Supplementary Terms / Service-Specific Conditions of regfish GmbH

13 sectionsapprox. 21 min read
Contents

As of June 2026

Note on the authoritative language: This English text is a non-binding convenience translation. The legally binding and authoritative version is the German original (available at regfish.de/legal/additional-terms). In the event of any discrepancy between this translation and the German version, or in the event of a dispute, the German version shall prevail.

Preamble and Scope

(1) These Supplementary Terms / Service-Specific Conditions (hereinafter the “Supplementary Terms”) specify and supplement the General Terms and Conditions of regfish GmbH (hereinafter “regfish”; available at regfish.de/legal/terms) for the individual services offered by regfish. The provider and contractual partner is regfish GmbH, Bleichstraße 8a, 35390 Gießen, Germany (managing directors: Carsten Müller and Andreas Mallek; commercial register at the Local Court (Amtsgericht) of Gießen, HRB 6589). (2) Insofar as these Supplementary Terms set out special obligations and conditions for a service that go beyond the General Terms and Conditions, these shall apply additionally. In all other respects, the General Terms and Conditions remain unaffected. (3) The following order of precedence of the contractual documents shall apply, insofar as they are incorporated in the individual case; in the event of conflicts, the higher-ranking document shall prevail in each case: individual agreement; for data protection, the data processing agreement (regfish.de/legal/dpa); Supplementary Terms / service description (this document); Service Level Agreement (regfish.de/legal/sla); General Terms and Conditions (regfish.de/legal/terms); Acceptable Use Policy (regfish.de/legal/acceptable-use). (4) These Supplementary Terms are addressed to customers (hereinafter uniformly the “customer”). A consumer is any natural person who enters into a legal transaction for purposes that predominantly can be attributed neither to their commercial nor to their self-employed professional activity (section 13 of the German Civil Code (BGB)); a business customer (entrepreneur within the meaning of section 14 BGB) is anyone who acts in the exercise of their commercial or self-employed professional activity. Clauses that expressly apply only to business customers are marked as such; vis-à-vis consumers, statutory rights remain unaffected. (5) Prices result from the price list valid at the time or from the product presentation during the ordering process at regfish.de. These Supplementary Terms do not contain any price information. (6) All services are subject to the Acceptable Use Policy (regfish.de/legal/acceptable-use). Availability commitments apply only insofar as a Service Level Agreement (regfish.de/legal/sla) has been expressly agreed or booked. Details on the processing of personal data result from the privacy policy (regfish.de/legal/privacy).

Section A: Domains (Registration, Transfer, Renewal)

§ A1 Service Description and Role of regfish

(1) regfish brokers and administers the registration, transfer and renewal of domains under various top-level domains (TLDs). In doing so, regfish acts as a broker and administrator by way of agency (Geschäftsbesorgung). Depending on the TLD, the actual domain contract and the right of use in the domain exist directly or indirectly vis-à-vis the competent registry (hereinafter the “registry”), for example DENIC eG for “.de”, EURid for “.eu”, nic.at for “.at” or Nominet for “.uk”. (2) The customer becomes the domain holder or substantively entitled party vis-à-vis the competent registry. A domain is not property but a contractual right of use vis-à-vis the registry. (3) regfish owes the careful endeavour to register, transfer or renew the desired domain, but does not owe any success in registration or allocation. Domains are allocated on a “first come, first served” basis and in accordance with the requirements of the respective registry. There is no claim to the allocation of a particular domain; availability indications are non-binding until confirmed by the registry. Registration may fail in particular due to lack of availability, an opposing registry decision, a dispute or dispute-resolution proceeding, or for legal reasons.

