Responsible Party
IT-Service Harting
Proprietor: Giovanni Harting
Hermann-Löns-Str. 9352078 Aachen
Germany
How is your data processed?
We store and use your personal data only for processing your orders and for contacting you. If you have subscribed to our newsletter, we also use your email address to send it.
What categories of data are collected?
Each time you access our websites and interfaces, your full IP address is stored together with the connection data of the request for seven days (details under "Server Log Files"). When you register with us, your contact details are stored. When you order products from us, your address and payment details are also stored.
Registration Data
As part of your registration with us, we must collect and process certain personal data from you as your registration data. For example, we need your name, address data, telephone number, payment data and your email address to process your orders.
When paying by credit card, we do not collect or store any payment transaction information such as credit card numbers or verification numbers. You only provide these directly to the respective payment service provider.
If you delete your user account, we anonymise the account data. Invoicing and accounting records must however be retained by law: accounting vouchers for eight years, books and records for ten years (§ 147 AO), and commercial and business letters for six years (§ 257 HGB). For the duration of those periods, processing is restricted under Art. 18 GDPR to fulfilling the retention obligation; the data is deleted once they expire. You can request deletion of your user account through the customer portal or by e-mail to service@itsh.dev.
Legal basis: Art. 6 para. 1 lit. b GDPR
Email Addresses & Newsletter
If you have subscribed to our newsletter, we also store your email address. We delete this data when you delete your user account or when you have unsubscribed from the newsletter.
To ensure consensual newsletter distribution, we use the so-called double opt-in procedure. In the course of this, the potential recipient can be added to a mailing list. The user then receives a confirmation email giving them the opportunity to legally confirm the registration.
You can revoke your consent to the storage of data at any time, for example via the "Unsubscribe" link in the newsletter.
Legal basis: Art. 6(1)(a) GDPR (consent). We retain the record of consent (time, IP address, confirmation link) under Art. 7(1) GDPR for the duration of the subscription and for three years thereafter.
Server Log Files
Every request to our websites, our customer portal and our programming interfaces passes through a central gateway. For each request it logs your full IP address, date and time, the request method and the address requested including query parameters, the response status, the amount of data transferred, the page you came from, and the type and version of your browser. Behind it, the programming interface and the web server of our customer portal keep their own logs with the same details, the programming interface additionally with the processing time. We do not truncate the IP address in these logs: attacks, abuse and targeted overloading can only be attributed to a source and blocked with the full address. The logs never leave our own infrastructure, which runs at Hetzner Online GmbH: they are processed in Nuremberg and, for as long as they are kept, stored in a Hetzner Online GmbH data centre in the EU. The same applies to the access log of our container registry, which likewise contains your full IP address and is deleted after seven days. We evaluate them only to detect and repel attacks, to investigate abuse and overload attacks, and to diagnose faults; we do not use them for any other purpose, in particular not for audience measurement or advertising. Requests to our customers' websites hosted with us pass through the same gateway (see "Web Hosting"). This is distinct from the storage of your IP address in your customer account's activity log, which we describe separately under "Anti-Abuse Checks for the Free Kubernetes Namespace".
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the security of our networks and systems (Recital 49 GDPR): being able to detect, repel and investigate attacks, abuse and targeted overloading, and to fix faults. This requires the full IP address, and beyond the end of the individual request, because attacks often only become recognisable from many requests viewed together over several days. Your interests do not override it: we evaluate the logs only when there is a specific reason, do not routinely combine them with your customer account or other data sources, do not pass them to third parties except where "Support requests and abuse notices" or "Disclosures to authorities" provide otherwise, and delete them after seven days. You may object to the processing at any time under Art. 21 GDPR.
Retention: seven days, after which the logs are deleted automatically. Entries we need to handle a specific security incident or abuse notice are taken into the respective case file, to which the period stated under "Support requests and abuse notices" applies.
Error Tracking (Sentry)
We use Sentry, a service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, for monitoring and diagnosing application errors. Its representative in the Union is Sentry Software Netherlands B.V., Amsterdam.
In the event of an error, the following data is collected: error logs, device information, browser information and IP address (anonymised). The data is stored for 90 days.
Sentry is certified under the EU-US Data Privacy Framework. Further information can be found in the Sentry Privacy Policy.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in the stability and improvement of the application)
Bot Protection (Cloudflare Turnstile)
We use Cloudflare Turnstile, a service of Cloudflare Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to protect against automated abuse (bots, spam).
