As of: October 2026
With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter referred to as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites and within external online presences (hereinafter collectively referred to as "online offering").
The terms used are gender-neutral.
Ihor Lapa / CloudForNet
Brandenburger Str., 23A
58089 Hagen, NRW, Germany
E-mail address: [email protected]
Imprint: https://cloud-for.net/impressum.html
E-mail: [email protected]
The following overview summarizes the types of data processed, the purposes of their processing, and refers to the data subjects.
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data:
National data protection regulations in Germany: In addition, the provisions of the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG) apply.
In accordance with legal requirements, we take appropriate technical and organizational measures (TOMs) to ensure a level of protection appropriate to the risk. This includes in particular the encryption of online connections using TLS/SSL technology (HTTPS).
We use the service Cloudflare on our website as a Content Delivery Network (CDN) as well as a security service (reverse proxy and web application firewall).
Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA / Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany.
Purpose of processing: Increasing the loading speed of our website, optimizing the worldwide provision of content, and warding off cyber attacks (e.g., DDoS attacks).
Legal basis: Legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f) GDPR in a secure, fast, and trouble-free delivery of our online offering.
Data transmission to third countries: Cloudflare processes data in the USA, among other places. Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework (DPF). In addition, we have concluded a Data Processing Agreement (DPA) with Cloudflare based on the EU Standard Contractual Clauses (SCC).
Further information: Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/.
In order to provide our online services securely and efficiently, we use the services of web hosting providers.
We use technically necessary cookies and similar storage technologies (e.g., session storage) on our website that are required for the operation of the customer portal and ticketing systems. The storage of and access to information on the terminal device is based on § 25 para. 2 no. 2 TDDDG. Subsequent data processing is based on Art. 6 para. 1 sentence 1 lit. b) GDPR (performance of contract) or Art. 6 para. 1 sentence 1 lit. f) GDPR (legitimate interest).
When contacting us (e.g., by e-mail or via our support ticket system at bill.cloud-for.net), the information provided by the inquiring persons will be processed to the extent necessary to respond to the inquiries and any requested measures.
Legal basis: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) as well as legitimate interest in processing inquiries (Art. 6 para. 1 sentence 1 lit. f) GDPR).
As part of our processing, data may be transmitted to other bodies, companies, or persons (e.g., IT service providers, payment service providers). In such cases, we comply with legal requirements and conclude appropriate contracts (e.g., Data Processing Agreements - DPA).
If we process data in third countries (outside the EU/EEA), this is done exclusively on the basis of adequacy decisions by the EU Commission (e.g., EU-U.S. Data Privacy Framework) or Standard Contractual Clauses (SCCs).
We delete personal data as soon as the legal basis or the original processing purpose ceases to apply. Statutory retention obligations remain unaffected:
As a data subject, you have the following rights under the GDPR (Art. 15 to 21 GDPR):
Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Kavalleriestr. 2-4, 40213 Düsseldorf, Germany
Phone: +49 (0)211/38424-0 | E-mail: [email protected]
Website: https://www.ldi.nrw.de
We process data of our customers within the scope of contracts and orders for web hosting, virtual servers, repairs, and consultations to fulfill our contractual obligations.
Legal bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b) GDPR), legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR).
For secure and efficient payment processing, we use the following payment service providers:
We adapt this privacy policy as soon as changes to our data processing procedures or legal requirements make this necessary.