Last updated: 30 August 2026
This Notice explains how boxbank s.r.o., operating under the WEBDANGER brand, addresses applicable requirements of Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (the “EU Data Act”).
The Data Act has applied since 12 September 2025.
For WEBDANGER, this Notice focuses primarily on Services that qualify as data processing services, including relevant cloud, infrastructure, platform or software services.
It explains:
- whether a Service may fall within the switching framework;
- Customer rights to switch provider or move to on-premises infrastructure;
- exportable data and digital assets;
- switching and porting procedures;
- data retrieval and deletion;
- technical interfaces and interoperability;
- switching charges;
- international-access transparency for non-personal data;
- and the difference between Data Act portability and personal-data rights.
This Notice should be read together with the:
- Terms of Service;
- Privacy Policy;
- Acceptable Use & Abuse Policy;
- Digital Services Act Notice;
- and any applicable service-specific terms.
PROVIDER IDENTITY
1. Operator
WEBDANGER is operated by:
boxbank s.r.o.
Registered office:
Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Company identification number (IČO):
24048232
Commercial Register:
Municipal Court in Prague, Section C, File No. C 437675
Primary website:
webdanger.com
Contact:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
SCOPE
2. Data processing services
The Data Act defines a “data processing service” by reference to digital services that provide ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources that can be rapidly provisioned and released with minimal management effort or provider interaction.
Depending on the product architecture, relevant delivery models may include:
- Infrastructure as a Service (IaaS);
- Platform as a Service (PaaS);
- Software as a Service (SaaS);
- cloud infrastructure;
- cloud storage;
- and other qualifying data processing services.
3. Not every WEBDANGER Service is covered in the same way
The following activities do not automatically become Chapter VI data processing services merely because they involve technology:
- website design;
- branding;
- software-development projects;
- consulting;
- domain registration;
- DNS administration;
- professional support;
- or one-off project delivery.
A managed hosting, cloud, server, storage, SaaS or similar Service may, however, fall within the Chapter VI framework depending on its actual technical and contractual structure.
4. Domain services
Domain registration and transfer are principally governed by the relevant:
- registry rules;
- registrar rules;
- ICANN rules where applicable;
- upstream-provider terms;
- and WEBDANGER domain terms.
A domain transfer is not treated as identical to a Data Act cloud-switching process merely because both involve moving a service.
5. Future products
If WEBDANGER later supplies connected products or related IoT services within Chapters II–III of the Data Act, additional product-data access and sharing obligations may apply.
This Notice does not represent that WEBDANGER currently manufactures connected products or operates a general IoT data platform.
SWITCHING RIGHTS
6. Removing switching obstacles
Where WEBDANGER is the source provider of a data processing service covered by Chapter VI of the Data Act, WEBDANGER does not intentionally impose pre-commercial, commercial, technical, contractual or organisational barriers that unlawfully prevent the Customer from:
- terminating the covered Service following the applicable switching process;
- entering into a contract with a different provider;
- porting exportable data and applicable digital assets;
- moving to on-premises ICT infrastructure;
- achieving the applicable level of functional equivalence where the Data Act requires source-provider assistance;
- or, where relevant, using data processing services from several providers in parallel.
7. Destination choices
Where the Data Act switching framework applies, a Customer may choose, as applicable, to:
- switch to another provider of data processing services;
- move to the Customer's on-premises ICT infrastructure;
- port/export the relevant exportable data and digital assets;
- erase the relevant exportable data and digital assets when terminating instead of switching;
- or use multiple providers in parallel where the relevant Data Act provisions apply.
8. No unnecessary lock-in
WEBDANGER does not intentionally create artificial lock-in by requiring Customers to keep a qualifying data processing Service solely because their exportable data cannot be retrieved in a usable form.
Technical limitations that genuinely exist are documented rather than concealed.
DATA EXPORT
9. Exportable data
For the purposes of the Data Act switching provisions, “exportable data” includes input and output data, including relevant metadata, directly or indirectly generated or co-generated by the Customer's use of the data processing Service.
The statutory definition excludes assets or data protected by intellectual-property rights or constituting trade secrets of the provider or third parties.
10. Examples of potentially exportable Service data
Depending on the Service, exportable data may include categories such as:
- Customer-uploaded files;
- Customer-created records;
- databases controlled by the Customer;
- application data;
- Customer content;
- configuration data where portable;
- Customer-generated logs where included in the Service;
- Customer-created website/project content;
- output data produced through use of the Service;
- and metadata required to understand or port the exportable data.
