When a business picks a website provider, the conversation usually revolves around drafts, features and price. The part that decides how much room to manoeuvre remains years later sits in the contract and in a handful of login details. Who is listed in the registry as the domain holder, the business or the service provider? Who owns the texts, the photos, the logo and the finished site? Who can reach hosting, email and analytics once the collaboration ends? These questions look secondary while everything runs smoothly, and they become expensive the moment something changes: a switch of provider, a handover inside the business, a provider who stops trading. This article collects them as a neutral question list you can put to any provider, expressly including us. The list accuses no one. It makes sure everyone understands the same thing before signing. It does not replace legal advice on an individual case.
The underrated part of the decision
Comparing offers works the same way almost everywhere: you look at drafts, read feature lists, compare figures and decide on instinct and rapport. That is understandable, because those are the visible things. What stays invisible is the second half of the decision, and it concerns a piece of operating equipment. In Bavaria, 92 percent (Bavarian State Office for Statistics) of companies with ten or more people employed run a website, and across Germany around 95 percent (Federal Statistical Office) of companies used a fixed internet connection in 2025. The website receives enquiries, carries the mandatory details required by the German Digital Services Act, hangs off the business email address and is often the first point of contact for new customers. Whoever decides about it decides about part of daily operations. The article on when a new website really pays off looks at the trigger; this one looks at the conditions under which the work happens.
Migration projects show a recurring pattern (project experience). First: the domain is registered in the service provider's name, because they registered it alongside their own years ago. Second: login details for hosting, DNS or analytics exist only there, often tied to one individual's personal email address. Third: images were licensed through the provider's account, so the licence is not issued to the business. None of this happens out of bad intent. It happens because it was quicker at the start and nobody asked the question. That is exactly why the best moment for the question list is not a dispute, but the first meeting. Which route to a website suits a business in the first place is covered in the overview of website builders, agencies and AI-assisted routes compared.
A question list, not an accusation
Block 1: Who ends up owning what
The first item is the domain, because everything else hangs from it: the website, the email addresses, the directory entries, the printed business cards. For .de domains, the registration contract exists between the domain holder and the registry; the provider acts as an intermediary and handles the technical side, but is not itself the contracting party for the domain (DENIC eG). Whoever is listed in the registry as the holder decides on transfer, renewal, assignment and deletion. At the end of June 2026, the stock passed 18 million (DENIC eG) registered .de domains for the first time; at the end of 2025 there were 17,663,886 (DENIC eG), of which around 15.5 million (DENIC eG) were held by holders with a German address. Every single one has exactly one holder in the registry, and that one line is the most important line of the whole project.
The question to ask a provider is therefore not "Will you take care of the domain?" but: in whose name and at which address will the domain be entered in the registry, and will we receive the registration confirmation? For existing domains the entry can be checked through the registry's lookup; for .de domains the holder details are not shown publicly for data protection reasons, but the business can have them confirmed through its provider (DENIC eG). How to set up a domain and business email cleanly is covered in technical detail in the article on domain and business email as the foundation; here the point is ownership alone.
| Item | What matters | Question to the provider |
|---|---|---|
| Domain | The registry entry decides transfer and renewal | In whose name will the domain be held after launch? |
| Website copy | What is granted are usage rights, not copyright itself | Which usage rights do we receive, and do they end with the contract? |
| Photos of the business | Rights of the photographer and of the people shown | May we use the shots outside the website as well? |
| Purchased images | The licence is tied to one named licensee | Who is the licence issued to, and does it transfer with the site? |
| Logo and word mark | Exclusive rights are a precondition for a trade mark filing | Do we receive exclusive and transferable usage rights? |
| The finished site | Structure, design, templates and source files | What is handed over at the end of the contract, and in what form? |
| Content data | Pages, images, enquiries, appointments, reviews | In which format can the content be exported? |
| Analytics data | The history is often lost in a migration | Can we download the reports before the switch? |
For text, photos and design a distinction helps that everyday language tends to blur: under section 29(1) of the German Copyright Act, copyright itself cannot be transferred; only usage rights can be granted, and section 31 allows them to be limited by territory, time and content (German Copyright Act, sections 29 and 31). The phrase "you get all rights" is therefore imprecise. Precise wording names three things: whether the usage right is non-exclusive or exclusive, whether it applies without limits of time and territory, and whether it can be passed on to third parties. Transferability is the point that later decides whether a text may move to a new website or has to be rewritten. For a logo that is meant to be filed as a trade mark later, the exclusive right is practically indispensable.
