Last revised: 20.07.2026 — this version replaces all previous versions.
This Privacy Policy explains which personal data Cotoax ("we", "us") processes when you visit our websites, create an account, or use our hosting services, for which purposes, on which legal bases, how long we keep it, and which rights you have under the General Data Protection Regulation (GDPR).
1.1 The controller within the meaning of Art. 4(7) GDPR is Cotoax, reachable at support@cotoax.com.
1.2 For all privacy-related requests, including the exercise of your rights under Article 10, contact privacy@cotoax.com or open a support ticket in the client area at store.cotoax.com.
2.1 Account data — name, email address, username, password (stored only as a salted hash), and address data where required for invoicing.
2.2 Billing data — invoices, payment status, the payment method you selected, and transaction references. Full payment credentials (e.g. card numbers) are processed by our payment providers, not stored by us.
2.3 Usage and log data — IP addresses, timestamps, requested resources, browser and operating system information from server logs, and per-service metrics such as bandwidth and resource consumption.
2.4 Support and communication data — the content of support tickets, emails, and messages you send us, including via our official Discord server.
2.5 Service content data — data you store or process on your server. We do not access this data except as described in Article 6.
3.1 Contract performance (Art. 6(1)(b) GDPR): account management, provisioning and operating your services, processing payments, invoicing, and customer support.
3.2 Legal obligations (Art. 6(1)(c) GDPR): retention of invoices and accounting records under commercial and tax law, and responses to lawful requests by competent authorities.
3.3 Legitimate interests (Art. 6(1)(f) GDPR): network and information security (including DDoS mitigation and abuse prevention), fraud prevention on orders, enforcement of our Terms of Service, and defence of legal claims. You may object to processing based on legitimate interests as described in Article 10.
3.4 Consent (Art. 6(1)(a) GDPR): marketing communications and non-essential cookies, where requested. Consent can be withdrawn at any time with effect for the future.
4.1 When you visit our websites, our web servers and our content delivery and security provider (Cloudflare, Inc.) process connection data (IP address, timestamp, requested URL, user agent) to deliver the site and to detect and block malicious traffic. Legal basis: Art. 6(1)(f) GDPR. Web server logs are automatically deleted or anonymized after no more than 30 days, unless a specific incident requires longer retention.
4.2 We use only strictly necessary cookies: a security cookie assigned to each visitor as part of our DDoS protection, which is required to access the website (Art. 6(1)(f) GDPR), and session and cart cookies in the client area (Art. 6(1)(b) GDPR). These cookies do not track you across other websites and are not used for marketing. Should we introduce cookies that require consent in the future, we will ask for it before setting them.
5.1 When you place an order, we process your account and billing data to conclude and perform the contract, including automated checks for indications of fraudulent orders (Art. 6(1)(b) and (f) GDPR).
5.2 Payments are processed by external payment service providers. Your payment credentials are transmitted directly to the respective provider; we receive only a confirmation of payment and a transaction reference. The provider you select is the controller for the processing of your payment credentials; their own privacy policies apply.
6.1 Data you store on your server remains under your control. We access it only where strictly necessary to operate the infrastructure, where you ask us to (e.g. for support), or where we are legally obliged to.
6.2 For network security, we automatically process traffic metadata (source and destination IP addresses, ports, packet rates) to detect and mitigate DDoS attacks and abuse. Legal basis: Art. 6(1)(f) GDPR and our obligation to protect our infrastructure and customers.
6.3 If you process personal data of third parties on your server, you are the controller of that data and we act as your processor. A data processing agreement pursuant to Art. 28 GDPR is available on request.
7.1 When you contact us by email, support ticket, or via our official Discord server, we process your contact details and the content of the communication to handle your request (Art. 6(1)(b) GDPR).
7.2 If you contact us via Discord, Discord Inc. processes your data under its own privacy policy; use of Discord is optional, and all support requests can also be made by email or support ticket.
8.1 We share personal data only with:
8.2 We do not sell personal data and do not share it with third parties for their own marketing purposes.
8.3 Where a recipient is located outside the European Economic Area (e.g. Cloudflare, Inc. and Discord Inc. in the United States), we ensure an adequate level of protection through an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework, where the recipient is certified) or through the EU Standard Contractual Clauses, supplemented by additional safeguards where necessary.
9.1 Account data is retained for the duration of the contractual relationship and deleted or anonymized no later than 12 months after the last service has been terminated, unless longer retention is required by law or for the defence of legal claims.
9.2 Invoices and accounting records are retained for the statutory commercial and tax retention periods (up to 10 years).
9.3 Server and security logs are retained for a maximum of 30 days, unless a specific security incident or legal proceeding requires longer retention of specific records.
9.4 Data stored on your services is deleted upon termination of the service in accordance with our Terms of Service.
10.1 Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent at any time and to lodge a complaint with a data protection supervisory authority (Art. 15–21, 7(3), and 77 GDPR).
10.2 A detailed explanation of each right and of the request procedure, including identity verification and response times, is available in our dedicated GDPR notice. To exercise your rights, contact privacy@cotoax.com.
11.1 We apply technical and organizational measures appropriate to the risk (Art. 32 GDPR), including transport encryption (TLS) for our websites and client area, salted password hashing, role-based access controls, network segregation, and logging of administrative access.
11.2 No method of transmission or storage is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required by Art. 34 GDPR, you.
12.1 We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). Automated fraud screening of orders may flag an order for manual review; the final decision is made by a human.
13.1 We update this Privacy Policy when our processing activities, service providers, or legal requirements change. The current version is always available on this page; the revision date at the top indicates the latest update. For material changes affecting active customers, we will additionally inform you by email or via the client area.
14.1 Questions about this Privacy Policy: privacy@cotoax.com or support@cotoax.com.