The exact export set is defined per Service.
11. Digital assets
Where applicable, the switching process may also concern Customer digital assets that can be ported under the relevant contract and law.
The portable set depends on the architecture and may differ from the statutory definition of exportable data.
12. Internal provider data
The Data Act does not require WEBDANGER to disclose or transfer provider or third-party assets protected by intellectual-property rights or trade secrets merely because a Customer requests a switch.
Internal categories may include, depending on the system:
- proprietary orchestration logic;
- internal anti-fraud rules;
- security detection logic;
- internal risk scores;
- proprietary provider algorithms;
- confidential infrastructure architecture;
- internal model weights;
- third-party licensed material;
- or other protected assets.
Any exclusion must not be used as a pretext to obstruct or delay a switching process that the Data Act requires.
13. Security limitations
WEBDANGER is not required to compromise the security or integrity of:
- the Customer's Service;
- another Customer;
- WEBDANGER systems;
- or a destination provider
in order to perform a switching operation.
Security controls may therefore apply to exports and transfer operations.
EXPORT FORMATS
14. Machine-readable formats
Where Article 30 requires it and no applicable common specification or harmonised interoperability standard governs the relevant same-service-type switch, WEBDANGER exports applicable exportable data, at the Customer's request, in a:
- structured;
- commonly used;
- and machine-readable
format.
15. Service-specific formats
Depending on the underlying Service, appropriate formats may include:
- JSON;
- CSV;
- SQL/database dumps;
- ZIP/TAR archives;
- standard backup formats;
- standard application export formats;
- standard DNS-zone formats where relevant to a separate DNS/domain process;
- or another documented machine-readable format.
A format is not promised merely because it appears in this list. The actual available formats are documented for each production Service.
16. Online portability register
For covered data processing Services, WEBDANGER makes available or references an up-to-date online register describing, as applicable:
- exportable data structures;
- data formats;
- relevant standards;
- open interoperability specifications;
- switching methods;
- porting methods;
- known restrictions;
- and known technical limitations.
The applicable register is kept aligned with the production Service.
CUSTOMER PORTAL
17. Data & Portability controls
Where technically appropriate for a production Service, WEBDANGER may provide a Customer-facing Data & Portability or equivalent interface.
It may include controls such as:
Download service data
Export service
Start provider switch
Switch status
Move to own infrastructure
Request service erasure
The availability of a self-service button is a product implementation choice; the underlying statutory rights are not limited merely because a particular Service requires an assisted switching process.
18. Personal-data download is different
A Data Act service export is not the same thing as exercising rights under the GDPR.
For clarity, WEBDANGER may provide separate mechanisms for:
Privacy / personal data
Requests concerning personal data under the Privacy Policy and applicable data-protection law.
Service portability / switching
Export and switching of covered Service data and digital assets under the Data Act and contract.
The same data may sometimes appear in both processes, but the legal purpose and scope are different.
SWITCHING PROCEDURE
19. Starting a switch
Where the Data Act applies, the Customer may request a switch using the available account, support or contractual channel.
A switching request may ask the Customer to specify:
- affected Service;
- destination provider, where applicable;
- destination details required to carry out the transfer;
- whether the Customer is moving to on-premises infrastructure;
- requested export/porting method;
- and whether the Customer wants erasure after the applicable retrieval period.
20. Maximum notice period
The written contract for a covered data processing Service must provide for a maximum notice period for initiation of the switching process that does not exceed two months.
A specific WEBDANGER Service may use a shorter notice period.
21. Transitional period
After the applicable notice period, the mandatory maximum transitional period for the switching process is generally 30 calendar days.
During the transitional period, the Service contract remains applicable and WEBDANGER performs the switching obligations required by the Data Act and contract.
22. Assistance and continuity
During an applicable switching process, WEBDANGER provides the assistance required by the Data Act, which may include:
- reasonable assistance to the Customer and authorised third parties;
- support for the Customer's exit strategy;
- continued provision of the contracted functions/services during the relevant period;
- information regarding known continuity risks;
- maintenance of an appropriate security level;
- documentation;
- technical information;
- and technical support appropriate to the Service.
23. Technically unfeasible 30-day transition
If the mandatory 30-calendar-day transitional period is technically unfeasible for the relevant Service and request, the Data Act permits an alternative process.
