§ 1

Scope and Definitions

1.1 These General Terms and Conditions (GTC) apply to all contracts between IT-Service Harting, proprietor Giovanni Harting, Friedrich-Wolf-Str. 18, 98527 Suhl, Germany (hereinafter "we" or "us"), and the customer. They also apply to future services and offers without needing to be incorporated again.

1.2 A consumer within the meaning of § 13 of the German Civil Code (BGB) is any natural person who enters into the contract for purposes that are predominantly outside their trade, business or profession. An entrepreneur within the meaning of § 14 BGB is a natural or legal person, or a partnership with legal capacity, acting in the exercise of their trade, business or profession when entering into the contract. Provisions of these GTC that apply only to consumers or only to entrepreneurs are marked accordingly.

1.3 Deviating, conflicting or supplementary terms of the customer do not become part of the contract unless we expressly agree to their application in text form.

1.4 Individual agreements between us and the customer always take precedence over these GTC pursuant to § 305b BGB. To avoid misunderstandings, we recommend having any verbal arrangements confirmed in text form.

1.5 In addition to these General Terms and Conditions, the product-specific service agreements (web hosting, e-mail hosting, Kubernetes, domains) and the Service Level Agreement apply. Where domains are the subject of the contract, the allocation conditions of the competent registry apply additionally.

1.6 Order of precedence
In the event of conflicts between the contractual documents, the following order of precedence applies: (1) the data processing agreement, (2) the product-specific service agreements, (3) the Service Level Agreement, (4) these General Terms and Conditions. The data processing agreement takes precedence over these GTC in particular with regard to liability for infringements of data protection law.

§ 2

Formation of Contract

2.1 Our offers are subject to change and non-binding unless expressly designated as binding. Technical and other changes remain reserved within reasonable limits.

2.2 By submitting the order via the "Order with obligation to pay" button, the customer makes a binding contractual offer. We may accept this offer within five working days, either by providing the service or by confirming in text form. An automated acknowledgement of receipt does not constitute acceptance.

2.3 The customer warrants that the data they provide is correct and complete. They will notify us of any changes within 14 days at the latest, in text form or via the customer portal. Upon reasoned request, they will provide evidence of the accuracy of the data.

2.4 Contract formation in electronic commerce
We store the text of the contract and send it to the customer together with these GTC in text form. The languages available for concluding the contract are German and English. Before submitting the order, the customer can review their entries in the order summary and change them at any time using the correction functions of the order form and the browser’s back function, or cancel the order.

§ 3

Contract Term and Termination

3.1 Unless otherwise agreed, contracts are concluded for an indefinite period.

3.2 Contracts of indefinite duration may be terminated by either party at any time without giving reasons, subject to one month’s notice. Individual products may be subject to deviating provisions under the relevant service agreement; in no case does a notice period longer than one month apply to consumers.

3.3 Extension of fixed-term contracts
Where a minimum term has exceptionally been agreed, the contract continues for an indefinite period after that term expires and may then be terminated at any time subject to one month’s notice. With entrepreneurs, an extension by the original term may be agreed instead.

3.4 Form of termination
Termination requires text form and may be declared by letter, by e-mail to service@itsh.dev, or via the customer portal. For consumer contracts concluded in electronic commerce, the termination button „Verträge hier kündigen“ is additionally available; it is permanently available on our website, directly and easily accessible, and can be used without logging in. We confirm receipt of a termination declared via this button without undue delay in text form, stating its content, the time of receipt and the date on which the contract ends.

3.5 Termination for cause
The right of both parties to terminate for good cause remains unaffected. Good cause exists for us in particular where the customer is in default with a not insignificant part of the remuneration and fails to pay despite a reminder and a reasonable grace period, or where they materially breach § 10 of these GTC despite a warning. No warning is required where it is unreasonable given the severity of the breach, in particular where the security or availability of our infrastructure is at risk or where content is manifestly criminal.

3.6 Transferring the contractual rights and obligations to a third party requires our consent and text form. We verify the authority of the transferring party and the identity of the third party.

§ 4

Scope of Services

4.1 The scope of the contractual service follows from the service description in force at the time of the order and the resulting agreements in text form. We may discontinue services offered free of charge, or offer them subject to charge in future, upon prior notice with reasonable warning.

4.2 Where the registration of domain names is the subject of the contract, we owe only the intermediation vis-à-vis the competent registry. We have no influence on the allocation decision. The customer may not assume allocation until we have confirmed it.

4.3 We undertake commercially reasonable efforts to achieve the availability stated in the Service Level Agreement. Details of measurement, exclusions and credits are governed by the Service Level Agreement.