§ A2 Incorporation of the Registry Conditions and Domain Policies

(1) In addition, the respective current conditions, policies and allocation rules of the competent registry apply to the respective domain, in particular the DENIC Domain Terms and Conditions and DENIC Domain Guidelines, the EURid Registration Terms and Conditions and the EURid Registration Policy (including Regulation (EU) 2019/517), the General Terms and Conditions and Registration Guidelines of nic.at, as well as the Terms and Conditions of Domain Name Registration of Nominet. (2) For generic TLDs, the requirements of ICANN apply additionally, in particular the Registrar Accreditation Agreement (RAA) in its respective valid version, the Registration Data Policy, the Transfer Policy and the dispute-resolution rules (UDRP/URS). (3) The relevant registry and ICANN conditions are made accessible to the customer prior to conclusion of the contract; they can be accessed via the respective registry as well as via regfish. The customer acknowledges these conditions upon ordering the respective domain. Insofar as mandatory registry or ICANN requirements conflict with these Supplementary Terms and regfish cannot influence them, the registry or ICANN requirements shall prevail.

§ A3 Mandatory Information, Data Accuracy and Verification

(1) The customer provides complete, correct and up-to-date holder and contact data for domain registration and administration. In the case of legal persons, the binding legal form as well as a telephone contact option must in particular be provided. The customer notifies any changes to the data without undue delay and keeps them up to date. (2) Due to statutory requirements (in particular the national transposition of Directive (EU) 2022/2555 (NIS2) for “.de” domains), registries carry out basic checks and verifications of holder and contact data in domain transactions, for example upon new registration, data change and change of holder. The customer cooperates with verification and validation requests of the registry within the applicable time limits and submits requested evidence in good time. regfish is entitled to forward such requests to the customer. (3) If the customer does not cooperate with a verification, or does not do so within the applicable time limit, the registry may place the affected domain in quarantine or delete it. regfish is not responsible for this and is not liable for any consequences arising therefrom, insofar as regfish has duly forwarded the request.

§ A4 Publication of Holder Data (RDAP/Whois)

(1) Personal data and organisational data required for domain registration are transmitted to the competent registry. Registries publish part of the registration data via the Registration Data Access Protocol (RDAP) or, insofar as still operated, via Whois. (2) In the case of “.de” domains, due to the NIS2 transposition, holder data of legal persons (in particular name, address, email address and telephone number) are displayed publicly via RDAP; data of natural persons, by contrast, remain protected and are not displayed publicly. For other TLDs, the scope and nature of publication are governed by the requirements of the respective registry and of ICANN. Details of the data processing are governed by the privacy policy (regfish.de/legal/privacy).

§ A5 AuthInfo, Transfer and Transfer Lock

(1) For the takeover of a domain by another provider (“outbound transfer”), regfish provides the entitled holder with the required AuthInfo/AuthCode and does not unreasonably delay its release. Vis-à-vis consumers, the outbound transfer is not made dependent on the settlement of outstanding claims; a right of retention in respect of the AuthInfo/AuthCode does not exist in this regard. Only vis-à-vis business customers may release be made dependent on the settlement of due, undisputed or legally established fees arising from the same contractual relationship. (2) To protect against unauthorised transfer, a transfer lock (Transfer Lock/ClientTransferProhibited) may be set; regfish lifts this at the request of the entitled holder. Registry-side lock periods must be observed, in particular the 60-day lock applicable to many generic TLDs after registration or change of holder, as well as, in the case of “.eu”, the time-limited validity of the AuthCode. (3) When taking over a domain to regfish (“inbound transfer”), regfish endeavours to initiate the process promptly. Success depends on a correct AuthInfo, any registry locks, ongoing dispute or dispute-resolution proceedings, as well as the required data verification.

§ A6 Change of Holder and Trade

(1) The change of the domain holder (change of holder/trade) is a separate process which, depending on the TLD, requires its own confirmation and verification steps. For generic TLDs, the change of holder may trigger a 60-day transfer lock. (2) The customer ensures that all data and confirmations required for a change of holder are available and cooperates with the data verification.