Where this rule is relied upon, WEBDANGER:
- notifies the Customer within 14 working days after the switching request;
- explains the technical reason;
- identifies an alternative transitional period;
- and does not set that alternative period beyond seven months.
This exception is used for genuine technical infeasibility, not as a standard delay.
24. Customer extension
Without prejudice to the technical-infeasibility rule, the relevant contract provides the Customer with the right to extend the transitional period once for a period that the Customer considers more appropriate for its own purposes, as required by Article 25(5).
RETRIEVAL AND DELETION
25. Retrieval period
The contract for a covered data processing Service provides a data-retrieval period of at least 30 calendar days starting after termination of the agreed transitional period.
During that retrieval period, the applicable exportable data remains available in accordance with the contract, security requirements and Data Act.
26. Erasure after retrieval
Following successful completion of the switch, WEBDANGER erases the exportable data and digital assets directly generated by or directly relating to the Customer after:
- expiry of the required retrieval period; or
- expiry of a later alternative period agreed with the Customer,
subject to legal retention obligations and any data that lawfully falls outside the required erasure scope.
27. Deletion is not instantaneous in every storage layer
Operational deletion can involve:
- active systems;
- replicas;
- backup cycles;
- logs;
- legal holds;
- and security records.
Where a law requires specific data to remain, that requirement is handled separately.
WEBDANGER does not deliberately use technical backup architecture to defeat the Data Act erasure obligation.
CONTRACT TERMINATION
28. Termination after switching
For covered contracts, the contract specifies when the Service is considered terminated and how the Customer is notified.
Depending on the Customer's chosen exit path, this may occur:
- upon successful completion of the switching process; or
- after the applicable notice period where the Customer chooses erasure instead of switching,
in accordance with Article 25 and the applicable contract.
29. Standard service fees
The Data Act distinguishes:
- standard service fees;
- early-termination penalties, where lawfully applicable;
- and switching charges.
The abolition of switching charges does not by itself require the source provider to waive ordinary charges for the Service while the contract remains applicable.
Any applicable standard fees or early-termination terms remain subject to the contract and other applicable law.
SWITCHING CHARGES
30. Transitional switching-charge rule
Until 12 January 2027, Article 29 permits reduced switching charges, provided that they do not exceed the costs incurred by the provider that are directly linked to the switching process.
Where any such charge applies, it must comply with the Data Act and the Customer must receive the legally required pre-contract information.
31. No switching charges from 12 January 2027
From 12 January 2027, providers of data processing services may not impose switching charges on the Customer for the switching process within Article 29.
This includes Data Act switching charges such as covered data-egress charges.
32. WEBDANGER implementation direction
WEBDANGER designs standard self-service portability and switching functionality to minimise unnecessary exit costs and vendor lock-in.
Any fee displayed for a switching operation must be distinguished from:
- ordinary Service fees;
- lawfully applicable early-termination charges;
- and separately requested additional professional services that go beyond the provider's mandatory switching obligations.
33. Optional additional services
A Customer may separately request professional migration work beyond the switching actions required by the Data Act.
Examples might include:
- application redesign;
- major database transformation;
- custom re-platforming;
- destination architecture design;
- bespoke DevOps work;
- or post-migration optimisation.
Such additional services may be separately priced where:
- they are genuinely additional;
- requested by the Customer;
- and the price is agreed in advance.
They are not re-labelled mandatory switching charges.
33A. Pre-contract information on switching complexity and cost
Before entering into a covered data processing contract, WEBDANGER provides the prospective Customer with the information required by Article 29 concerning:
- applicable standard service fees;
- possible early-termination penalties;
- any reduced switching charges that may lawfully apply before 12 January 2027;
- and, where relevant, Services that involve highly complex or costly switching or for which switching is impossible without significant interference in the data, digital assets or Service architecture.
Where Article 29 requires this information to be made publicly available, WEBDANGER provides it through a dedicated website section or another easily accessible method.
This information must reflect the actual Service architecture and must not be used to create artificial lock-in.
IaaS / INFRASTRUCTURE
34. Infrastructure-level Services
For a qualifying data processing Service limited to scalable and elastic infrastructure elements such as:
- servers;
- networks;
- and virtual infrastructure resources
without providing access to the operating services, software and applications deployed on those elements, the specific Article 30(1) technical regime applies.
