Privacy Policy
As of 03.10.2026
This is a courtesy translation. Only the German version is legally binding.
This privacy policy informs you, in accordance with Art. 13 and 14 GDPR, about which personal data we process when you visit the Nexlo website, create a customer account and use our hosting services.
1. Controller
Helmut Fürpaß, sole proprietor (Software-Hub / Nexlo)
Farch 2a, 8741 Weißkirchen in Steiermark, Austria
Email: office@software-hub.org · Phone: +43 650 4230506
A data protection officer is not required by law and has not been appointed. You can reach us at the email address above for all data protection matters.
2. Visiting the website
When you access our website, the web server automatically processes technically necessary data: IP address, date and time, page accessed, amount of data transferred, status code, browser and operating system, and the previously visited page.
- Purpose: secure and stable operation, defence against attacks
- Legal basis: legitimate interest (Art. 6 (1)(f) GDPR)
- Retention: no longer than 14 days, unless a security incident has to be investigated
We use no analytics, tracking or advertising services and do not embed external fonts, maps or social media elements.
3. Cookies and local storage
We only use technically necessary cookies:
- Session cookie (
nexlo-session): keeps you logged in and remembers form input; expires 2 hours after your last activity. - Security cookie (
XSRF-TOKEN): protects against forged form requests (CSRF); same lifetime. - Login cookie (
remember_web_…): only if you choose "Stay logged in" when logging in; valid until you log out, at most 400 days.
In addition, we store locally in your browser (local storage) your choice between light and dark design (nx-theme) and whether you have closed the cookie notice (nx-cookie-notice). This information is not transmitted to us.
These storage operations are necessary for operation or expressly requested by you (§ 165 (3) Austrian Telecommunications Act 2021, Art. 6 (1)(b) and (f) GDPR) and do not require consent. We do not use analytics, tracking or advertising cookies.
If protection against automated sign-ups (Cloudflare Turnstile, Cloudflare Inc., USA) is active on the login and registration pages and on community fund pages, technical characteristics of your browser and your IP address are transmitted to Cloudflare to detect bots (Art. 6 (1)(f) GDPR). The transfer to the USA is based on the adequacy decision for the EU-US Data Privacy Framework.
4. Customer account and contract processing
When you create an account and order services, we process:
-
Master data: name, company and VAT ID if applicable, address, country, phone number, preferred language
-
Login data: email address, password (stored only as a secure hash), two-factor key if applicable
-
Contract and billing data: ordered services, credit, bookings, invoices
-
Usage and log data: IP addresses and times of logins and security-relevant actions (e.g. retrieving access data, deletions), support tickets
-
Purpose: provision and billing of services, customer support, protection against abuse
-
Legal basis: performance of contract (Art. 6 (1)(b) GDPR), legal obligations (point c) and legitimate interest in security and abuse prevention (point f)
We send emails that are necessary for the contract (e.g. confirmations, invoices, low balance warnings, expiry of services). We do not send advertising newsletters.
Partner program: If you visit our website via a referral link (?ref=…), we store the code only in your existing session – without an additional cookie – and prefill it during registration (you can remove it). If you register with a code or redeem it later, we store which partner you are assigned to and since when. In their partner area, the partner only sees your customer number and the date and amount of your top-ups and the resulting commission – not your name or contact details. If you take part in the partner program yourself, we additionally process your commissions and, for payouts, your IBAN or PayPal address (stored encrypted). The legal basis is the performance of the contract (Art. 6 (1)(b) GDPR) and our legitimate interest in settling referrals (point f).
Community fund: If you pay into a server's community fund via a fund link, we process the amount, the time and – voluntarily – the name and message you enter. The payment is handled by Mollie (see section 6); we do not receive any account or card details. The server owner sees your name, message and amount. If the owner has enabled the supporter list, they are also shown publicly on the fund page; the owner can hide individual entries. Leave the name field empty if you want to stay anonymous. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR); we keep the data like payment records (section 8).