4.4 Where the service includes the assignment of an IP address, there is no entitlement to a specific IP address. The IP address is not checked against blocklists. We may change the IP address for technical or operational reasons upon prior notice.

4.5 Support services going beyond the respective service description are charged separately upon prior agreement.

§ 5

Prices, Payment and Default

5.1 The prices published on itsh.dev at the time of the order apply. Vis-à-vis consumers, all prices are total prices including statutory value added tax and all other price components. Vis-à-vis entrepreneurs, prices are exclusive of statutory value added tax.

5.2 Depending on the contractual agreement, billing is monthly, quarterly, semi-annually or annually via the payment method chosen by the customer. The customer observes the terms of the payment service they use.

5.3 If the customer defaults on payment, the statutory provisions of §§ 286, 288 BGB apply. Vis-à-vis consumers, default under § 286(3) BGB only occurs if we have specifically drawn attention to this consequence in the invoice.

5.4 Invoices are issued free of charge in electronic form. For postal delivery we charge the costs actually incurred, provided the customer expressly requests it.

5.5 The customer is obliged to comply with applicable export and import control regulations insofar as their use of the services is affected.

§ 6

Changes to these GTC and to Prices

6.1 Changes to these GTC
We may amend these GTC where necessary to adapt to a changed legal situation or supreme court case law, to technical developments, or to changes in the range of services, and where this does not unreasonably disadvantage the customer. We notify the change in text form at least six weeks before the intended effective date and specifically draw attention to the right of objection, the deadline and the consequences of failing to object. If the customer does not object within this period, the change is deemed approved; if they object, the contract continues on the previous terms.

6.2 This right of amendment is limited to changes that do not materially alter the balance of performance and consideration. In particular, it does not apply to price increases; these are governed exclusively by the following paragraphs.

6.3 Changes to prices
We are entitled to adjust prices for continuing obligations at our reasonable discretion (§ 315 BGB) in order to reflect changes in our costs. Only the following are relevant: changes in the costs of data centre and infrastructure services, energy, hardware and software including licences, third-party inputs such as registries and payment service providers, personnel, and changes in statutory levies and taxes.

6.4 In exercising our reasonable discretion, we choose the timing of a price adjustment such that cost reductions are not taken into account on terms less favourable to the customer than cost increases; cost reductions therefore take effect on prices at least to the same extent as cost increases.

6.5 Price changes take effect at the earliest from the beginning of the billing period following the announcement. We announce them in text form at least six weeks in advance. In that case the customer may terminate the contract in text form without notice period, effective from the date the change takes effect; we specifically draw attention to this right in the notice of change. This does not apply where the change is based exclusively on a change in taxes or levies imposed by public authority, or where it operates in the customer’s favour.

§ 7

Customer Obligations and Data Backup

7.1 For the vServer/VPS service areas, the customer holds sole administration rights. They administer and secure these systems at their own cost and risk.

7.2 The customer sets up and operates the systems they administer so that the integrity and availability of third-party networks, servers and data are not endangered. In particular, use for (D)DoS attacks and the operation of open mail relays or comparable systems are prohibited. In the event of breaches we are entitled to suspend the affected service; § 3.5 remains unaffected.

7.3 The customer uses the services provided properly and refrains from abusive and unlawful acts.

7.4 We create platform-side backups of the services we provide; scope, frequency and retention period follow from the respective product description. These backups do not replace the customer’s own data backup. The customer remains responsible for their own backup, held separately from the system, and performs a full data backup before any change they initiate.

§ 8

Data Protection and Processing on Behalf

8.1We process personal data in accordance with the General Data Protection Regulation. Details of processing carried out under our own responsibility can be found in our privacy policy.

8.2 Where the customer processes third-party personal data using our services, they remain the controller within the meaning of the GDPR. We process such data as a processor pursuant to Art. 28 GDPR.

8.3 Data processing agreement
For web hosting, e-mail hosting, Kubernetes and object storage, the data processing agreement forms part of the service contract and is concluded together with the order. The customer may declare to us in text form that they do not process any third-party personal data via our services and therefore require no data processing agreement; we record such a declaration in the customer account. The current data processing agreement is available in the customer portal.

8.4 The customer informs us of the details required for processing on their behalf, in particular the purpose and the categories of data processed and of data subjects, insofar as these do not already follow from the data processing agreement.

8.5 The customer is responsible for the security of the content they upload and the configuration they choose. The technical and organisational measures we take are set out in the data processing agreement.

§ 9

Use by Third Parties

9.1 The customer is entitled to grant third parties a right to use the services they have ordered. In this case they remain our sole contractual partner and continue to be liable to us for compliance with the contractual agreements.