35. Functional equivalence assistance
For such infrastructure Services, where the Customer switches to a service covering the same service type, WEBDANGER takes the reasonable measures within its power required by Article 30 to facilitate functional equivalence.
This may include:
- capabilities;
- information;
- documentation;
- technical support;
- and appropriate tools.
Functional equivalence does not mean that WEBDANGER guarantees that a third-party destination environment is identical to the source environment.
PaaS / SaaS / OTHER COVERED SERVICES
36. Open interfaces
For covered data processing Services other than the infrastructure-only category in Article 30(1), WEBDANGER makes the open interfaces required by Article 30 available:
- to Customers;
- and to concerned destination providers,
to an equal extent and free of charge for the switching process.
Those interfaces provide sufficient information concerning the Service to facilitate development of software for data portability and interoperability.
37. Standards and common specifications
Where references to applicable common specifications or harmonised interoperability standards have been published in the central Union standards repository under Article 35, covered non-IaaS Services are made compatible according to the Article 30 timeline.
The Data Act provides a minimum 12-month period after publication of the relevant references in that repository before the Article 30(3) compatibility requirement applies.
38. No invented standard
WEBDANGER does not claim compliance with a harmonised standard merely because a similar industry format exists.
The production register identifies the actual standard/specification relied upon.
PARALLEL / MULTI-CLOUD USE
39. In-parallel use
Where applicable, the Data Act also supports interoperability for Customers using several data processing providers in parallel.
Relevant switching/interoperability requirements apply mutatis mutandis under Article 34.
40. Egress charges for in-parallel use
The general prohibition on switching charges from 12 January 2027 does not mean that every form of continuing multi-cloud data traffic must always be free.
For in-parallel use under Article 34(2), providers may impose data-egress charges only to pass on the egress costs incurred and without exceeding those costs.
WEBDANGER distinguishes ongoing multi-cloud traffic from a one-off switching process.
PROVIDER-SPECIFIC EXCEPTIONS
41. Custom-built Services
Article 31 currently provides a specific regime for certain data processing Services where:
- the majority of the main features has been custom-built for the specific needs of an individual Customer; or
- all components were developed for that individual Customer;
- and the Service is not offered at broad commercial scale through the provider's service catalogue.
For qualifying Services, Article 31 exempts specific Chapter VI obligations identified in that Article.
WEBDANGER does not apply this exception to an ordinary catalogue SaaS/cloud product merely because a Customer has custom settings or configuration.
42. Testing/evaluation Services
Chapter VI does not apply to a data processing Service provided as:
- a non-production version;
- for testing and evaluation;
- and for a limited period,
where Article 31(2) applies.
The prospective Customer must be informed before contract conclusion about applicable Article 31 exclusions.
DIGITAL OMNIBUS STATUS
43. Proposed 2025–2026 amendments are not yet relied upon
The European Commission proposed a Digital Omnibus in November 2025 that would, among other changes, modify parts of the Data Act and propose additional targeted cloud-switching relief for certain SMEs, small mid-caps and customised services/contracts.
As of 30 August 2026, that proposal remains in the EU legislative process.
WEBDANGER therefore does not treat proposed exemptions as enacted law.
If the proposal is adopted and enters into force, WEBDANGER will reassess this Notice and affected contracts.
UPSTREAM INFRASTRUCTURE
44. Hetzner
WEBDANGER may use Hetzner as an upstream infrastructure provider for relevant server/cloud Services.
The existence of an upstream provider does not by itself determine whether WEBDANGER is the “provider of data processing services” to the Customer.
The legal role depends on the actual supply chain and contract.
45. Provider-of-record analysis
Two arrangements must not be confused.
WEBDANGER sells the Service to the Customer
If the Customer contracts with WEBDANGER for a qualifying data processing Service and WEBDANGER uses Hetzner underneath it, WEBDANGER may have direct Data Act obligations as the source provider to that Customer.
Customer contracts directly with the upstream provider
If the Customer has the relevant service contract directly with Hetzner and WEBDANGER only provides consulting, migration or management services, the Chapter VI provider obligations may primarily sit with the upstream provider for that supply relationship.
Each production product is classified according to its actual contract and architecture.
46. Upstream restrictions do not justify artificial lock-in
Where WEBDANGER is itself subject to a Chapter VI switching obligation, WEBDANGER does not rely on upstream architecture as a blanket excuse to prevent Customer portability.
