Privacy Policy (Datenschutzerklärung)
1. Website delivery and server logs
When this website is accessed, the server may process the visitor's IP address, date and time, requested path, HTTP status, transferred data volume, referrer, browser or user-agent information and host name. This is necessary to deliver the website, maintain security, diagnose faults and prevent abuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of the website. Log files are subject to automated size-based rotation and are removed when the configured limits are reached, unless an individual security event requires temporary preservation.
2. Contact form and business inquiries
The contact form processes name, business email address, selected platform and message. Company, website and country are optional. We also store a randomly generated inquiry ID and the time received.
The data is used to assess, answer and manage the business inquiry and, where requested, to take steps before entering into a contract. The legal bases are Article 6(1)(b) GDPR for pre-contractual requests and Article 6(1)(f) GDPR for general B2B communication and orderly lead management.
Required fields are necessary to handle the inquiry. Without them, the form cannot be submitted.
For protection against automated abuse, the visitor's IP address is held temporarily in memory for a rate limit of up to ten accepted submissions per 15-minute period. The IP address is not written into the stored inquiry record.
3. Contract and billing data
If a contract is concluded, we process the necessary business contact, contract, service and billing data to perform the contract (Article 6(1)(b) GDPR where the data subject is the contracting party), to administer the business relationship (Article 6(1)(f) GDPR) and to comply with statutory accounting and tax obligations (Article 6(1)(c) GDPR).
4. Storage periods
Inquiry and CRM data that does not result in a contract is reviewed regularly and ordinarily deleted no later than 12 months after the last relevant activity, unless it is still needed for an ongoing request or for the establishment, exercise or defence of legal claims.
If a contract is concluded, contract, accounting and tax records are retained separately for the applicable statutory periods. Deleted live data may remain in encrypted, access-restricted backups until scheduled backup rotation removes it, ordinarily within six months.
5. Hosting and email recipients
The website and its local inquiry storage are hosted using services of Hetzner Online GmbH, Germany. Contact-form notifications are transmitted through SMTP2GO, a service of Sand Dune Mail Ltd, New Zealand, using SMTP2GO's EU SMTP infrastructure. A data processing agreement with SMTP2GO applies. Namecheap, Inc., United States, provides DNS and email forwarding for the public business email aliases. Business emails are received in a mailbox supplied by Proton AG, Switzerland.
These providers process only the data required to provide their respective hosting or communication service.
Where personal data is transferred outside the European Economic Area and no adequacy decision applies, the transfer is based on an applicable safeguard under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses. Namecheap's data-processing terms provide for those clauses for relevant EEA transfers.
6. Public business information and B2B prospecting
For B2B prospecting we may review public company websites and store publicly available business information such as company name, website, business contact details, platform indicators and internal assessment notes. The purpose is to identify potentially suitable business customers.
The legal basis is Article 6(1)(f) GDPR and our legitimate interest in targeted B2B acquisition. If this information relates to an identifiable person and was not obtained directly from that person, the information required by Article 14 GDPR is supplied no later than the first communication or within one month, as applicable. An objection ends use for direct marketing.
7. Merchant and payment data
This policy covers NetPayCrypto's own website and business administration. Where NetPayCrypto processes a merchant's customer or payment-related data solely to provide the managed service, the merchant remains the controller. NetPayCrypto processes such data as a processor under a data processing agreement pursuant to Article 28 GDPR.
The merchant is responsible for its own customer-facing privacy information.
8. Cookies and tracking
The public website currently uses no advertising trackers, analytics services or non-essential cookies. If this changes, this policy and any legally required consent mechanism will be updated before activation.
9. Rights
Subject to the statutory conditions, data subjects have rights of access, rectification, erasure, restriction, data portability and objection. Consent, where used, may be withdrawn for the future.
Requests can be sent to contact@netpaycrypto.com .
Where processing is based on Article 6(1)(f) GDPR, you may object under Article 21 GDPR on grounds relating to your particular situation. You may object to direct marketing at any time.
10. Complaints
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.
11. Changes
This policy is updated when the website, processing activities or legal requirements change. The current version is published on this page.
12. Controller and contact details
NetPayCryptoOwner: Leo Lustig
Berkaer Str. 28
14193 Berlin
Deutschland
Email: contact@netpaycrypto.com