation. These details serve one purpose only, namely the proof of consent that
Art. 7(1) GDPR requires of us. Legal basis for that proof: Art. 6(1)(c) GDPR in
conjunction with Art. 7(1) GDPR.
Withdrawal: every newsletter carries an unsubscribe
link. One click on it is enough, no reason is needed and no account either. If you
have an account you can also switch the newsletter off in your settings, and a
message to info@webxtrend.com works just as
well. Withdrawal does not affect the lawfulness of processing carried out
beforehand.
Retention: a subscription that is never confirmed is
deleted after 30 days. After a withdrawal we keep the proof of the consent and of
the withdrawal for three years and delete it afterwards; during that time you
receive no further newsletters.
Our email is sent over our own mail server; it is not handed to a
third-party bulk mailing provider. We do not use tracking pixels and do not measure
whether you open a message or click a link.
10. Contacting us
If you contact us by email, telephone or through our contact form, we
process the details you provide (typically your name, your email address and
the content of your message) in order to answer you.
Legal basis: Art. 6(1)(b) GDPR where your enquiry
relates to a contract or to entering into one, otherwise Art. 6(1)(f) GDPR (our
legitimate interest in answering enquiries).
Retention: until your enquiry is fully dealt with and
no further questions arise, unless statutory retention periods apply.
11. Data about domains and their operators
Our database describes domains, not people. It is compiled from publicly
available sources: the public DNS system, publicly reachable web pages and the
social media profiles those pages link to. In individual cases such information can
nevertheless relate to an identifiable natural person, for example where a
domain carries a personal name or a private site links to a personal profile.
Purpose: providing a domain and DNS intelligence
service for market research, competitive analysis, IT security and brand protection.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest,
and that of our customers, is in analysing publicly accessible information about the
domain name system. We have weighed this against the interests of the persons
concerned; the data originates from sources that are public by design and is
processed in the context in which it was published.
If you believe that information we display about a domain relates
to you as a private individual and should not be shown, please contact us at
info@webxtrend.com. You have a right to
object under Art. 21 GDPR; see Section 15.
12. Hosting
Our website, databases and mail server run on servers located in
Germany, operated for us by Hetzner Online GmbH, Industriestr. 25,
91710 Gunzenhausen, Germany. The provider acts as a processor
on our behalf under a data processing agreement pursuant to Art. 28 GDPR and
processes personal data only on our instructions.
13. Third-party content on our pages
Google Fonts. Our pages load typefaces from Google
Fonts, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4,
Ireland. When a page opens, your browser connects to Google's servers, which
receives your IP address and the address of the page you are viewing. Google may
transfer data to Google LLC in the United States; the transfer is covered by
standard contractual clauses and Google's certification under the EU–U.S. Data
Privacy Framework. The fonts are used to present our pages consistently. Legal
basis: Art. 6(1)(f) GDPR. Google's privacy policy:
policies.google.com/privacy.
Cloudflare cdnjs. The order page loads one
JavaScript library from the cdnjs service of Cloudflare, Inc., 101 Townsend St., San
Francisco, CA 94107, USA. Your browser transmits your IP address to Cloudflare for
this purpose. Legal basis: Art. 6(1)(f) GDPR. Cloudflare's privacy policy:
cloudflare.com/privacypolicy.
14. Recipients and transfers
We do not sell personal data, and we do not pass it on for advertising
purposes. Personal data is disclosed only to:
— our hosting provider, as a processor (Section 12)
— Stripe, for payment processing (Section 8)
— Google and Cloudflare, where your browser loads their
content (Section 13)
— our tax adviser and, where legally required, tax
authorities, courts or law enforcement
Transfers outside the European Economic Area occur only in the cases
described in Sections 8 and 13 and are based on the European Commission's standard
contractual clauses and, where applicable, the EU–U.S. Data Privacy Framework.
