How is your data processed?

We store and use your personal data only for processing your orders and for contacting you. If you have subscribed to our newsletter, we also use your email address to send it.

What categories of data are collected?

Each time you access our websites and interfaces, your full IP address is stored together with the connection data of the request for seven days (details under "Server Log Files"). When you register with us, your contact details are stored. When you order products from us, your address and payment details are also stored.

Registration Data

As part of your registration with us, we must collect and process certain personal data from you as your registration data. For example, we need your name, address data, telephone number, payment data and your email address to process your orders.

When paying by credit card, we do not collect or store any payment transaction information such as credit card numbers or verification numbers. You only provide these directly to the respective payment service provider.

If you delete your user account, we anonymise the account data. Invoicing and accounting records must however be retained by law: accounting vouchers for eight years, books and records for ten years (§ 147 AO), and commercial and business letters for six years (§ 257 HGB). For the duration of those periods, processing is restricted under Art. 18 GDPR to fulfilling the retention obligation; the data is deleted once they expire. You can request deletion of your user account through the customer portal or by e-mail to service@itsh.dev.

Email Addresses & Newsletter

If you have subscribed to our newsletter, we also store your email address. We delete this data when you delete your user account or when you have unsubscribed from the newsletter.

To ensure consensual newsletter distribution, we use the so-called double opt-in procedure. In the course of this, the potential recipient can be added to a mailing list. The user then receives a confirmation email giving them the opportunity to legally confirm the registration.

You can revoke your consent to the storage of data at any time, for example via the "Unsubscribe" link in the newsletter.

Server Log Files

Every request to our websites, our customer portal and our programming interfaces passes through a central gateway. For each request it logs your full IP address, date and time, the request method and the address requested including query parameters, the response status, the amount of data transferred, the page you came from, and the type and version of your browser. Behind it, the programming interface and the web server of our customer portal keep their own logs with the same details, the programming interface additionally with the processing time. We do not truncate the IP address in these logs: attacks, abuse and targeted overloading can only be attributed to a source and blocked with the full address. The logs never leave our own infrastructure, which runs at Hetzner Online GmbH: they are processed in Nuremberg and, for as long as they are kept, stored in a Hetzner Online GmbH data centre in the EU. The same applies to the access log of our container registry, which likewise contains your full IP address and is deleted after seven days. We evaluate them only to detect and repel attacks, to investigate abuse and overload attacks, and to diagnose faults; we do not use them for any other purpose, in particular not for audience measurement or advertising. Requests to our customers' websites hosted with us pass through the same gateway (see "Web Hosting"). This is distinct from the storage of your IP address in your customer account's activity log, which we describe separately under "Anti-Abuse Checks for the Free Kubernetes Namespace".

Error Tracking (Sentry)

We use Sentry, a service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, for monitoring and diagnosing application errors. Its representative in the Union is Sentry Software Netherlands B.V., Amsterdam.

In the event of an error, the following data is collected: error logs, device information, browser information and IP address (anonymised). The data is stored for 90 days.

Sentry is certified under the EU-US Data Privacy Framework. Further information can be found in the Sentry Privacy Policy.

Bot Protection (Cloudflare Turnstile)

We use Cloudflare Turnstile, a service of Cloudflare Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to protect against automated abuse (bots, spam).

When using this service, the following data is collected: browser information, IP address and interaction patterns. Unlike traditional CAPTCHA solutions, Turnstile does not use tracking cookies and is designed to be more privacy-friendly.

Cloudflare is certified under the EU-US Data Privacy Framework. Further information can be found in the Cloudflare Privacy Policy.

Website Analytics

We use the open-source web analytics tool Matomo as a self-hosted system. Matomo stores no cookies and does not otherwise access your terminal equipment, so no consent under § 25 TDDDG is required. What is processed is a truncated IP address, the pages viewed, the referring source and browser and device details. The data does not leave our own infrastructure.

Marketing & Advertising (Google Ads)

With your explicit consent, we use Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure the effectiveness of our advertising campaigns.

When you give your consent, the following data is collected: Google Click ID (GCLID), page views, conversion events and IP address. This data is used to analyse and optimise our advertising measures.

You can revoke your consent at any time via the "Cookie Settings" link in the footer.

The entity certified under the EU-US Data Privacy Framework is Google LLC, to which Google Ireland Limited passes the data; standard contractual clauses are in place in addition. Further information is available in the Google Privacy Policy.

Data Sharing with Third Parties

Besides us, external service providers who support us in delivering our services have access to your data. Our entire infrastructure runs at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen: the live systems and your active data in Nuremberg (Germany), backups and long-term log storage in a further Hetzner Online GmbH data centre in the EU. Domains are registered through INWX GmbH, Prinzessinnenstraße 30, 10969 Berlin. Both are our processors. A current list of the sub-processors we use is available in the customer portal.

