Transparent about the data we process.
This policy describes the data flows implemented in Eichi.me, from customer accounts and hosting to domains, payments, community, support and cookies.
1. Controller
The controller responsible for personal-data processing in connection with Eichi.me is:
Eichi.me - Webhosting Solutions
Christian Eichenberger
Schulgasse 12
8214 Gächlingen
Schweiz
Phone: +41 76 261 96 90
Swiss mobile number. Calls from abroad, including the EU, may incur additional charges depending on the caller's provider and tariff.
Email: info@eichi.me
Privacy requests may be sent to the email address above or to the contact address published in the legal notice.
2. Applicable data-protection law
Eichi.me processes personal data primarily under the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies to a particular processing activity, its requirements are also taken into account.
Where the GDPR applies, processing may in particular be based on performance of a contract or pre-contractual steps, legal obligations, legitimate interests in secure and efficient operation, or consent where consent is required.
3. Technical data when visiting the website
When the website is accessed, technically necessary data may be processed, including IP address, date and time, requested URL, referrer, browser/device information, HTTP status and technical error data. These data are used to deliver the website, maintain system security, analyse errors, prevent abuse and ensure stability.
For the internal live-visitor overview in the administration area, Eichi.me may additionally store a pseudonymous visitor/session key, a cryptographic hash of the IP address, the current page, referrer domain, language, selected display currency, browser identifier, first/last activity and page-view count. The plain IP address is not stored in this live table. The overview is used for technical operational monitoring and is visible only to administrators; live records are automatically removed after a short retention period.
Eichi.me also maintains a pseudonymised visitor counter for internal operational statistics such as visits today, yesterday and overall as well as page views. For each calendar day, a pseudonymous session key, page-view count and first/last activity are stored. This statistic does not contain plain IP addresses, names or email addresses. The data are used solely for internal reach and operational overview.
The operator may optionally enable MaxMind GeoIP. If enabled, the current IP address is transmitted server-side to MaxMind to determine an approximate country and, where available, city. Eichi.me only stores the resulting location data in the live overview and still does not store the plain IP address there. MaxMind is used only when this feature is explicitly enabled in the administration area.
A technically necessary session cookie is used for sessions, authentication and CSRF protection. If a language is selected, that preference may be stored. The cookie choice itself is also stored in a necessary first-party cookie.
4. Customer account, profile and authentication
Depending on use, customer-account data may include name, first and last name, email address, phone number, account type, company, billing address, country, VAT/UID or company-register details, password hash, login timestamps, account status and an optional uploaded profile image.
Customer passwords are not stored as plain-text passwords. Secrets or authorisation codes required for specific technical hosting processes are encrypted where the system provides for encrypted storage.
5. Orders, web hosting, domains and game servers
For orders and service provisioning we process contract and product data such as plan, term, price, currency, order number, payment status, hosting username, technical customer/resource IDs, domain name, transfer status, encrypted auth codes, registration status, nameserver and expiry data as well as provisioning and error logs.
For new web-hosting and domain orders, Eichi.me also records when the Terms were accepted, which legal-text/DPA version applied and which correspondence language was selected. For web hosting, the time of an express request to begin technical performance is also stored. A hashed IP reference and shortened browser/user-agent data may be stored for abuse prevention and evidentiary purposes. Product contracts and DPAs are archived in the customer portal as order snapshots. These data are used for contract administration and evidence.
Web-hosting management actions relating to domains, email accounts, databases, FTP, cron jobs, DNS, certificates or other resources may be logged with customer ID, product ID, action, resource type, result, timestamp and security-related IP information.
For game servers, server name, IP/port, runtime, player/server status, control commands, RCON output, events and configurations may be processed.
6. Invoices and payments
For billing and payments we process invoice number, billing-address snapshots, line items, amount, tax information, due date, payment method, payment status, payment time and payment-provider references.
When PayPal is selected, the data required to process the payment are transmitted to or received from PayPal. Eichi.me stores the order/capture references and statuses required for verification and allocation; full PayPal payment-instrument details are not stored by Eichi.me.