When using this service, the following data is collected: browser information, IP address and interaction patterns. Unlike traditional CAPTCHA solutions, Turnstile does not use tracking cookies and is designed to be more privacy-friendly.
Cloudflare is certified under the EU-US Data Privacy Framework. Further information can be found in the Cloudflare Privacy Policy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against abuse). Turnstile already loads when a form page such as the login is opened, that is before any cookie consent. The associated access to your terminal equipment is strictly necessary under § 25(2) No. 2 TDDDG in order to protect the service you requested against automated attacks, and therefore requires no consent.
Website Analytics
We use the open-source web analytics tool Matomo as a self-hosted system. Matomo stores no cookies and does not otherwise access your terminal equipment, so no consent under § 25 TDDDG is required. What is processed is a truncated IP address, the pages viewed, the referring source and browser and device details. The data does not leave our own infrastructure.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in designing our offering to meet demand and in measuring its reach; because the analysis takes place without accessing your device and without combining it with other data sources, your interests do not override it. You may object at any time under Art. 21 GDPR.
Retention: 14 months.
Marketing & Advertising (Google Ads)
With your explicit consent, we use Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure the effectiveness of our advertising campaigns.
When you give your consent, the following data is collected: Google Click ID (GCLID), page views, conversion events and IP address. This data is used to analyse and optimise our advertising measures.
You can revoke your consent at any time via the "Cookie Settings" link in the footer.
The entity certified under the EU-US Data Privacy Framework is Google LLC, to which Google Ireland Limited passes the data; standard contractual clauses are in place in addition. Further information is available in the Google Privacy Policy.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
Data Sharing with Third Parties
Besides us, external service providers who support us in delivering our services have access to your data. Our entire infrastructure runs at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen: the live systems and your active data in Nuremberg (Germany), backups and long-term log storage in a further Hetzner Online GmbH data centre in the EU. Domains are registered through INWX GmbH, Prinzessinnenstraße 30, 10969 Berlin. Both are our processors. A current list of the sub-processors we use is available in the customer portal.
Domain Registration
When we register a domain for you, we pass the holder data required for that purpose (name, address, e-mail address, telephone number) to our registrar INWX GmbH (Germany) and through them to the registry responsible for the TLD in question. Depending on the TLD the registry may be established outside the EEA; the transfer is then necessary for the performance of your order (Art. 49(1)(b) GDPR). Part of this data may be retrievable through public directory services (WHOIS/RDAP) where the registry provides for that. Further recipients are applications the holder of the customer account connects to it: they receive the holder's own default contacts in full, including a contact person named there, and of every other domain contact only the identifier, type, country and verification status, for organisations also the company name (see "Connected applications and AI agents").
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the accuracy of the registration data additionally Art. 6(1)(c) GDPR in conjunction with § 49 BSIG.
Payment Processing (Stripe)
Payments are processed through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. For customers in the European Economic Area this is our contracting party, and it passes the data on to Stripe, Inc., South San Francisco, USA. The data transmitted comprises name, e-mail address, payment information and IP address.
Stripe, Inc. is certified under the EU-US Data Privacy Framework; standard contractual clauses under Art. 46(2)(c) GDPR are in place in addition.
Further information can be found in the Stripe Privacy Policy.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfilment)
Debt Collection
If you fail to settle due claims despite a reminder, we pass the data required for recovery (name, address, amount and grounds of the claim) to a debt collection company.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in enforcing outstanding claims).
Third Countries
Transfers to third countries take place only to the recipients and categories of recipients named in this policy. For the US recipients Stripe, Inc., Functional Software, Inc. (Sentry), Cloudflare, Inc. and Google LLC we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); in addition we have agreed standard contractual clauses under Art. 46(2)(c) GDPR with those recipients, which continue to apply should the adequacy decision fall away. We will provide a copy of the safeguards on request. In addition, data may reach recipients an application you connected to your account passes it on to; who that is and in which country it sits is determined by your choice of application and its setup. The details and the legal basis are set out under "Connected applications and AI agents".