Domain Registration

When we register a domain for you, we pass the holder data required for that purpose (name, address, e-mail address, telephone number) to our registrar INWX GmbH (Germany) and through them to the registry responsible for the TLD in question. Depending on the TLD the registry may be established outside the EEA; the transfer is then necessary for the performance of your order (Art. 49(1)(b) GDPR). Part of this data may be retrievable through public directory services (WHOIS/RDAP) where the registry provides for that. Further recipients are applications the holder of the customer account connects to it: they receive the holder's own default contacts in full, including a contact person named there, and of every other domain contact only the identifier, type, country and verification status, for organisations also the company name (see "Connected applications and AI agents").

Payment Processing (Stripe)

Payments are processed through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. For customers in the European Economic Area this is our contracting party, and it passes the data on to Stripe, Inc., South San Francisco, USA. The data transmitted comprises name, e-mail address, payment information and IP address.

Stripe, Inc. is certified under the EU-US Data Privacy Framework; standard contractual clauses under Art. 46(2)(c) GDPR are in place in addition.

Further information can be found in the Stripe Privacy Policy.

Debt Collection

If you fail to settle due claims despite a reminder, we pass the data required for recovery (name, address, amount and grounds of the claim) to a debt collection company.

Third Countries

Transfers to third countries take place only to the recipients and categories of recipients named in this policy. For the US recipients Stripe, Inc., Functional Software, Inc. (Sentry), Cloudflare, Inc. and Google LLC we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); in addition we have agreed standard contractual clauses under Art. 46(2)(c) GDPR with those recipients, which continue to apply should the adequacy decision fall away. We will provide a copy of the safeguards on request. In addition, data may reach recipients an application you connected to your account passes it on to; who that is and in which country it sits is determined by your choice of application and its setup. The details and the legal basis are set out under "Connected applications and AI agents".

Data Processing

Your content, hosting and customer data is processed exclusively in ISO 27001 certified Hetzner Online GmbH data centres within the EU: the live systems in Nuremberg (Germany), backups and long-term log storage at a further EU site. Your data does not leave the EU through our infrastructure. Excepted are the auxiliary services with a third-country element named individually in this policy (payment processing, error diagnostics, bot protection and — where you have consented — advertising measurement); the safeguards stated there apply to those. Also excepted is data that an application you connected passes on to recipients of your choosing (see "Connected applications and AI agents").

Online Presence on Social Media

We maintain online presences within social networks and platforms in order to communicate with our customers, prospective customers and users and to inform them about our services.

For the processing of usage data on the platform pages we are joint controllers with the respective provider (Art. 26 GDPR). The platform operators make the essence of the arrangements available in their own terms; we have no determining influence over the processing that takes place there. You may exercise your data subject rights against us as well as against the platform operator.

Product Advice via Live Chat

For support requests we use the Zammad ticket and chat system. The chat widget loads only in the signed-in customer area, not on the public pages. What is processed is the message content you send, your contact details and technical connection data. We run Zammad on our own infrastructure in the EU (operated in Germany, backups at a further EU site); no data is passed to third parties.

Email Hosting

As part of our Email Hosting service, we process email content (messages, attachments), email metadata (sender, recipient, subject, timestamps), login data (IP addresses, times) and IMAP and SMTP session data.

Processing takes place on our self-hosted mail server in ISO 27001 certified Hetzner Online GmbH data centres in the EU: operation in Germany, backups and logs at a further EU site. No transfer to third countries takes place.

E-mail content is stored for the duration of the contractual relationship and, after it ends, deleted or returned in accordance with the data processing agreement. Login logs and message metadata are deleted automatically after 90 days.

Web Hosting

As part of our Web Hosting service, we store website content, database content and files uploaded via file access (SFTP) provided by the customer.

Requests to websites hosted with us pass through the same gateway as our own pages. For each request it logs the visitor's full IP address, time, request method, address requested including query parameters, status, amount of data, referring page and browser. SFTP logins are logged with time and IP address. Both logs serve solely the security and fault diagnosis of the platform and are deleted automatically after seven days; where they are stored and how they are evaluated is described under "Server Log Files". For this processing we are the customer's processor; the controller towards the visitors of the website is the customer, who informs them in its own privacy policy.

For personal data of third parties stored by customers on web hosting, the customer is the data controller within the meaning of the GDPR (cf. § 8 of our Terms).