7. Domain registration through Openprovider
For domain registration, transfer, renewal and administration, required holder/contact data are disclosed to Openprovider and, depending on the top-level domain, to relevant registries, registrars or other domain-name-system entities. This may include name, address, email, phone, company, register/tax details, domain name and technical domain data.
8. Support, contact and abuse
Support tickets, contact requests and abuse reports may contain contact information, subject, category, priority, target/domain, message text, replies, status, timestamps and, for abuse prevention, a hash of the source IP. Please do not publish passwords or confidential account details through public community features.
If you use the live chat on the home page, we store the message history, timestamps, language, current page, a pseudonymous chat key and – if voluntarily provided – your name and email address. For logged-in customers, the conversation may be linked to the customer account. A cryptographic hash of the source IP is stored for abuse prevention; the plain IP address is not stored in the chat history. After the first message, a technically necessary first-party cookie is used to recognise the ongoing chat. Closed chats are deleted after the retention period configured in the system; the default is 180 days. The live chat may use a rule-based FAQ assistant labelled “Eichi Bot”. Message text is matched only inside the Eichi.me application against keywords and answers maintained by the operator. No external AI API is called for this feature and the message content is not transferred to an AI provider.
9. Community, Q&A, reviews and public content
Community questions and answers are stored with content, time, category, status and customer-account association and are public when published. Customer reviews may include product reference, display name, star rating, title, review text, moderation status and timestamps.
The historical game-server/server-list area may process player names, server assignment, score, play duration and observation times. Pseudonymised IP hashes may be stored for ratings or comments to limit abuse.
10. Email delivery and notifications
Order, payment, renewal, security, contract, community and support messages may involve the recipient address, subject, generated message body, selected correspondence language, delivery status, delivery time and technical error information. Transactional messages are generated from administratively managed German and English templates. Delivery uses an SMTP service or server mail function depending on configuration.
11. Security, login and administration logs
To protect the platform, Eichi.me may log login events, usernames, success/failure status, pseudonymised IP values, user agent, timestamps, technical customer actions and administrative changes for attack detection, error analysis, accountability and abuse prevention.
12. Backups and restoration
Eichi.me may create technical database backups, which may include personal data stored in production systems at the time of backup. Configured backup retention is generally 30 days where backups are enabled, unless different technical or legal retention is required.
Deleting data from a production system does not necessarily remove it immediately from previously created backups. Such copies are overwritten or deleted through the normal backup cycle and are used only for restoration, security and evidentiary purposes.
13. Cookies and similar technologies
Eichi.me uses necessary cookies for secure sessions, authentication, language preferences and storage of your cookie choice. Optional advertising or tracking technologies are loaded only where the required consent has been obtained. You can refuse optional cookies or change a previous choice through "Cookie settings".
- Session cookie: login, session state and security; normally for the session.
- eichi_lang: remembers an actively selected language; up to 12 months.
- eichi_currency: remembers the selected CHF/EUR price display; up to 12 months.
- eichi_cookie_consent: stores the optional-cookie choice; up to 6 months.
- eichi_live_chat: is set only after a chat conversation is started and recognises the ongoing chat; up to 30 days.
14. Recipients and service providers
Personal data are disclosed only where required for the purposes described above. Recipients may include data-centre/server/network providers, Openprovider and domain registries/registrars, PayPal, MaxMind where GeoIP is enabled, Google and advertising-technology providers where AdSense is enabled and consent exists, email/SMTP providers, IT/security/support processors, and authorities or courts where legally required.
KeyHelp and Pterodactyl are used as technical administration software for hosting and game-server functions. Whether an external recipient is involved depends on the concrete server/panel configuration; administrative API calls are generally server-side.
15. Processing outside Switzerland
The current web-hosting infrastructure is operated in St. Louis, Missouri, USA on infrastructure supplied by velia.net. Customer and hosting data may therefore be stored or processed in the United States. PayPal, Google, MaxMind (if enabled), Openprovider or domain registries may also process data outside Switzerland.
