How is your data processed?

We store and use your personal data only for processing your orders and for contacting you. If you have subscribed to our newsletter, we also use your email address to send it.

What categories of data are collected?

Each time you access our website, your IP address is stored in anonymised form, among other things. When you register with us, your contact details are stored. When you order products from us, your address and payment details are also stored.

Registration Data

As part of your registration with us, we must collect and process certain personal data from you as your registration data. For example, we need your name, address data, telephone number, payment data and your email address to process your orders.

When paying by credit card, we do not collect or store any payment transaction information such as credit card numbers or verification numbers. You only provide these directly to the respective payment service provider.

If you delete your user account, we anonymise the account data. Invoicing and accounting records must however be retained by law: accounting vouchers for eight years, books and records for ten years (§ 147 AO), and commercial and business letters for six years (§ 257 HGB). For the duration of those periods, processing is restricted under Art. 18 GDPR to fulfilling the retention obligation; the data is deleted once they expire. You can request deletion of your user account through the customer portal or by e-mail to service@itsh.dev.

Email Addresses & Newsletter

If you have subscribed to our newsletter, we also store your email address. We delete this data when you delete your user account or when you have unsubscribed from the newsletter.

To ensure consensual newsletter distribution, we use the so-called double opt-in procedure. In the course of this, the potential recipient can be added to a mailing list. The user then receives a confirmation email giving them the opportunity to legally confirm the registration.

You can revoke your consent to the storage of data at any time, for example via the "Unsubscribe" link in the newsletter.

Server Log Files

Each time you access our website we automatically store certain data. This includes the IP address, the type and version of the browser used, the time, the date and the website you came from. In the web server logs the IP address is stored truncated (the last octet, or the last 80 bits for IPv6, is removed). Truncation makes attribution considerably harder but does not rule it out with certainty, so we continue to treat the logs as personal data. This is distinct from the untruncated storage of your IP address in your customer account activity log, described separately under "Abuse prevention".

Error Tracking (Sentry)

We use Sentry, a service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, for monitoring and diagnosing application errors. Its representative in the Union is Sentry Software Netherlands B.V., Amsterdam.

In the event of an error, the following data is collected: error logs, device information, browser information and IP address (anonymised). The data is stored for 90 days.

Sentry is certified under the EU-US Data Privacy Framework. Further information can be found in the Sentry Privacy Policy.

Bot Protection (Cloudflare Turnstile)

We use Cloudflare Turnstile, a service of Cloudflare Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to protect against automated abuse (bots, spam).

When using this service, the following data is collected: browser information, IP address and interaction patterns. Unlike traditional CAPTCHA solutions, Turnstile does not use tracking cookies and is designed to be more privacy-friendly.

Cloudflare is certified under the EU-US Data Privacy Framework. Further information can be found in the Cloudflare Privacy Policy.

Website Analytics

We use the open-source web analytics tool Matomo as a self-hosted system. Matomo stores no cookies and does not otherwise access your terminal equipment, so no consent under § 25 TDDDG is required. What is processed is a truncated IP address, the pages viewed, the referring source and browser and device details. The data does not leave our own infrastructure.

Marketing & Advertising (Google Ads)

With your explicit consent, we use Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure the effectiveness of our advertising campaigns.

When you give your consent, the following data is collected: Google Click ID (GCLID), page views, conversion events and IP address. This data is used to analyse and optimise our advertising measures.

You can revoke your consent at any time via the "Cookie Settings" link in the footer.

The entity certified under the EU-US Data Privacy Framework is Google LLC, to which Google Ireland Limited passes the data; standard contractual clauses are in place in addition. Further information is available in the Google Privacy Policy.

Data Sharing with Third Parties

Besides us, external service providers who support us in delivering our services have access to your data. Our entire infrastructure runs at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in data centres in Germany. Domains are registered through INWX GmbH, Prinzessinnenstraße 30, 10969 Berlin. Both are our processors. A current list of the sub-processors we use is available in the customer portal.

Domain Registration

When we register a domain for you, we pass the holder data required for that purpose (name, address, e-mail address, telephone number) to our registrar INWX GmbH (Germany) and through them to the registry responsible for the TLD in question. Depending on the TLD the registry may be established outside the EEA; the transfer is then necessary for the performance of your order (Art. 49(1)(b) GDPR). Part of this data may be retrievable through public directory services (WHOIS/RDAP) where the registry provides for that.

