Privacy policy
Detailed information on the processing of personal data
1. Controller
The controller is Marc Bollue – CenterView, Röntgenstraße 8, 59457 Werl, Germany. Email: info@centerview.info.
No data protection officer is currently designated. Privacy requests may be sent directly to the above email address.
2. Scope and principles
This policy covers the public website, registration, customer and reseller portals, and the provision of domains, DNS, SSL, hosting, email, website and support services. Personal data is processed only for specified purposes and on the applicable legal basis, and is limited to what is necessary for operation, contract performance, security and legal obligations. Service providers are identified only where they are actually used by CenterView or shown in the relevant order process.
3. Data categories
- identity, company, address and contact data;
- account, authentication, role and language data;
- contract, order, domain, hosting, mailbox, invoice and payment data;
- support content and business communications;
- IP addresses, timestamps, browser/device data, session, error and security logs;
- customer content stored or transmitted through hosting and email services.
4. Website access and logs
Connection and log data is processed to deliver the website, maintain stability, investigate errors and defend against attacks. The legal basis is legitimate interest in secure operation. Logs are deleted or anonymised when no longer required; relevant records may be retained for longer in the event of security incidents, abuse or legal obligations.
5. Cookies and language
CenterView uses technically essential cookies or comparable storage to manage sessions, login, CSRF protection, shopping or order state, the selected language and the cookie choice. These operations are required for the digital service expressly requested by the user.
On the first public visit, users can choose “Accept all”, “Essential only” or “Settings”. Optional categories are not preselected. The decision is stored for no more than six months in the essential first-party cookie cv_cookie_consent. It contains the selected categories, the consent version and the time of the choice, but no name or email address.
The choice can be changed or withdrawn for the future at any time through “Cookie settings”. External media and optional analytics scripts are loaded only after consent. The minimal server-side basic statistics do not use an analytics cookie and store only day, country and page path as aggregates. No IP address, browser details or persistent visitor identifier is stored for these basic statistics. Detailed visitor analytics with referrer, device/browser, a pseudonymous visitor hash and the IP address for a limited period are stored for real visitors only after consent to the analytics category. Without that consent, no external geo service is called for country detection; only available Cloudflare/proxy country information, local GeoIP or existing cache hits are used.
6. Accounts and registration
Registration data is used to create and secure the account, confirm the email address, associate reserved orders and perform contracts. Passwords are stored as cryptographic verification values, not in plain text. Login attempts and security-relevant changes may be logged.
7. Orders, contracts and accounting
Contact, product, term, price, tax, status, invoice and payment data is processed for pre-contractual steps and contract performance. Tax and commercial records are retained for the statutory periods, commonly six, eight or ten years depending on the document.
8. Domains and registries
Domain checks, registrations, transfers, renewals, holder changes and cancellations require the necessary domain and holder data to be transmitted to the relevant registrar, registry and technical providers. CenterView may use Netim or another registrar shown in the order process or customer portal. Registrars and registries may act as independent controllers and international registries may require transfers outside the EEA under applicable safeguards.
9. Hosting and email
CenterView processes technical contract and usage data for webspace, databases, DNS, certificates and mailboxes. Business-customer content is generally processed on that customer's behalf and is covered by the data processing agreement. Access to customer content is limited to support, maintenance, security, recovery, abuse prevention and legal obligations.
10. Infrastructure and processors
CenterView operates parts of the infrastructure itself and uses server or data-centre services from IONOS SE for other components. Processors are selected, contractually bound and used only to the extent required. Software or hardware vendors do not automatically receive customer content merely because their products are used.
11. Certificates, payments and wallet
Certificate issuance may require domain and validation data to be sent to a certification authority; certificate transparency logs may be public. Bank transfers involve the participating banks. PayPal transactions, particularly reseller wallet top-ups, require payment and confirmation data to be sent to PayPal, which may process payment and risk data as an independent controller.
For optional invoice reconciliation, authorised administrators or resellers can upload bank statements or transaction exports that they obtained themselves in CAMT/XML or CSV format. CenterView processes booking date, amount, currency, counterparty, masked account information and remittance information in order to match incoming payments with invoices. The uploaded original file is not retained as a bank-statement file after processing. Bank PINs, TANs, SecureGo credentials or other online-banking credentials are not required and are not stored.
12. Resellers, contact and support
Reseller applications involve business, contact and verification data. Once activated, customer, pricing, wallet, order, invoice and support data is processed for the reseller contract. Contact and ticket data is used to respond, perform contracts and document relevant communications.
Electronic cancellation and withdrawal notices are processed with the name, contact address, contract reference, content of the declaration, time of receipt and technical evidence data. The purposes are receipt, unambiguous allocation, immediate confirmation and legally reliable handling. The legal bases are Article 6(1)(b) and (c) GDPR and Article 6(1)(f) GDPR for evidence of receipt and handling.
13. Security, abuse and authorities
Logs, IP addresses and account events may be processed to prevent spam, phishing, malware, unauthorised access, fraud and attacks. Data may be disclosed to courts, law-enforcement, tax or supervisory authorities where legally required or ordered.
14. Backups
Protected backups are created for operational recovery. Under the current backup concept, backup sets may be retained for up to twelve months and then overwritten or deleted on a rolling basis. Backups are not a permanent archive and individual file or email restoration is only owed if included in the booked service.
15. Recipients and international transfers
Recipients may include infrastructure providers, registrars and registries, certification authorities, payment providers, banks, communication providers, tax or legal advisers and authorities. Transfers outside the EEA occur only where necessary and on an adequacy decision, appropriate safeguards such as standard contractual clauses, or a statutory exception.
16. Legal bases and retention
Processing is based on contract performance, legal obligations, legitimate interests in secure operation and claims management, or consent where expressly requested. Data is erased or restricted when the purpose ends unless retention duties, claims, security incidents or evidence requirements continue to apply.
17. Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn for the future. Requests should be sent to info@centerview.info; appropriate identity verification may be requested.
18. Supervisory authority
You may complain to a data protection authority. The authority particularly competent for CenterView is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
19. Automated decisions and updates
CenterView does not make solely automated decisions producing legal or similarly significant effects. Automated security or availability checks may trigger manual review. This policy is updated when services, recipients, technology or law change.