Data Processing
Your content, hosting and customer data is processed exclusively in ISO 27001 certified Hetzner Online GmbH data centres within the EU: the live systems in Nuremberg (Germany), backups and long-term log storage at a further EU site. Your data does not leave the EU through our infrastructure. Excepted are the auxiliary services with a third-country element named individually in this policy (payment processing, error diagnostics, bot protection and — where you have consented — advertising measurement); the safeguards stated there apply to those. Also excepted is data that an application you connected passes on to recipients of your choosing (see "Connected applications and AI agents").
Online Presence on Social Media
We maintain online presences within social networks and platforms in order to communicate with our customers, prospective customers and users and to inform them about our services.
For the processing of usage data on the platform pages we are joint controllers with the respective provider (Art. 26 GDPR). The platform operators make the essence of the arrangements available in their own terms; we have no determining influence over the processing that takes place there. You may exercise your data subject rights against us as well as against the platform operator.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communication and public presence).
Product Advice via Live Chat
For support requests we use the Zammad ticket and chat system. The chat widget loads only in the signed-in customer area, not on the public pages. What is processed is the message content you send, your contact details and technical connection data. We run Zammad on our own infrastructure in the EU (operated in Germany, backups at a further EU site); no data is passed to third parties.
Legal basis: Art. 6(1)(b) GDPR for handling contract-related requests, otherwise Art. 6(1)(f) GDPR (interest in answering enquiries).
Retention: support cases are deleted three years after closure.
Email Hosting
As part of our Email Hosting service, we process email content (messages, attachments), email metadata (sender, recipient, subject, timestamps), login data (IP addresses, times) and IMAP and SMTP session data.
Processing takes place on our self-hosted mail server in ISO 27001 certified Hetzner Online GmbH data centres in the EU: operation in Germany, backups and logs at a further EU site. No transfer to third countries takes place.
E-mail content is stored for the duration of the contractual relationship and, after it ends, deleted or returned in accordance with the data processing agreement. Login logs and message metadata are deleted automatically after 90 days.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
Web Hosting
As part of our Web Hosting service, we store website content, database content and files uploaded via file access (SFTP) provided by the customer.
Requests to websites hosted with us pass through the same gateway as our own pages. For each request it logs the visitor's full IP address, time, request method, address requested including query parameters, status, amount of data, referring page and browser. SFTP logins are logged with time and IP address. Both logs serve solely the security and fault diagnosis of the platform and are deleted automatically after seven days; where they are stored and how they are evaluated is described under "Server Log Files". For this processing we are the customer's processor; the controller towards the visitors of the website is the customer, who informs them in its own privacy policy.
For personal data of third parties stored by customers on web hosting, the customer is the data controller within the meaning of the GDPR (cf. § 8 of our Terms).
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
Connected applications and AI agents (OAuth 2.1 / MCP)
You can connect applications, including AI agents such as Claude or ChatGPT, to your customer account. The connection uses OAuth 2.1 and the Model Context Protocol (MCP): the application requests specific permissions, you decide on our consent page which of them it receives, and the application then accesses your account on your behalf. This processing only takes place if you connect an application yourself.
For the application we store what it submits when it registers with us or what we retrieve from the metadata document it publishes: name, redirect addresses, technical metadata and, where present, the host we retrieved that document from. We do not check who is behind an application; the consent page says so. If it shows an application as "verified", that only means its name and metadata came from the stated host, not that we know the operator or have examined the application itself.
For each connection we store the permissions requested and granted, the interfaces it applies to, the expiry you set, the spending limit (currently always zero, because no application can trigger purchases or orders), the status, the time and reason of any termination, and the time a token of the connection was last presented, including a request we refused. As evidence of your decision we additionally store the time of consent, the version of the consent text shown to you, whether you consented to the transfer to a third country and the version of the notice shown to you for it, your IP address and your browser identifier.
Access and refresh tokens are stored only as a keyed hash; no valid token can be reconstructed from our database. For each token we store its permissions, interfaces and expiry, and for access tokens also the last use. Access tokens are valid for at most 24 hours, refresh tokens for at most 30 days and never beyond the connection. Authorisation codes and pending authorisation requests contain the redirect address, the application's state value and the PKCE challenge; a code is valid for one minute, a request for ten. A request you did not answer is deleted when it expires. All other tokens, codes and requests are deleted seven days after their expiry date by the half-hourly cleanup run; revoked and used ones stay marked unusable until then, so we can answer support requests about a connection.