9.2 Where changes require the cooperation of the third party, the customer ensures already upon granting the right of use that the statutory and contractual provisions are complied with.

9.3 If the third party breaches the contractual obligations or fails to fulfil obligations to cooperate, the customer is liable for the resulting damage under the general provisions and indemnifies us against justified third-party claims based on that breach. The indemnity covers the necessary costs of legal defence.

§ 10

Permitted Use, Content and Notice Procedure

10.1 The customer independently reviews and observes the statutory provisions applicable to their use, in particular the German Telecommunications Act and the German Digital Services Act (DDG), as well as the provisions of copyright, trade mark, personality, competition and data protection law. They indemnify us against justified third-party claims based on a culpable breach of these obligations.

10.2 The customer does not publish content that infringes applicable law or the rights of third parties. This includes in particular, but not exhaustively, content that violates criminal law, content harmful to minors, unlawful gambling, and content infringing copyright, name, trade mark or personality rights.

10.3 Sending unsolicited advertising (spam) is prohibited, as is providing false sender data or otherwise disguising the sender’s identity. Also prohibited is the operation of applications for mining cryptocurrencies, including mining, farming and plotting.

10.4 Notice and action procedure
Notices of illegal content on services we operate can be submitted at any time via the reporting form on our website or by e-mail to abuse@itsh.dev. We handle notices in accordance with Art. 16 of Regulation (EU) 2022/2065 (Digital Services Act), confirm receipt and communicate the decision taken.

10.5 Where, on the basis of a notice or our own knowledge, we restrict access to the customer’s content or suspend a service, we notify the customer of the decision with a statement of reasons pursuant to Art. 17 of Regulation (EU) 2022/2065. The statement of reasons sets out the scope of the measure, the underlying facts, the legal basis, a reference to any automated decision-making, and the possibilities for redress. The customer may object to the measure within 14 days in text form; we review the objection and communicate the result with reasons.

§ 11

Warranty and Liability

11.1 We are liable for defects in our services in accordance with the statutory provisions.

11.2 Liability
We are liable without limitation for intent and gross negligence, for injury to life, body or health, under the provisions of the German Product Liability Act, and to the extent of any guarantee we have assumed.

11.3 In cases of ordinary negligence we are liable only for breach of a material contractual obligation, that is, an obligation whose fulfilment is essential to the proper performance of the contract and on whose observance the customer may regularly rely. In that case liability is limited to the foreseeable damage typical for this type of contract; vis-à-vis entrepreneurs it is additionally limited to the remuneration paid for the affected service in the preceding twelve months.

11.4 Liability is otherwise excluded. This does not entail any change in the burden of proof to the customer’s detriment.

11.5 We are liable for loss of data to the extent set out above only insofar as the loss would also have occurred had the customer carried out proper and regular data backups pursuant to § 7.4.

11.6 The above limitations of liability also apply in favour of our legal representatives, employees and vicarious agents.

11.7 If the customer breaches § 10 of these GTC, they are liable to us for the resulting damage under the general provisions and indemnify us against justified third-party claims based on that breach.

§ 12

Right of Withdrawal for Consumers

12.1 Withdrawal instructions
Consumers have a right of withdrawal. You have the right to withdraw from this contract within fourteen days without giving any reason. The withdrawal period is fourteen days from the day of conclusion of the contract. To exercise your right of withdrawal, you must inform us – IT-Service Harting, proprietor Giovanni Harting, Friedrich-Wolf-Str. 18, 98527 Suhl, Germany, telephone +49 3681 4662972, e-mail service@itsh.dev – of your decision to withdraw from this contract by an unequivocal statement (e.g. a letter sent by post or an e-mail). You may use the attached model withdrawal form, but it is not obligatory. To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired.

12.2 Effects of withdrawal
If you withdraw from this contract, we shall reimburse to you all payments received from you, including the costs of delivery (with the exception of the supplementary costs resulting from your choice of a type of delivery other than the least expensive type of standard delivery offered by us), without undue delay and in any event not later than fourteen days from the day on which we are informed about your decision to withdraw from this contract. We will carry out such reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.

12.3 Early commencement of the service and compensation for value
If you requested that the service should begin during the withdrawal period, you shall pay us an amount which is in proportion to what has been provided until you have communicated to us your exercise of the right of withdrawal from this contract, in comparison with the full coverage of the contract.

12.4 Early expiry of the right of withdrawal
In the case of a contract for the supply of services, the right of withdrawal expires upon complete performance of the service if you expressly consented, before performance began, to us beginning performance before the expiry of the withdrawal period, and confirmed your awareness that you lose your right of withdrawal upon complete performance of the contract. We obtain this consent and confirmation separately during the ordering process.

