Privacy Policy

Privacy policy
Below you can see our new GDPR compliant privacy policy

Privacy policy Server24
For INCUBATEC S.r.l. (“server24”), protecting your personal data is a priority. We comply with all relevant data protection legislation and the following privacy notice is intended to provide transparency about how we handle your personal data.

Personal data and the provision of services
When you order one of our products, we only ask for information that is essential to deliver our products and services to you or for invoicing reasons. In most cases this is limited to name, address, contact data and bank details.

1. Contract and invoicing data
Prior to sign up
On the server24 web pages we offer prospective and actual customers practical tools and services, for example, to check how easy it is to locate your website or company on the Internet. The tool needs only some basic address data. For the best results and continous improvement of our services, your entries are recorded anonymously.

Sign up
Upon ordering our products, we ask for data we need to provision the services. Your data is stored securely on our systems and you are able to access and change your data in our control panel. Information on how you access the control panel will usually be sent by email or alternatively by post.

Billing
In order to provide you with transparent billing, it is necessary to temporarily store certain usage data. Examples include your configurations of our Cloud-Server or performance of our Webhosting products, if those are the basis for billing. Whether your product usage data is recorded, will be in the respective product chapter in this privacy notice.

2. Usage and content data
Usage data
We aim to provide quality and reliability but on occasion, issues may arise. In order to react quickly, it may be necessary to temporarily record usage and traffic data to provide to our Support staff. We do this to ensure we fulfil our obligations to you and to design products and services aligned to your needs

Content data
We offer certain products, for example, online storage or email accounts, where personal files may be stored. These files are automatically encrypted and may only be viewed by individuals with access rights. In order to protect your data and for maintenance purposes, we create and file encrypted backups. The file contents of these backups can not be decrypted or viewed by us.

3. Usage of your data
The usage of your personal data
Some of your personal data we need for processing your order and for providing customer focused services.

Data processing upon receiving your order
Our commitment to you is to provide value for money top products and servicesto our customers. In order to ensure smooth and trouble-free order processes, your order is thoroughly vetted and invest in fraud prevention before confirming your contract.

Contract and customer information
You will receive the order confirmation and information by email. We use the email address you have provided to order the product. You will also receive your invoices and helpful information in the same manner.

Product information
In order to fully capture the benefits of our products, we send you tips, tricks and useful complementing product solutions by email andcontrol panel. Wee may also inform you about interesting new products via telephone, provided that you have consented to receive such information. . If you wish to stop receiving information of this kind, you can always revoke your consent in the control panel.

Usage data as part of our services and products
Certain data is recorded during use of our products and services to enable us to identify issues with our products and to continously improve our products and services. In order to ensure the safety of your personal data, we pseudonymize or anonymize such personal data prior to any analysis.

Opinion polls
In order to offer you the best possible products and services, we do need your support. Therefore, we send out surveys to our customers from time to time via email or provide them on our websites. Participation in these surveys is optional and you may revoke your consent to receiving opinion polls from us after the first email.

4. Transferring data to third parties
Server24 is part of INCUBATEC S.r.l.
We, and other subisidaries and affiliates, are part of INCUBATEC S.r.l.. In order to avoid duplicate copies of address data and adhere to negative data, as for example email black lists, it is sometimes necessary to transfer customer data to INCUBATEC S.r.l. and its affiliates.

External partner companies
As we work with selected partners to offer you a wide range of productsand sometimes act as an intermediary for our partners, it is necessary to transfer certain personal data to third parties, for example, registering domain namesor issuing SSL certificates.

Law enforcement
Occasionally,we are obliged to disclose personal data to prosecution authorities and courts for law enforcement purposes. We always ask for the correct paperwork before disclosing any information.

Reporting of faulty products and fraud
In case of faulty products or disagreements and we are committed to seek amicable solutions. Is this not possible, we evaluate the situation carefully, when and to whom we report faulty products or fraudulent usage.

Cookies
For information on the cookies we use, please click here.

Product specific data protection information
With some of our products we rely on the expertise of specialised partner companies to ensurethat we provide the best possible products and services experience. In the event you cease to use our products and services, we will delete your personal data within a given timeframe.

Webhosting
Content Delivery Network CDN
Purpose of processing
Using CDNs content data will be stored in Cloudflare data centers.