15. Your rights
Under the GDPR you have the right to:
— access your personal data and receive a
copy of it (Art. 15)
— have inaccurate data corrected (Art. 16)
— have your data erased (Art. 17)
— have processing restricted (Art. 18)
— receive your data in a portable, machine-readable format
(Art. 20)
— withdraw consent at any time, with effect
for the future (Art. 7(3))
Right to object (Art. 21 GDPR). Where we process
your data on the basis of a legitimate interest (in particular under Sections
3, 4, 7, 11 and 13) you have the right to object at any time on grounds
relating to your particular situation. We will then stop processing your data unless
we can demonstrate compelling legitimate grounds that override your interests,
rights and freedoms, or the processing serves to establish, exercise or defend legal
claims.
To exercise any of these rights, write to
info@webxtrend.com. We answer without undue
delay and at the latest within one month.
Right to lodge a complaint (Art. 77 GDPR). You may
complain to a supervisory authority, in particular in the member state of your
residence, place of work or of the alleged infringement. The authority competent for
us is:
Sächsische Datenschutz- und Transparenzbeauftragte
We do not use automated decision-making or profiling within the meaning
of Art. 22 GDPR. Nothing about you is decided by an algorithm alone.
17. Obligation to provide data
You are not legally obliged to provide us with personal data. However,
without an email address we cannot create an account for you, and without billing
details we cannot process a paid order. Searching public domain data does not
require an account.
18. Data security
All traffic between your browser and our servers is encrypted with
TLS; you can recognise this by the lock symbol in the address bar. Passwords
are stored as bcrypt hashes, session cookies are set to HttpOnly and Secure, and
access to our systems is restricted to the persons who need it. We keep our
technical and organisational measures under review as the state of the art
develops.
19. Changes to this policy
We update this policy when our service or the legal requirements change.
The version published here always applies; the date of the last change is shown at
the top of the page.
Last updated: 9 September 2026
1. Controller
The controller responsible for the processing described here is:
Aiko Berge
Sole proprietor, trading as webXtrend
Altsporbitz 3
01259 Dresden
Germany
Email: info@webxtrend.com
Phone: +49 351 20734087
We are not required to appoint a data protection officer under Sec. 38 of the German Federal Data Protection Act (BDSG). For any question about this policy, please write to the address above.
2. Scope
This policy applies to the website webxtrend.com, including the customer area you reach there after signing in, and to the customer API at api.webxtrend.com. It does not apply to third-party websites you reach through links or through data shown in our search results.
webXtrend is a domain intelligence service. The data we publish about domains (DNS records, redirects, reverse-IP neighbours, linked social media accounts and crawled start pages) is collected from public sources such as the public DNS system and publicly reachable websites. Where such information relates to an identifiable natural person, Section 11 of this policy applies.
3. Visiting our website (server log files)
Each time a page is requested, our web server automatically records:
Purpose: delivering the website, ensuring stability and security, and investigating attacks or abuse.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the service.
Retention: 14 days, then automatic deletion by log rotation. Longer only where a specific incident is being investigated.
4. Domain searches
When you run a search, we log the search term, the time of the request, how long it took, a summary of the result and the IP address the request came from. The search term is a domain name; the IP address is personal data.
Purpose: detecting and preventing automated abuse and scraping, enforcing usage limits, and capacity planning.
Legal basis: Art. 6(1)(f) GDPR.
Retention: 90 days.
We do not build usage profiles from these records, and we do not link them to your account unless we are investigating a specific case of abuse.
5. Cookies
We use only cookies that are strictly necessary to provide the service you requested. We do not use analytics, advertising, retargeting or social media cookies, and we do not track you across websites. This is why you do not see a cookie banner.
sessionLegal basis: Sec. 25(2) No. 2 TDDDG (strictly necessary cookies, no consent required) in conjunction with Art. 6(1)(b) and (f) GDPR.
Some interface components store display preferences in your browser's local storage: the colour scheme you picked for the dashboard (
wx-dash-theme) and the sorting and page length of result tables. That information stays on your device and is never transmitted to us.6. Customer account
To register an account we process: email address, password, and (where you provide them) company name, contact name, street, postal code, city and country. We also store your email notification preferences and, until your address is confirmed, a one-time confirmation code.