12.5 Special provision for domain registrations
The registration of a domain name is completely performed upon entry in the registry, because at that moment we irrevocably acquire the registration period from the registry. If you have consented to immediate commencement pursuant to paragraph 4, the right of withdrawal expires in that respect upon registration. The right of withdrawal remains unaffected as regards holding and administering the domain beyond the registration period.

12.6 Model withdrawal form
We provide the model withdrawal form on our website under "Withdrawal instructions" for retrieval and for electronic submission.

§ 13

Switching Providers and Data Portability

13.1 This section applies to data processing services within the meaning of Regulation (EU) 2023/2854 (Data Act), in particular web hosting, e-mail hosting, Kubernetes, vServer and object storage.

13.2 Notice of switching
The customer may give notice at any time in text form of switching to another provider or to their own IT infrastructure. The notice period is a maximum of two months.

13.3 Transitional period
Following notice of switching, the transitional period is a maximum of 30 calendar days; during this period we continue to provide the service unchanged. The customer may extend the transitional period once by a period they consider appropriate. If switching is technically not feasible within 30 calendar days, we notify the customer within 14 working days of receipt of the notice, give reasons, and state an alternative transitional period of no more than seven months.

13.4 Assistance and exportable data
We provide the customer with reasonable assistance in switching, maintain business continuity, point out risks known to us, and ensure a high level of data security. Which data and digital assets are exportable, and through which interfaces the export takes place, follows from the respective service description. Not exportable are components that serve exclusively our internal operations and whose disclosure would infringe trade or business secrets, in particular system architecture, platform code, security infrastructure and internal operational and monitoring data.

13.5 Retrieval period and deletion
After the transitional period has expired, we make the exportable data available for retrieval for at least 30 calendar days. After that retrieval period expires, we delete the data.

13.6 Charges for switching
We do not charge for switching or for the associated data transfer. From 12 January 2027, charging switching fees is in any event prohibited under Art. 29 of Regulation (EU) 2023/2854.

§ 14

Dispute Resolution and Final Provisions

14.1 We are neither willing nor obliged to participate in dispute resolution proceedings before a consumer arbitration board.

14.2 These GTC and the contractual relationship between us and the customer are governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods. For consumers, this choice of law applies only insofar as it does not deprive them of the protection afforded by mandatory provisions of the law of the state in which they have their habitual residence.

14.3 If the customer is a merchant, a legal entity under public law or a special fund under public law, the exclusive – including international – place of jurisdiction for all disputes arising from the contractual relationship is our place of business in Suhl. In that case we are also entitled to bring proceedings at the customer’s general place of jurisdiction. For consumers, the statutory places of jurisdiction apply.

14.4 Authoritative language version
These GTC and the other contractual documents are provided in German and English. Only the German version is authoritative; the English version is provided for information only.

14.5 Should any provision of these GTC be or become wholly or partly invalid or unenforceable, the validity of the remaining provisions remains unaffected. The statutory provisions take the place of the invalid or unenforceable provision.

Web Hosting Service Agreement

1

Contact, Customer Support

All account types include free written support during the specified support hours. If this is included in the respective offer, free telephone support is also offered. Written support requests by the customer are made via the self-service customer portal. The customer must use their customer access to the customer portal (login: contact email, password: customer password).

In general, support orders by the customer are included in the flat rate of the product. Special support requests that are not included in the services of IT-Service Harting are only processed in exceptional cases. If more than 15 minutes of working time is required to resolve these problems, IT-Service Harting charges, after prior consultation with the customer, EUR 19.99 (incl. 19% VAT) per commenced quarter of an hour.

2

Monitored Services

  • Web server (HTTP)
  • Mail system (SMTP, POP3, IMAP, spam filter, virus scanner, mail sending volume)
  • Server services (SFTP)
  • Databases
  • Server load
  • Storage utilisation
3

System Outages and Maintenance

A system outage is usually announced on https://status.itsh.dev or announced in advance for planned maintenance work. Status notifications by email can be subscribed to in the self-service customer portal.

4

Mass Emails

The hourly sending volume of emails must not exceed 500 emails. Sending mass emails/newsletters via email accounts of the web hosting account or via the website of the web hosting account is not permitted. Sending unsolicited advertising is prohibited. IT-Service Harting is entitled to immediately block customer accounts that violate this.

5

Data Backup

All web hosting packages include daily, weekly and monthly backups of all data. Data is retained for up to 6 months. Restoring the backup is possible via our support. Both restoring individual files and complete folders or an account is possible.