Where data are disclosed abroad, Eichi.me observes the requirements of Swiss data-protection law and, where applicable, the GDPR. Depending on the recipient, this may involve an adequacy decision, certification under a recognised data-protection framework, appropriate standard contractual clauses or another legally permitted safeguard or exception.
16. Retention
Personal data are retained only as long as needed for the relevant purpose, contract performance, security, evidence or legal obligations. Contract/customer/product data are generally kept for the business relationship and afterwards where needed for claims or legal duties. Accounting records are retained for 10 years where Article 958f of the Swiss Code of Obligations applies. Support/security data are kept as long as needed for the relevant case and abuse prevention. Closed live-chat conversations are deleted after the configured retention period, which defaults to 180 days. Public community/review content remains until deletion, moderation or anonymisation where no overriding reason requires retention. Backups follow the configured rotation cycle.
17. Automated workflows
The platform uses automated operational workflows, for example for payment allocation, web-hosting provisioning, domain processing, renewal notices, payment reminders and possible technical suspension based on contract/payment status. The live chat may also use a rule-based FAQ assistant to answer known questions from maintained keywords; unknown questions remain open for personal support. Community, profile or chat data are not used for unrelated automated personality scoring.
18. Your rights
Under applicable data-protection law you may in particular request access to your personal data, correction of inaccurate data and, where the conditions are met, deletion or restriction. Where the GDPR applies, additional rights may include data portability, objection and withdrawal of consent. Statutory retention duties and compelling grounds for continued processing remain reserved.
19. Data security
Eichi.me uses appropriate technical and organisational measures including access restrictions, password hashing, server-side API access, encryption of selected secrets, CSRF protection, secure session cookies, security logging and backups. No system can guarantee absolute security.
20. Supervisory authority
For Swiss data-protection law, the Federal Data Protection and Information Commissioner (FDPIC/EDÖB) is the competent supervisory authority. Where the GDPR applies, a right to lodge a complaint with a competent European data-protection authority may also exist.
21. Changes
This Privacy Policy may be updated when functions, providers or legal requirements change. The version published on this website applies.
Last updated: 24 August 2026
Bug report form
The public bug report form lets visitors report technical errors and display issues. Eichi.me processes the contact details voluntarily provided, the affected page, issue type, description and reproduction steps as well as browser/user-agent information. For abuse prevention, the source IP address is not stored in plain text but only as a cryptographic hash. For signed-in customers, the report may be linked to the customer account. The data are used for troubleshooting, communication and traceability of the resolution process.
Two-step customer sign-in by email security code
To protect customer accounts, after a successful email-address and password check Eichi.me may additionally send a 6-digit one-time code to the email address stored in the account. This security check processes the customer account, timestamps and expiry, the number of failed code entries, a cryptographic IP hash and shortened browser/user-agent information. The one-time code itself is not stored in plain text, but only as a password hash. Successfully used or expired challenges are marked as consumed.
Account sessions and sign-in history
To protect customer accounts, Eichi.me manages active sign-in sessions server-side. This includes a random session token stored only in hashed form, timestamps, shortened browser/device information, a cryptographic IP hash and – where MaxMind is enabled – country and city. Customers can view and revoke active sessions in their account. Successful and failed sign-in events are logged for a limited period for security purposes. If sign-in notifications are enabled, the customer receives a security email after a successful sign-in.
Extended reach analytics
For internal optimisation of the website, navigation and order flows, Eichi.me may count pseudonymised events such as page views and completed domain or web-hosting order flows. Stored data include a pseudonymous visitor key, event type, path, referrer host, coarse country and device type. This statistic does not store names, email addresses or plain IP addresses. Event data are retained for 90 days by default; the operator may adjust this period.
Confidential security reports
The responsible-disclosure form can be used to report security vulnerabilities confidentially to Eichi.me. Eichi.me processes contact details, technical description, potential impact, browser information, a cryptographic IP hash, handling status and internal review notes. The information is used solely for security analysis, communication and incident documentation.
Legal information maintained centrally.
CMS changes apply automatically to the website and customer portal.