Privacy policy
Version: 14 September 2026, revision 2.
Controller and contact
Dymmer is a trading brand of Altenwald, the controller for account, contracting and service administration data. Address: Antilopestraat 7, 1338 KN Almere, Netherlands. KvK: 84033401. BTW-ID: NL003904833B64. For privacy enquiries or to exercise your rights, write to info@dymmer.com or that postal address.
This policy explains processing connected with using Dymmer, including purchases initiated without signing in. If you manage other people's data through the service, you must have a lawful basis and inform them. Where Altenwald processes content on a customer's behalf, the relevant instructions and obligations must be set out in the applicable processing agreement; this policy does not replace that agreement.
This policy provides information about processing your data; it is not a general authorisation to use it. Acknowledging that you have read it does not replace consent where required or turn contractual or legally required processing into consent-based processing. The service agreement and the commercial contact choice are separate.
Data, purposes and lawful bases
- Account and access: email address, name, language, hashed password, tokens and authentication records. We use these to create and manage the account, identify users and send messages necessary to access or recover access. Basis: performance of a contract or requested pre-contractual steps.
- Orders and domains: selected items, domain registrant and contacts, address, telephone and identification where required by the extension, transaction history and information returned by the registrar. Purpose: purchases, registrations, transfers, renewals and changes. Basis: contract; compliance with legal obligations where applicable. A registrar's contractual requirements are not, by themselves, a legal obligation.
- Payments and invoicing: tax and postal details, country, amounts, balance, invoices and payment and subscription references and statuses. Purpose: collection, reconciliation and compliance with accounting and tax obligations. Bases: contract and legal obligation. PayPal handles payment instruments provided on its platform; Dymmer receives information needed to identify and confirm transactions.
- Email and managed resources: mailboxes and forwarding, DNS configuration, projects, servers, permissions, connection credentials, technical logs and metrics that customers add or enable. Purpose: supplying and administering requested features. Basis: contract for the customer relationship; third-party content processed on a customer's behalf is subject to their instructions and the corresponding agreement.
- Security and support: support correspondence, IP address, access and error events, and abuse prevention signals. Purpose: resolving incidents, protecting accounts and systems and preventing fraud. Basis: legitimate interests in a secure service, balanced against individuals' rights; contract when handling a customer's request. If a check prevents access, you can request review by a person.
- Approximate country: the IP address may be checked against a local geolocation database to suggest a billing country. This is not precise location and you can correct it. Basis: legitimate interests in facilitating accurate initial details, without replacing your confirmation.
Data comes from you, people you authorise to manage resources, use of the service and providers involved in transactions. Without information required to identify you, issue invoices or meet domain requirements, the corresponding service may not be possible. Accepting terms does not mean consenting to every processing activity. Where processing requires consent, it must be requested for a specific purpose and can be withdrawn.
Voluntary commercial contact
If you choose to receive Dymmer news and offers by email, your specific consent will be the basis for that processing. Full information and the declaration accompanying that choice appear in the commercial contact consent document. Purchasing, opening an account or reading this policy does not mean consenting to those messages.
Data needed for this purpose is your email address, communication language and the minimum information needed to demonstrate and manage your choice: identity or account reference, date and origin of the declaration, the text and version of the information shown, and subsequent changes or withdrawals. Mailbox contents, server credentials and payment details are not needed for a commercial mailing list.
The choice does not authorise third-party advertising, calls, SMS or individual tracking of opens or clicks. Any future additional purposes or technologies must be explained and have an appropriate lawful basis. Before starting mailings after inactivity, we will check that consent remains valid and matches the purpose explained.
You can withdraw consent free of charge by emailing info@dymmer.com. Every commercial message that is sent must also include an easy unsubscribe method. After withdrawal, your address will not be used for new commercial messages; minimum evidence may be retained to demonstrate management of your choice, handle claims during applicable periods and prevent unauthorised re-enrolment. That evidence will not be used to send advertising.
Necessary access, security, order, billing and service administration messages retain their own contractual or legal bases and do not depend on commercial consent. The commercial mailing system has not been chosen: this text does not assume an active platform or authorise automatic reuse of earlier lists. Before an external provider is used, applicable information about recipients and transfers will be provided.
