mildnode

Privacy Policy (Datenschutzerklärung)

Last updated: 11 June 2026

1. Controller

The controller responsible for the processing of your personal data is David Miler, c/o IP-Management #6108, Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany. You can contact us at contact@mildnode.com.

2. What data we process

To provide our services we process, in particular:

  • Order and registrant data — your name, organization (if any), email address, postal address, phone number, the domain and configuration you choose, and (for domain registration) the registrant contact required by the registry;
  • Payment data — payment confirmation and transaction identifiers from our payment provider (we never receive or store your full card details);
  • Consent records — proof of the terms you accepted at checkout, including the version, a timestamp, and your IP address and browser user agent, kept as evidence of consent;
  • Service data — for managed email, your mailbox addresses and the emails sent and received; for monitoring, the URL and alert address you provide;
  • Technical and log data — data automatically generated when you use the site (such as IP address, request data, and security logs) needed to operate and secure the service.

3. Purposes and legal bases

  • Performing the contract with you and taking pre-contractual steps (Art. 6(1)(b) GDPR) — setting up and operating the services you order;
  • Legal obligations (Art. 6(1)(c) GDPR) — e.g. retention of commercial and tax records, and acting on lawful notices;
  • Our legitimate interests (Art. 6(1)(f) GDPR) — operating, securing, and improving the platform, preventing abuse and fraud, and keeping evidence of consent and of contract performance.
  • Your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG) — where we set non-essential cookies for web analytics and advertising measurement (see section 10). You can withdraw this at any time with effect for the future.

4. Recipients and processors (subprocessors)

We use carefully selected service providers who process data on our behalf under data-processing agreements:

  • Supabase — database, authentication and file storage.
  • Cloudflare — hosting, DNS and network security.
  • Stripe — payment processing.
  • Resend — transactional (outgoing) email delivery.
  • Zoho (Zoho Corporation) — hosting of our inbound contact mailbox, so messages you send us at our contact address are processed there.
  • Migadu (Migadu Email, Switzerland; mail servers in the EU) — managed email hosting for the mailboxes we operate on your domain (your domain, mailbox addresses and the emails sent/received).
  • Namecheap (USA) — domain registrar used to register the domain in your name (registrant contact details). Note that registrant data may be published in the WHOIS/RDAP directory subject to the applicable privacy options.
  • Google (Google Ireland Ltd., Ireland) — only with your consent, web analytics and advertising measurement (Google Analytics and Google Ads); see section 10.

Business customers: where you use the managed email to process personal data of your own contacts, we act as your processor for that mailbox content. A data-processing agreement (Auftragsverarbeitung, Art. 28 GDPR) is available — see our Data Processing Agreement.

5. International transfers

Some providers are located in the USA or process data there. Where data is transferred to a country without an adequacy decision, the transfer is safeguarded by the EU Standard Contractual Clauses and additional measures where appropriate. You can request a copy of the relevant safeguards from us.

6. Confidentiality of your email and our access

You set your own mailbox password via a secure, single-use invitation link, so we never see, store, or hold your password and do not sign in to your mailbox in normal operation. That said, as the operator of the hosting service we — and our email-hosting subprocessor (Migadu) and the providers upstream of it — necessarily retain technical administrative access to the mail infrastructure on which your mailboxes run, and could in principle reset a password or access a mailbox. We treat the content of your mailboxes as confidential and do not read, use, or disclose it except where strictly necessary to provide, secure, repair, or migrate the service, to prevent or investigate abuse, or where we are required to by law.

Please be aware that standard email is not end-to-end encrypted. If you need the contents of specific messages to remain secret even from the host, you should apply end-to-end encryption yourself (for example PGP or S/MIME) — this is the only way any hosted email service can be made inaccessible to the operator. The secure page with your details is additionally protected by a passphrase that you choose and that we do not store.

7. Government and other lawful access requests

We, our subprocessors (including Migadu, based in Switzerland with mail servers in the EU), and the providers upstream of them may be legally compelled by courts or competent authorities to preserve or disclose data, including in jurisdictions outside the EU/EEA. Depending on the legal instrument, the recipient of such a request may be prohibited by law from notifying the affected customer. We disclose only what we are legally obliged to disclose and, where we are lawfully permitted to do so, we will inform you.

8. Retention

We keep personal data only as long as necessary for the purposes above or as required by statutory retention periods (in particular commercial and tax-law periods of generally 6 to 10 years for invoices and contract records). Pre-payment configurator drafts are purged on a short cycle. Service data is deleted following termination, subject to any export you request and statutory obligations.

9. Your rights

Under the GDPR you have the right to:

  • access your personal data (Art. 15);
  • rectification (Art. 16) and erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interests (Art. 21); and
  • withdraw any consent at any time with effect for the future, without affecting the lawfulness of prior processing.

To exercise these rights, contact us at contact@mildnode.com. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit.

10. Cookies, web analytics and advertising

Cookies and similar technologies that are strictly necessary to operate the site and the secure checkout are always active (Art. 6(1)(f) GDPR, § 25(2) TDDDG).

In addition, only with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG) we use Google Analytics and Google Ads (provided by Google Ireland Ltd.) to measure how the site is used and the performance of our advertising. These set cookies and transmit data — including online identifiers and a truncated/processed IP address — to Google; data may be transferred to the USA on the basis of the EU Standard Contractual Clauses.

No analytics or advertising cookies are set until you accept them in our cookie banner. We use Google Consent Mode, which keeps all analytics and advertising storage set to denied by default. You can change or withdraw your choice at any time — as easily as you gave it — via the “Cookie settings” link in the site footer, with effect for the future; withdrawal does not affect processing carried out beforehand. Google also offers a browser opt-out add-on at tools.google.com/dlpage/gaoptout.

11. Automated decision-making and security

We do not use automated decision-making with legal or similarly significant effects on you. We protect your data with appropriate technical and organizational measures; credentials are encrypted at rest and delivered through one-time secure links that can additionally be protected with a passphrase you choose and that we do not store.