Categories of personal data
Content data, usage data, traffic data

Legal basis
Contract performance

Involved third parties
Cloudflare, San Francisco, USA

WebSite Creator
Purpose of processing
Editing and publishing of a website

Categories of personal data
Usage data, content data

Legal basis
Contract performance

Involved third parties
cm4all AG, Köln, Germany

Mobile Website Builder
Purpose of processing
Creation, editing and publishing of a website

Categories of personal data
Usage data, content data

Legal basis
Contract performance

Involved third parties
Afilias plc, Dublin, Ireland

Google Sitemaps
Purpose of processing
Using Google Sitemaps Google information is provided to make the content of the webspace accessible via Google Search.

Categories of personal data
Content data

Legal basis
Contract performance

Involved third parties
Google, Mountain View CA, USA

SiteLock911
Purpose of processing
Using SiteLock911, malware is recognised and automatically and deleted.

Categories of personal data
Content data

Legal basis
Contract performance

Retention period
SiteLock stores the webspace of customer for 7 days (the grace period). Deletion of personal data is within 30 days after cleanup.

Involved third parties
SiteLock, Scottsdale, USA

MyWebsite
Current product generation

Website Editor
Purpose of processing
Editing and publishing of website

Categories of personal data
Contact data, content data

Legal basis
Contract performance

Involved third parties
Duda Inc., Tel Aviv, Israel
Amazon Web Services, Inc., Seattle WA, USA

Webspace
Purpose of processing
Hosting of website

Categories of personal data
Contact data, content data

Legal basis
Contract performance

Involved third parties
AWS – Amazon Web Services, Datacenter Frankfurt, Germany
Amazon Web Services, Inc., Seattle WA, United States

Online Business Card
Purpose of processing
Fast publishing of an online business card. Customers have the choice of which information will be displayed on this business card. User data will be sent to Google and Facebook in order to display publicly available information.

Categories of personal data
Contract data, usage data, content data

Legal basis
Contact performance

Involved third parties
Google, Mountain View CA, USA
Facebook, Menlo Park CA, USA

Shop
Purpose of processing
Seamless integration of an online shop in the Website-Editor using personal data to prefill the shop. For example, the email address of the customer is used as the standard email address of the shop.

Categories of personal data
Contact data

Legal basis
Contract performance

Involved third parties
Ecwid, Encinitas CA, USA

Image editor
Purpose of processing
A webservice is used in order to edit images in the Website-Editor, for example to add effects, adjust colours and brightness or to adjust the size of a picture.

Categories of personal data
Content data

Legal basis
Contract performance

Involved third parties
Adobe Systems Inc. (former: Aviary), San José CA, USA

Route description
Purpose of processing
MyWebsite uses address data to show the location of a company on a map. In order to do so the product transfers this data to Mapbox. This takes place automatically when setting up the first project.

Categories of personal data
Contact data

Legal basis
Contract performance

Involved third parties
Mapbox, Washington D.C., USA

Website Translator
Purpose of processing
MyWebsite sends the text content of the website to Google Translate in order to translate the content to one or several other languages. This takes place when the custome sets up multilanguage texts.

Categories of personal data
Content data

Legal basis
Contract performance

Involved third parties
Google, Mountain View CA, USA

Multi Location
Purpose of processing
MyWebsite uses adress data to mark one or several locations of a company on a map. Data is sent to the map company Mapbox. This takes place automatically when adding this widget and with additional locations.

Categories of personal data
Contact data, content data

Legal basis
Contract performance

Involved third parties
Mapbox, Washington D.C., USA

MyWebsite (Vers. 8)
Google Maps
Purpose of processing
MyWebsite 8 transfers address data of the customer to Google in order to prefill address data in the Google maps module or if selected sends another stored address to Google.

Categories of personal data
Contact data, content data

Legal basis
Contract performance

Involved third parties
Google, Mountain View, USA

Google Sitemaps
Purpose of processing
When a domain is connected to a website project, MyWebsite transfers the data to the Google Sitemap-service in order to improve SEO results for the customer.

Categories of personal data
Contact data

Legal basis
Contract performance

Involved third parties
Google, Mountain View, USA

My Data
Purpose of processing
On the publishing of the MyWebsite homepage customer and other user defined data will be added to the website in schema.org format, in order to support search engines and improve SEO results.

Categories of personal data
Contact data, Content data

Legal basis
Contract performance

Involved third parties
Public

MyShop
Please see the entry on the server24 eShop for information on the MyShop integration.