6

Content and Data of Created Accounts

Changes by support staff, such as deleting, moving, overwriting content and sensitive data uploaded and/or received by the customer, can only be carried out if this request is verified via the self-service customer portal or in writing with company stamp and handwritten signature. For work that can be done by the customer themselves and is possible, there is no entitlement to execution by support staff.

7

Changes to Configuration Files

In general, except for the listed exceptions, no individual adjustments in configuration files are possible for web hosting accounts. This applies to system settings and the services offered. The following settings can be changed:

PHP

Selected PHP settings can be changed via the self-service customer portal. Settings that exceed the available values and set limitations cannot be changed. Additional PHP modules other than those offered will not be installed. Own PHP solutions, such as own PHP binaries, are not supported. Activated PHP modules can be viewed in the product overview.

IMAP

The value for parallel IMAP connections per IP address is limited for server stability reasons. An increase of this value is possible on request, but there is no entitlement to it.

SMTP

The offered settings such as forwards, autoresponder, spam filter, etc. can be changed by the customer. Further individual settings and configurations for the mail system will not be created. SPF records and DKIM/DMARC are automatically set by us and cannot be changed by the customer.

Databases

Individual settings on the database configuration are not possible for web hosting products. For each database created by the customer, a database user is set up who may only access this database. A global database user or users who have access to multiple databases will not be set up for security reasons.

8

Process Monitoring

To ensure the security and stability of the server, process monitoring takes place, which terminates the corresponding process in case of excessive runtime and/or RAM utilisation.

9

Installation of Additional Software

The installation of additional software or libraries is not carried out by support. The operation of additional software that requires root rights for installation or operation is generally not possible.

10

Protecting the Email Service from Spam and Viruses

All email accounts include a server-side spam filter that automatically sorts suspicious emails into the Junk folder. The Junk folder is accessible via IMAP and webmail. The spam filter uses rule-based detection, DNS-based blocklists and machine learning. Emails exceeding a critical spam score are rejected at SMTP level and not delivered.

Incoming emails are automatically scanned for viruses and malware. Emails detected as infected are rejected at SMTP level and not delivered. Virus definitions are updated automatically several times a day.

Senders listed in the recipient's address book are automatically classified as trusted. Spam filter sensitivity is configured by IT-Service Harting. Individual filter rules can be set up by the customer using Sieve scripts.

For customers with a separate Email Hosting product, the Email Hosting Service Agreement applies.

11

Prohibited Actions

To enable us to operate a high-performance and reliable network for our customers, the operation of applications for mining cryptocurrencies is prohibited.

Email Hosting Service Agreement

1

Contact, Customer Support

All Email Hosting products include free written support during the specified support hours. Written support requests are made via the self-service customer portal.

Support covers questions about the email infrastructure, delivery issues and account configuration. Special support requests that go beyond the standard services are charged at EUR 19.99 (incl. 19% VAT) per commenced quarter of an hour after prior consultation.

2

Monitored Services

  • IMAP (mailbox access)
  • SMTP (email sending and receiving)
  • Webmail
  • Spam filter and virus scanner
3

Storage and Billing

Each Email Hosting product includes a base storage allocation (pooled storage) shared across all mailboxes of the domain. The current storage amount is determined by the offer information valid at the time of ordering.

If the included storage is exceeded, the additional usage is billed on a usage-based model. Billing occurs monthly according to the current price list on itsh.dev.

Current storage usage can be viewed at any time in the self-service customer portal.

4

Mailboxes and Aliases

The customer can create an unlimited number of mailboxes and email aliases on their domain. All mailboxes share the available pooled storage.

App passwords allow the use of email clients and third-party applications without sharing the main password. The customer is responsible for the secure storage of their credentials.

5

Sending Limits

The number of outgoing emails is limited as follows: 200 messages per hour and 2,000 messages per day per authenticated user. The monthly sending quota included in the product is determined by the offer information valid at the time of ordering.

If the included quota is exceeded, the additional sending is billed on a usage-based model. Billing occurs monthly according to the current price list on itsh.dev.

Sending unsolicited advertising (spam), mass emails and newsletters via the email service is not permitted. Sending emails with falsified sender data or disguised sender identity is prohibited. IT-Service Harting is entitled to immediately block customer accounts that violate these provisions.

6

DKIM, SPF and DMARC

For each domain set up in Email Hosting, DKIM signatures, SPF records and a DMARC policy are automatically configured. These settings ensure the authenticity and deliverability of outgoing emails.

The automatically set DNS records for DKIM, SPF and DMARC cannot be changed by the customer. When using external domains, the customer is responsible for the correct configuration of the corresponding DNS records with their DNS provider.

7

Mailing Lists and Delegation

The customer can set up mailing lists for internal communication. Mailing lists distribute incoming emails to all registered members.

