Privacy Policy
1. Privacy at a glance
sitedomains.net is a reference site for domain names. We show which domains have been deleted, which are about to be released and which are available. To do so we mainly process data about domains – not about their registrants.
- If you only read the site, you leave nothing behind except the technically necessary server log files.
- No user account is required.
- We only store an e-mail address if you use the watchlist with notifications – and only after explicit confirmation.
- Advertising is loaded only after consent.
- We do not process registrant data from WHOIS or RDAP.
2. Controller
The controller within the meaning of Article 4(7) GDPR is:
Tilo Kaschube
Grundstraße 137
01326 Dresden
Deutschland
Germany
E-mail: info@sitedomain.de
No data protection officer has been appointed. In our assessment the conditions of Article 37 GDPR and Section 38 BDSG are not met, because as a rule fewer than twenty people are permanently engaged in the automated processing of personal data and none of the special categories applies.
3. No registrant data
This is the most important point of this policy. Regarding domains, we process exclusively:
- the domain name,
- the registration status and EPP status codes,
- dates and deadlines (deletion date, end of the redemption period, release date),
- name servers and technical delegation data,
- our own technical metrics such as length, word components and score.
We do not store or display names, addresses, e-mail addresses, telephone numbers or any other contact details of domain holders, administrative or technical contacts. Where registries still return such data in RDAP responses, it is discarded during import and never enters our database.
In individual cases a domain name may nevertheless relate to a person, for example firstname-lastname.de. If you believe that a domain name listed here relates to you, you can request removal of the entry at info@sitedomain.de. Please state the full domain name and, if possible, a brief explanation of the personal reference. We will review the case and remove the entry unless overriding legitimate grounds prevent this; your rights under Articles 17 and 21 GDPR apply irrespective of this.
4. Hosting and server log files
This website is hosted by Hostinger (Hostinger International Ltd., Cyprus). The provider processes data on our behalf; the processing is governed by a data processing agreement pursuant to Article 28 GDPR.
When a page is called up, your browser transmits technically necessary data which the server stores in log files:
- IP address of the requesting device,
- date and time of the request,
- address requested and volume of data transferred,
- message indicating whether the request was successful,
- browser type and operating system as well as the previously visited page, where transmitted by the browser.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in technically faultless operation, the security of our systems and the prevention of attacks and abusive bulk queries. Log files are deleted after 14 days at the latest, unless they are required to investigate a specific security incident. This data is not merged with other data sources.
5. Cookies and storage on your device
We use as few cookies as possible.
- Strictly necessary cookies – for example for a session when logging into the back end, or for the watchlist. They do not require consent under Section 25(2) no. 2 TDDDG because they are strictly necessary to provide the service expressly requested by the user. The legal basis for the subsequent processing is Article 6(1)(f) GDPR.
- Consent cookie – stores your decision about advertising so that it is not requested again on every visit. It contains only the value of that decision, not an identifier for cross-site recognition.
- Advertising cookies – are only set once consent has been given. Without consent, a neutral notice is shown in place of an advertisement.
Storing information on and accessing information stored on your device is governed by Section 25 TDDDG (the German Telecommunications Digital Services Data Protection Act, called TTDSG until May 2024). Consent may be withdrawn at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR). Cookies can also be deleted and blocked in your browser.
6. Advertising
To finance the service we display advertisements from Google AdSense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
Advertisements are loaded only after prior consent. As long as no consent has been given, the advertising network’s script is not executed and no advertising cookies are set. The legal basis for storing and reading information on your device is Section 25(1) TDDDG; the legal basis for the subsequent processing of personal data is Article 6(1)(a) GDPR.
With advertising enabled, Google may also transfer data to the United States. For this transfer Google relies on the European Commission’s adequacy decision on the EU-US Data Privacy Framework of 10 July 2023, supplemented by standard contractual clauses pursuant to Article 46(2)(c) GDPR. Details of Google’s processing are set out in its own privacy policy.
Consent can be withdrawn at any time via the settings on this site.
7. Domain status queries (RDAP)
To determine the status of a domain we query the Registration Data Access Protocol (RDAP) of the responsible registry – worldwide, not only DENIC. Only the domain name is transmitted. No visitor data is transmitted to registries: neither IP address nor browser identification nor the fact that someone searched for a particular domain. Queries run server-side and, as a rule, independently of any page view, as part of the scheduled refresh of our data.
From the response we take status, deadlines and name servers. Any registrant information is discarded. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in offering an accurate and up-to-date directory.
8. Zone files (ICANN CZDS)
For some generic top-level domains we obtain zone files through ICANN’s Centralized Zone Data Service (CZDS). Zone files contain delegated domain names and their name servers – no personal data. We analyse them to detect changes in the domain inventory. The legal basis for processing the access credentials assigned to us is Article 6(1)(b) and (f) GDPR; those credentials concern us as the applicant, not the users of this site.