Image editor
Please see the entry on the image editor of the current product generation

Domain & SSL Certificate
Domain
Purpose of processing
Registering, transfer, configuration, maintenance and deletion of the domain name

Categories of personal data
Contact data

Legal basis
Contract performance

Retention period
Differs for the various top level domains (TLDs) depending on the Registrar Accredation Agreement (RAA) of the registry.

Involved third parties
A dedicated overview for regitries and escrow provider is available here.

SSL certificate
Purpose of processing
Registering, transfer, configuration, mainteance and deletion of SSL certificates. Automatic processing in MyWebsite products when connecting the domain with the website project.

Categories of personal data
Contact data

Legal basis
Contract performance

Involved third parties
DigiCert, Lehi UT, USA

Note
In the process of acquisition and maintenance of SSL certificates, server24 is only an intermediary between the customer and the respective issuer of the SSL certificate. server24 has no influence on the issuance of certificates and does not accept any liability that the certificate is assigned to the customer and that it will permanently exist.

server24 eShop, E-Mail & Office & weitere Produkte
server24 eShop
Purpose of processing
Editing, maintenance and operation of online shops oft he customer.

Categories of personal data
Contact data, content data

Legal basis
Contract performance

Retention period
Shop data will be deleted 31 days after contract termination.

Involved third parties
ePages, Hamburg, Germany

server24 Mail
Purpose of processing
Provision of email services, including setting up, configuring and deleting email addresses

Categories of personal data
Contact data, content data, traffic data

Legal basis
Contract performance

Retention period
7 days after deletion/ termination

Involved third parties
Open-Xchange, Nürnberg, Germany

Hosted Exchange
Purpose of processing
Provision of email services, including setting up, configuring and deleting email addresses

Categories of personal data
Contract data, content data, traffic data

Legal basis
Contract performance

Retention period
End of contract lifetime

Microsoft Office 365
Purpose of processing
Usage of Microsoft Office 365, including setting up, configuring and deletion of accounts and users

Categories of personal data
Contract data, content data

Legal basis
Contract performance

Retention period
User data will be stored up to one year after termination of the license.

Involved third parties
Microsoft, Redmond WA, USA
T-Systems International, Frankfurt am Main, Germany

List Local
Purpose of processing
Publishing and synchronisation of company data in online listings to improve rankings in search engines

Categories of personal data
Contact data, content data

Legal basis
Contract performance

Retention period
30 days after termination of the contract

Involved third parties
uberall, San Francisco CA, USA

rankingCoach
Purpose of processing
Optimisation of search rankings of customer websites in Google search engine. Using the pro version and additionally setting up Google ad word campaigns

Categories of personal data
Contact data

Legal basis
Contract performance

Involved third parties
rankingCoach, Köln, Germany

Search Engine Marketing
Purpose of processing
Setting up and managing Google Ad Words campaigns for the customer website.

Categories of personal data
Contact data

Legal basis
Contract performance

Retention period
30 days

Involved third parties
Latitude, Warrington, UK

server24 Online Accounting
Purpose of processing
Online accounting and billing

Categories of personal data
Contact data

Legal basis
Contract performance

Retention period
End of contract lifetime

Involved third parties
SEVENIT, Offenburg, Germany

Hosting Mobile App
Purpose of processing
Mobile access to the server24 Control-Center.

Categories of personal data
Contact data, usage data

Legal basis
Contract performance

Retention period
12 months for usage data

Involved third parties
Adobe Analytics, San José CA, USA
Google, Mountain View CA, USA

server24 WebAnalytics
Purpose of processing
Statistic analysis and technical optimisation of the web offering. Data is process fully anonymised.

Categories of personal data
Contact data, usage data, content data

Legal basis
Contract performance

Server
The following information applies to Cloud Servers, Dedicated Servers, Virtual Server Cloud, vServers & Bare Metal Server products:

With respect to the products above, the customer decides which personal data is processed in which way.

Categories of personal data
Defined by the customer

Retention period
Defined by the customer

Legal basis
Defined by the customer

Involved third parties
Defined by the customer

Transparency is our aim
All data we receive from you during the lifetime of your contract is used primarily to provide the level of service you would expect. All internal analysis performed to improve products and services is conducted in full compliance with existing data protection legislation and is anonymised or pseudonymised.

