Skip to content
PageSpeed 100 as the delivery default
Recht

Choosing a Website Provider: Contract and Access

Who owns the domain, the content and the accounts? A neutral question list on ownership, logins and contract terms to put to every provider you consider.

15 min read VertragDomainZugängeAnbieterwechsel

When a business picks a website provider, the conversation usually revolves around drafts, features and price. The part that decides how much room to manoeuvre remains years later sits in the contract and in a handful of login details. Who is listed in the registry as the domain holder, the business or the service provider? Who owns the texts, the photos, the logo and the finished site? Who can reach hosting, email and analytics once the collaboration ends? These questions look secondary while everything runs smoothly, and they become expensive the moment something changes: a switch of provider, a handover inside the business, a provider who stops trading. This article collects them as a neutral question list you can put to any provider, expressly including us. The list accuses no one. It makes sure everyone understands the same thing before signing. It does not replace legal advice on an individual case.

Contract and access: the question listOwnership, accounts and contract terms — the same questions for every provider18m .de domains (DENIC)1 · Ownership2 · Access3 · ContractDomain in registryBusinessTexts and photosBusinessLogo and brandBusinessImage licencestransferWhatever the business pays forshould belong to the business.RegistrarDNSHostingEmailProfileAnalyticsSSLBackupsBusiness stays main owner,provider gets added access.Term and notice periodAutomatic renewalPrice adjustmentsResponse timesDPA under Article 28The list applies to everyprovider — including us.Switching providers in four steps1Take stockList domain, content,accounts and access rights2Request AuthInfoPrepare the transfer atthe registrar3Run the migrationSwitch DNS, new SSL,set up redirects4End the old contractNotice, deletion recordand data export2 years max term (B2C terms)8 mandatory DPA items (Art. 28)92% of firms have a website

The underrated part of the decision

Comparing offers works the same way almost everywhere: you look at drafts, read feature lists, compare figures and decide on instinct and rapport. That is understandable, because those are the visible things. What stays invisible is the second half of the decision, and it concerns a piece of operating equipment. In Bavaria, 92 percent (Bavarian State Office for Statistics) of companies with ten or more people employed run a website, and across Germany around 95 percent (Federal Statistical Office) of companies used a fixed internet connection in 2025. The website receives enquiries, carries the mandatory details required by the German Digital Services Act, hangs off the business email address and is often the first point of contact for new customers. Whoever decides about it decides about part of daily operations. The article on when a new website really pays off looks at the trigger; this one looks at the conditions under which the work happens.

Migration projects show a recurring pattern (project experience). First: the domain is registered in the service provider's name, because they registered it alongside their own years ago. Second: login details for hosting, DNS or analytics exist only there, often tied to one individual's personal email address. Third: images were licensed through the provider's account, so the licence is not issued to the business. None of this happens out of bad intent. It happens because it was quicker at the start and nobody asked the question. That is exactly why the best moment for the question list is not a dispute, but the first meeting. Which route to a website suits a business in the first place is covered in the overview of website builders, agencies and AI-assisted routes compared.

A question list, not an accusation

The questions below do not test a provider's honesty. They settle responsibilities that have to be settled anyway, in writing and before the contract starts. A provider who knows the questions answers them in minutes, usually gladly, because it saves later back-and-forth. At the end of this article we answer them for ourselves too, in the same form in which we would expect them from others.

Block 1: Who ends up owning what

The first item is the domain, because everything else hangs from it: the website, the email addresses, the directory entries, the printed business cards. For .de domains, the registration contract exists between the domain holder and the registry; the provider acts as an intermediary and handles the technical side, but is not itself the contracting party for the domain (DENIC eG). Whoever is listed in the registry as the holder decides on transfer, renewal, assignment and deletion. At the end of June 2026, the stock passed 18 million (DENIC eG) registered .de domains for the first time; at the end of 2025 there were 17,663,886 (DENIC eG), of which around 15.5 million (DENIC eG) were held by holders with a German address. Every single one has exactly one holder in the registry, and that one line is the most important line of the whole project.

The question to ask a provider is therefore not "Will you take care of the domain?" but: in whose name and at which address will the domain be entered in the registry, and will we receive the registration confirmation? For existing domains the entry can be checked through the registry's lookup; for .de domains the holder details are not shown publicly for data protection reasons, but the business can have them confirmed through its provider (DENIC eG). How to set up a domain and business email cleanly is covered in technical detail in the article on domain and business email as the foundation; here the point is ownership alone.