Payment Processing (Stripe)

Payments are processed through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. For customers in the European Economic Area this is our contracting party, and it passes the data on to Stripe, Inc., South San Francisco, USA. The data transmitted comprises name, e-mail address, payment information and IP address.

Stripe, Inc. is certified under the EU-US Data Privacy Framework; standard contractual clauses under Art. 46(2)(c) GDPR are in place in addition.

Further information can be found in the Stripe Privacy Policy.

Debt Collection

If you fail to settle due claims despite a reminder, we pass the data required for recovery (name, address, amount and grounds of the claim) to a debt collection company.

Third Countries

Transfers to third countries take place only to the recipients named individually in this policy. For the US recipients Stripe, Inc., Functional Software, Inc. (Sentry), Cloudflare, Inc. and Google LLC we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); in addition we have agreed standard contractual clauses under Art. 46(2)(c) GDPR with those recipients, which continue to apply should the adequacy decision fall away. We will provide a copy of the safeguards on request.

Data Processing

Your content, hosting and customer data is processed exclusively in ISO 27001 certified data centres in Germany. Excepted are the auxiliary services with a third-country element named individually in this policy (payment processing, error diagnostics, bot protection and — where you have consented — advertising measurement); the safeguards stated there apply to those.

Online Presence on Social Media

We maintain online presences within social networks and platforms in order to communicate with our customers, prospective customers and users and to inform them about our services.

For the processing of usage data on the platform pages we are joint controllers with the respective provider (Art. 26 GDPR). The platform operators make the essence of the arrangements available in their own terms; we have no determining influence over the processing that takes place there. You may exercise your data subject rights against us as well as against the platform operator.

Product Advice via Live Chat

For support requests we use the Zammad ticket and chat system. The chat widget loads only in the signed-in customer area, not on the public pages. What is processed is the message content you send, your contact details and technical connection data. We run Zammad on our own infrastructure in Germany; no data is passed to third parties.

Email Hosting

As part of our Email Hosting service, we process email content (messages, attachments), email metadata (sender, recipient, subject, timestamps), login data (IP addresses, times) and IMAP and SMTP session data.

Processing takes place on our self-hosted mail server in ISO 27001:2022 certified data centres in Germany. No transfer to third countries takes place.

E-mail content is stored for the duration of the contractual relationship and, after it ends, deleted or returned in accordance with the data processing agreement. Login logs and message metadata are deleted automatically after 90 days.

Web Hosting

As part of our Web Hosting service, we store website content, database content and files uploaded via file access (SFTP) provided by the customer.

Web server access logs (IP address in anonymised form, time, pages accessed) and SFTP access logs are collected for security purposes.

For personal data of third parties stored by customers on web hosting, the customer is the data controller within the meaning of the GDPR (cf. § 8 of our Terms).

Cookies and access to your terminal equipment

Storing information in your terminal equipment and accessing information already stored there is permitted under § 25(1) TDDDG only with your consent. Excepted is storage strictly necessary to provide a service you have expressly requested (§ 25(2) No. 2 TDDDG). The provision is technology-neutral and therefore covers not only cookies but also your browser's local storage.

NamePurposeDurationCategory
cookieConsentStores your cookie choice so the banner does not reappear.Until withdrawnNecessary
Session tokenKeeps you signed in to your customer account.Until sign-outNecessary
ad_attribution, gclidAttributes a contract conclusion to the advertising campaign you arrived through. Stored only after you consent.90 daysConsent
Google Ads cookies (_gcl_*)Measuring the effectiveness of our advertising campaigns.Up to 90 daysConsent

You can withdraw your consent at any time via the "Cookie settings" link in the footer. Withdrawal takes effect for the future: advertising identifiers already stored are deleted and measurement stops; processing carried out beforehand remains lawful.

Telephone verification (SMS and voice call)

For domain registrations and for the free Kubernetes namespace we verify the telephone number on file. To do so we transmit your telephone number and the verification code to seven communications GmbH & Co. KG, Willestraße 4-6, 24103 Kiel, Germany, which sends the SMS or places the voice call on our behalf.

The dispatch provider is our processor and the processing takes place in Germany. We store the telephone number, the time and the outcome of the verification.