§ A7 Term, Renewal, Deletion, Transit and Redemption

(1) Domains are registered for the subscription period specified by the registry. This technical subscription period is to be distinguished from the term of any framework or continuing-obligation relationship. (2) Insofar as agreed, the domain is automatically renewed for the respective subscription period at the price valid at the time, unless terminated in good time before expiry. Termination and deletion periods are TLD-dependent. Vis-à-vis consumers, the statutory provisions on term and tacit renewal apply (section 309 no. 9 BGB); consumers may terminate continuing contracts for a fee via the button provided for this purpose (section 312k BGB). (3) Upon termination of the contract or non-payment, the domain may be deleted or, in the case of “.de”, transferred into the direct administration of DENIC (TRANSIT); the holder must then, within the period stated in the TRANSIT notice, arrange for a change of provider or for deletion, failing which the domain will be deleted. (4) After deletion, for many TLDs (such as “.de”) there is a protection period (Redemption Grace Period, regularly 30 days) during which only the previous holder or a party authorised by them can reclaim the domain. A restoration may incur separate costs and require the customer’s cooperation; success of the recovery is not warranted.

§ A8 Dispute and Dispute Resolution

(1) regfish implements binding decisions from registry dispute proceedings (such as DENIC Dispute), from dispute-resolution proceedings (UDRP, URS, ADR), as well as from court or authority orders (in particular suspension, transfer or deletion of the domain). (2) During ongoing dispute, dispute-resolution, court or authority proceedings, the transfer of a domain may be blocked. A DENIC Dispute entry leaves the domain usable but excludes its transfer.

§ A9 Responsibility for Name and Trademark Rights; Indemnification

(1) The customer bears sole responsibility for ensuring that the choice and use of the domain do not infringe any rights of third parties, in particular no name, trademark, identifier or competition rights. regfish does not examine the legal permissibility of chosen domains. (2) The customer indemnifies regfish against claims of third parties asserted against regfish on account of an unlawful choice or use of a domain or unlawful content for which the customer is responsible, including the necessary and reasonable costs of legal defence. Vis-à-vis consumers, this applies only insofar as the consumer is responsible for the claim being made. regfish informs the customer without undue delay of any such claim and gives the customer the opportunity to conduct the legal defence.

§ A10 Premium and Special-Price Domains

(1) Certain domains are listed by the registry as premium or special-price domains and are subject to differing fees that are higher than for standard domains. These higher fees may also be incurred upon renewal and may change compared to the initial registration. (2) The price indicated during the ordering process applies for the indicated subscription period. Price changes by the registry as well as any ICANN transaction fees are passed on.

Section B: DNS Services

§ B1 Service Description

(1) regfish offers DNS-related services, in particular DNS hosting (authoritative name servers), DNSSEC (signing of zones), DynDNS (dynamic updating of DNS records), Hidden Primary (concealed primary name server), as well as DNS automation via the regfish API (see Section G). (2) The specific scope of services results from the respective product presentation during the ordering process.

§ B2 Availability

(1) A particular availability of the DNS services is warranted only insofar as a Service Level Agreement (regfish.de/legal/sla) has been expressly agreed or booked. Without such an agreement, the customary provision appropriate to the state of the art applies.

§ B3 Customer’s Responsibility for Zone Content

(1) The customer is responsible for the accuracy, lawfulness and maintenance of the DNS zones and records administered by them, including the correct configuration of DNSSEC and the references to target systems. Misconfigurations by the customer shall not be to the detriment of regfish. (2) The use of the DNS services is subject to the Acceptable Use Policy (regfish.de/legal/acceptable-use). Misuse, in particular use for unlawful purposes, attacks or violations of the Acceptable Use Policy, is prohibited; abuse reports are to be directed to abuse@regfish.de.

