Privacy policy
1. Controller
Wigandt Technology, owner Johannes Wigandt, St. Georgenstr. 17, 56751 Polch, Germany. Email: info@domainwarn.com, phone: +49 170 9052570. No data protection officer has been appointed because the legal requirements are not met.
2. Overview
DomainWarn consists of the website domainwarn.com (information and free checking tools) and the application app.domainwarn.com (monitoring service for registered organisations). This policy describes which personal data we process, for what purpose, on which legal basis and for how long. We use no tracking, advertising or analytics services.
3. Hosting
Website and application are hosted on servers of IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, in data centres located in Germany. IONOS processes data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Legal basis for using a hosting provider is Art. 6(1)(f) GDPR (legitimate interest in secure and efficient operation) and Art. 6(1)(b) GDPR towards registered users.
4. Server log files
On every request the IP address, date and time, requested address, HTTP status, transferred data volume, referrer and user agent are stored in log files. The data serve to ensure operation, analyse errors and defend against attacks and are deleted after 14 days. Legal basis: Art. 6(1)(f) GDPR.
5. Free tools
When you use the tools (SPF, DMARC, DNS, MX, SSL, header and redirect checker) we process the entered domain or URL to run the check; publicly available information of the entered domain (DNS records, certificates, HTTP responses) is queried. We store the entered domain or URL and a hash of the IP address for 30 days to limit abuse and evaluate the use of the tools; we cannot identify a person from the hash. Results are cached for five minutes. Legal basis: Art. 6(1)(f) GDPR (provision of the service, protection against abuse).
Above an elevated number of requests we use Cloudflare Turnstile to detect automated access. Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (in the EU: Cloudflare Germany GmbH, Rosental 7, 80331 Munich) then processes technical characteristics of the browser and the IP address. Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. Legal basis: Art. 6(1)(f) GDPR. Turnstile is only loaded when required and sets no advertising cookies.
6. Registration and use of the application
On registration we process name, email address, password (hash only), language, time zone, IP address and time of registration, and the organisation name. During use we process the clients, domains, monitors, notification channels and settings you create, the check results for the entered domains, and a security log (sign-ins, invitations, changes to roles and settings, with IP address and user agent). Legal basis: Art. 6(1)(b) GDPR (performance of contract) and, for the security log, Art. 6(1)(f) GDPR.
Optionally you can set up two-factor authentication (TOTP) and passkeys. We then store the encrypted TOTP secret, encrypted recovery codes or the public key of the passkey. Private keys never leave your device.
Detailed check results are stored for 7 to 90 days depending on the plan and afterwards as daily and hourly aggregates. After deletion of an organisation all associated data are permanently deleted after a period of 30 days; the security log is retained for up to 12 months for accountability.
7. Monitoring of entered domains and processing on behalf
The service regularly retrieves publicly available information of the entered domains: DNS records, mail server entries, SPF and DMARC records, TLS certificates, HTTP responses of the home page and registration data (RDAP). Where such data are personal (e.g. names in certificates or registration data), we process them as a processor for the customer who entered the domain. Agencies monitoring their clients' domains conclude a data processing agreement pursuant to Art. 28 GDPR with us, available on request at info@domainwarn.com.
Our monitoring agent is identifiable by the user agent DomainWarn-Monitor. See the page about the monitoring agent for details.
8. Notifications
At your request we send notifications by email or to services you configure (webhook, Slack, Discord, Telegram). The respective provider receives the content of the notification (domain name, type of event, time). The privacy policies of those providers apply to their services. Legal basis: Art. 6(1)(b) GDPR.
Transactional emails (registration, password, notifications, reports) are sent via an email service provider with servers in the EU under a data processing agreement. We name the current provider on request.
9. Client reports
If you enable the monthly report for a client, we send the report as PDF to the client contact address you provided and make it available via a signed link valid for 60 days. You are responsible for ensuring that the contact person agrees to receive it.
10. Payment processing
Paid plans are processed via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe processes payment data (payment method, billing address, VAT ID, payment history) as an independent controller for payment processing and as a processor for invoicing and tax calculation. We do not store complete payment data ourselves, only the Stripe customer ID, type and last four digits of the payment method and the subscription status. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (tax retention obligations, 10 years under § 147 AO). Stripe privacy policy: stripe.com/privacy.
11. Cookies and local storage
The website domainwarn.com sets no cookies. The application app.domainwarn.com uses a session cookie and a CSRF cookie, both strictly necessary for sign-in and protection against attacks, as well as the browser's local storage for display preferences (last selected organisation). Legal basis: § 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR. No consent is required.
12. Contact
If you contact us by email we process your details to handle the request and follow-up questions. The data are deleted once the request is settled and no statutory retention obligations apply. Legal basis: Art. 6(1)(b) or (f) GDPR.
13. Recipients and third-country transfers
Recipients are the processors named above (IONOS, email service provider, Stripe, Cloudflare) and the notification services you choose yourself. Transfers to third countries take place only for Cloudflare Turnstile (USA) and the services you choose; for Cloudflare based on the adequacy decision for the EU-US Data Privacy Framework and standard contractual clauses.
14. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) GDPR (Art. 21). Contact info@domainwarn.com. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz, Germany.
15. Security
All connections are TLS-encrypted. Passwords are hashed with bcrypt; secrets for two-factor authentication and channels are stored encrypted. Access to production systems is restricted to the provider and logged. Backups are stored encrypted in data centres in Germany.
16. Changes
We update this policy when the service or the legal situation changes. The version published here applies.
Last updated: 10 September 2026