Your rights
Apart from the right to information, you are also have the right to have your data corrected if it is incorrect, a right to be forgotten andthe right of portability of your data. You have the right to object to the processing of your data.

If you wish to exercise one of these rights, please contact our data protection officer and we get this done for you.

Please contact the following address:

INCUBATEC S.r.l.
V. Scurcia’str. 36
39046 Ortisei BZ
Italy

Supervisory authorities

You have the right to file a complaint with the respective supervisory authority:

https://www.garanteprivacy.it/

Here you can download our current privacy policy in PDF format.
Last update: May 2018

Previous version:

We inform the User or Visitor of our site that the Italian Legislative Decree no. 196/2003 (the so-called “Code on Personal Data Protection, hereinafter also called the “Code”) provides for the protection of physical persons with regard to the processing of personal data. In accordance with the provisions of the aforesaid Code and with the current relevant laws, the processing of data shall be governed by principles of correctness, lawfulness and transparency, respecting the basic rights and freedoms, as well as the dignity of the concerned person, with special reference to the confidentiality, personal identity and right to the protection of personal data. This information is provided pursuant to art. 13 of the Code and it is subject to updates, which shall be published on our site.

The Data Controller

The data controller is incubatec GmbH – Srl (EU-VAT no. IT 02283140214) located in V. Scurciàstr. 36, 39046 Ortisei BZ, ITALY (“server24”).

Persons to whom data may be communicated or who may become acquainted with it in their working roles

Data processing connected with this website services takes place on the premises of server24’s registered offices, those of its subsidiaries, associated companies and data centers, and is performed solely by personnel charged with processing tasks. Personal data provided by users who forward requests for information, navigation data, cookies, or job applications, is utilised for the sole purpose of providing or performing the service requested, and is communicated to third party suppliers and/or collaborators solely where necessary to this end. Such data will be processed by server24 and may be sent to affiliated companies for the purpose of performing the services.

Method of Data Processing

Personal data is processed by automated and non-automated means for the amount of time strictly necessary to accomplish the purposes for which it has been gathered. Specific security measures are observed to prevent loss of data, illegitimate or improper use and unauthorised access.

Rights of the Person Concerned

The person concerned has the rights set out under Article 7 of Legislative Decree No 196 of 2003 (Right of access to personal data and other rights), as outlined below:
1. A data subject shall have the right to obtain confirmation as to whether or not personal data concerning him exist, regardless of their being already recorded, and communication of such data in intelligible form.
2. A data subject shall have the right to be informed
a) of the source of the personal data;
b) of the purposes and methods of the processing;
c) of the logic applied to the processing, if the latter is carried out with the help of electronic means;
d) of the identification data concerning data controller, data processors and the representative designated as per Section 5(2);
e) of the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated representative(s) in the State’s territory, data processor(s) or person(s) in charge of the processing.
3. A data subject shall have the right to obtain
a) updating, rectification or, where interested therein, integration of the data;
b) erasure, anonymization or blocking of data that have been processed unlawfully, including data whose retention is unnecessary for the purposes for which they have been collected or subsequently processed;
c) certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected.
4. A data subject shall have the right to object, in whole or in part,
a) on legitimate grounds, to the processing of personal data concerning him/her, even though they are relevant to the purpose of the collection;
b) to the processing of personal data concerning him/her, where it is carried out for the purpose of sending advertising materials or direct selling or else for the performance of market or commercial communication surveys.

Optional Nature of Supplying Personal Data

We inform our Users that, except for navigation data, data communication is optional; however, a refusal may prevent server24 from providing a punctual and correct management of the contact request or of the service supply application submitted by the concerned party.

Security of Information

All the information collected on the website is saved and stored in secure operating environments with access limited only to authorized personnel. The Website is monitored on a regular basis to check for any violation of security, and to ensure that all the collected information is safe from unauthorized viewing. server24 adopts all the security measures required by the relevant laws and regulations, and all the appropriate measures according to the latest modern standards, to ensure and guarantee the confidentiality of personal data of users, and reduce as much as possible, the dangers posed by unauthorized access, by the cancellation, loss or damage of personal data of users.