Section C: TLS/SSL and Other Certificates

§ C1 Service Description and Role of regfish

(1) regfish brokers and administers digital certificates of publicly trusted certification authorities (hereinafter “CA”), in particular from DigiCert, Sectigo, GeoTrust, Thawte and RapidSSL. Depending on the product, domain-validated (DV), organisation-validated (OV) and extended-validation (EV) TLS/SSL certificates, wildcard and SAN/multi-domain certificates, S/MIME certificates as well as code-signing certificates are offered. (2) regfish is itself not a CA and not a qualified trust service provider within the meaning of Regulation (EU) No 910/2014 (eIDAS). regfish forwards applications and validation data to the issuing CA and administers the lifecycle of the certificates.

§ C2 Incorporation of the CA Conditions and Precedence

(1) In addition, the conditions of the issuing CA apply to the respective certificate, in particular its Subscriber Agreement as well as its Certificate Policy / Certification Practice Statement (CP/CPS). regfish refers to these conditions prior to conclusion of the contract; the customer accepts them upon placing the order. (2) The requirements of the CA/Browser Forum (in particular the TLS Baseline Requirements, the S/MIME Baseline Requirements and the Code Signing Baseline Requirements) in their respective valid version are also binding. regfish cannot contract out of these requirements; they apply to the customer by virtue of the incorporation of the CA conditions. In the event of conflict, the mandatory CA and CA/Browser Forum requirements shall prevail over these Supplementary Terms, insofar as regfish cannot influence them.

§ C3 Validation and Cooperation (Duty of the Customer)

(1) The customer warrants that all information transmitted for DV, OV, EV or S/MIME validation is correct, complete and up to date, and that the customer is entitled to use the relevant domain as well as to bind the stated organisation. (2) The customer cooperates with the domain, organisation and identity validation without undue delay, for example by setting a DNS record, by file upload, by confirmation email or by submitting suitable evidence. (3) Issuance as well as the maximum validity period and the permissible reuse of validated data are governed by the respective applicable requirements of the CA/Browser Forum. These requirements change; in particular, the maximum certificate validity periods will be shortened in stages from 2026. regfish does not owe any validity period exceeding the respective applicable requirements. The shortened validity periods may make more frequent re-validation and re-issuance necessary; automation via the regfish API (Section G) is recommended.

§ C4 Certificate Transparency and Publicity (Notice)

(1) The customer takes note of the fact that publicly trusted TLS certificates are entered into public Certificate Transparency logs (CT logs). As a result, the domain names contained in the certificate, and in the case of OV and EV certificates the organisation name, become permanently and irrevocably publicly viewable. Deletion from the CT logs is technically not possible. (2) The customer takes this into account when selecting the names to be certified, in particular for internal hostnames and subdomains as well as when choosing between wildcard and SAN certificates.

§ C5 Key Protection and Code Signing (Duty of the Customer)

(1) The customer is solely responsible for the secure generation and safekeeping of their private keys. (2) For code-signing certificates, key generation and storage take place mandatorily on certified hardware (hardware security module or token) in accordance with the respective applicable Code Signing Baseline Requirements of the CA/Browser Forum. Software- or browser-based key safekeeping is excluded. The responsibility for the hardware-supported key protection lies with the customer.

§ C6 Revocation and Security Notification (Duty of the Customer)

(1) The customer notifies regfish or the CA without undue delay if a private key has been compromised or there is reason to fear this, if certificate information becomes incorrect or a misuse exists; the customer immediately ceases use of the affected certificate. regfish ensures organisationally that such notifications are forwarded to the CA without undue delay. (2) The customer takes note of the fact that the CA must revoke certificates in accordance with the requirements of the CA/Browser Forum, in particular within 24 hours in the case of key compromise, misuse or mis-issuance, as well as within five days in the case of incorrect information or rule violations. Such revocation may take place at any time and without reimbursement, insofar as the ground for revocation lies within the customer’s sphere or is mandatory. If a revocation is based on a circumstance for which regfish is responsible, any reimbursement or compensation claims remain unaffected. A re-issuance or a key change (re-key) takes place in accordance with the CA.