ItemWhat mattersQuestion to the provider
DomainThe registry entry decides transfer and renewalIn whose name will the domain be held after launch?
Website copyWhat is granted are usage rights, not copyright itselfWhich usage rights do we receive, and do they end with the contract?
Photos of the businessRights of the photographer and of the people shownMay we use the shots outside the website as well?
Purchased imagesThe licence is tied to one named licenseeWho is the licence issued to, and does it transfer with the site?
Logo and word markExclusive rights are a precondition for a trade mark filingDo we receive exclusive and transferable usage rights?
The finished siteStructure, design, templates and source filesWhat is handed over at the end of the contract, and in what form?
Content dataPages, images, enquiries, appointments, reviewsIn which format can the content be exported?
Analytics dataThe history is often lost in a migrationCan we download the reports before the switch?

For text, photos and design a distinction helps that everyday language tends to blur: under section 29(1) of the German Copyright Act, copyright itself cannot be transferred; only usage rights can be granted, and section 31 allows them to be limited by territory, time and content (German Copyright Act, sections 29 and 31). The phrase "you get all rights" is therefore imprecise. Precise wording names three things: whether the usage right is non-exclusive or exclusive, whether it applies without limits of time and territory, and whether it can be passed on to third parties. Transferability is the point that later decides whether a text may move to a new website or has to be rewritten. For a logo that is meant to be filed as a trade mark later, the exclusive right is practically indispensable.

Purchased images are where the most common gap sits. Image licences are issued to a specific licensee, and that is whoever holds the account and pays the invoice. If the service provider buys the licence in their own name, the business effectively uses the image through a third party without being the licensee. When the collaboration ends, the basis for the use ends with it, and the image has to be replaced. The clean options are a licence issued in the name of the business, or a written arrangement that expressly permits onward transfer and hands over the licence documents. Which records are worth keeping is described in the article on image rights for stock photos, team photos and AI pictures.

Usage rights do not end automatically with the project

A common misconception says: whoever paid the invoice may use everything. What is paid for is the agreed service, and the scope of use follows from what the contract says. If there is no arrangement, in case of doubt only the scope needed for the agreed purpose applies. It is therefore easier for a business to settle the scope once in writing than to reconstruct later what was meant. Where individual wordings raise doubts, a legal review is advisable; this article only orders the questions.

Block 2: The accounts the business should own

Owning content is worth little if nobody at the business can reach the accounts that hold it. Access is therefore not a technical detail but the practical side of the ownership question. This is not about operating everything yourself. Very few businesses want to maintain DNS records or renew certificates, and they do not have to. It is about every account being registered to the business, with the service provider added as an extra user. The difference only becomes visible when someone wants to withdraw access, and at that moment it decides everything.

Domain registrar

The registrar account through which the domain is managed. This is where the AuthInfo code originates that any transfer requires.

DNS management

The zone holding records for website, email and verification. Whoever can change it controls where requests go.

Hosting and delivery

The contract for storage and delivery. Without your own access, exporting the files depends on the provider.

Email mailboxes

Mailboxes, aliases and forwarding. Business correspondence belongs in an account owned by the business.

Google Business Profile

The listing with opening hours and reviews. Ownership can be transferred, but it costs time and evidence.

Analytics and reporting

The account where traffic and search queries come together. The history is the real value and rarely migrates.

Certificates and SSL

Issuing and renewing certificates. If the host handles it automatically, a record of where it is set up is enough.

Backups

Location, frequency and retention of backups, plus the question of who may trigger a restore.

Editing access

Access for editing content, ideally with an individual user account per person instead of one shared password.

One rule for every account: the business is the main owner, the service provider gets additional access. Not the other way round. That single rule removes most of the discussion when a provider changes.

In practice this means three things. First, accounts are created on a business email address, not on a private or personal address of one individual. A neutral shared address that several authorised people can reach survives holidays, illness and staff changes. Second, instead of passing passwords around, roles and individual user accounts are issued, so that withdrawing access later is one click rather than a round of password changes. Third, two-factor confirmation sits on a device belonging to the business, not on the provider's phone. Why this is more than a tidiness question is shown in the article on keeping a website's attack surface small. For the Google listing, transferring ownership is a process of its own, described in the article on setting up and maintaining a Google Business Profile.