Recipients and external services
Hetzner hosts the application, database and Dymmer's central data in Germany, and backups in Finland. It provides infrastructure subject to the corresponding data processing agreement.
We use Vultr, DigitalOcean, netcup and Hetzner for DNS infrastructure. The additional providers host DNS data, not the central customer database. DNS records may include domain names, IP addresses and other values you configure; published records are intended to be queried by third parties. Do not include unnecessary personal data in them.
Data needed to manage a domain is communicated to the provider used — Netim, Resellbiz or DonDominio — and, where applicable, the extension's registry and organisations involved in its administration, such as ICANN. Access to or publication of registration data depends on applicable rules; this does not mean all your data is public.
Mailgun sends transactional emails, such as sign-in links, domain expiry reminders and necessary service communications. We use its United States region. Delivering these messages involves processing email addresses, content and sending and delivery metadata. Open and click tracking are disabled. This use does not depend on marketing consent and is not a newsletter. Email correspondence is also retained on Dymmer's mail servers.
PayPal receives and processes information needed for payment and fraud prevention under its own obligations. On access and registration forms, hCaptcha, provided by Intuition Machines, processes browser and connection signals to detect automated use. Its involvement and browser storage are also described in the cookie policy.
The website requests typefaces from Google Fonts. Downloading them communicates the browser's IP address and technical request information to Google. The purpose is to display the interface's typefaces; this external connection is not a Dymmer advertising tool. See Google's privacy policy.
We may communicate data to authorities, courts or advisers where there is an obligation or lawful basis. Providers may act on Altenwald's behalf or as controllers for their own processing, depending on the service and their obligations.
Further information: Hetzner, Vultr, DigitalOcean, netcup, Mailgun, Netim, Resellbiz, DonDominio, PayPal and hCaptcha.
International transfers
The central hosting and backups described above are in the European Economic Area. Sending through Mailgun involves processing in the United States. Its terms incorporate the Sinch data processing agreement, which provides for international transfer safeguards, including standard contractual clauses where applicable. Its policy also describes participation in the EU–US Data Privacy Framework; reliance on an adequacy decision depends on the entity and processing covered.
Domain registries, DNS providers and other international services may involve processing outside the EEA. The provider's registered office does not determine where all processing takes place. Transfers must have an adequacy decision or other valid safeguards and, where needed, supplementary measures. Accepting the contract or this policy does not replace those safeguards.
You can ask info@dymmer.com about recipients, countries and safeguards applicable to your service and request a copy of safeguards, subject to restrictions needed to protect other people's data.
Retention and security
Account and configuration information is needed during the relationship and delivery of services. At termination, data that is no longer necessary must be distinguished from information required for legal obligations or specific claims.
Accounting documentation subject to the general Dutch retention obligation is kept for seven years; certain tax records, such as those covered by VAT One Stop Shop schemes where applicable, require ten years. This does not justify retaining all account content or data for those periods.
We have not yet established a general deletion period after account closure or for support correspondence. Retention needs must be assessed according to resolution of the enquiry or incident, applicable obligations and any claims requiring that information. This policy does not announce automatic deletion after a fixed number of days. You can request erasure or information about retention of your data at info@dymmer.com; the absence of a general period does not limit your rights or authorise indefinite retention.
Metrics have the retention applicable to the service or add-on purchased. Backups and provider systems require handling separate from deletion in active systems and must be included when assessing an erasure request. Terminating a service does not immediately erase invoices or all information in external systems.
We apply access controls and technical and organisational measures appropriate to the risk. No measure guarantees that an incident will never occur.
Your rights
You may request access, rectification, erasure, restriction and, where applicable, portability of your data. You may object to processing based on legitimate interests for reasons relating to your particular situation. Where processing relies on consent, you can withdraw it without affecting the lawfulness of earlier processing.
Email info@dymmer.com with your request. We may request proportionate information to verify your identity where necessary. We generally respond within one month; if complexity or the number of requests justifies a statutory extension, we will inform you within that first month. Rights may be subject to legal exceptions, which we will explain where applicable.
You may complain to the Dutch Autoriteit Persoonsgegevens or the competent data protection authority in your habitual residence, place of work or where the alleged infringement occurred.
Changes and related information
The version date identifies this text. Material changes will be communicated appropriately; publishing an update does not create new consent. See also the terms of service, cookie policy and business identification.