Delegation allows assigning individual app passwords and restricted access rights to mailboxes. The customer is responsible for managing delegation rights and controlling delegated mailboxes.

8

Data Backup

All Email Hosting products include daily, weekly and monthly backups of email data. Data is retained for up to 6 months.

Restoration requests can be made via the self-service customer portal or support. The customer is additionally responsible for backing up important emails and data themselves.

9

Prohibited Actions

In addition to the prohibitions stated in § 10 of the General Terms and Conditions, the following is specifically prohibited:

  • Sending spam, unsolicited advertising or phishing emails
  • Falsifying sender data or email headers
  • Using the service as an open mail relay
  • Operating applications for mining cryptocurrencies

Violations may result in immediate suspension of access and termination without notice.

Kubernetes Service Agreement

1

Contact, Customer Support

All Kubernetes products include free written support during the specified support hours. Written support requests are made via the self-service customer portal.

Support covers questions about the Kubernetes infrastructure, but not debugging of customer applications or support for application development. Special support requests that go beyond the standard services are charged, after prior consultation, at EUR 19.99 (incl. 19% VAT) per commenced quarter of an hour.

2

Product Tiers

Namespace: Shared control plane with dedicated resource quotas (vCPU, RAM). Suitable for development, testing and smaller production environments.

Cluster: Dedicated control plane and worker nodes. Full network isolation and dedicated hardware available.

Add-ons: Optional extensions such as persistent storage (RWX), managed databases (PostgreSQL, Redis) and extended backup capacities.

3

Resource Limits and Fair Use

Resource usage (CPU, RAM, storage) is limited according to the booked product tier. If the included quotas are exceeded, usage-based billing takes place according to the current price list on itsh.dev.

Processes that consume excessive resources and endanger the stability of the infrastructure may be terminated without prior notice. The operation of applications for mining cryptocurrencies is prohibited pursuant to § 10.3 of the General Terms and Conditions.

4

Availability and Maintenance

We aim for network availability of 99% as an annual average (cf. § 4.3 of the General Terms and Conditions). Planned maintenance work is announced via the status page.

Updates and security patches are automatically applied by IT-Service Harting. Nodes may be automatically restarted as part of regular maintenance to apply operating system updates.

Important: The customer is responsible for configuring their deployments to be tolerant of node restarts or failures (e.g. through multiple replicas, Pod Disruption Budgets).

5

Data Backup and Recovery

All Kubernetes products include daily backups of the cluster configuration and persistent volumes. The retention period depends on the booked product.

Recovery requests can be made via the self-service customer portal. The customer is additionally responsible for application-specific backups of their data and configurations.

6

Security and Isolation

Namespace-Tier: Isolation through Kubernetes RBAC and Network Policies within a shared control plane.

Cluster-Tier: Complete network isolation with dedicated hardware and private networking available.

All tiers are operated in ISO 27001 certified EU data centres. SSL/TLS encryption is enabled by default.

7

Access and Management

Access to the Kubernetes cluster is via kubectl with the provided kubeconfig file. The customer is responsible for the secure storage and management of their access credentials.

Root or admin access to the underlying infrastructure (nodes, control plane) is not granted. Changes to the infrastructure are made exclusively by IT-Service Harting.

8

Prohibited Use

In addition to the prohibitions mentioned in § 10 of the General Terms and Conditions, the following are particularly prohibited:

  • Operation of tools for (D)DoS attacks or network scanning of other customers
  • Exploiting security vulnerabilities in the Kubernetes infrastructure
  • Resource abuse that affects the stability or performance of other customers

Violations may result in immediate throttling or blocking of access as well as termination without notice.

9

Free Namespace (Free Tier)

IT-Service Harting offers a free Kubernetes namespace ("Free Tier") intended as a technical evaluation and trial environment.

Resource and Feature Scope
The Free Tier is subject to the following limits: 200 mCPU (equivalent to 0.2 vCPU), 512 MiB memory, 1 GiB persistent storage (exclusively via the NFS-based StorageClass), a maximum of 5 pods, and a monthly outbound network traffic (egress) limit of 10 GiB. A free OCI registry is provisioned alongside the namespace and is limited to 1 GiB of storage and 10 GiB of monthly egress.

Hostnames and Networking
Free Tier namespaces are reachable exclusively under subdomains of the form *.<namespace>.itsh-apps.dev. Custom domains are not available on the Free Tier. Outbound network traffic is restricted to TCP/80 (HTTP), TCP/443 (HTTPS) and UDP/53 (DNS, to designated resolvers); other protocols and ports are blocked.