§ C7 Disclosure of Data to the CA

(1) For the issuance and administration of the certificates, regfish transmits the required application and validation data to the issuing CA and its validation bodies. From a data-protection perspective, these are independent controllers in this respect and not processors of regfish. Details, including any transfers to third countries and the safeguards provided for this, are governed by the privacy policy (regfish.de/legal/privacy).

§ C8 No Withdrawal After Issuance; Liability

(1) Upon the expressly requested issuance of the certificate, the brokerage and provision service is fully rendered. In the case of consumers, any right of withdrawal lapses upon full performance of the service, after the consumer has expressly consented to the commencement of performance before expiry of the withdrawal period and has confirmed their awareness of the loss of the right of withdrawal (see withdrawal instructions, regfish.de/legal/withdrawal). After issuance, withdrawal is no longer possible. (2) For the services incumbent upon the CA, in particular the validation decision, the issuance, the revocation and the operation of the CT infrastructure, regfish is liable only within the scope of its own breaches of duty; in all other respects, the liability and reliance provisions of the CA apply. The liability provisions of the General Terms and Conditions (regfish.de/legal/terms) remain unaffected.

Section D: Email Services

§ D1 Service Description

(1) regfish offers email services, in particular email mailboxes and email forwarding. The specific scope of services, including any storage limits and sending limits, results from the respective product presentation during the ordering process.

§ D2 Anti-Spam and Mail Policy

(1) The use of the email services is subject to the Acceptable Use Policy (regfish.de/legal/acceptable-use). The sending of unsolicited bulk emails (spam), the use for unlawful purposes, as well as violations of applicable anti-spam and mail policies, are prohibited. regfish is entitled to take measures against misuse within the framework of the Acceptable Use Policy and the statutory requirements.

§ D3 Storage Limits and Availability

(1) Storage and other resource limits result from the respective product presentation. A particular availability of the email services is warranted only insofar as a Service Level Agreement (regfish.de/legal/sla) has been expressly agreed or booked. (2) The customer is co-responsible for backing up their email data in a manner appropriate to their risk. The liability provisions for data loss under the General Terms and Conditions (regfish.de/legal/terms) remain unaffected.

Section E: Web Hosting / WordPress Hosting

§ E1 Service Description

(1) regfish offers web hosting and WordPress hosting. The specific scope of services, in particular storage space, computing resources and other resource limits, results from the respective product presentation during the ordering process.

§ E2 Resources and Fair Use

(1) The resources made available are to be used within the framework of reasonable use (fair use). A demand significantly exceeding the agreed limits or customary use may lead to an adjustment or restriction of the service in accordance with the product presentation and the Acceptable Use Policy (regfish.de/legal/acceptable-use).

§ E3 Security, Updates and Responsibility of the Customer

(1) The customer is responsible for the applications, content and configurations they use, in particular for the currency and security of the software installed by them (such as the WordPress core, themes and plugins), insofar as the maintenance thereof is not expressly covered by a booked managed-service package. Security vulnerabilities in software managed by the customer shall not be to the detriment of regfish. (2) Prohibited and unlawful content as well as abusive use are governed by the Acceptable Use Policy (regfish.de/legal/acceptable-use).

§ E4 Backups and Data Backup

(1) Insofar as regfish provides backups, the scope and frequency result from the respective product presentation. Irrespective thereof, the customer bears the duty to back up their data regularly and independently in a manner appropriate to the respective risk. The liability provisions for data loss under the General Terms and Conditions (regfish.de/legal/terms) remain unaffected.

§ E5 Availability

(1) A particular availability of the web hosting is warranted only insofar as a Service Level Agreement (regfish.de/legal/sla) has been expressly agreed or booked.

Section F: Web Forwarding

§ F1 Service Description

(1) regfish offers the setup of HTTP forwardings (web forwardings) with which calls to a domain are forwarded to a target determined by the customer.

