1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Hans Jürgen Jelen
Bokelholm, Bokeler Straße 5
24802 Emkendorf
Germany
Email: support@xeltrik.com
A data protection officer has not been appointed, as there is no legal obligation to do so.
2. General Information on Data Processing
We process personal data exclusively in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws.
Data processing is carried out in particular on the following legal bases:
- Art. 6(1)(b) GDPR (performance of a contract)
- Art. 6(1)(c) GDPR (legal obligation)
- Art. 6(1)(f) GDPR (legitimate interest)
- Art. 6(1)(a) GDPR (consent)
3. Rights of Data Subjects
You have the right at any time to:
- access your data (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing (Art. 21 GDPR)
You may withdraw any consent you have given at any time with effect for the future.
You also have the right to lodge a complaint with a supervisory authority.
4. Hosting, Server Locations and Logs
To provide our hosting and server services, we make use of services provided by netcup GmbH.
Data processing takes place in data centers within the European Union, in particular in Germany (including Nuremberg) and Austria.
When operating our website, customer panel and server services, the following data is processed in particular:
- IP addresses
- login and access data
- system, security and error logs
- abuse and network data
This processing is carried out to ensure technical operation, IT security, abuse prevention and compliance with legal obligations.
5. Registration and Customer Account (Paymenter)
When registering and using our customer panel, the following data is processed, among others:
- name and address
- email address
- date of birth
- contract and billing data
- IP addresses during logins and orders
This data is required for contract performance and billing.
6. Payment Processing
Payment processing is carried out via external payment service providers, in particular:
- Stripe
- Klarna
- Google Pay
- Credit cards
- Alipay
- Amazon Pay
We do not store complete payment details such as credit card numbers or IBANs.
7. Support, Contact and Live Chat
When contacting us via email, ticket system or live chat, personal data is processed for the purpose of handling the inquiry.
8. Newsletter and System Emails
We send system emails (e.g. invoices, service notifications) as well as newsletters.
Newsletters are sent only after prior consent (double opt-in).
Consent may be withdrawn at any time.
9. Cookies and Consent Management
Our website uses cookies. In addition to technically necessary cookies, cookies for analytics and marketing purposes (e.g. Google Ads, Hotjar) are used only after your consent.
Consent can be withdrawn or adjusted at any time via the cookie settings or the consent tool used.
10. Google Ads
We use Google Ads including conversion tracking.
Cookies are used to analyze the effectiveness of advertising measures.
Legal basis: Art. 6(1)(a) GDPR (consent).
11. Hotjar
We use Hotjar to analyze user behavior on our website.
Processing is carried out in a pseudonymized manner and only with your consent.
12. Cloudflare (CDN and Security)
We use Cloudflare as a content delivery network and security service.
This may involve the transfer of personal data (e.g. IP addresses) to third countries, in particular the United States.
Cloudflare is certified under the EU-U.S. Data Privacy Framework.
13. Transfers to Third Countries
Where personal data is transferred to service providers in third countries, this is done only in compliance with legal requirements (e.g. adequacy decisions, standard contractual clauses).
14. Social Media Links
Our website contains links to external social networks (e.g. Discord, Instagram, Facebook, YouTube).
When clicking these links, the privacy policies of the respective providers apply.
15. Google Fonts
If Google Fonts are used, the IP address may be transmitted to Google.
16. Data Processing Agreements
Data processing agreements pursuant to Art. 28 GDPR have been concluded with service providers who process personal data on our behalf.
17. Data Retention
Personal data is stored only for as long as necessary for the respective purposes or as required by statutory retention obligations.
18. Data Security
We implement appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access.
19. Changes to this Privacy Policy
We reserve the right to amend this privacy policy in order to adapt it to legal or technical changes.
Last updated: 2026