Certifications & Compliance
Our active certifications and compliance frameworks demonstrate our commitment to protecting your data.
DATA PROTECTION OFFICER
ExpiredThis shall stand to prove that he has the expertise in the legal basis (Austrian Data Protection Act, EU General Data Protection Regulation) with the resulting rights and duties for the data protection officer as well as the information requirements for organisations required for the quality programme 'Certified Data Protection Officer (DATB)', and is able to assist with the development of data protection management systems within a company.
Issued März 2019 · Expires März 2022
Download reportGDPR (ITDL)
CompliantSelf-attested framework
European Union regulation governing the processing of personal data of individuals in the EU and EEA, including data subject rights and cross-border transfers. Information on data processing pursuant to Articles 13 and 14 of the GDPR (when using our services, remote management/maintenance) .
GDPR (Websites)
CompliantSelf-attested framework
European Union regulation governing the processing of personal data of individuals in the EU and EEA, including data subject rights and cross-border transfers. Information on data processing pursuant to Articles 13 and 14 of the GDPR (when visiting our websites and portals).
View documentationGeprüfte/r Datenschutzexpertin/-experte
Certifiedincite
Geprüfte Datenschutzexpertinnen/-experten sind mit ihrem erworbenen Wissen in der Lage, Risiken in Unternehmen und von Behörden zu minimieren (z.B. Verhinderung von Gesetzesverstößen, Bußgeldern, u.v.m.) sowie Imageverluste und Kosten als Folge von Datenschutzverstößen zu vermeiden. Sie stärken das Vertrauen von Kundinnen und Kunden sowie Beschäftigten in die informationsverarbeitenden und -speichernden Systeme des jeweiligen Unternehmens.
Issued März 2018 · Expires Dez. 2099
Download reportSubprocessors
Third-party services that process data on our behalf, along with their purposes and data handling agreements.
| Name | Purpose | Data Processed | Location | DPA | Website |
|---|---|---|---|---|---|
| Hetzner | Cloud and dedicated server hosting provider. | Application data, user-generated content, system logs, and backups stored on compute and storage services. | DE | Signed | hetzner.com |
| INWX GmbH | Domain Registration Services | Personal data (first and last name, postal address, phone number, contact e-mail) | DE | Signed | www.inwx.de |
Data Practices
What we collect and how we handle your data.
Account & Authentication
- Session tokens
- Last sign-in IP
- User name
- Authentication state
Infrastructure Hosting
- Account information
- Application state
Payment Processing
- Name
- Billing address
- Email address
- Payment method (tokenized)
- Transaction history
Security & Audit Logging
- IP address
- Action performed
- Timestamp
- User agent
Get in touch
- Data Protection Officer
- Alois Kratochwill gdpr@wdns.at
- Security Team
- abuse@wdns.at
- Contact Form
- Open the contact form →
- Mailing Address
- KRATOCHWILL - IT Dienstleistungen u. D.V. Kieslingerstraße 9/1 8430 Leibnitz, Steiermark AUSTRIA
- Company Registration
- GISA-Zahl: 20297794, 20299323 GLN (der öffentlichen Verwaltung): 9110003490720
- VAT / Tax ID
- ATU54135706
Frequently Asked Questions
Quick answers to the questions we hear most.
What is a trust center?
A trust center is a public page where a company shares information about how it handles security, privacy, and compliance. It usually includes security policies, a list of subprocessors, compliance certifications, and details about how customer data is handled. The goal is to give customers, partners, and prospects one place to answer due diligence questions without having to email anyone.
What is a Data Processing Agreement (DPA)?
A Data Processing Agreement, or DPA, is a contract between a company that collects personal data and a company that processes that data on its behalf. It defines what data can be processed, for what purpose, how long it can be kept, and what security measures must be in place. Under privacy laws like the GDPR, a DPA is required whenever one company processes personal data for another.
What is a subprocessor?
A subprocessor is a third-party service that a company uses to help deliver its product, and that may come into contact with customer data along the way. Common examples include cloud hosting providers, email delivery services, analytics platforms, and customer support tools. Companies publish subprocessor lists so customers can see exactly which vendors may handle their data.
What is the difference between a data controller and a data processor?
The data controller is the party that decides why and how personal data is collected and used. The data processor is the party that handles that data on the controller's behalf, following the controller's instructions. A SaaS customer is usually the controller of their end-user data, while the SaaS vendor acts as the processor. Each role carries different legal responsibilities under privacy laws like the GDPR.
What is personal data?
Personal data is any information that can be used to identify a living person, either on its own or when combined with other information. Obvious examples include names, email addresses, phone numbers, and home addresses. Less obvious examples include IP addresses, device identifiers, cookies, and location data. Privacy laws such as the GDPR and CCPA treat personal data as something that must be collected, stored, and shared with care.
What is responsible disclosure?
Responsible disclosure is the practice of reporting a security vulnerability privately to the company that owns the affected system, giving them a reasonable amount of time to fix it before any details are shared publicly. It protects users from being exposed to a known issue before a patch is available. Most trust centers include a contact address or form for reporting vulnerabilities this way.
What is a compliance certification?
A compliance certification is a formal statement, usually issued by an independent auditor, confirming that a company meets the requirements of a specific security or privacy standard. Certifications give customers a way to trust a company's practices without having to inspect them directly. The scope, issuing body, and validity period are typically listed alongside each certification in a trust center.
What is a security policy?
A security policy is a written document that describes how a company protects its systems, data, and people. Policies commonly cover topics like access control, incident response, acceptable use, vendor management, and business continuity. Publishing policies in a trust center lets customers see how security is handled without needing to sign an NDA first.
Why do companies publish a list of subprocessors?
Publishing a subprocessor list is a transparency practice, and in many cases a legal requirement, that lets customers see every third party that may handle their data. It gives customers the chance to review new vendors before they start processing data, and it makes it easier to meet their own compliance obligations. Most trust centers also offer a way to be notified when the list changes.
What is a data practice?
A data practice describes a specific way a company collects, uses, stores, or shares information. Each practice usually spells out what data is involved, why it is collected, how long it is kept, and who it is shared with. Grouping data practices by category, such as account data, usage data, or support data, helps customers understand exactly what happens to their information.