Upstream technical limitations are documented and addressed within the scope of the law and the applicable contract.
47. Openprovider/domain distinction
Openprovider may be used as an upstream registrar/domain-services provider.
Domain registration is not automatically a “data processing service” under Chapter VI merely because the domain is managed through an online account.
Domain transfer/export functionality is handled under the domain-registration and registrar framework.
INTERNATIONAL GOVERNMENTAL ACCESS
48. Infrastructure jurisdiction information
For covered data processing Services, WEBDANGER makes available and keeps up to date the information required by Article 28 concerning:
- the jurisdiction to which the ICT infrastructure used for processing the relevant Service is subject; and
- a general description of the technical, organisational and contractual measures used to help prevent conflicting international governmental access to or transfer of non-personal data held in the Union.
The relevant website location is referenced in the applicable Service contract as required.
49. No invented data-location promise
A statement such as:
“All WEBDANGER data is stored only in Czechia”
must not be published unless it is technically true for the relevant Service and its backups/subprocessors.
WEBDANGER instead maintains service-specific infrastructure information based on the real production environment.
50. Third-country governmental requests for non-personal data
Where Article 32 applies to non-personal data held in the Union, WEBDANGER applies appropriate technical, organisational and legal measures to protect against international or third-country governmental access or transfer that would conflict with Union or applicable Member State law.
Requests are assessed under the legal framework applicable to the request.
Where a qualifying third-country request can lawfully be complied with under Article 32, WEBDANGER limits disclosure to the minimum amount of data permissible on the basis of a reasonable interpretation of the request.
50A. Customer notification about third-country requests
Where Article 32 applies, WEBDANGER informs the Customer about the existence of a third-country authority request to access the Customer's non-personal data before complying with the request, except where the request serves law-enforcement purposes and for as long as notification must be delayed to preserve the effectiveness of that law-enforcement activity.
Where no applicable international agreement governs the request, WEBDANGER may seek the opinion of the relevant national body or authority competent for international cooperation in legal matters in accordance with Article 32.
SECURITY DURING SWITCHING
51. Security level
Data portability does not mean eliminating access controls.
Switching and export processes may use:
- re-authentication;
- MFA;
- role checks;
- signed export URLs;
- short-lived credentials;
- encryption in transit;
- integrity checks;
- export manifests;
- destination verification;
- audit logging;
- and rate controls.
52. Tenant isolation
A Customer export must not expose:
- another Customer's data;
- shared secrets;
- provider credentials;
- internal infrastructure secrets;
- or unrelated tenant metadata.
53. Destination-provider authorisation
Where WEBDANGER transfers exportable data directly to a destination provider or third party, WEBDANGER may require evidence that the Customer has authorised that destination.
EXPORT INTEGRITY
54. Export manifest
Where appropriate, an export package may contain a manifest describing:
- export ID;
- Customer/Service;
- creation time;
- covered data categories;
- format;
- file checksums;
- schema/version;
- known exclusions;
- and relevant technical notes.
55. Large exports
Large data sets may require:
- asynchronous export jobs;
- multipart downloads;
- temporary object storage;
- resumable transfer;
- API transfer;
- or provider-to-provider transfer.
The size of a dataset does not by itself eliminate applicable portability obligations.
ACCOUNT BALANCE, PAYMENTS AND BILLING
56. Service export does not mean cash withdrawal
The WEBDANGER Service Credit Balance, invoices, payments and billing rights are governed by the Terms of Service and applicable financial/consumer law.
A Data Act export does not transform Service Credits into:
- e-money;
- a bank deposit;
- a payment account;
- or an unrestricted withdrawal right.
Where account/billing records form part of an export or legal retention obligation, they are handled accordingly.
PRIVACY
57. GDPR remains applicable
Where exportable data contains personal data, the GDPR and other applicable data-protection rules remain independently applicable.
The Data Act does not create a legal basis to transfer personal data to an unauthorised destination.
58. Data subject versus Customer
A Customer may control a data processing Service that contains personal data relating to other individuals.
A Customer's switching request therefore does not mean that every person represented in the data is the Customer.
WEBDANGER applies the Customer/controller/processor structure described in the Privacy Policy and DPA where applicable.
CUSTOMER RESPONSIBILITIES
59. Destination readiness
The destination provider or on-premises environment may need to support:
- compatible formats;
- suitable infrastructure;
- credentials;
- network capacity;
- security controls;
- application versions;
- and dependencies.