Connected applications and AI agents (OAuth 2.1 / MCP)

You can connect applications, including AI agents such as Claude or ChatGPT, to your customer account. The connection uses OAuth 2.1 and the Model Context Protocol (MCP): the application requests specific permissions, you decide on our consent page which of them it receives, and the application then accesses your account on your behalf. This processing only takes place if you connect an application yourself.

For the application we store what it submits when it registers with us or what we retrieve from the metadata document it publishes: name, redirect addresses, technical metadata and, where present, the host we retrieved that document from. We do not check who is behind an application; the consent page says so. If it shows an application as "verified", that only means its name and metadata came from the stated host, not that we know the operator or have examined the application itself.

For each connection we store the permissions requested and granted, the interfaces it applies to, the expiry you set, the spending limit (currently always zero, because no application can trigger purchases or orders), the status, the time and reason of any termination, and the time a token of the connection was last presented, including a request we refused. As evidence of your decision we additionally store the time of consent, the version of the consent text shown to you, whether you consented to the transfer to a third country and the version of the notice shown to you for it, your IP address and your browser identifier.

Access and refresh tokens are stored only as a keyed hash; no valid token can be reconstructed from our database. For each token we store its permissions, interfaces and expiry, and for access tokens also the last use. Access tokens are valid for at most 24 hours, refresh tokens for at most 30 days and never beyond the connection. Authorisation codes and pending authorisation requests contain the redirect address, the application's state value and the PKCE challenge; a code is valid for one minute, a request for ten. A request you did not answer is deleted when it expires. All other tokens, codes and requests are deleted seven days after their expiry date by the half-hourly cleanup run; revoked and used ones stay marked unusable until then, so we can answer support requests about a connection.

When a connected application calls an MCP tool that changes something in your account or goes beyond merely reading, we log it before the tool runs: connection and account, tool name, HTTP method, route template and path (never the query parameters), permissions used, status, outcome and duration, the IP address the application accessed from, the name the application reports for itself, and the time. Of the call's arguments, only the values the respective tool names are kept in clear text, such as the name, type and content of a DNS record or the targets of a forward: at most 255 characters per text value, at most 50 entries per list, at most 4,096 bytes per call in total; anything beyond that is truncated or omitted, and the entry says so. All arguments together are additionally stored as a keyed digest from which the values cannot be recovered. Passwords, keys and tokens are never stored in clear text; confirmation codes are left out of the digest as well. Where a change replaces or deletes an existing value, such as the content of a DNS record or the targets of a forward, we keep the previous value in full up to 4,096 bytes, and above that only its size and a SHA-256 checksum. Where an application sets up forwarding to addresses outside your domains, we record separately the targets outside your domains that the change newly added. Read-only access is not logged.

If we refuse a request made with a connected application's token, for instance because the permission is missing, the route is closed to applications, the token was issued for a different interface, or connecting applications is not enabled for your account, we store connection, account, method, route template (never the concrete path), reason, required permissions, the token's interface, status, the caller's IP address and the time. Per connection, reason and route we store at most one entry per hour, at most 200 per connection and 1,000 per account per day. These entries show you what an application attempted and let us detect a lost token being replayed against our interface.

Whatever a connected application retrieves within its permissions, for example your account data, domains or subscriptions, we send to that application. Where the data goes from there is determined by your choice of application and its settings, not by us: to the application's vendor, if it runs the application for you (such as Anthropic for claude.ai or OpenAI for ChatGPT), to the provider of the AI model the application presents the results to, to both, or to nobody, if the application and the model run on your own devices. We cannot tell which setup you use. In this section, "recipient" means whoever receives the data from the application in this way. A recipient processes the data either as an independent controller, for example on consumer plans; which data it keeps, for how long, and whether it uses it to train AI models is then governed by its terms and its privacy policy. Or it processes the data on your behalf, for example on business and API plans; then you decide what happens to it. Which company is your contracting party in that case, and whether and on what basis it transfers data to countries outside the EEA, follows from the respective vendor's terms and privacy policy; we are not involved in that onward disclosure and have no influence over it. If your permissions cover data of other people, that data reaches the recipient too, for example mailbox names under mail permissions; of domain contacts that are not your own default contacts, however, the application receives only the identifier, type, country and verification status, and for organisations also the company name.