When a connected application calls an MCP tool that changes something in your account or goes beyond merely reading, we log it before the tool runs: connection and account, tool name, HTTP method, route template and path (never the query parameters), permissions used, status, outcome and duration, the IP address the application accessed from, the name the application reports for itself, and the time. Of the call's arguments, only the values the respective tool names are kept in clear text, such as the name, type and content of a DNS record or the targets of a forward: at most 255 characters per text value, at most 50 entries per list, at most 4,096 bytes per call in total; anything beyond that is truncated or omitted, and the entry says so. All arguments together are additionally stored as a keyed digest from which the values cannot be recovered. Passwords, keys and tokens are never stored in clear text; confirmation codes are left out of the digest as well. Where a change replaces or deletes an existing value, such as the content of a DNS record or the targets of a forward, we keep the previous value in full up to 4,096 bytes, and above that only its size and a SHA-256 checksum. Where an application sets up forwarding to addresses outside your domains, we record separately the targets outside your domains that the change newly added. Read-only access is not logged.
If we refuse a request made with a connected application's token, for instance because the permission is missing, the route is closed to applications, the token was issued for a different interface, or connecting applications is not enabled for your account, we store connection, account, method, route template (never the concrete path), reason, required permissions, the token's interface, status, the caller's IP address and the time. Per connection, reason and route we store at most one entry per hour, at most 200 per connection and 1,000 per account per day. These entries show you what an application attempted and let us detect a lost token being replayed against our interface.
Whatever a connected application retrieves within its permissions, for example your account data, domains or subscriptions, we send to that application. Where the data goes from there is determined by your choice of application and its settings, not by us: to the application's vendor, if it runs the application for you (such as Anthropic for claude.ai or OpenAI for ChatGPT), to the provider of the AI model the application presents the results to, to both, or to nobody, if the application and the model run on your own devices. We cannot tell which setup you use. In this section, "recipient" means whoever receives the data from the application in this way. A recipient processes the data either as an independent controller, for example on consumer plans; which data it keeps, for how long, and whether it uses it to train AI models is then governed by its terms and its privacy policy. Or it processes the data on your behalf, for example on business and API plans; then you decide what happens to it. Which company is your contracting party in that case, and whether and on what basis it transfers data to countries outside the EEA, follows from the respective vendor's terms and privacy policy; we are not involved in that onward disclosure and have no influence over it. If your permissions cover data of other people, that data reaches the recipient too, for example mailbox names under mail permissions; of domain contacts that are not your own default contacts, however, the application receives only the identifier, type, country and verification status, and for organisations also the company name.
If your application, model included, runs entirely on your own devices, nobody but you receives the data and no transfer to a third country takes place. If a recipient is established in the EEA, we ourselves transfer no data to a third country; its own onward transfers to third countries are its responsibility under its terms and its privacy policy. If your application sends the data to a recipient outside the EEA, or we do not know the recipient, the following applies: we have no contract with it and cannot agree safeguards under Art. 46 GDPR on its behalf; whether an adequacy decision of the European Commission applies to its country (Art. 45 GDPR), for example because it is certified under the EU-US Data Privacy Framework, depends on the application and its setup. Where no adequacy decision applies, we base the transfer of your own data on your explicit consent under Art. 49(1)(a) GDPR, which you give when connecting the application after we have informed you there of the risks: in the third country there may be no supervisory authority, no processing principles equivalent to the GDPR and no enforceable data subject rights, and we have no influence over the recipient's processing. Because we can tell neither the recipient nor its role, we ask for this consent when you connect any application that is not ours. It takes effect only insofar as a transfer to a third country without an adequacy decision actually occurs; if your application runs only on your devices or the recipient sits in the EEA, it has no object. You can withdraw the consent at any time by disconnecting the application. The lawfulness of transfers made before the withdrawal is not affected, and data already transferred is not recalled by it.
You can see your connections and the log, and from the consent evidence the time, your IP address and your consent to the third-country transfer, in the customer portal under "Connected applications"; the complete evidence including browser identifier and text versions is in your account's data export. Our support sees them in the customer portal only when signing in to your account for troubleshooting; every such sign-in is logged. Team members and resellers who switch into your account do not see them. The application itself can only retrieve its own connection, without IP address and browser identifier.