Passwords are never stored in plain text. They are hashed with bcrypt and cannot be read by us.
Purpose: creating and administering your account, authentication, and providing the service you subscribed to.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual steps).
Retention: for as long as your account exists. After deletion of the account, data is erased unless we must keep it to meet statutory retention obligations (see Section 8).
When you sign in, we store a random session identifier together with your user ID and the time of your last activity, so that the session can be validated and expired. Sessions are removed when you log out.
To stop passwords from being guessed, we count failed sign-in attempts. We store a checksum of the email address that was entered, the IP address the attempt came from and the time. We do not store the address itself, only a value that cannot be reversed, and a successful sign-in deletes the entries straight away.
Purpose: preventing automated sign-in attempts.
Legal basis: Art. 6(1)(f) GDPR.
Retention: 24 hours.
7. API access and downloads
If you use the customer API, we store your API token and a daily count of the calls made with it, in order to enforce the query limit of your plan and to bill correctly.
When you download a purchased data export, we record which user downloaded which file, when, over which channel, how many bytes were transferred, the IP address and the browser user agent.
Purpose: enforcing plan limits, and proving that purchased data was actually delivered, for instance if a payment is charged back on the claim that nothing was received.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (our legitimate interest in evidence for claims and defence against chargebacks).
Retention: delivery records for 3 years from the end of the year of delivery, matching the statutory limitation period; usage counters for as long as needed for billing.
8. Orders, payment and invoices
Payments are processed by Stripe Payments Europe, Ltd., The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland.
Card numbers and other payment credentials are entered directly on Stripe's payment page. We never receive or store them. What we transmit to Stripe is your email address, your name or company name, your billing address, the order number and the product purchased. Stripe returns the payment status, the billing address you confirmed, and its own customer, session and invoice identifiers, which we store alongside your order.
We also keep a technical log of the payment communication, including the requests and responses exchanged with Stripe and the IP address of incoming Stripe webhook notifications. This technical log is kept for 3 years and serves solely to trace payment problems and defend against claims; it is separate from the accounting records described below.
Stripe may transfer data to Stripe, Inc. in the United States. Such transfers are covered by the European Commission's standard contractual clauses and by Stripe's certification under the EU–U.S. Data Privacy Framework. Stripe processes payment data as an independent controller for its own fraud prevention and regulatory obligations; see Stripe's own privacy policy at stripe.com/privacy.
Purpose: processing your order, taking payment, issuing invoices, managing subscriptions and handling refunds or disputes.
Legal basis: Art. 6(1)(b) GDPR for performing the contract, and Art. 6(1)(c) GDPR for the statutory bookkeeping obligations that follow from it.
Retention: invoices, orders and the underlying booking records are kept for eight to ten years as required by Sec. 147 of the German Fiscal Code (AO) and Sec. 257 of the German Commercial Code (HGB). During that period the data is retained and no longer used for any other purpose.
9. Emails we send
Service emails: address confirmation, password resets, sign-in notifications, warnings when you approach your query limit, invoices and notices about incidents affecting the service. These are part of the contract and cannot be switched off individually where they are legally or contractually required. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.
Newsletter: only if you have explicitly opted in and then confirmed that subscription. Legal basis: Art. 6(1)(a) GDPR and Sec. 7(2) No. 3 of the German Act against Unfair Competition (UWG).
We use the double opt-in procedure. After you subscribe we send a single mail to the address you gave us, containing a confirmation link. The address goes on the list only once you open that link; without confirmation we send no newsletter to it.
What we store for this: your email address, the time of the subscription, the IP address and browser identification used, the wording of the consent shown to you at the time, and the time and IP address of the confirmation. These details serve one purpose only, namely the proof of consent that Art. 7(1) GDPR requires of us. Legal basis for that proof: Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
Withdrawal: every newsletter carries an unsubscribe link. One click on it is enough, no reason is needed and no account either. If you have an account you can also switch the newsletter off in your settings, and a message to info@webxtrend.com works just as well. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Retention: a subscription that is never confirmed is deleted after 30 days. After a withdrawal we keep the proof of the consent and of the withdrawal for three years and delete it afterwards; during that time you receive no further newsletters.
