Privacy Policy

Information about our data collection practices and your rights

Last updated: August 13, 2026


1) Introduction and Controller Contact Information

1.1 We are pleased that you visit our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website, customer panel, and related services. Personal data is all data with which you can be personally identified.

1.2 The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is Liam Kremer trading as Trivox, Auf Staffels 44, 53619 Rheinbreitbach, Germany, Tel.: +49 170 9071597, Email: contact@trivox.sh. The controller for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

1.3 This Privacy Policy covers processing for which Trivox acts as controller (in particular website usage, customer accounts, billing, support, and marketing preferences). Where Trivox hosts customer content on infrastructure services (VPS, dedicated servers, game servers, web hosting, colocation, and similar), Trivox typically acts as processor under Art. 28 GDPR. That processing is governed by the Data Processing Agreement in Section 19 of our Terms and Conditions (AVV).

2) Data Collection When Visiting Our Website

2.1 During purely informational use of our website, i.e., if you do not register or otherwise provide us with information, we only collect the data that your browser transmits to the site server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:

• Our visited website
• Date and time of access
• Amount of data sent in bytes
• Source/reference from which you came to the page
• Browser used
• Operating system used
• IP address used (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser line.

3) Hosting, CDN & Infrastructure Location

3.1 Cloudflare

We use Cloudflare as CDN, DNS, and security/proxy layer for our public websites and related services (including trivox.sh and v2.trivox.sh). Provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA / Cloudflare Germany GmbH where applicable.

This service helps deliver content securely and quickly and may process IP addresses and related technical request metadata. The processing takes place to protect our legitimate interest in improving the stability, security, and functionality of our online services according to Art. 6(1)(f) GDPR. We have concluded a data processing agreement with the provider. For transfers to the USA, Cloudflare participates in the EU-US Data Privacy Framework where applicable.

3.2 jsDelivr (limited use)

On certain product pages we may load map/topology assets from the jsDelivr CDN operated by Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, United Kingdom. This may involve transmission of your IP address to the CDN. Processing is based on Art. 6(1)(f) GDPR (legitimate interest in a performant presentation). An adequate level of protection for the United Kingdom is supported by the European Commission's adequacy decision.

3.3 Location of customer infrastructure

Customer servers and related hosting workloads are operated primarily in data centers in Amsterdam, the Netherlands (EEA), currently including facilities operated by Databarn and NorthC AMS / NorthC Datacenters. Administration and support may also be carried out from Germany. Details of Trivox's role as processor for customer content are set out in the AVV (AGB Section 19).

4) Cookies & Consent

To make visiting our website attractive and to enable the use of certain functions, we use cookies and similar technologies. Some cookies are automatically deleted after closing the browser (session cookies); others remain stored longer (persistent cookies).

Necessary cookies are required for basic operation (e.g. security, load balancing, consent storage, shopping cart). Optional categories (functional, analytics, marketing) are used only if you consent via our cookie banner. Legal bases: Art. 6(1)(b) GDPR for contract-related necessary processing, Art. 6(1)(a) GDPR for consent-based categories, and Art. 6(1)(f) GDPR for strictly necessary technical cookies based on legitimate interests.

You can change or withdraw cookie preferences at any time via the cookie settings on our website or your browser settings. Restricting cookies may limit website functionality.

5) Contact

When you contact us (e.g., via contact form, ticket system, or email), personal data is processed exclusively for handling your inquiry and only to the extent necessary.

The legal basis is our legitimate interest in responding to your inquiry pursuant to Art. 6(1)(f) GDPR. If your contact aims at concluding a contract, Art. 6(1)(b) GDPR also applies. Data are deleted when the matter is conclusively clarified, unless statutory retention obligations require longer storage.

6) Customer Account, Billing Profile & Panel

6.1 When you register for and use our customer panel (v2.trivox.sh) and related APIs (apiv2.trivox.sh), we process account and profile data required to provide the services pursuant to Art. 6(1)(b) GDPR, in particular:

• Login data (email address, password hash, optional two-factor authentication secrets);
• Name (first name, surname) and account status/role;
• Billing profile (billing email, address, city, ZIP/postal code, country/VAT rate, phone number, company name, contact person, tax ID / VAT ID, customer type);
• Account balance and payment-interval settings;
• Email communication preferences (e.g. newsletter, incidents, marketing, stock alerts) and unsubscribe tokens;
• Linked external service accounts needed to provision infrastructure (see Section 8).

6.2 Sessions and security. After login we issue a session token (JWT), typically stored in an HttpOnly cookie (cp_jwt) and/or returned to the client application. We store session metadata (session ID, IP address, user agent, timestamps, revoke status) to protect accounts and detect abuse (Art. 6(1)(b) and (f) GDPR). Failed login / 2FA / password-reset attempts may be logged by IP. Session records are retained for a limited period (typically around 90 days) and then removed or inactivated.

6.3 Account deletion. You may request deletion/closure of your customer account (subject to contractual blockers such as unpaid balances or still-active paid services). Where deletion proceeds, we anonymize or remove direct identifiers in the user and billing profile. Invoice archives, payment records, and certain service/support history may be retained as described in Section 14.

7) Email Communication & Direct Marketing

7.1 Transactional emails (order confirmations, invoices, service/security notices, password resets, support replies, expiry/suspension notices) are sent as required to perform the contract or based on legitimate interests / legal obligations (Art. 6(1)(b), (c) and/or (f) GDPR).

7.2 Optional newsletter / marketing / product-stock emails are sent according to your stored preferences and, where required, your consent (Art. 6(1)(a) GDPR) or another lawful basis. You can change preferences or unsubscribe at any time via the panel, List-Unsubscribe headers, or by contacting us.