Public server status pages: Customers can enable a public status page for their server. For this, we regularly query the customer's server and display what it publishes itself (e.g. for Minecraft: player count, version, server description and possibly a selection of player names) as well as its availability. The respective customer is responsible for this content and the notice text. When a status page is visited, we only process the server log data listed in section 2.
Team access and Discord: If a customer invites another person to a server, we process that person's e-mail address for the invitation; after accepting, they see the server data according to their role, and their actions are logged and visible to the owner. If a customer enters a Discord webhook, we store it encrypted and send the events chosen by the customer (e.g. server online/offline, name and amount of fund contributions) to Discord Inc., USA. For this transfer to the USA we rely on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses. Gift cards, server list and API: When a gift card is bought, we process the recipient data provided by the buyer (name, email address, message) to deliver the card by email – on request at a chosen date (Art. 6(1)(b) GDPR towards the buyer, (f) towards the recipient: legitimate interest in delivering the gift). We store which customer account redeemed the card and tell the buyer about the redemption. If a customer adds their server to the public server list, we publish the title, description, links, the server address and the game data publicly provided by the server (e.g. player count, version, server icon). For API tokens we only store a hash of the token plus the time and IP address of its last use (Art. 6(1)(b) and (f) GDPR – abuse detection). If you apply as a reseller, we process your details (company, website, information on target group and volume, and the uploaded proof of business registration) to review the application and contact you about it (Art. 6(1)(b) GDPR – pre-contractual measures). The proof of business registration is not publicly accessible; only administrators can view it. If the application is rejected, we delete it after 6 months.
5. Server and domain services
- Servers: Your servers are provided in data centers in Germany via our infrastructure partner. The data required for operation (server configuration, hostname, IP addresses, SSH keys if applicable) is transmitted to the partner, who acts as our processor (Art. 28 GDPR). You process the content you store on your servers yourself – you are the controller within the meaning of the GDPR for this content.
- Domains: To register and manage domains, we transmit the registrant data (name, address, email, phone) to InterNetX GmbH, Johanna-Dachs-Straße 55, 93055 Regensburg, Germany, and from there to the respective registry (e.g. DENIC eG for .de, nic.at for .at). This is mandatory for registration (Art. 6 (1)(b) GDPR). Depending on the extension, registries may be located outside the EU; the transfer is then necessary for the performance of the contract (Art. 49 (1)(b) GDPR). Depending on their rules, registries publish registrant data in WHOIS/RDAP.
- Availability check: When you search for a domain, we query the registries' public information services (RDAP/WHOIS). Only the domain name searched for is transmitted, no data about you.
6. Payments
We process credit top-ups via Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. Mollie processes your payment data (e.g. account details, card details) under its own responsibility or as part of payment processing; we only receive the amount, payment method and payment status. The legal basis is the performance of the contract (Art. 6 (1)(b) GDPR). Depending on the payment method chosen (e.g. PayPal, credit card), further payment service providers are involved, whose privacy notices apply.
7. Recipients
We only share data where necessary for the purposes mentioned or where there is a legal obligation: with the service providers mentioned above (infrastructure, domains, payments), the operator of our email server, tax advisors, and authorities and courts within the scope of legal obligations.
8. Retention period
We store data for as long as it is required for the respective purpose. After your account is deleted, we delete or anonymise your data unless statutory retention obligations apply. We keep invoices and accounting records for seven years in accordance with § 132 Austrian Federal Fiscal Code (BAO). We store logs of security-relevant actions for no longer than two years.
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can change much of your information yourself in your customer account under "Profile & security" or delete your account there.
You can also lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
10. Data security
Data is transmitted exclusively in encrypted form (TLS). We store passwords only as hashes and server access data encrypted. Retrieving access data requires re-entering your password and is logged. Two-factor authentication is available to you.
11. Changes
We update this policy when our processing changes. The version published here applies.
Last updated: October 2026