  • For every account it is documented which email address it is registered to and who at the business has access.
  • The business is the main owner for registrar, DNS, hosting and email, with the provider listed as additional access.
  • Editing access uses one user account per person with a matching role.
  • Two-factor confirmation sits on a device or in a process the business can reach.
  • The access overview is kept somewhere reachable even if one individual is unavailable.
  • There is a fixed routine for withdrawing access when a provider or an employee leaves.
  • Ownership of the business listing and of the analytics accounts has been verified, not merely assumed.

Block 3: The contract terms you read first

The third block concerns the contract itself. Most website contracts are continuing obligations: something is not just built once, it is hosted, maintained, monitored and billed on an ongoing basis. That makes the term and the notice period the two numbers that determine your room to manoeuvre. A minimum term is nothing sinister; it often reflects an advance service, such as the build being spread across monthly instalments. What matters is that the term is visible, that it is clear when it starts, and that the notice period is proportionate to it. The Federation of German Consumer Organisations regularly points out in its market monitoring that long terms and automatic renewals are among the most frequent points of dispute in continuing contracts (Federation of German Consumer Organisations).

The second point is automatic renewal. It is common in commercial dealings and unproblematic in itself, as long as the renewal period and the notice period fit together. It becomes awkward when a contract renews for twelve months and notice must arrive three months in advance, because then a missed deadline binds a whole year. The third point is price adjustment: whether, when and by how much prices may be adjusted belongs in the contract, as does the right to terminate for cause when an adjustment happens. How to separate one-off from ongoing items cleanly is described in the article on planning a website budget across one-off and ongoing costs.

Contract pointWhy it mattersWhat should be set out
TermTies up budget and room to manoeuvreStart, duration and whether the build is included
Notice periodDecides whether a deadline is realistically metLength, form of notice and recipient
Automatic renewalExtends the contract without an active decisionRenewal period and a reminder before the deadline
Price adjustmentAffects ongoing costs over yearsTrigger, notice period and right to terminate
Scope of serviceSeparates what is included from extra workWhat is included per month and what is billed separately
Response timesDetermines how quickly faults are handledAvailability, response time by urgency, reporting channel
Provider failureKeeps operations running in an emergencyHandover of data and access, a named deputy contact
End of contractDecides whether you can switch at allData export, deletion record, cooperation during migration
Data processingRequired as soon as personal data is processedAgreement under Article 28 with annexes on measures and subprocessors

Response times are where expectation and reality diverge most often. For a business, a website that is down is something different from a typo on a subpage, and exactly that distinction should be in the contract: a short response time for faults affecting the operation of the site, a longer one for change requests. The distinction between response and resolution matters too. What can usually be promised is when a reply arrives, not when every cause is removed, because some causes lie with third parties. Which tasks come up regularly anyway and who takes them on is covered in the article on the maintenance routine a small firm's website needs.

The most uncomfortable point is the one most rarely settled: what happens if the provider fails? This means not only insolvency but also a long illness at a one-person business, a sale, or a decision to stop trading. The answer has two parts. The first is preventive and was described above: if the domain, hosting and accounts are held by the business, a failure is annoying but not a loss of control. The second is contractual: an undertaking that data and access will be handed over on request, a deadline for doing so, and a named deputy contact. Anyone who treats a website as operating equipment plans for this case as naturally as they would leave a spare key with someone.

Describe the data handover concretely

The phrase "data will be handed over on request" helps little in an emergency. Four details make it concrete: what is handed over (page content, image files, form messages, reports), in which format (open, readable file formats rather than a provider-specific dump), within which deadline (for example ten working days from request) and at what cost. Add an undertaking that the data will be deleted after handover and that the deletion will be confirmed.

Data processing: the contract next to the contract

As soon as the website processes personal data, which it does at the latest through the contact form and the server logs, the provider works on behalf of the business. Article 28 of the General Data Protection Regulation requires a separate agreement for this arrangement. Paragraph 3 first sets the frame of subject matter, duration, nature and purpose of the processing, types of data and categories of data subjects, and then lists eight (General Data Protection Regulation, Article 28) points in letters a to h. As to form, paragraph 9 accepts writing, expressly including electronic form (General Data Protection Regulation, Article 28). Letter g matters most for this topic: after the end of the service, the data is deleted or returned at the choice of the business (General Data Protection Regulation, Article 28). Handing over data at a switch is therefore not merely a commercial bargaining position but a contractually foreseen duty.

