Legal information
Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how personal data is processed when you visit yfind.de, perform a website check or suggest a domain for inclusion in the YFind directory.
1. Controller
Irlanda Salazar
Robert-Koch-Str. 17
85521 Ottobrunn
Germany/Deutschland
Email: [email protected]
Further legal information is available in the Imprint.
2. General information
YFind provides basic technical checks for publicly accessible websites and domains. No user account is required.
We do not sell personal data. YFind does not use advertising trackers, behavioural profiling or analytics cookies.
3. Hosting and server log files
YFind is hosted on server infrastructure provided by:
netcup GmbH
Emmy-Noether-Straße 10
76131 Karlsruhe
Germany
When you access YFind, the web server may process the following technical information:
- IP address of the requesting device,
- date and time of the request,
- requested page or resource,
- HTTP method and response status,
- amount of data transferred,
- referring page, where transmitted by the browser, and
- browser and operating-system information.
This information is processed to deliver the website, maintain stable operation, detect technical problems and prevent misuse or attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of YFind and the prevention of abuse.
Regular server log files are deleted after seven days. Data required to investigate a specific security incident may be retained until that incident has been resolved.
4. Technically necessary session cookie
YFind uses a technically necessary session cookie. It is used to protect forms against misuse, maintain the current session and make a temporary check result available to the requesting browser.
The cookie is not used for advertising, analytics or cross-site tracking. It is deleted when the browser session ends. Server-side session data is deleted after no more than 30 minutes of inactivity.
Storage in the user's device is based on Section 25(2) no. 2 TDDDG. The associated processing of personal data is based on Article 6(1)(f) GDPR.
5. Website and domain checks
When you enter a domain for checking, YFind processes the entered domain name and retrieves publicly accessible technical information. Depending on the available data, this may include:
- DNS records, such as A, AAAA, NS, MX and TXT records,
- HTTP and HTTPS status codes,
- redirect destinations,
- TLS certificate information,
- page title and meta description,
- canonical and robots directives, and
- response times and technical error messages.
The check is initiated by the YFind server. The operator of the checked website therefore receives a request from the YFind server, including the YFind server IP address and a technical user-agent identifier. The visitor's own IP address is not forwarded to the checked website by YFind.
Temporary check results are associated with the current session and are not published automatically. Results that are not connected with a domain submission are deleted after no more than 24 hours.
The legal basis for providing the requested check is Article 6(1)(b) GDPR. Security and abuse-prevention measures are additionally based on Article 6(1)(f) GDPR.
6. Abuse prevention and rate limiting
To prevent automated mass requests and misuse, YFind may create a pseudonymised identifier derived from the requesting IP address. This identifier is generated using a secret server-side key and is not published.
The identifier is used only for rate limiting and security purposes and is deleted after no more than seven days.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the protection of YFind and third-party websites against excessive or abusive automated requests.
7. Suggesting a domain
After completing a technical check, you may voluntarily suggest the domain for inclusion in the public YFind directory.
The submission form may process:
- the submitted domain,
- a display name,
- a description,
- a category,
- a language code,
- an optional email address, and
- the date and status of the submission.
The email address is used only if a question concerning the submission arises. It is not displayed publicly.
Submitted domains are reviewed manually. A submission does not create a right to publication. Until approval, the domain is not included in the public directory or sitemap.
The legal basis is Article 6(1)(b) GDPR insofar as processing is necessary to handle the submission requested by you. Manual review, abuse prevention and operation of the curated directory are also based on Article 6(1)(f) GDPR.
8. Publication in the YFind directory
If a submission is approved, the following information may be published:
- domain name,
- display name,
- description,
- category and language, and
- publicly available technical check results.
The optional submitter email address, IP-related rate-limit information and internal review notes are never published.
Approved entries may be indexed by search engines. An approved entry remains available until it is removed, the website ceases to qualify for inclusion or the operator requests a justified review or removal.
9. Retention of submissions
- Pending submissions are deleted if no decision has been made within 90 days.
- Rejected submissions and associated contact details are deleted no later than 30 days after the decision, unless temporary retention is necessary to prevent repeated misuse.
- Optional email addresses are deleted no later than 30 days after the review has been completed.
- Approved directory entries remain stored while they are published.
- Historical technical check results are retained for no more than 12 months.
10. Contact requests
If you contact us by email, we process the information contained in your message, including your email address, in order to respond.
The legal basis is Article 6(1)(b) GDPR where the communication concerns a service or submission requested by you. In other cases, processing is based on Article 6(1)(f) GDPR and our legitimate interest in responding to enquiries.
Correspondence is deleted when the matter has been completed and no statutory retention obligation applies.
11. Recipients of data
Personal data may be processed by the hosting provider and by technical service providers acting on our instructions where this is necessary to operate and secure YFind.
Data is otherwise disclosed only where required by law, necessary for the establishment or defence of legal claims, or expressly requested by the person concerned.
YFind does not sell personal data to advertisers or other third parties.
12. International data transfers
YFind does not intentionally transfer personal data to countries outside the European Union or the European Economic Area.
This statement must be updated before introducing a content delivery network, external analytics service, external font provider or another service whose processing may take place outside the European Economic Area.
13. Automated decision-making
YFind may automatically classify technical check results as successful, noteworthy or problematic. These classifications do not produce legal effects and are not automated decisions within the meaning of Article 22 GDPR.
Decisions concerning publication in the public directory are made manually.
14. Your rights
Subject to the applicable legal requirements, you have the right to:
- request access to your personal data,
- request correction of inaccurate data,
- request deletion of your data,
- request restriction of processing,
- receive data you provided in a portable format, where applicable,
- object to processing based on legitimate interests, and
- lodge a complaint with a data-protection supervisory authority.
To exercise your rights, please contact: [email protected].
15. Right to object
Where processing is based on Article 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation. We will then stop the processing unless compelling legitimate grounds override your interests, rights and freedoms, or the processing is required for legal claims.
16. Security
YFind uses encrypted HTTPS connections and appropriate technical and organisational measures intended to protect data against unauthorised access, alteration, loss and misuse.
17. Changes to this Privacy Policy
This Privacy Policy may be updated when YFind's functions, data processing activities or legal requirements change. The current version is always published on this page.