If your application, model included, runs entirely on your own devices, nobody but you receives the data and no transfer to a third country takes place. If a recipient is established in the EEA, we ourselves transfer no data to a third country; its own onward transfers to third countries are its responsibility under its terms and its privacy policy. If your application sends the data to a recipient outside the EEA, or we do not know the recipient, the following applies: we have no contract with it and cannot agree safeguards under Art. 46 GDPR on its behalf; whether an adequacy decision of the European Commission applies to its country (Art. 45 GDPR), for example because it is certified under the EU-US Data Privacy Framework, depends on the application and its setup. Where no adequacy decision applies, we base the transfer of your own data on your explicit consent under Art. 49(1)(a) GDPR, which you give when connecting the application after we have informed you there of the risks: in the third country there may be no supervisory authority, no processing principles equivalent to the GDPR and no enforceable data subject rights, and we have no influence over the recipient's processing. Because we can tell neither the recipient nor its role, we ask for this consent when you connect any application that is not ours. It takes effect only insofar as a transfer to a third country without an adequacy decision actually occurs; if your application runs only on your devices or the recipient sits in the EEA, it has no object. You can withdraw the consent at any time by disconnecting the application. The lawfulness of transfers made before the withdrawal is not affected, and data already transferred is not recalled by it.

You can see your connections and the log, and from the consent evidence the time, your IP address and your consent to the third-country transfer, in the customer portal under "Connected applications"; the complete evidence including browser identifier and text versions is in your account's data export. Our support sees them in the customer portal only when signing in to your account for troubleshooting; every such sign-in is logged. Team members and resellers who switch into your account do not see them. The application itself can only retrieve its own connection, without IP address and browser identifier.

DataPurposeRetentionLegal basis
Application (name, redirect addresses, metadata, verified host)Identifying and calling back the applicationAs long as a connection, including an ended one, or a pending authorisation request refers to the application; an application nothing refers to any more is deleted automatically by the cleanup run, at the earliest 30 days after its registration. An application we have blocked is kept so that the block stays in force.Art. 6(1)(b) GDPR
Connection with consent evidenceCarrying out the access you allowed; evidence of your decisionUntil your account is deleted, including after the connection is disconnected; IP address and browser identifier are removed at that point at the latestArt. 6(1)(b) GDPR; evidence: Art. 6(1)(f) GDPR, and for the consent to the third-country transfer Art. 6(1)(c) in conjunction with Art. 7(1) GDPR
Tokens, authorisation codes, pending requestsCarrying out the accessTokens until expiry or revocation (access tokens at most 24 hours, refresh tokens at most 30 days), codes one minute, requests ten minutes; deleted seven days after the expiry date by the half-hourly cleanup run, unanswered requests at expiryArt. 6(1)(b) GDPR
Log of changes made by the applicationVisibility for you; traceability and evidence; abuse detection12 months, then deleted automaticallyArt. 6(1)(b) and (f) GDPR
Refused requestsAbuse detection; visibility for you30 days, then deleted automaticallyArt. 6(1)(f) GDPR

If you delete your account, or we anonymise a deactivated account, we delete the log, all tokens, codes and requests, end all active connections and remove the IP address and browser identifier from every consent record. Where payment transactions are attributed to a connection, the connection record (application, permissions, times, spending limit) is kept without those details as part of the accounting voucher for the periods stated under "Registration Data" and is restricted under Art. 18 GDPR to fulfilling the retention obligation; all other connection records are deleted.

You can disconnect any connection at any time in the customer portal; the application loses access to your account immediately. Connections, consent evidence and the log are part of your account's data export (Art. 15 and Art. 20 GDPR). You may object under Art. 21 GDPR to the logging based on Art. 6(1)(f) GDPR (see "Your right to object"). Connecting applications is voluntary and not required for any contract with us.

Cookies and access to your terminal equipment

Storing information in your terminal equipment and accessing information already stored there is permitted under § 25(1) TDDDG only with your consent. Excepted is storage strictly necessary to provide a service you have expressly requested (§ 25(2) No. 2 TDDDG). The provision is technology-neutral and therefore covers not only cookies but also your browser's local storage.

NamePurposeDurationCategory
cookieConsentStores your cookie choice so the banner does not reappear.Until withdrawnNecessary
Session tokenKeeps you signed in to your customer account.Until sign-outNecessary
ad_attribution, gclidAttributes a contract conclusion to the advertising campaign you arrived through. Stored only after you consent.90 daysConsent
Google Ads cookies (_gcl_*)Measuring the effectiveness of our advertising campaigns.Up to 90 daysConsent

You can withdraw your consent at any time via the "Cookie settings" link in the footer. Withdrawal takes effect for the future: advertising identifiers already stored are deleted and measurement stops; processing carried out beforehand remains lawful.

Telephone verification (SMS and voice call)

For domain registrations and for the free Kubernetes namespace we verify the telephone number on file. To do so we transmit your telephone number and the verification code to seven communications GmbH & Co. KG, Willestraße 4-6, 24103 Kiel, Germany, which sends the SMS or places the voice call on our behalf.