If you delete your account, or we anonymise a deactivated account, we delete the log, all tokens, codes and requests, end all active connections and remove the IP address and browser identifier from every consent record. Where payment transactions are attributed to a connection, the connection record (application, permissions, times, spending limit) is kept without those details as part of the accounting voucher for the periods stated under "Registration Data" and is restricted under Art. 18 GDPR to fulfilling the retention obligation; all other connection records are deleted.
You can disconnect any connection at any time in the customer portal; the application loses access to your account immediately. Connections, consent evidence and the log are part of your account's data export (Art. 15 and Art. 20 GDPR). You may object under Art. 21 GDPR to the logging based on Art. 6(1)(f) GDPR (see "Your right to object"). Connecting applications is voluntary and not required for any contract with us.
Legal basis: Art. 6(1)(b) GDPR for setting up and carrying out the connection, including the transmission to the application you chose, and for the activity view. Art. 6(1)(f) GDPR for the consent evidence, the log of changes and the entries on refused requests; for the evidence of your consent to the third-country transfer, Art. 6(1)(c) in conjunction with Art. 7(1) GDPR. Our legitimate interest, which is also yours: being able to attribute changes to your account to the application that made them, detecting misuse of lost tokens, and being able to prove your decision in a dispute. Your interests do not override it: the log contains no credentials and, of content, only what the application itself wrote or replaced, you can see all of it yourself, and it is deleted after fixed periods. For data of other people that an application retrieves with your permissions and for which we are ourselves the controller, such as the company name of another organisation contact or the contact person in your own organisation contact, Art. 6(1)(f) GDPR applies: your interest in managing your services with tools of your choice; only what your permissions cover is transmitted, out of data you already manage in your account. For the transfer of your own data to a third country without an adequacy decision: Art. 49(1)(a) GDPR. Your consent does not cover the transfer of other people's data. An application therefore receives domain contacts in full only where they are your own default contacts: the person created with your account and, if your account has an organisation, that organisation. Of every other contact it receives only the identifier, type, country and verification status, and for organisations also the company name; the name, address, telephone, fax and e-mail address of other contacts never reach an application. Where we process other people's data on your behalf (e-mail, web hosting, Kubernetes and storage data), we transmit it on your documented instruction under the data processing agreement; you are responsible as controller for the lawfulness of that transfer.
Cookies and access to your terminal equipment
Storing information in your terminal equipment and accessing information already stored there is permitted under § 25(1) TDDDG only with your consent. Excepted is storage strictly necessary to provide a service you have expressly requested (§ 25(2) No. 2 TDDDG). The provision is technology-neutral and therefore covers not only cookies but also your browser's local storage.
You can withdraw your consent at any time via the "Cookie settings" link in the footer. Withdrawal takes effect for the future: advertising identifiers already stored are deleted and measurement stops; processing carried out beforehand remains lawful.
Telephone verification (SMS and voice call)
For domain registrations and for the free Kubernetes namespace we verify the telephone number on file. To do so we transmit your telephone number and the verification code to seven communications GmbH & Co. KG, Willestraße 4-6, 24103 Kiel, Germany, which sends the SMS or places the voice call on our behalf.
The dispatch provider is our processor and the processing takes place in Germany. We store the telephone number, the time and the outcome of the verification.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for domain registrations additionally Art. 6(1)(c) GDPR in conjunction with § 49 BSIG, which requires us to keep accurate registration data.
Retention: the verification result is kept for the duration of the contract; the verification code is deleted after 10 minutes at the latest.
Server-side advertising attribution
If you have consented to advertising measurement and reached us through a Google Ads advertisement, we store the click identifier (Google Click ID) on our servers together with your customer account and your order.
After a contract is concluded we transmit that identifier, together with the time and value of the conclusion, to Google so the effectiveness of the campaign can be measured. We do not transmit personal details such as your name or e-mail address.
If you withdraw your consent, we delete the stored identifier and do not transmit future conclusions.
Legal basis: Art. 6(1)(a) GDPR (consent).
Retention: 90 days from the click, and no longer than until consent is withdrawn.
Support requests and abuse notices
When you write to us via the contact or ticket form we process your details in order to handle the request. If you submit an abuse notice we additionally process the domain or address you report, your reasoning and your contact details.