Purchased images are where the most common gap sits. Image licences are issued to a specific licensee, and that is whoever holds the account and pays the invoice. If the service provider buys the licence in their own name, the business effectively uses the image through a third party without being the licensee. When the collaboration ends, the basis for the use ends with it, and the image has to be replaced. The clean options are a licence issued in the name of the business, or a written arrangement that expressly permits onward transfer and hands over the licence documents. Which records are worth keeping is described in the article on image rights for stock photos, team photos and AI pictures.
Usage rights do not end automatically with the project
Block 2: The accounts the business should own
Owning content is worth little if nobody at the business can reach the accounts that hold it. Access is therefore not a technical detail but the practical side of the ownership question. This is not about operating everything yourself. Very few businesses want to maintain DNS records or renew certificates, and they do not have to. It is about every account being registered to the business, with the service provider added as an extra user. The difference only becomes visible when someone wants to withdraw access, and at that moment it decides everything.
Domain registrar
The registrar account through which the domain is managed. This is where the AuthInfo code originates that any transfer requires.
DNS management
The zone holding records for website, email and verification. Whoever can change it controls where requests go.
Hosting and delivery
The contract for storage and delivery. Without your own access, exporting the files depends on the provider.
Email mailboxes
Mailboxes, aliases and forwarding. Business correspondence belongs in an account owned by the business.
Google Business Profile
The listing with opening hours and reviews. Ownership can be transferred, but it costs time and evidence.
Analytics and reporting
The account where traffic and search queries come together. The history is the real value and rarely migrates.
Certificates and SSL
Issuing and renewing certificates. If the host handles it automatically, a record of where it is set up is enough.
Backups
Location, frequency and retention of backups, plus the question of who may trigger a restore.
Editing access
Access for editing content, ideally with an individual user account per person instead of one shared password.
In practice this means three things. First, accounts are created on a business email address, not on a private or personal address of one individual. A neutral shared address that several authorised people can reach survives holidays, illness and staff changes. Second, instead of passing passwords around, roles and individual user accounts are issued, so that withdrawing access later is one click rather than a round of password changes. Third, two-factor confirmation sits on a device belonging to the business, not on the provider's phone. Why this is more than a tidiness question is shown in the article on keeping a website's attack surface small. For the Google listing, transferring ownership is a process of its own, described in the article on setting up and maintaining a Google Business Profile.
- For every account it is documented which email address it is registered to and who at the business has access.
- The business is the main owner for registrar, DNS, hosting and email, with the provider listed as additional access.
- Editing access uses one user account per person with a matching role.
- Two-factor confirmation sits on a device or in a process the business can reach.
- The access overview is kept somewhere reachable even if one individual is unavailable.
- There is a fixed routine for withdrawing access when a provider or an employee leaves.
- Ownership of the business listing and of the analytics accounts has been verified, not merely assumed.
Block 3: The contract terms you read first
The third block concerns the contract itself. Most website contracts are continuing obligations: something is not just built once, it is hosted, maintained, monitored and billed on an ongoing basis. That makes the term and the notice period the two numbers that determine your room to manoeuvre. A minimum term is nothing sinister; it often reflects an advance service, such as the build being spread across monthly instalments. What matters is that the term is visible, that it is clear when it starts, and that the notice period is proportionate to it. The Federation of German Consumer Organisations regularly points out in its market monitoring that long terms and automatic renewals are among the most frequent points of dispute in continuing contracts (Federation of German Consumer Organisations).
The second point is automatic renewal. It is common in commercial dealings and unproblematic in itself, as long as the renewal period and the notice period fit together. It becomes awkward when a contract renews for twelve months and notice must arrive three months in advance, because then a missed deadline binds a whole year. The third point is price adjustment: whether, when and by how much prices may be adjusted belongs in the contract, as does the right to terminate for cause when an adjustment happens. How to separate one-off from ongoing items cleanly is described in the article on planning a website budget across one-off and ongoing costs.