Type of Data Which is Processed

Navigation Data

The computer systems and software procedures used to operate this website obtain, during normal usage, certain personal data the transmission of which is implicit in the use of internet communication protocols. The personal data relates to internet traffic which, due to its nature, cannot be automatically associated to identified users, but by being processed or associated with data held by third parties, it may allow the identification of users/visitors of the website (e.g. IP addresses). This type of data is only used for anonymous statistic information relevant to website visits or to check that such website is working correctly. Such personal data is stored by the company server24 only for as long as it is necessary and in any case in accordance with the relevant laws in force.

Data Provided by Users

The voluntary, facultative and explicit sending of data to server24 by the user (for example, on registering with the server24 database or on entering data when filling in the appropriate forms, even where this has the purpose of checking whether access to the services provided is possible, as well as the sending of emails to the email addresses shown on this website), entails the acquisition of the sender’s address and the data supplied by the sender, for the processing of which, the user hereby expressly issues their consent. Should users enter or in any other way process the data of third parties, the user herewith guarantees, on the assumption of any liability arising in this connection, that she/he has in advance provided these third-parties with the information referred to under Article 13 of Legislative Decree No 196 of 2003, and has obtained the third-party’s consent for this processing.

Cookies

General Information, Disabling and Managing Cookies

Cookies are data sent by the website and stored by the Internet browser on the user’s computer or on any other device (e.g., a tablet or a cell phone). The server24 web site and the relevant sub-domains may install technical cookies and third party cookies. In any case, the user may manage or request the general disabling or deletion of the cookies, changing the settings of his/her Internet browser. However, disabling might slow down or prevent access to certain sections of the site. Settings to manage or disable cookies may vary according to the Internet browser used; therefore, to get more information on how to perform such operations, we recommend Users to consult the manual of the device used or the “Help” function of the Internet browser. Find here below the links that explain how to manage or disable cookies for most popular Internet browsers:

– Internet Explorer: http://windows.microsoft.com/it-IT/internet-explorer/delete-manage-cookies
– Google Chrome: https://support.google.com/chrome/answer/95647
– Mozilla Firefox: http://support.mozilla.org/it/kb/Gestione%20dei%20cookie
– Opera: http://help.opera.com/Windows/10.00/it/cookies.html
– Safari: https://support.apple.com/kb/PH19255

Technical Cookies

The use of technical cookies, which are cookies necessary to send data through the electronic communication network or cookies that the supplier needs to provide the service requested by the customer, allow safe and efficient use of our site. Session cookies may be installed in order to enable initial and continued access to the portal reserved area as an authorized user. Technical cookies are essential for a correct operation of our internet site, and are used to enable users to navigate normally and use the advanced services offered by our website. The technical cookies that are used can be divided into session cookies, which are stored only for the duration of the navigation and until the browser is closed; and permanent cookies, which are saved in the memory of the user’s device until their expiry or until they are deleted by the user. Our site uses the following technical cookies: • Navigation or session technical cookies, used to manage normal web navigation and the user’s authentication; • Functional technical cookies, used to save customizations selected by the user, such as the language; • Analytics technical cookies, used to learn the way users use our website, so as to evaluate and improve its operation.

Third Party Cookies

Third party cookies may be installed: these are analytics and profiling cookies of Google Analytics, Google Doubleclick, Piwik and Facebook. They are sent by the internet sites of the aforesaid third parties external to our site. Third party analytics cookies are used to collect information on the users’ behavior when they visit the site. The collection is performed in an anonymous way in order to improve the use of the site. Third party profiling cookies are used to create users’ profiles in order to propose advertising messages consistent with the choices made by users. The use of these cookies is governed by the rules set out by said third parties; therefore, we invite users to read the information on privacy and the instructions to manage or disable cookies published in the following web pages:

For Google Analytics cookies:
– privacy policy: https://www.google.com/intl/it/policies/privacy/
– instructions to manage or disable cookies: https://support.google.com/accounts/answer/61416?hl=it

For Google Doubleclick cookies:
– privacy policy: https://www.google.com/intl/it/policies/privacy/
– instructions to manage or disable cookies: https://www.google.com/settings/ads/plugin

For Facebook cookies:
– privacy policy: https://www.facebook.com/privacy/explanation
– instructions to manage or disable cookies: https://www.facebook.com/help/cookies/

Information

Information and requests about privacy may be addressed to server24 via:
– e-mail to: privacy@server24.eu
– standard surface mail to: incubatec GmbH – Srl, V. Scurciàstr. 36, 39046 Ortisei BZ, ITALY.