The dispatch provider is our processor and the processing takes place in Germany. We store the telephone number, the time and the outcome of the verification.

Server-side advertising attribution

If you have consented to advertising measurement and reached us through a Google Ads advertisement, we store the click identifier (Google Click ID) on our servers together with your customer account and your order.

After a contract is concluded we transmit that identifier, together with the time and value of the conclusion, to Google so the effectiveness of the campaign can be measured. We do not transmit personal details such as your name or e-mail address.

If you withdraw your consent, we delete the stored identifier and do not transmit future conclusions.

Support requests and abuse notices

When you write to us via the contact or ticket form we process your details in order to handle the request. If you submit an abuse notice we additionally process the domain or address you report, your reasoning and your contact details.

We handle abuse notices in accordance with Art. 16 of Regulation (EU) 2022/2065. We confirm receipt, communicate the decision taken, and inform the affected customer of any measures; in doing so your notice may be passed to the customer, without your contact details where they are not needed to handle the matter.

Disclosures to authorities

As a provider of domain registration services we are required by § 50 BSIG to disclose domain registration data to legitimate access seekers upon reasoned request. Legitimate access seekers are, under § 2 No. 2 BSIG, the Federal Office for Information Security, Land authorities, prosecuting authorities, the federal and Land police forces and the constitutional protection authorities.

What may be disclosed is the domain holder's name, address, e-mail address and telephone number, together with the registration and expiry dates. We do not release credentials, payment information or correspondence; that requires a separate judicial order. Every request is checked for legitimacy, legal basis and proportionality, and is logged.

Anti-Abuse Checks for the Free Kubernetes Namespace

When a free Kubernetes namespace (Free Tier) is requested, we perform technical checks to prevent multiple registrations and automated abuse. The following data categories are processed in this context:

  • Verified phone number of the applicant, compared against phone numbers held on other active customer accounts to detect duplicate accounts.
  • Domain portion of the email address on file, compared against a publicly maintained list of disposable email providers.
  • IP address used at the time of the request, evaluated to detect repeated requests originating from the same network range.
  • IP address used at the time of the request, evaluated to determine (a) the approximate country of origin and (b) the network operator (autonomous system), in order to enforce the geographic availability of the Free Tier and to detect requests from cloud or hosting networks. This evaluation uses a local geolocation database (MaxMind GeoLite2); the IP address is not transmitted to the database provider or any other third party for this purpose.
  • VAT identification number, where provided, compared against the VAT IDs of other active Free Tier customer accounts.

The applicant's IP address is recorded together with the request in the customer account activity log. The decision on provisioning is made automatically on the basis of these checks. You may request review by a member of staff, express your point of view and contest the decision by contacting service@itsh.dev. The data processed for these checks is not shared with third parties and is used exclusively for the purpose of abuse prevention. Technical warnings generated by these checks contain the IP address and are subject to the seven-day retention of the server log files.

Retention period: The activity logs follow the general retention of the customer account and are anonymised together with the account upon account closure.

Dedicated Egress IP for the Free Tier

Outbound network traffic originating from Free Tier Kubernetes namespaces is routed through a dedicated IP address (PTR record: egress.itsh-apps.dev). This is a technical measure to separate the Free Tier's reputation from the rest of the platform and does not itself constitute additional processing of personal data beyond the processing already documented for server log files.

Your right to object

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. This covers in particular the server logs, audience measurement, bot protection, error diagnostics, our social media presences, abuse prevention, and the consent evidence and log of connected applications.

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to establish, exercise or defend legal claims.

Where your data is processed for direct marketing, you may object at any time without giving reasons; we will then stop processing it for that purpose.

An objection requires no particular form — an e-mail to service@itsh.dev is sufficient.

Your Rights

You have the following rights regarding your personal data:

  • Right of Access – Right to information about the processed data
  • Right to Rectification – Right to correction of incorrect data
  • Right to Erasure – Right to deletion of your data
  • Right to Restriction – Right to restriction of processing
  • Right to Object – Right to object to processing
  • Data Portability – Right to transfer your data
  • Right to Complain – Right to lodge a complaint with a supervisory authority

Visiting our website and subscribing to the newsletter are possible without providing personal data, or are revocable at any time. To conclude a contract, however, we require your name, address and e-mail address, and for domain registrations and the free Kubernetes namespace additionally a verified telephone number; without these we cannot conclude the contract in question. The legal basis is Art. 6(1)(b) GDPR, and for telephone verification of domains additionally Art. 6(1)(c) GDPR in conjunction with § 49 BSIG. Connecting applications and AI agents is voluntary; without a connection, the processing described there does not take place.