  1. Is there an agreement under Article 28 for the website, and does it cover every service involved, meaning hosting, form handling, backups and reporting?
  2. Does it contain a concrete annex on technical and organisational measures rather than a statement of intent?
  3. Is there a list of subprocessors with name, service and place of processing, plus a rule on how changes are notified?
  4. Is it settled how the provider supports access and deletion requests and through which channel security incidents are reported?
  5. Does it state what happens at the end of the contract, with deadline, format and proof of deletion?
  6. Is the agreement kept up to date when the scope of service changes, rather than signed once at the start?

An Article 28 agreement does not shift responsibility onto the provider; it stays with the business that decides on purposes and means. It is, however, the document that carries the collaboration and provides the evidence in case of doubt. How the agreement is structured, which other roles exist alongside it and what a record of processing activities looks like for a small business is set out in detail in the article on data processing agreements with website vendors.

Why consumer protection does not automatically apply in B2B

This is the point that surprises people most often in conversations. Many business owners know consumer protection rules from private life and assume they apply to their commercial contracts as well. That is not the case. Section 309 number 9 of the German Civil Code sets three limits for standard terms in continuing obligations: a binding period of no more than two years, tacit renewal only into an indefinite relationship with a right to terminate at any time, and a notice period of no more than one month before the end of the originally agreed term (German Civil Code, section 309). The current wording applies to contracts concluded on or after 1 March 2022 (German Civil Code, section 309).

a term of the contract binding the other party for more than two years

German Civil Code, section 309 number 9 letter a

The decisive addition sits in section 310(1): the prohibitions in sections 308 and 309 do not apply to standard terms used towards an entrepreneur; what remains applicable is the general fairness review under section 307(1) and (2), with due regard to the practices and customs of commercial dealings (German Civil Code, section 310). In practice this means the two-year limit does not act as a hard ceiling towards businesses, but at most as a reference point within an open balancing exercise. A business that signs a five-year commitment cannot rely on that commitment falling away automatically. In commercial dealings the contract itself is the measure of things, which is why the time before signing is the time when something can still be changed.

The same applies to the familiar cancellation button. Section 312k of the German Civil Code obliges traders who allow consumers to conclude a paid continuing obligation through a website to provide a clearly legible cancellation button; if it is missing or not compliant, the consumer may terminate at any time without notice (German Civil Code, section 312k). The provision sits in the chapter on consumer contracts and addresses the relationship between trader and consumer. A business commissioning a website acts as an entrepreneur and can generally not rely on it. The practical consequence: the route to giving notice belongs in the contract expressly, including form, address and a confirmation of receipt. One duty stays with the business regardless of the provider: section 5 of the German Digital Services Act requires the service provider to keep the listed details easily recognisable, directly accessible and permanently available (German Digital Services Act, section 5). Which details those are in practice is set out in the article on imprint and privacy policy as mandatory pages.

Orientation, not legal advice

The notes in this section reproduce the wording of the law and its generally accepted reading. Whether a particular clause is valid in an individual case depends on the contract as a whole, on the negotiating situation and on the sector, and courts weigh those factors. For long commitments, high amounts or unusual wording, a legal review before signing is the cheaper route compared with clarifying matters afterwards.

Five questions before you sign

The three blocks condense into a short list that fits into any first meeting. It is deliberately brief so that it actually gets asked. Anyone who has the five answers in writing has anticipated most of the friction that comes later. The questions are the same for every provider, whether the offer comes from an agency project, a website builder, an acquaintance from the neighbourhood or a platform.

  1. In whose name will the domain be entered in the registry, and will we receive the registration confirmation?
  2. Which usage rights to texts, photos, logo and the finished site do we receive, and are they transferable?
  3. For which accounts is the business the main owner, and which address are they registered to?
  4. How long are the term, the renewal and the notice period, and under what conditions may prices be adjusted?
  5. What happens at the end of the contract: which data do we get, in which format, within which deadline, and who confirms deletion?