Server-side advertising attribution

If you have consented to advertising measurement and reached us through a Google Ads advertisement, we store the click identifier (Google Click ID) on our servers together with your customer account and your order.

After a contract is concluded we transmit that identifier, together with the time and value of the conclusion, to Google so the effectiveness of the campaign can be measured. We do not transmit personal details such as your name or e-mail address.

If you withdraw your consent, we delete the stored identifier and do not transmit future conclusions.

Support requests and abuse notices

When you write to us via the contact or ticket form we process your details in order to handle the request. If you submit an abuse notice we additionally process the domain or address you report, your reasoning and your contact details.

We handle abuse notices in accordance with Art. 16 of Regulation (EU) 2022/2065. We confirm receipt, communicate the decision taken, and inform the affected customer of any measures; in doing so your notice may be passed to the customer, without your contact details where they are not needed to handle the matter.

Disclosures to authorities

As a provider of domain registration services we are required by § 50 BSIG to disclose domain registration data to legitimate access seekers upon reasoned request. Legitimate access seekers are, under § 2 No. 2 BSIG, the Federal Office for Information Security, Land authorities, prosecuting authorities, the federal and Land police forces and the constitutional protection authorities.

What may be disclosed is the domain holder's name, address, e-mail address and telephone number, together with the registration and expiry dates. We do not release credentials, payment information or correspondence; that requires a separate judicial order. Every request is checked for legitimacy, legal basis and proportionality, and is logged.

Anti-Abuse Checks for the Free Kubernetes Namespace

When a free Kubernetes namespace (Free Tier) is requested, we perform technical checks to prevent multiple registrations and automated abuse. The following data categories are processed in this context:

  • Verified phone number of the applicant, compared against phone numbers held on other active customer accounts to detect duplicate accounts.
  • Domain portion of the email address on file, compared against a publicly maintained list of disposable email providers.
  • IP address used at the time of the request, evaluated to detect repeated requests originating from the same network range.
  • IP address used at the time of the request, evaluated to determine (a) the approximate country of origin and (b) the network operator (autonomous system), in order to enforce the geographic availability of the Free Tier and to detect requests from cloud or hosting networks. This evaluation uses a local geolocation database (MaxMind GeoLite2); the IP address is not transmitted to the database provider or any other third party for this purpose.
  • VAT identification number, where provided, compared against the VAT IDs of other active Free Tier customer accounts.

The applicant's IP address is recorded together with the request in the customer account activity log. The decision on provisioning is made automatically on the basis of these checks. You may request review by a member of staff, express your point of view and contest the decision by contacting service@itsh.dev. The data processed for these checks is not shared with third parties and is used exclusively for the purpose of abuse prevention.

Retention period: The activity logs follow the general retention of the customer account and are anonymised together with the account upon account closure.

Dedicated Egress IP for the Free Tier

Outbound network traffic originating from Free Tier Kubernetes namespaces is routed through a dedicated IP address (PTR record: egress.itsh-apps.dev). This is a technical measure to separate the Free Tier's reputation from the rest of the platform and does not itself constitute additional processing of personal data beyond the processing already documented for server log files.

Your right to object

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. This covers in particular the server logs, audience measurement, bot protection, error diagnostics, our social media presences and abuse prevention.

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to establish, exercise or defend legal claims.

Where your data is processed for direct marketing, you may object at any time without giving reasons; we will then stop processing it for that purpose.

An objection requires no particular form — an e-mail to service@itsh.dev is sufficient.

Your Rights

You have the following rights regarding your personal data:

  • Right of Access – Right to information about the processed data
  • Right to Rectification – Right to correction of incorrect data
  • Right to Erasure – Right to deletion of your data
  • Right to Restriction – Right to restriction of processing
  • Right to Object – Right to object to processing
  • Data Portability – Right to transfer your data
  • Right to Complain – Right to lodge a complaint with a supervisory authority

Visiting our website and subscribing to the newsletter are possible without providing personal data, or are revocable at any time. To conclude a contract, however, we require your name, address and e-mail address, and for domain registrations and the free Kubernetes namespace additionally a verified telephone number; without these we cannot conclude the contract in question. The legal basis is Art. 6(1)(b) GDPR, and for telephone verification of domains additionally Art. 6(1)(c) GDPR in conjunction with § 49 BSIG.