9. Data transfer from sitedomain.de
Part of the inventory is taken over from our sister site sitedomain.de through a dedicated interface. Only domain names and technical metrics (status, deadlines, TLD, score) are transferred. No user data, watchlists or e-mail addresses are exchanged through this interface. The interface is protected by a token. The legal basis is Article 6(1)(f) GDPR.
10. Watchlist and e-mail notifications
If you add a domain to the watchlist and wish to be notified, you provide an e-mail address. We store:
- the e-mail address,
- the domain names being watched,
- the chosen language (for the language of the notification),
- the time of sign-up and of confirmation,
- a random confirmation key.
Sign-up uses the double opt-in procedure: after you submit the form we send an e-mail containing a confirmation link. The entry only becomes active when that link is clicked. Without confirmation the entry is deleted after 30 days at the latest. The procedure serves to demonstrate consent under Articles 5(2) and 7(1) GDPR and prevents third-party addresses from being entered.
The legal basis is consent pursuant to Article 6(1)(a) GDPR. Consent may be withdrawn at any time – via the unsubscribe link in every notification or informally to info@sitedomain.de. After withdrawal the data is deleted. Withdrawal does not affect the lawfulness of processing carried out beforehand (Article 7(3) GDPR).
Notifications are sent using our hosting provider’s mail service.
11. Redirects to registrars and click counting
Links to registrars run through our own addresses of the form sitedomains.net/go/…. When such an address is called, we count the click and redirect immediately.
The only thing stored is a daily hash of the IP address: the IP address is combined with a secret value and the current date, passed through a one-way function (SHA-256) and stored in truncated form only. The IP address itself is not stored in clear text. Because the hash changes every day, recognition beyond that day is impossible. The value serves solely to distinguish repeated clicks from the same origin on a single day. We do not set a cookie for this; Section 25 TDDDG does not apply because nothing is accessed on or stored on your device.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in verifying affiliate settlements and detecting click fraud. The data is deleted after 90 days.
After the redirect, the privacy policy of the respective registrar applies. Their own cookies apply there, in particular to attribute the referral. We have no influence over that processing. Details are set out in the advertising and affiliate disclosure.
12. Application programming interface (REST API)
This site offers a public API. To prevent overload and abusive bulk queries we limit the number of requests per origin. Here too we use the daily IP hash described above, not the IP address in clear text. We store the hash and a counter, both short-lived. The legal basis is Article 6(1)(f) GDPR in conjunction with Article 32 GDPR (security of processing).
13. Language selection
The interface language follows from the language code in the address, for example /de/ or /en/. On a first visit we evaluate the Accept-Language header sent by your browser and redirect to the matching language version. This evaluation happens at request time; we do not build a profile from it and do not store the language preference in a way that identifies a person. The legal basis is Article 6(1)(f) GDPR.
14. Contacting us
If you write to us by e-mail, we process your details in order to handle the enquiry and any follow-up questions. The legal basis is Article 6(1)(b) GDPR where the enquiry relates to the performance or initiation of a contract, otherwise Article 6(1)(f) GDPR based on our legitimate interest in responding. Messages are deleted once they are no longer required; statutory retention obligations remain unaffected.
15. Recipients
We only pass on personal data where this is necessary for operating the site or required by law. Recipients are:
- the hosting provider (processor under Article 28 GDPR),
- the advertising network – only where consent has been given,
- registrars, when an advertising link is clicked and the redirect is carried out.
We do not sell data. Registries receive no user data from us.
16. Retention periods
- Server log files: 14 days at most.
- Click data (daily IP hash): 90 days.
- Rate-limit counters: minutes to hours.
- Watchlist: until withdrawal or deletion of the entry; unconfirmed sign-ups 30 days at most.
- E-mail correspondence: until the matter is concluded; longer only where a statutory retention obligation applies.
17. Your rights
You have the following rights against us:
- access to the data stored about you (Article 15 GDPR),
- rectification of inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- objection to processing based on legitimate interests (Article 21 GDPR),
- withdrawal of consent with effect for the future (Article 7(3) GDPR).
Notice regarding the right to object under Article 21 GDPR: where we process data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An informal message to info@sitedomain.de is sufficient to exercise these rights.
18. Right to lodge a complaint with a supervisory authority
Without prejudice to other remedies, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us is:
Die Sächsische Datenschutz- und Transparenzbeauftragte
Postfach 11 01 32
01330 Dresden, Germany
Visiting address: Maternistraße 17, 01067 Dresden
Phone: +49 351 85471-101
E-mail: post@sdtb.sachsen.de
Web: www.datenschutz.sachsen.de
19. No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Article 22 GDPR. The score we display relates to the domain name, not to a person.
20. Is providing data required?
Using the site does not require you to provide personal data. An e-mail address is only required for watchlist notifications; without it, that function cannot be provided. There is no statutory or contractual obligation to provide data.
21. Changes to this policy
We update this policy when our processing or the legal situation changes. The version published on this page applies.
Last updated: 2026-08-15