Switching & data portability
Information under Art. 26 and Art. 28 Data Act
Anyone using our web hosting, cloud or SaaS services should be able to switch at any time — to another provider or to their own infrastructure. This page describes how that works, which data comes out in which formats, and where your data is held.
Regulation (EU) 2023/2854 (Data Act) requires providers of data processing services to make this information available (Art. 26) and to keep it up to date on their website (Art. 28). The corresponding contractual provisions are set out in section 13 of our terms and conditions .
How switching works
- Announce the switch — informally to info@hexle.at. The notice period for initiating a switch is at most two months; shorter periods agreed in your contract continue to apply in your favour.
- Transitional period — 30 calendar days from the end of the notice period. The service keeps running, we assist with the transfer and flag any known risks to uninterrupted operation. You may extend this period once, by a duration you consider appropriate.
- Retrieval period — after the transitional period you have at least a further 30 calendar days to retrieve your data.
- Erasure — after that we erase all exportable data and digital assets in full, provided the switch has been completed. Statutory retention obligations remain unaffected.
Should the 30-day transitional period not be technically feasible, we tell you within 14 working days of your request, with reasons and an alternative period not exceeding seven months.
Procedures, formats and limitations
| Data category | Procedure | Format | Known limitations |
|---|---|---|---|
| Website and application files | SFTP, FTPS or archive download | Original files, directory structure preserved; optionally tar.gz or zip | none |
| Databases | Dump on request or self-service export | SQL dump (MySQL/MariaDB, PostgreSQL), CSV per table on request | Server-side objects such as events and triggers may need adapting to the target system |
| Mailboxes | IMAP access or export | IMAP, Maildir or mbox; folder structure and attachments preserved | Server-side filter rules and autoresponders are provider-specific and are supplied as a text list |
| DNS zone data | Export on request | BIND zone file (RFC 1035) | none |
| Configuration and settings data | Export on request | JSON or CSV | Only settings made by you; platform-internal parameters see below |
| Content and master data of the SaaS services | In-application export or on request | JSON or CSV, structured and machine-readable | File attachments are delivered separately as an archive |
| Access and error logs | Export on request | Plain text, combined log format | Only where attributable to you and still retained (30 days) |
Not transferred is data specific to the internal functioning of our platform: monitoring and capacity data, configurations of our security and defence systems, metadata of the backup and orchestration systems, and infrastructure logs not attributable to an individual customer. These exclusions neither hinder nor delay a switch.
No harmonised interoperability standards or common specifications for our types of service are currently published in the central Union database under Art. 35(8) Data Act. On request we therefore export all exportable data in a structured, commonly used and machine-readable format, and we update this statement once relevant standards exist.
Switching charges
We charge no fees for completing a switch. From 12 January 2027 switching charges are prohibited in any case (Art. 29(1) Data Act). This does not affect the ongoing service fees until the contract ends, nor any agreed provisions on early termination; we inform you about both before the contract is concluded.
We are not aware of any of our services for which switching would be highly complex or costly, or impossible without significant interference with data, digital assets or service architecture.
Jurisdiction of the ICT infrastructure
| Service | Infrastructure operator | Location | Jurisdiction |
|---|---|---|---|
| Web hosting, e-mail, databases | IONOS SE | Germany | Germany / EU |
| Server infrastructure of the cloud and SaaS services | Pein GbR | Germany | Germany / EU |
| Content delivery and DDoS protection | Cloudflare Inc. | global edge network | USA; EU-US Data Privacy Framework, supplemented by standard contractual clauses |
The complete list of sub-processors with data categories and third-country safeguards is available at Approved sub-processors .
Safeguards against international governmental access
We have taken the following measures to prevent international governmental access to, or transfer of, non-personal data held in the Union where such access or transfer would conflict with Union law or the national law of the Member State concerned (Art. 28(1)(b) Data Act):
- Technical: storage and processing exclusively on infrastructure within the European Union; transport encryption throughout, encryption of data at rest and of backups; access logged and limited to what is necessary.
- Organisational: access only for named authorised individuals bound to confidentiality; requests from authorities are handled exclusively by management, and every request is documented and legally assessed.
- Contractual: data processing agreements under Art. 28 GDPR with all sub-processors; for providers with a third-country nexus, standard contractual clauses in addition to the EU-US Data Privacy Framework.
- Procedural: we comply with a request from a third-country authority only where it is based on an international agreement in force or the conditions of Art. 32(3) Data Act are met. We then provide only the minimum permissible amount of data and inform the affected customer beforehand, as far as legally permitted.
When these rules do not apply
For services developed individually for a single customer and not offered at broader commercial scale from our service catalogue, the obligations under Art. 23(d), Art. 29 and Art. 30(1) and (3) Data Act do not apply. The same holds for services provided for a limited period for testing and evaluation. We inform you before the contract is concluded which obligations do not apply in your case.
Contact
Questions about switching or data export: info[a]hexle.at
Data protection matters: privacy@hexle.at · Security vulnerabilities: hexle.at/en/security