Responsible Party
IT-Service Harting
Friedrich-Wolf-Str. 1898527 Suhl
Germany
How is your data processed?
We store and use your personal data only for processing your orders and for contacting you. If you have subscribed to our newsletter, we also use your email address to send it.
What categories of data are collected?
Each time you access our website, your IP address is stored in anonymised form, among other things. When you register with us, your contact details are stored. When you order products from us, your address and payment details are also stored.
Registration Data
As part of your registration with us, we must collect and process certain personal data from you as your registration data. For example, we need your name, address data, telephone number, payment data and your email address to process your orders.
When paying by credit card, we do not collect or store any payment transaction information such as credit card numbers or verification numbers. You only provide these directly to the respective payment service provider.
We delete this data within 24 months once you delete your user account with us or when the statutory retention period has expired. You can delete your user account by sending us an email to service@itsh.dev requesting deletion.
Legal basis: Art. 6 para. 1 lit. b GDPR
Email Addresses & Newsletter
If you have subscribed to our newsletter, we also store your email address. We delete this data when you delete your user account or when you have unsubscribed from the newsletter.
To ensure consensual newsletter distribution, we use the so-called double opt-in procedure. In the course of this, the potential recipient can be added to a mailing list. The user then receives a confirmation email giving them the opportunity to legally confirm the registration.
You can revoke your consent to the storage of data at any time, for example via the "Unsubscribe" link in the newsletter.
Legal basis: Art. 6 para. 1 lit. a or Art. 6 para. 1 lit. b GDPR
Server Log Files
Each time you access our website, we automatically store certain data. This includes, among other things, IP address, type and version of the browser used, time, date and the website from which users access our site. The IP address is stored in anonymised form. A personal reference can no longer be established.
Legal basis: Art. 6 para. 1 lit. f GDPR
Error Tracking (Sentry)
We use Sentry, a service of Functional Software Inc., 132 Hawthorne Street, San Francisco, CA 94107, USA, for monitoring and diagnosing application errors.
In the event of an error, the following data is collected: error logs, device information, browser information and IP address (anonymised). The data is stored for 90 days.
Sentry is certified under the EU-US Data Privacy Framework. Further information can be found in the Sentry Privacy Policy.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in the stability and improvement of the application)
Bot Protection (Cloudflare Turnstile)
We use Cloudflare Turnstile, a service of Cloudflare Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to protect against automated abuse (bots, spam).
When using this service, the following data is collected: browser information, IP address and interaction patterns. Unlike traditional CAPTCHA solutions, Turnstile does not use tracking cookies and is designed to be more privacy-friendly.
Cloudflare is certified under the EU-US Data Privacy Framework. Further information can be found in the Cloudflare Privacy Policy.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in protection against abuse)
Website Analytics
We use the open source web analytics tool Matomo as a self-hosted system on our website. Matomo does not use cookies on our site.
Marketing & Advertising (Google Ads)
With your explicit consent, we use Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure the effectiveness of our advertising campaigns.
When you give your consent, the following data is collected: Google Click ID (GCLID), page views, conversion events and IP address. This data is used to analyse and optimise our advertising measures.
You can revoke your consent at any time via the "Cookie Settings" link in the footer.
Google is certified under the EU-US Data Privacy Framework. Further information can be found in the Google Privacy Policy.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
Data Sharing with Third Parties
In addition to the responsible party, external service providers who support us in providing our services may have access to your data.
Domain Registration
When we register a domain for you, we pass on the necessary data to the relevant registration authority.
Payment Processing (Stripe)
Credit card payments are processed by Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA. The transmitted data includes: name, email address, payment information and IP address.
Stripe is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection.
Further information can be found in the Stripe Privacy Policy.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfilment)
Debt Collection
In the case of debt collection, the required data is passed on to an external service provider.
Third Countries
Data transfers to third countries take place in compliance with the legally regulated admissibility requirements (Art. 45 or Art. 46 GDPR).
Data Processing
Data is processed exclusively in ISO 27001 certified data centres in Germany.
Online Presence on Social Media
We maintain online presences within social networks and platforms in order to communicate with our customers, prospective customers and users and to inform them about our services.
Legal basis: Art. 6 para. 1 lit. f GDPR
Product Advice via Live Chat
We use the Zammad chat system for our support. Each time you access our site, this component collects and stores data for web analytics and to operate the live chat system. Zammad is operated on our own server. The data is not shared.
Your Rights
You have the following rights regarding your personal data:
- Right of Access – Right to information about the processed data
- Right to Rectification – Right to correction of incorrect data
- Right to Erasure – Right to deletion of your data
- Right to Restriction – Right to restriction of processing
- Right to Object – Right to object to processing
- Data Portability – Right to transfer your data
- Right to Complain – Right to lodge a complaint with a supervisory authority
Providing your data is completely voluntary. However, you cannot use certain services if you do not provide us with your data.