§ F2 Responsibility for Target Content

(1) The customer is solely responsible for the forwarding target determined by them and for the content available there. They ensure that the forwarding and the target content do not infringe any rights of third parties and any statutory requirements. The Acceptable Use Policy (regfish.de/legal/acceptable-use) applies accordingly. (2) The web forwarding is provided as a best-effort service without a separate availability commitment, unless a Service Level Agreement (regfish.de/legal/sla) has been expressly agreed or booked.

Section G: Public API

§ G1 Service Description

(1) regfish provides a public application programming interface (API) for the automation of DNS- and TLS-related operations. The scope of functions results from the respective current technical documentation.

§ G2 Use, Rate Limits and Key Security (Duty of the Customer)

(1) The use of the API is subject to the respective technical documentation, these Supplementary Terms and the Acceptable Use Policy (regfish.de/legal/acceptable-use). regfish is entitled to set and enforce reasonable usage limits (rate limits) to safeguard operations. (2) The customer treats their API keys and access credentials confidentially, secures them against unauthorised access and notifies any loss or misuse without undue delay. The customer is responsible for actions carried out via their access credentials, insofar as the customer is responsible for the misuse.

§ G3 Misuse and Availability

(1) Abusive use of the API, in particular the circumvention of usage limits, automated attacks or violations of the Acceptable Use Policy, is prohibited. regfish is entitled to restrict or suspend access in the event of misuse. (2) No particular availability is warranted for the API, unless a Service Level Agreement (regfish.de/legal/sla) has been expressly agreed or booked.

Section H: Resellers

§ H1 Passing On to Third Parties

(1) The customer is entitled to pass on services obtained from regfish to third parties (end customers) for a fee (reseller). The customer remains the sole contractual partner vis-à-vis regfish and owes the agreed fees independently of their contracts with end customers.

§ H2 Self-Responsible End-Customer Contracts and Information Obligations

(1) The customer concludes contracts with their end customers on their own responsibility, in their own name and for their own account. The customer is solely responsible for compliance with the statutory obligations existing vis-à-vis their end customers, in particular for information, consumer-protection, withdrawal and data-protection obligations, as well as for the effective incorporation of the relevant registry, ICANN and CA conditions. (2) The customer is responsible for the completeness and accuracy of the data provided for their end customers and for their cooperation, in particular in the data verification (Section A § A3) and the certificate validation (Section C § C3).

§ H3 Indemnification

(1) The customer indemnifies regfish against claims of third parties, in particular of their end customers, that are based on a breach of the customer’s obligations under the reseller relationship for which the customer is responsible, including the necessary and reasonable costs of legal defence. Insofar as the customer is a consumer, this applies only insofar as the consumer is responsible for the claim being made. regfish informs the customer without undue delay of any such claim and gives the customer the opportunity to conduct the legal defence.

Section I: Optional Further Services

§ I1 Server and Colocation Services (Insofar as Offered)

(1) Insofar as regfish offers server or colocation services in an individual case, the separately agreed service descriptions and conditions apply additionally to these. Such services are not part of the regular range of services in the online shop.

Final Provisions

(1) These Supplementary Terms supplement the General Terms and Conditions (regfish.de/legal/terms). In all other respects, the General Terms and Conditions, the Service Level Agreement (regfish.de/legal/sla), the Acceptable Use Policy (regfish.de/legal/acceptable-use), the withdrawal instructions (regfish.de/legal/withdrawal), the privacy policy (regfish.de/legal/privacy) as well as the data processing agreement (regfish.de/legal/dpa) apply in their respective valid version. (2) Should individual provisions of these Supplementary Terms be or become invalid, the validity of the remaining provisions remains unaffected; the statutory provisions shall take the place of the invalid provisions. regfish GmbH, Bleichstraße 8a, 35390 Gießen, support@regfish.de, Telephone 0641 / 49 888 530

As of June 2026