| Contract point | Why it matters | What should be set out |
|---|---|---|
| Term | Ties up budget and room to manoeuvre | Start, duration and whether the build is included |
| Notice period | Decides whether a deadline is realistically met | Length, form of notice and recipient |
| Automatic renewal | Extends the contract without an active decision | Renewal period and a reminder before the deadline |
| Price adjustment | Affects ongoing costs over years | Trigger, notice period and right to terminate |
| Scope of service | Separates what is included from extra work | What is included per month and what is billed separately |
| Response times | Determines how quickly faults are handled | Availability, response time by urgency, reporting channel |
| Provider failure | Keeps operations running in an emergency | Handover of data and access, a named deputy contact |
| End of contract | Decides whether you can switch at all | Data export, deletion record, cooperation during migration |
| Data processing | Required as soon as personal data is processed | Agreement under Article 28 with annexes on measures and subprocessors |
Response times are where expectation and reality diverge most often. For a business, a website that is down is something different from a typo on a subpage, and exactly that distinction should be in the contract: a short response time for faults affecting the operation of the site, a longer one for change requests. The distinction between response and resolution matters too. What can usually be promised is when a reply arrives, not when every cause is removed, because some causes lie with third parties. Which tasks come up regularly anyway and who takes them on is covered in the article on the maintenance routine a small firm's website needs.
The most uncomfortable point is the one most rarely settled: what happens if the provider fails? This means not only insolvency but also a long illness at a one-person business, a sale, or a decision to stop trading. The answer has two parts. The first is preventive and was described above: if the domain, hosting and accounts are held by the business, a failure is annoying but not a loss of control. The second is contractual: an undertaking that data and access will be handed over on request, a deadline for doing so, and a named deputy contact. Anyone who treats a website as operating equipment plans for this case as naturally as they would leave a spare key with someone.
Describe the data handover concretely
Data processing: the contract next to the contract
As soon as the website processes personal data, which it does at the latest through the contact form and the server logs, the provider works on behalf of the business. Article 28 of the General Data Protection Regulation requires a separate agreement for this arrangement. Paragraph 3 first sets the frame of subject matter, duration, nature and purpose of the processing, types of data and categories of data subjects, and then lists eight (General Data Protection Regulation, Article 28) points in letters a to h. As to form, paragraph 9 accepts writing, expressly including electronic form (General Data Protection Regulation, Article 28). Letter g matters most for this topic: after the end of the service, the data is deleted or returned at the choice of the business (General Data Protection Regulation, Article 28). Handing over data at a switch is therefore not merely a commercial bargaining position but a contractually foreseen duty.
- Is there an agreement under Article 28 for the website, and does it cover every service involved, meaning hosting, form handling, backups and reporting?
- Does it contain a concrete annex on technical and organisational measures rather than a statement of intent?
- Is there a list of subprocessors with name, service and place of processing, plus a rule on how changes are notified?
- Is it settled how the provider supports access and deletion requests and through which channel security incidents are reported?
- Does it state what happens at the end of the contract, with deadline, format and proof of deletion?
- Is the agreement kept up to date when the scope of service changes, rather than signed once at the start?
An Article 28 agreement does not shift responsibility onto the provider; it stays with the business that decides on purposes and means. It is, however, the document that carries the collaboration and provides the evidence in case of doubt. How the agreement is structured, which other roles exist alongside it and what a record of processing activities looks like for a small business is set out in detail in the article on data processing agreements with website vendors.
Why consumer protection does not automatically apply in B2B
This is the point that surprises people most often in conversations. Many business owners know consumer protection rules from private life and assume they apply to their commercial contracts as well. That is not the case. Section 309 number 9 of the German Civil Code sets three limits for standard terms in continuing obligations: a binding period of no more than two years, tacit renewal only into an indefinite relationship with a right to terminate at any time, and a notice period of no more than one month before the end of the originally agreed term (German Civil Code, section 309). The current wording applies to contracts concluded on or after 1 March 2022 (German Civil Code, section 309).
a term of the contract binding the other party for more than two years
The decisive addition sits in section 310(1): the prohibitions in sections 308 and 309 do not apply to standard terms used towards an entrepreneur; what remains applicable is the general fairness review under section 307(1) and (2), with due regard to the practices and customs of commercial dealings (German Civil Code, section 310). In practice this means the two-year limit does not act as a hard ceiling towards businesses, but at most as a reference point within an open balancing exercise. A business that signs a five-year commitment cannot rely on that commitment falling away automatically. In commercial dealings the contract itself is the measure of things, which is why the time before signing is the time when something can still be changed.
