Skip to content
3 Active Certifications

WDNS.at | Trust Center

Transparency and security you can trust.

3 Certifications
2 Subprocessors
Updated Juni 15, 2026

Certifications & Compliance

Our active certifications and compliance frameworks demonstrate our commitment to protecting your data.

DATA PROTECTION OFFICER

Expired

This shall stand to prove that he has the expertise in the legal basis (Austrian Data Protection Act, EU General Data Protection Regulation) with the resulting rights and duties for the data protection officer as well as the information requirements for organisations required for the quality programme 'Certified Data Protection Officer (DATB)', and is able to assist with the development of data protection management systems within a company.

Issued März 2019 · Expires März 2022

Download report

GDPR (ITDL)

Compliant

Self-attested framework

European Union regulation governing the processing of personal data of individuals in the EU and EEA, including data subject rights and cross-border transfers. Information on data processing pursuant to Articles 13 and 14 of the GDPR (when using our services, remote management/maintenance) .

GDPR (Websites)

Compliant

Self-attested framework

European Union regulation governing the processing of personal data of individuals in the EU and EEA, including data subject rights and cross-border transfers. Information on data processing pursuant to Articles 13 and 14 of the GDPR (when visiting our websites and portals).

View documentation

Geprüfte/r Datenschutzexpertin/-experte

Certified

incite

Geprüfte Datenschutzexpertinnen/-experten sind mit ihrem erworbenen Wissen in der Lage, Risiken in Unternehmen und von Behörden zu minimieren (z.B. Verhinderung von Gesetzesverstößen, Bußgeldern, u.v.m.) sowie Imageverluste und Kosten als Folge von Datenschutzverstößen zu vermeiden. Sie stärken das Vertrauen von Kundinnen und Kunden sowie Beschäftigten in die informationsverarbeitenden und -speichernden Systeme des jeweiligen Unternehmens.

Issued März 2018 · Expires Dez. 2099

Download report
Updated Mai 29, 2026

Subprocessors

Third-party services that process data on our behalf, along with their purposes and data handling agreements.

Name Purpose Data Processed Location DPA Website
Hetzner Cloud and dedicated server hosting provider. Application data, user-generated content, system logs, and backups stored on compute and storage services. DE Signed hetzner.com
INWX GmbH Domain Registration Services Personal data (first and last name, postal address, phone number, contact e-mail) DE Signed www.inwx.de
Updated Mai 29, 2026

Data Practices

What we collect and how we handle your data.

  • Session tokens
  • Last sign-in IP
  • User name
  • Authentication state
  • Account information
  • Application state
  • Name
  • Billing address
  • Email address
  • Payment method (tokenized)
  • Transaction history
  • IP address
  • Action performed
  • Timestamp
  • User agent

Get in touch

Data Protection Officer
Alois Kratochwill gdpr@wdns.at
Security Team
abuse@wdns.at
Mailing Address
KRATOCHWILL - IT Dienstleistungen u. D.V. Kieslingerstraße 9/1 8430 Leibnitz, Steiermark AUSTRIA
Company Registration
GISA-Zahl: 20297794, 20299323 GLN (der öffentlichen Verwaltung): 9110003490720
VAT / Tax ID
ATU54135706

Frequently Asked Questions

Quick answers to the questions we hear most.

What is a trust center?

A trust center is a public page where a company shares information about how it handles security, privacy, and compliance. It usually includes security policies, a list of subprocessors, compliance certifications, and details about how customer data is handled. The goal is to give customers, partners, and prospects one place to answer due diligence questions without having to email anyone.

What is a Data Processing Agreement (DPA)?

A Data Processing Agreement, or DPA, is a contract between a company that collects personal data and a company that processes that data on its behalf. It defines what data can be processed, for what purpose, how long it can be kept, and what security measures must be in place. Under privacy laws like the GDPR, a DPA is required whenever one company processes personal data for another.

What is a subprocessor?

A subprocessor is a third-party service that a company uses to help deliver its product, and that may come into contact with customer data along the way. Common examples include cloud hosting providers, email delivery services, analytics platforms, and customer support tools. Companies publish subprocessor lists so customers can see exactly which vendors may handle their data.

What is the difference between a data controller and a data processor?

The data controller is the party that decides why and how personal data is collected and used. The data processor is the party that handles that data on the controller's behalf, following the controller's instructions. A SaaS customer is usually the controller of their end-user data, while the SaaS vendor acts as the processor. Each role carries different legal responsibilities under privacy laws like the GDPR.

What is personal data?

Personal data is any information that can be used to identify a living person, either on its own or when combined with other information. Obvious examples include names, email addresses, phone numbers, and home addresses. Less obvious examples include IP addresses, device identifiers, cookies, and location data. Privacy laws such as the GDPR and CCPA treat personal data as something that must be collected, stored, and shared with care.

What is responsible disclosure?

Responsible disclosure is the practice of reporting a security vulnerability privately to the company that owns the affected system, giving them a reasonable amount of time to fix it before any details are shared publicly. It protects users from being exposed to a known issue before a patch is available. Most trust centers include a contact address or form for reporting vulnerabilities this way.

What is a compliance certification?

A compliance certification is a formal statement, usually issued by an independent auditor, confirming that a company meets the requirements of a specific security or privacy standard. Certifications give customers a way to trust a company's practices without having to inspect them directly. The scope, issuing body, and validity period are typically listed alongside each certification in a trust center.

What is a security policy?

A security policy is a written document that describes how a company protects its systems, data, and people. Policies commonly cover topics like access control, incident response, acceptable use, vendor management, and business continuity. Publishing policies in a trust center lets customers see how security is handled without needing to sign an NDA first.

Why do companies publish a list of subprocessors?

Publishing a subprocessor list is a transparency practice, and in many cases a legal requirement, that lets customers see every third party that may handle their data. It gives customers the chance to review new vendors before they start processing data, and it makes it easier to meet their own compliance obligations. Most trust centers also offer a way to be notified when the list changes.

What is a data practice?

A data practice describes a specific way a company collects, uses, stores, or shares information. Each practice usually spells out what data is involved, why it is collected, how long it is kept, and who it is shared with. Grouping data practices by category, such as account data, usage data, or support data, helps customers understand exactly what happens to their information.