WEBDANGER's obligation to facilitate switching does not guarantee that an incompatible destination can run every Customer workload without adaptation.
60. Customer cooperation
The Customer should provide information and cooperation reasonably required for the switching process, including, where applicable:
- destination details;
- authorisation;
- technical contacts;
- required credentials;
- preferred timing;
- and acknowledgement of known destination-side limitations.
All parties involved in switching are expected to cooperate in good faith.
CUSTOMER CONTACT
61. Switching requests
Until a dedicated switching interface is publicly activated, Customers may contact:
contact@webdanger.com
for questions about applicable Service portability and switching.
When the Customer portal provides a dedicated Data & Portability interface, that route may be used for eligible Services.
61A. Complaints and statutory remedies
Nothing in this Notice limits rights available under Articles 38 and 39 of the Data Act.
Where applicable, a natural or legal person who considers that its rights under the Data Act have been infringed may lodge a complaint with the relevant competent authority in the Member State of that person's:
- habitual residence;
- place of work; or
- establishment.
The Data Act also provides for an effective judicial remedy in relation to legally binding decisions of competent authorities and, in accordance with national law, where a competent authority fails to act on a complaint.
Questions to WEBDANGER may first be sent to:
contact@webdanger.com
Using WEBDANGER's internal contact route does not remove a statutory right to complain to a competent authority.
CHANGES
62. Changes to this Notice
WEBDANGER may update this Notice when:
- the Data Act is amended;
- the Digital Omnibus is adopted or materially changes;
- new EU interoperability standards are referenced;
- WEBDANGER launches a new data processing Service;
- export formats change;
- infrastructure jurisdictions change;
- or switching procedures change.
The current review date appears at the top.
APPENDIX A — INDICATIVE SERVICE CLASSIFICATION
| WEBDANGER activity | Indicative Data Act Chapter VI treatment | Final product classification |
|---|---|---|
| One-off website design | Usually not a data processing service merely because software is delivered | Required |
| Custom software development | Professional/project service; may be outside Chapter VI unless qualifying hosted service is also supplied | Required |
| Managed web hosting | Potential data processing service | Required |
| VPS/cloud server sold by WEBDANGER | Potential data processing service / infrastructure category | Required |
| Cloud storage | Potential data processing service | Required |
| WEBDANGER SaaS/CRM/ERP | Potential SaaS data processing service | Required |
| AI web application/dashboard | Potential SaaS data processing service depending architecture | Required |
| Domain registration | Not automatically Chapter VI cloud service | Required under domain framework |
| DNS management | Not automatically Chapter VI data processing service | Required |
| Direct Hetzner account owned by Customer | Upstream may be provider; WEBDANGER may be manager/consultant | Required |
| Hetzner-backed service sold by WEBDANGER | WEBDANGER may be source provider to Customer | Required |
This table is indicative only.
APPENDIX B — INDICATIVE EXPORT PACKAGE
A WEBDANGER SaaS/hosting export may use a structure such as:
```text webdanger-export/ ├── manifest.json ├── account/ │ └── service-profile.json ├── service/ │ ├── data.json │ ├── configuration.json │ └── metadata.json ├── files/ ├── database/ │ └── export.sql ├── logs/ │ └── customer-available-logs.json └── README.txt ```
Only production categories actually portable for the Service should be included.
Do not include:
- other tenants;
- secrets;
- provider internal credentials;
- protected internal algorithms;
- unrelated internal risk data.
APPENDIX C — SWITCHING STATUS EXAMPLE
```text Switch request: SW-2026-000123
Service: WEBDANGER Cloud / Example Service
Destination: Customer-selected provider
Status: Preparing export
Requested: 30 August 2026
Notice period ends: [calculated from applicable contract]
Transitional period: [applicable period]
Retrieval until: [at least 30 calendar days after transition ends]
Deletion: Scheduled after retrieval period, subject to applicable legal retention. ```
APPENDIX D — CUSTOMER PORTAL CONCEPT
Recommended customer interface:
```text Settings └── Data & Portability ├── Download service data ├── Export service ├── Start provider switch ├── Switch status ├── Move to own infrastructure ├── Data formats & schemas └── Request service erasure ```
Privacy rights remain separately available under:
```text Privacy └── Personal data request ```
Effective / review date: 30 August 2026