The same applies to the familiar cancellation button. Section 312k of the German Civil Code obliges traders who allow consumers to conclude a paid continuing obligation through a website to provide a clearly legible cancellation button; if it is missing or not compliant, the consumer may terminate at any time without notice (German Civil Code, section 312k). The provision sits in the chapter on consumer contracts and addresses the relationship between trader and consumer. A business commissioning a website acts as an entrepreneur and can generally not rely on it. The practical consequence: the route to giving notice belongs in the contract expressly, including form, address and a confirmation of receipt. One duty stays with the business regardless of the provider: section 5 of the German Digital Services Act requires the service provider to keep the listed details easily recognisable, directly accessible and permanently available (German Digital Services Act, section 5). Which details those are in practice is set out in the article on imprint and privacy policy as mandatory pages.
Orientation, not legal advice
Five questions before you sign
The three blocks condense into a short list that fits into any first meeting. It is deliberately brief so that it actually gets asked. Anyone who has the five answers in writing has anticipated most of the friction that comes later. The questions are the same for every provider, whether the offer comes from an agency project, a website builder, an acquaintance from the neighbourhood or a platform.
- In whose name will the domain be entered in the registry, and will we receive the registration confirmation?
- Which usage rights to texts, photos, logo and the finished site do we receive, and are they transferable?
- For which accounts is the business the main owner, and which address are they registered to?
- How long are the term, the renewal and the notice period, and under what conditions may prices be adjusted?
- What happens at the end of the contract: which data do we get, in which format, within which deadline, and who confirms deletion?
A good answer is recognisable by one feature: it is concrete and verifiable. "Of course everything belongs to you" is not an answer; "The domain will be registered to your company at your address and you will receive the confirmation by email" is. A second observation from those conversations (project experience): the speed of the answer says more than its content. Providers who have settled these points reply immediately, because the answer already exists in writing. Where long queries arise, the reason is usually not reluctance but a point that has not been considered so far, and that too is useful information before deciding.
How a clean provider switch works
A switch is not a rupture but a project with a fixed order. If access is in order, it takes a few days; if it is not, the effort moves from technology into correspondence. The most important principle: secure first, migrate second, terminate third. Anyone who terminates first and starts securing afterwards is working against a deadline they set themselves. The second principle concerns the order around the domain: moving the domain and moving the website are two separate operations that do not have to happen on the same day.
- Take stock: bring domain, accounts, content, images with licence records, form recipients, running contracts and deadlines together into one list.
- Secure content: export texts, images at original resolution, existing reports and the complete list of page addresses while the old access still exists.
- Clarify ownership: check who the domain, hosting, email and business listing are registered to, and request open items in writing.
- Request AuthInfo: ask the previous provider for the code needed to change registrar; for .de domains it is the precondition for the transfer (DENIC eG).
- Rebuild: complete and review the new site in full before any record is switched over.
- Switch over: change DNS records, set up the certificate, check email delivery and verify that all important addresses respond.
- Set redirects: point every previous address to its new target so that links and search results keep working.
- End the old contract: give notice in time, have receipt confirmed, request the data export and deletion record, and withdraw the old provider's access.
The redirect step is underestimated most often because it is invisible. When addresses change, existing links, directory entries and search results run into nothing, and visibility suffers. A complete list of previous addresses and their targets therefore belongs in the migration plan, not in the follow-up work. How to plan that in a structured way is described in the article on a relaunch without ranking loss through carefully planned redirects. If you want to follow the domain move technically, the steps around AuthInfo, renewal and email delivery are covered in the article on domain and business email.
Plan a time buffer
How we answer these questions
A question list you do not answer yourself would be worth little. So here are the answers for XICflow, in the same form in which we would expect them from others. If you want to see the points together with the scope of service, they are in the overview of builder, hosting and domain features; the allocation to plans is in the pricing overview with what each plan includes, and the comparison with other routes to a website is in the side-by-side view of the approaches.
- The domain is registered to the business and stays that way. An existing domain can be connected without changing registrar.
- Content, images and texts belong to the business; the website content can be exported.
- Accounts are created on a business address; additional people receive their own access with roles.
- Term, renewal, notice period and the scope of each plan are set out in writing and visible before signing.
- For the processing of personal data there is an agreement under Article 28 with annexes on measures and subprocessors.
- At the end of the contract the content is exported and the data is deleted or returned, as you choose.
If you would like to apply the list from this article, we are happy to go through it together, for our own documents as well as for offers already on your desk. A conversation about contract, access and the ability to switch rarely takes longer than half an hour, and the sequence of a project from first sketch to launch is described in the walkthrough of the individual steps.
Sources and studies