Version 4 — published 30 August 2026
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Yannick Dreher
Gertrude-Neumark-Weg 17
90431 Nürnberg
Deutschland
E-Mail: yannick.dreher@dremaxx.de
A data protection officer is not legally required and has not been appointed.
This statement informs about the processing of personal data when visiting this website, when using the offered DNS resolvers (DNS-over-TLS and DNS-over-HTTPS) and when using the authoritative DNS hosting for your own zones.
When accessing this website, technically necessary server logs are processed by the hosting provider. These may contain:
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure and stable operation of the website).
Storage period: These logs are stored for a maximum of 14 days and then automatically deleted, unless security incidents require longer retention.
When using the DNS resolvers offered, DNS queries via DNS-over-TLS (DoT) or DNS-over-HTTPS (DoH) are accepted and forwarded to authoritative nameservers. The IP address of the requesting device is technically required to deliver the response.
No persistent storage (no logging) of DNS queries or associated IP addresses takes place. No analysis of individual users' query behaviour is performed.
Anonymised technical metrics (e.g. queries per second, response times, error rates) may be collected and evaluated to ensure operation. These metrics do not allow conclusions about individual users or queries.
To prevent abuse (e.g. DNS amplification attacks, bot traffic), suspicious IP addresses may be cached briefly and temporarily blocked. This data is used solely to ensure proper operation and is deleted once the cause has been resolved.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the provision, security and stability of the service).
No personal data is transferred to third parties, with the exception of:
The resolvers of the service are operated at the following locations: Düsseldorf and Berlin (Germany), Zurich (Switzerland), Houston, Texas (United States) and Worcester (United Kingdom). The authoritative nameservers are located in Berlin (Germany) and in Lenexa, Kansas (United States).
Which location answers a query is determined by anycast routing based on network topology. A particular location can therefore not be guaranteed; every query is handled at whichever location is best reachable from the requesting network.
For Switzerland and the United Kingdom an adequacy decision of the European Commission under Art. 45 GDPR is in place. A transfer to these countries is therefore equivalent to a transfer within the European Union.
At the location in the United States the same data is processed as at every other location: the requested domain and the IP address of the requesting connection, held exclusively in memory and only for the duration of the resolution. No query logs are written and no data is retained that could subsequently be attributed to a person.
Beyond this, resolving DNS queries may technically require communication with authoritative nameservers worldwide.
This website does not set any first-party cookies for tracking or analytics purposes and does not embed any advertising networks or third-party social-media plug-ins.
For the statistical analysis of visitor numbers, the privacy-friendly web analytics service "Umami" (Umami Software, Inc., Wilmington, Delaware, USA) is used. Umami works without cookies and does not perform any cross-device recognition. Only aggregated, anonymised usage data is processed:
A single visitor is identified only for the current session by an anonymous, daily rotating hash of the IP address and user agent. No profiling takes place; conclusions about individual natural persons are not possible.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in privacy-friendly audience measurement to improve the offering). Since no information stored on the end device is read or stored within the meaning of § 25 (1) TTDSG, no consent is required.
Processor / third country: Umami Cloud processes the data mentioned within the European Union. The provider itself is based in the USA; a transfer to the USA cannot be ruled out in the course of contract performance and is based on the EU Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR.
Objection: You can prevent collection by Umami by enabling "Do Not Track" in your browser, using an ad or tracking blocker, or blocking the domain cloud.umami.is.
Towards the controller, you have the following rights:
Due to the deliberately minimal data processing (no logging), individual rights may effectively run empty as no personal data about you is held.
You have the right to lodge a complaint with a data protection supervisory authority. The Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, is in particular responsible.
Anyone who creates an optional user account on this website provides the following personal data, which is stored in the service database:
Legal basis: Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) for master data and authentication; Art. 6(1)(a) GDPR (consent) for receiving technical service emails. Consent can be withdrawn at any time in the profile.
Technical service emails: Cover only explicitly requested emails on technical topics (e.g. planned maintenance windows, outages, security-relevant notices). No advertising use takes place and no data is shared with third parties for marketing purposes.
Retention: Account data is stored as long as the account exists. After deletion of the account, all related data is removed without delay; subsequent restoration is no longer possible.
Anyone who uses the optional service for authoritative hosting of their own DNS zones provides data that is stored persistently in the service database and in the nameserver software used (PowerDNS). The following is processed in particular:
Legal basis: Art. 6(1)(b) GDPR (provision of the hosting service offered free of charge to the user) and Art. 6(1)(f) GDPR (legitimate interest in security, accountability and abuse prevention, in particular with regard to the audit logs).
Responsibility for content: The user is solely responsible for the DNS records created in the hosted zones and the content reachable through them. The operator does not carry out any content review.
Public nature of authoritative DNS data: Authoritative DNS records are by their nature publicly retrievable. Anyone creating a record deliberately makes the information contained therein (e.g. hostnames, IP addresses) publicly accessible.
Retention: Zones, records and related data are stored as long as the respective zone or account exists. After deletion of a zone or the account, the related data is removed without delay. Audit logs may be retained beyond this for a limited period for security and accountability purposes.
Anyone who uses the optional DynDNS service (dynamic DNS updating) provides data that is stored persistently in the service database and in the nameserver software used. The following is processed in particular:
Legal basis: Art. 6(1)(b) GDPR (provision of the DynDNS service offered free of charge to the user) and Art. 6(1)(f) GDPR (legitimate interest in security, stability and abuse prevention, in particular with regard to the update logs and rate limits).
Public nature of the DNS data: The chosen hostname and the associated IP address are published as an authoritative DNS record in the public DNS and are thus retrievable worldwide. Since an IP address may have a personal reference, the user deliberately makes this information publicly accessible by creating a DynDNS address.
Retention: Hostnames, suffixes, IP addresses and credentials are stored as long as the respective DynDNS address or account exists. After deletion of the address or the account, the related data is removed without delay and the associated public DNS record is withdrawn. Update logs may be retained for a limited period for security and accountability purposes.
Anyone who uses the optional monitoring service (availability monitoring of their own hosts and services) provides data that is stored in the service database and is collected regularly through active checks (probes) run from the operator's infrastructure. The following is processed in particular:
Legal basis: Art. 6(1)(b) GDPR (provision of the monitoring service offered free of charge to the user) and Art. 6(1)(f) GDPR (legitimate interest in security, stability and abuse prevention, in particular with regard to the check logs and rate limits).
Checking only your own hosts: Only hosts over which you are authorised to dispose may be monitored; this is proven via a DNS TXT record before the checks are activated. The active checks are performed from fixed, published source IP addresses of the operator and are directed exclusively at the targets specified by the user.
Retention: Targets, checks, channels and incidents are stored as long as the respective target or account exists. Raw probe data is only kept for a short period and is then condensed into anonymised history values or deleted. After deletion of a target or the account, the related data is removed without delay.
This statement may be adapted in case of changes to the service or the legal situation. The respective current version is available on this page.