7.3 Email delivery. We send emails via our own mail infrastructure (currently on ws1.trivox.sh under trivox.sh domains). Recipient addresses and message metadata are processed for delivery, bounce/abuse handling, and support threading.

8) Orders, Payments & Service Provisioning

8.1 Orders and invoices. To perform contracts we store order/invoice data, including invoice items, amounts, status, gateway, timestamps, and a billing snapshot (invoice recipient data). Invoice PDF/XML documents may be stored on our file storage (FTP) linked to the invoice record. Legal basis: Art. 6(1)(b) and (c) GDPR.

8.2 Payment providers:

- PayPal — PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. We transmit payment/order data needed to create and capture payments or subscriptions and store provider references (e.g. order/capture/subscription IDs, payer ID, subscriber email where provided) and technical request/webhook payloads. PayPal also processes data under its own privacy policy for the payment relationship. Art. 6(1)(b) GDPR.

- Cryptocurrency (NOWPayments) — NOWPayments Ltd. / related entities. We transmit amount, currency, invoice reference and callback data and store NOWPayments invoice/payment IDs, status, currencies, invoice URL, and technical payloads/webhooks. Art. 6(1)(b) GDPR.

- Bank transfer — We match incoming SEPA/bank payments using payment references and our company IBAN. Your bank remains controller of the banking transaction.

8.3 Provisioning systems (platforms we operate to deliver services). Depending on the product, account identifiers and contact data are transmitted to or created in:

VPS (VirtFusion) at vm.trivox.sh — typically name and email linked to your Trivox user ID;
Dedicated / IPMI (TenantOS) at ipmi.trivox.sh — typically a Trivox-generated username/name and credentials;
Web hosting (Keyweb panel / webspace) on ws1.trivox.sh — contact data such as name, company, phone, address, city, ZIP, country, and client reference;
Game servers (Pterodactyl) at game.trivox.cat — service provisioning under Trivox control-plane accounts/API keys linked to your user ID;
Cloudflare — reverse DNS / DNS updates for customer IPs where you use our rDNS features (IP and hostname), in addition to CDN use for our websites (Section 3).

Legal basis: Art. 6(1)(b) GDPR.

8.4 Reseller / API access. If you enable reseller API keys or webhooks/IPN endpoints, we store API key metadata, optional IP locks, webhook URLs/secrets, and delivery logs needed to operate those features.

9) Support Tickets & Contact Forms

Support tickets and contact-form submissions are stored in our ticket system (subject, category, status, messages, optional contact name/email, and structured payload fields such as company or technical details). Email-based tickets may store mail headers/thread IDs. Attachments may be stored on dedicated ticket file storage. Legal basis: Art. 6(1)(b) and/or (f) GDPR.

10) First-Party Usage / Marketing Measurement

We do not currently use Matomo, Google Analytics, or similar third-party analytics suites on trivox.sh.

Our API may record first-party marketing/funnel events (e.g. campaign attribution, product views, cart/checkout steps), including IP address, user agent, approximate country (e.g. from Cloudflare headers), referrer, page path, UTM parameters, a session key, and—if you are logged in—your user ID. Legal basis: Art. 6(1)(a) GDPR where consent is required for non-essential cookies/storage; otherwise Art. 6(1)(f) GDPR for strictly necessary operational measurement.

11) Social Media & Internal Operations Notifications

11.1 We maintain public profiles on platforms such as Discord, Telegram, Instagram, Facebook, and X/Twitter. Interactions on those platforms are governed by the respective providers' terms and privacy policies.

11.2 For internal operations (e.g. payment events, new orders, ticket alerts, abuse/ops monitoring), we may send automated notifications to private Discord webhook channels. Those notifications can include limited customer identifiers such as user ID, name, and email together with service/invoice references. Discord processes such data as a recipient under its terms. Legal basis: Art. 6(1)(f) GDPR (secure and efficient operations).

12) Processing of Customer Content on Hosted Servers (Art. 28)

If you store personal data of your own end users on Trivox infrastructure, you generally remain the controller for that processing. Trivox processes such content on your behalf as a processor. The binding terms are set out in AGB Section 19 (AVV / Data Processing Agreement), including subject matter, TOMs, sub-processors, deletion, and audit rights.

13) Rights of the Data Subject

13.1 The applicable data protection law grants you the following rights vis-à-vis the controller, subject to the statutory requirements:

• Right of access according to Art. 15 GDPR;
• Right to rectification according to Art. 16 GDPR;
• Right to erasure according to Art. 17 GDPR;
• Right to restriction of processing according to Art. 18 GDPR;
• Right to notification according to Art. 19 GDPR;
• Right to data portability according to Art. 20 GDPR;
• Right to withdraw consents granted according to Art. 7(3) GDPR;
• Right to lodge a complaint according to Art. 77 GDPR with a supervisory authority (for Trivox in Germany, typically the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz).

13.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR LEGITIMATE INTEREST BY MEANS OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

14) Duration of Storage & Deletion Practice

Storage duration depends on purpose and legal basis:

Account/session data — for the life of the account / session retention window; anonymized or deleted after account closure where feasible;
Invoices, invoice snapshots, and tax-relevant billing archives — retained for statutory commercial/tax periods under German law (typically up to 10 years);
Payment-provider records (PayPal/NOWPayments references and payloads) — retained as needed for accounting, chargebacks, fraud prevention, and statutory duties;
Support tickets / attachments — retained as long as needed for support history, abuse handling, and legal claims, then deleted or anonymized;
Marketing events — retained for analysis/attribution for a limited operational period, then deleted or aggregated;
Consent-based processing — until withdrawal of consent.

After account deletion requests we typically anonymize login and billing-profile identifiers while retaining invoice and statutory records. Upstream provisioning accounts (VirtFusion / TenantOS / web hosting) are deleted where technically supported and not blocked by remaining services.