Availability
The Free Tier is provided without an availability commitment, without a Service Level Agreement and without any entitlement to support. § 4.3 of the General Terms and Conditions as well as the Service Level Agreement do not apply to the Free Tier; service may be interrupted at any time without prior notice.

No Entitlement to the Offer
There is no entitlement to the provisioning, continuation or restoration of a Free Tier namespace. IT-Service Harting reserves the right to amend, discontinue or convert the Free Tier into a paid offering after prior notification (cf. § 4.1 of the General Terms and Conditions).

Testbed for New Features
The Free Tier additionally serves as a testbed for new or not yet generally available features of the ITSH platform. Such features may be made available to, modified within, or removed from the Free Tier without prior notice; there is no entitlement to their availability or continuation.

Intended Use
The Free Tier is intended for evaluation, development, and testing. Use for production or business-critical workloads, or for the processing of third-party personal data, is expressly discouraged; the customer bears sole risk in that regard.

10

Free Tier – Eligibility and Anti-Abuse

Eligibility
Provisioning of a Free Tier namespace requires a registered customer account with successful phone verification. The Free Tier may be claimed once per customer account (one-shot lifetime); after release or closure of a Free Tier namespace, a renewed claim from the same account is not possible. Customers with paid Kubernetes products may additionally claim a single Free Tier namespace alongside their paid resources.

Anti-Abuse Checks
To prevent multiple registrations and automated abuse, technical checks are performed prior to provisioning. These include uniqueness of the verified phone number, exclusion of disposable email providers, request frequency from the same IP network range and – where supplied – uniqueness of the VAT identification number. Further information on the data processed and the legal basis is set out in our Privacy Policy.

Rejection and Manual Review
The check is automated; if it yields a match, provisioning of the Free Tier namespace is refused. If you believe the refusal is incorrect, you may contact service@itsh.dev. We will then have the case reviewed by a member of staff, tell you the outcome, and provision the namespace if the refusal was not justified. The Free Tier may not be combined with promotional credits or discount campaigns.

No Resale or Third-Party Use
The Free Tier may not be resold, sublicensed, used on behalf of third parties, or used as the basis for any service the customer offers to its own customers (no service-bureau, reselling, or timesharing use).

Sanctions and Export Controls
The customer warrants that it is not located in an EU- or OFAC-sanctioned jurisdiction and is not on any applicable restricted-party list. Use in violation of Regulation (EU) 2021/821 or EU sanctions regimes is prohibited.

Investigative Access on Abuse Suspicion
Where IT-Service Harting has reasonable grounds to suspect abuse – in particular matches in reputation services, inbound abuse complaints from third parties, or anomalous egress or claim patterns – IT-Service Harting may technically access namespace contents (pods, logs, persistent volumes) to the extent necessary for investigation. Legal basis: Art. 6(1)(f) GDPR; access is logged.

Geographic Availability
The Free Tier is provided only to requests originating from the European Economic Area, the United Kingdom, Switzerland, the United States, Canada, Australia, and New Zealand. Requests from sanctioned jurisdictions are technically refused. The paid Kubernetes plans are not subject to this geographic restriction.

Payment Method Verification
Where a Free Tier request is assessed as presenting an elevated risk of abuse, provisioning may be made conditional on the verification of a valid payment method. Verification is carried out by way of a zero-amount authorisation via our payment service provider; no charge is made and no recurring payment is set up. The requirement does not apply to the majority of requests, and completing the verification does not affect the free nature of the Free Tier. The specific criteria used to assess risk are not disclosed, in order to preserve the effectiveness of the measure.

Origin of the Request
The Free Tier is intended to be claimed over an ordinary residential or mobile internet connection. Requests originating from cloud, hosting, data-centre, or comparable networks – identified by the network operator (autonomous system) of the IP address used – may be technically refused. This restriction serves to prevent automated and large-scale abuse and does not apply to the paid Kubernetes plans.

11

Free Tier – Suspension, Data Retention and Upgrade Path

Automatic Suspension
Without prejudice to the rights set out in § 3.5 of the General Terms and Conditions, Free Tier namespaces may be suspended automatically if: (a) the monthly egress limit of 10 GiB is reached, (b) no outbound HTTP traffic is observed for 30 consecutive calendar days (inactivity), or (c) abuse signals are present (in particular matches in recognised reputation services – such as PhishTank or comparable public phishing databases –, inbound abuse complaints from third parties, or anomalous claim patterns).

Resumption
Where suspension was triggered by the egress limit, the namespace is resumed automatically on the first day of the following calendar month. Where suspension was triggered by inactivity, the customer can resume the namespace via the self-service customer portal; a notification email is sent from day 23 of inactivity. Where suspension was triggered by abuse signals, no automatic resumption takes place; reactivation requires manual review by our team.