We handle abuse notices in accordance with Art. 16 of Regulation (EU) 2022/2065. We confirm receipt, communicate the decision taken, and inform the affected customer of any measures; in doing so your notice may be passed to the customer, without your contact details where they are not needed to handle the matter.
Legal basis: Art. 6(1)(b) GDPR for contract-related requests, Art. 6(1)(c) GDPR for handling notices under the Digital Services Act, otherwise Art. 6(1)(f) GDPR.
Retention: notices and the associated case file are deleted three years after closure.
Disclosures to authorities
As a provider of domain registration services we are required by § 50 BSIG to disclose domain registration data to legitimate access seekers upon reasoned request. Legitimate access seekers are, under § 2 No. 2 BSIG, the Federal Office for Information Security, Land authorities, prosecuting authorities, the federal and Land police forces and the constitutional protection authorities.
What may be disclosed is the domain holder's name, address, e-mail address and telephone number, together with the registration and expiry dates. We do not release credentials, payment information or correspondence; that requires a separate judicial order. Every request is checked for legitimacy, legal basis and proportionality, and is logged.
Legal basis: Art. 6(1)(c) GDPR in conjunction with § 50 BSIG. Where we handle requests from other bodies voluntarily, we rely on Art. 6(1)(f) GDPR following a case-by-case assessment.
Anti-Abuse Checks for the Free Kubernetes Namespace
When a free Kubernetes namespace (Free Tier) is requested, we perform technical checks to prevent multiple registrations and automated abuse. The following data categories are processed in this context:
- Verified phone number of the applicant, compared against phone numbers held on other active customer accounts to detect duplicate accounts.
- Domain portion of the email address on file, compared against a publicly maintained list of disposable email providers.
- IP address used at the time of the request, evaluated to detect repeated requests originating from the same network range.
- IP address used at the time of the request, evaluated to determine (a) the approximate country of origin and (b) the network operator (autonomous system), in order to enforce the geographic availability of the Free Tier and to detect requests from cloud or hosting networks. This evaluation uses a local geolocation database (MaxMind GeoLite2); the IP address is not transmitted to the database provider or any other third party for this purpose.
- VAT identification number, where provided, compared against the VAT IDs of other active Free Tier customer accounts.
The applicant's IP address is recorded together with the request in the customer account activity log. The decision on provisioning is made automatically on the basis of these checks. You may request review by a member of staff, express your point of view and contest the decision by contacting service@itsh.dev. The data processed for these checks is not shared with third parties and is used exclusively for the purpose of abuse prevention. Technical warnings generated by these checks contain the IP address and are subject to the seven-day retention of the server log files.
Retention period: The activity logs follow the general retention of the customer account and are anonymised together with the account upon account closure.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the prevention of abuse and duplicate registrations for free services)
Dedicated Egress IP for the Free Tier
Outbound network traffic originating from Free Tier Kubernetes namespaces is routed through a dedicated IP address (PTR record: egress.itsh-apps.dev). This is a technical measure to separate the Free Tier's reputation from the rest of the platform and does not itself constitute additional processing of personal data beyond the processing already documented for server log files.
Your right to object
Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. This covers in particular the server logs, audience measurement, bot protection, error diagnostics, our social media presences, abuse prevention, and the consent evidence and log of connected applications.
If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to establish, exercise or defend legal claims.
Where your data is processed for direct marketing, you may object at any time without giving reasons; we will then stop processing it for that purpose.
An objection requires no particular form — an e-mail to service@itsh.dev is sufficient.
Your Rights
You have the following rights regarding your personal data:
- Right of Access – Right to information about the processed data
- Right to Rectification – Right to correction of incorrect data
- Right to Erasure – Right to deletion of your data
- Right to Restriction – Right to restriction of processing
- Right to Object – Right to object to processing
- Data Portability – Right to transfer your data
- Right to Complain – Right to lodge a complaint with a supervisory authority
Visiting our website and subscribing to the newsletter are possible without providing personal data, or are revocable at any time. To conclude a contract, however, we require your name, address and e-mail address, and for domain registrations and the free Kubernetes namespace additionally a verified telephone number; without these we cannot conclude the contract in question. The legal basis is Art. 6(1)(b) GDPR, and for telephone verification of domains additionally Art. 6(1)(c) GDPR in conjunction with § 49 BSIG. Connecting applications and AI agents is voluntary; without a connection, the processing described there does not take place.