Our email is sent over our own mail server; it is not handed to a third-party bulk mailing provider. We do not use tracking pixels and do not measure whether you open a message or click a link.
10. Contacting us
If you contact us by email, telephone or through our contact form, we process the details you provide (typically your name, your email address and the content of your message) in order to answer you.
Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or to entering into one, otherwise Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries).
Retention: until your enquiry is fully dealt with and no further questions arise, unless statutory retention periods apply.
11. Data about domains and their operators
Our database describes domains, not people. It is compiled from publicly available sources: the public DNS system, publicly reachable web pages and the social media profiles those pages link to. In individual cases such information can nevertheless relate to an identifiable natural person, for example where a domain carries a personal name or a private site links to a personal profile.
Purpose: providing a domain and DNS intelligence service for market research, competitive analysis, IT security and brand protection.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and that of our customers, is in analysing publicly accessible information about the domain name system. We have weighed this against the interests of the persons concerned; the data originates from sources that are public by design and is processed in the context in which it was published.
If you believe that information we display about a domain relates to you as a private individual and should not be shown, please contact us at info@webxtrend.com. You have a right to object under Art. 21 GDPR; see Section 15.
12. Hosting
Our website, databases and mail server run on servers located in Germany, operated for us by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The provider acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR and processes personal data only on our instructions.
13. Third-party content on our pages
Google Fonts. Our pages load typefaces from Google Fonts, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When a page opens, your browser connects to Google's servers, which receives your IP address and the address of the page you are viewing. Google may transfer data to Google LLC in the United States; the transfer is covered by standard contractual clauses and Google's certification under the EU–U.S. Data Privacy Framework. The fonts are used to present our pages consistently. Legal basis: Art. 6(1)(f) GDPR. Google's privacy policy: policies.google.com/privacy.
Cloudflare cdnjs. The order page loads one JavaScript library from the cdnjs service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Your browser transmits your IP address to Cloudflare for this purpose. Legal basis: Art. 6(1)(f) GDPR. Cloudflare's privacy policy: cloudflare.com/privacypolicy.
14. Recipients and transfers
We do not sell personal data, and we do not pass it on for advertising purposes. Personal data is disclosed only to:
Transfers outside the European Economic Area occur only in the cases described in Sections 8 and 13 and are based on the European Commission's standard contractual clauses and, where applicable, the EU–U.S. Data Privacy Framework.
15. Your rights
Under the GDPR you have the right to:
Right to object (Art. 21 GDPR). Where we process your data on the basis of a legitimate interest (in particular under Sections 3, 4, 7, 11 and 13) you have the right to object at any time on grounds relating to your particular situation. We will then stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
To exercise any of these rights, write to info@webxtrend.com. We answer without undue delay and at the latest within one month.
Right to lodge a complaint (Art. 77 GDPR). You may complain to a supervisory authority, in particular in the member state of your residence, place of work or of the alleged infringement. The authority competent for us is:
Sächsische Datenschutz- und Transparenzbeauftragte
Devrientstraße 5, 01067 Dresden, Germany
www.saechsdsb.de
16. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Nothing about you is decided by an algorithm alone.
17. Obligation to provide data
You are not legally obliged to provide us with personal data. However, without an email address we cannot create an account for you, and without billing details we cannot process a paid order. Searching public domain data does not require an account.
18. Data security
All traffic between your browser and our servers is encrypted with TLS; you can recognise this by the lock symbol in the address bar. Passwords are stored as bcrypt hashes, session cookies are set to HttpOnly and Secure, and access to our systems is restricted to the persons who need it. We keep our technical and organisational measures under review as the state of the art develops.
19. Changes to this policy
We update this policy when our service or the legal requirements change. The version published here always applies; the date of the last change is shown at the top of the page.