Data Retention During Suspension and on Release
During suspension, kubectl access is removed. All pods are terminated and deleted; data stored on persistent volumes (PVCs) is retained until the namespace is released. If the Free Tier namespace is released by the customer (via the "Release" function in the self-service customer portal) or deprovisioned as part of abuse handling, all namespace contents including persistent volumes are permanently deleted. Recovery is not possible thereafter. The customer is responsible for maintaining their own off-platform backups (cf. § 7.4 of the General Terms and Conditions).

Upgrade to a Paid Tier
Upgrading from the Free Tier to a paid Kubernetes tier is available at any time. Existing namespace contents are preserved during the upgrade; existing *.itsh-apps.dev hostnames continue to work after the upgrade.

Domain Service Agreement

1

Domain Registration

IT-Service Harting acts as an intermediary between the customer and the respective registration authority in domain registration. There is no entitlement to allocation of a specific domain (cf. § 4.2 of the General Terms and Conditions).

The customer is responsible for checking whether the desired domain violates the rights of third parties (in particular trademark, name or identification rights). IT-Service Harting does not carry out any such check.

2

Allocation Guidelines

For the registration and management of domains, the respective allocation conditions of the competent registration authorities additionally apply. This includes in particular:

  • DENIC eG for .de domains
  • ICANN-accredited registrars for generic TLDs (.com, .net, .org, etc.)
  • National registration authorities for country-specific TLDs (.at, .ch, .eu, etc.)

The customer undertakes to comply with the applicable guidelines in each case. The current conditions can be viewed on the websites of the respective registration authorities.

3

Holder Data and WHOIS

The customer is obliged to provide correct and complete holder data (registrant data). This is a requirement of ICANN and other registration authorities. Changes to the data must be notified within 14 days in accordance with § 2.3 of the General Terms and Conditions.

WHOIS privacy protection is offered for supported TLDs, insofar as this is permitted by the respective registration authority.

4

Domain Transfer

Domains are equipped with a transfer lock by default to prevent unauthorised transfers. This can be deactivated by the customer in the self-service customer portal.

For transfer to another provider, an AuthCode (authorisation code) is required, which can be requested via the self-service customer portal. The AuthCode is valid for 30 days. The customer is responsible for initiating the transfer with the new provider.

5

DNS Management

All domains include complete DNS management via the self-service customer portal. 26 different DNS record types are supported (including A, AAAA, CNAME, MX, TXT, SRV, CAA).

The customer is responsible for the correct configuration of their DNS records. IT-Service Harting assumes no liability for malfunctions resulting from incorrect DNS configurations.

6

Contract Term, Termination and Registration Period

The domain contract is concluded for an indefinite period and may be terminated by either party at any time on one month's notice (§ 3.2 of the General Terms and Conditions). With entrepreneurs, renewal for successive twelve-month periods may be agreed instead.

Registration period
This is distinct from the registration period at the registry. Depending on the TLD it is usually twelve months, and we acquire it from the registry in advance and irrevocably on ordering and on each renewal. The domain remains active until the end of each paid registration period.

Refunds
If the contract ends during a running registration period, we refund fees paid in advance on a pro-rata basis. This does not apply to the fee for the registration period itself insofar as the registry does not refund it to us; we acquired that period irrevocably and cannot return it. The value remains yours: the domain continues to the end of the paid period and can be transferred to another provider by AuthCode at any time until then. We delete a domain early only on your express instruction.

Verification of registrant data
We are required by § 49 BSIG to maintain accurate and complete registration data. To that end the customer verifies the e-mail address and telephone number on file within 14 days of registration or of any change to that data. The procedure is described in our NIS2 guidelines.

Consequences of failed verification
If verification is not completed after the deadline and a reminder allowing a further seven days, we may suspend the domain; it is then not reachable on the internet. The suspension is lifted once verification is completed. For the duration of a suspension for which the customer is responsible, the agreed remuneration remains payable, because the registration period at the registry continues unchanged. If verification remains outstanding for more than 60 days, we may terminate the contract for good cause and release the domain.

Objection
The customer may object to a suspension within 14 days in text form. We review the objection and communicate the result with reasons within seven working days.

After the contract ends, the domain is released in accordance with the rules of the competent registry.

7

Dispute Resolution

Domain disputes (e.g. due to trademark infringements) are handled according to the procedures of the competent registration authority. For generic TLDs, the Uniform Domain-Name Dispute-Resolution Policy (UDRP) of ICANN particularly applies.

IT-Service Harting is not a party to domain disputes between the customer and third parties and does not assume any mediator role.