A good answer is recognisable by one feature: it is concrete and verifiable. "Of course everything belongs to you" is not an answer; "The domain will be registered to your company at your address and you will receive the confirmation by email" is. A second observation from those conversations (project experience): the speed of the answer says more than its content. Providers who have settled these points reply immediately, because the answer already exists in writing. Where long queries arise, the reason is usually not reluctance but a point that has not been considered so far, and that too is useful information before deciding.

How a clean provider switch works

A switch is not a rupture but a project with a fixed order. If access is in order, it takes a few days; if it is not, the effort moves from technology into correspondence. The most important principle: secure first, migrate second, terminate third. Anyone who terminates first and starts securing afterwards is working against a deadline they set themselves. The second principle concerns the order around the domain: moving the domain and moving the website are two separate operations that do not have to happen on the same day.

  1. Take stock: bring domain, accounts, content, images with licence records, form recipients, running contracts and deadlines together into one list.
  2. Secure content: export texts, images at original resolution, existing reports and the complete list of page addresses while the old access still exists.
  3. Clarify ownership: check who the domain, hosting, email and business listing are registered to, and request open items in writing.
  4. Request AuthInfo: ask the previous provider for the code needed to change registrar; for .de domains it is the precondition for the transfer (DENIC eG).
  5. Rebuild: complete and review the new site in full before any record is switched over.
  6. Switch over: change DNS records, set up the certificate, check email delivery and verify that all important addresses respond.
  7. Set redirects: point every previous address to its new target so that links and search results keep working.
  8. End the old contract: give notice in time, have receipt confirmed, request the data export and deletion record, and withdraw the old provider's access.

The redirect step is underestimated most often because it is invisible. When addresses change, existing links, directory entries and search results run into nothing, and visibility suffers. A complete list of previous addresses and their targets therefore belongs in the migration plan, not in the follow-up work. How to plan that in a structured way is described in the article on a relaunch without ranking loss through carefully planned redirects. If you want to follow the domain move technically, the steps around AuthInfo, renewal and email delivery are covered in the article on domain and business email.

Plan a time buffer

Between requesting the AuthInfo code, the transfer at the registrar and the propagation of changed DNS records, expect hours to a few days, depending on the record lifetimes set and on processing at the previous provider. A switch immediately before a trade fair, a seasonal peak or year-end creates avoidable pressure. Two to four weeks of buffer between the start of the migration and the end of the old contract has proven practical (project experience).

How we answer these questions

A question list you do not answer yourself would be worth little. So here are the answers for XICflow, in the same form in which we would expect them from others. If you want to see the points together with the scope of service, they are in the overview of builder, hosting and domain features; the allocation to plans is in the pricing overview with what each plan includes, and the comparison with other routes to a website is in the side-by-side view of the approaches.

  • The domain is registered to the business and stays that way. An existing domain can be connected without changing registrar.
  • Content, images and texts belong to the business; the website content can be exported.
  • Accounts are created on a business address; additional people receive their own access with roles.
  • Term, renewal, notice period and the scope of each plan are set out in writing and visible before signing.
  • For the processing of personal data there is an agreement under Article 28 with annexes on measures and subprocessors.
  • At the end of the contract the content is exported and the data is deleted or returned, as you choose.

If you would like to apply the list from this article, we are happy to go through it together, for our own documents as well as for offers already on your desk. A conversation about contract, access and the ability to switch rarely takes longer than half an hour, and the sequence of a project from first sketch to launch is described in the walkthrough of the individual steps.

Sources and studies

This article is based on data from: the German Civil Code, in particular section 309 (prohibited clauses without the possibility of evaluation, duration of continuing obligations), section 310 (scope of application, in particular towards entrepreneurs) and section 312k (termination of consumer contracts via a button); Regulation (EU) 2016/679 (General Data Protection Regulation), in particular Article 28 on processors; the German Copyright Act, in particular section 29 on the non-transferability of copyright and section 31 on granting usage rights; section 5 of the German Digital Services Act on general information duties; the domain terms and the registration figures of DENIC eG for de domains as of June 2026 and the annual figures for 2025; the digital market monitoring of the Federation of German Consumer Organisations on contract terms and cost traps; the 2025 survey on the use of information and communication technology in enterprises by the Federal Statistical Office and the regional results of the Bavarian State Office for Statistics for 2025.