Privacy
Privacy Policy
This is a convenience translation. In case of discrepancies, the German version is legally binding. This policy explains how we process personal data when you visit our website or use our services.
Effective: 19 July 2026
Controller
The controller responsible for the processing of personal data under the EU General Data Protection Regulation (GDPR) is:
Dominic Stilma
Friedhofsweg 10, 49843 Uelsen, Germany
Email: contact@headpat.space
We operate as a small business (Kleinunternehmer) under § 19 UStG. There is no statutory obligation to appoint a Data Protection Officer.
Overview
We process personal data solely on the basis of the GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG). Personal data is any information relating to an identified or identifiable natural person.
The sections below explain which data we process, for which purposes, on which legal basis, how long we retain it, and what rights you have.
Processing when you visit the website
Server log files. When you access our website, the following data is automatically recorded: IP address, date and time, URL accessed, referrer, browser and operating system, HTTP status code.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure operation of the website and in detecting and preventing attacks. Log files are deleted or anonymized after no more than 14 days.
Contact form and email. When you contact us, we process your name, email address and message content in order to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR for general inquiries. Retention: until your request has been fully processed.
Newsletter / email sign-up. If you sign up for our newsletter, we process your email address to send you the messages. Sign-up uses a double opt-in procedure. As proof of your consent we store the IP address, timestamp and user agent of the double opt-in confirmation (Art. 7(1) GDPR). Legal basis: Art. 6(1)(a) GDPR. You can withdraw your consent at any time using the unsubscribe link in the newsletter.
Bot protection (Cloudflare Turnstile). On contact, newsletter, status and cancellation forms, and on the customer portal's sign-in, registration, password-reset and accessibility feedback forms, we use Cloudflare Turnstile to distinguish humans from bots. This transmits your IP address and technical signals to Cloudflare, Inc. (USA). Cloudflare is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(f) GDPR (prevention of spam and abuse).
Processing for our domain services
Customer account. To use our services we create a customer account for you. We process your name, address, email and any other contact details required. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Domain registration data. To register a domain on your behalf, we transmit your data (in particular name, address, email) to our registrar Openprovider B.V. and to the relevant domain registry (e.g. DENIC eG for .de domains). This data is entered into the registry's databases and, where applicable, into WHOIS directories. The scope, visibility and retention of this data is governed by the policies of each registry and by ICANN rules for generic TLDs.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal obligation toward registries).
DNS data. Through our nameservers (ns1.hpatdns.de, ns2.hpatdns.de) we process the DNS records you configure for your domain. By the nature of DNS, this data is publicly resolvable. Legal basis: Art. 6(1)(b) GDPR.
Customer account and hosting services
Panel account. For your account in our customer panel we process your name, email address, authentication data and activity/audit logs. Legal basis: Art. 6(1)(b) GDPR.
Provisioning and operation of booked services. We process the data required to provision and operate the services you book: virtual machines, containers, PaaS apps (e.g. WordPress, databases), game servers (managed via the Provider's game-server panel software) and email services. Email services are provided on Microsoft 365 infrastructure; the recipient of the data required for this is Microsoft Ireland Operations Ltd. (email customers only). Legal basis: Art. 6(1)(b) GDPR.
Content data. Content you store on the booked services (files, databases, backups, game saves) is processed on our own infrastructure. Backups are stored on our own S3-compatible storage. You remain responsible for personal data you process within your services.
Notifications. Account and service notifications are sent via our own mail infrastructure.
Retention. We retain account data for the duration of the contract plus statutory retention periods. Content data is deleted within 30 days after the service ends.
Payments and invoicing
Payments via Stripe. Payments for all of our services are processed by Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Dublin, Ireland. Payment data (e.g. card details) is transmitted directly to Stripe and is not stored by us. Stripe acts as an independent controller for payment data. Where data is transferred to the parent company Stripe, Inc. in the USA, this is safeguarded by EU Standard Contractual Clauses or the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(b) GDPR. Stripe's privacy notice.
Invoicing. To comply with tax and commercial law obligations we process your invoicing data. Legal basis: Art. 6(1)(c) GDPR in conjunction with § 147 of the German Tax Code (AO). Retention: 10 years.
Error monitoring (Sentry, self-hosted)
For error diagnostics and performance monitoring we operate a self-hosted Sentry instance on our own infrastructure. No data is transmitted to Sentry Inc. or to any third country.
This includes session replay: all text content is masked and media is blocked before any data is transmitted - only interaction metadata reaches our server. We process technical error context, a truncated or anonymizable IP address, and browser and operating system.
Legal basis: Art. 6(1)(f) GDPR (stable and secure operation of our services). Retention: 90 days.
Recipients and processors
We disclose your personal data only to the following categories of recipients. We have entered into data processing agreements under Art. 28 GDPR with our processors:
- -Openprovider B.V., Hoogoorddreef 60, 1101 BE Amsterdam, Netherlands (domain registrar)
- -DENIC eG, Theodor-Stern-Kai 1, 60596 Frankfurt am Main, Germany (registry for .de domains)
- -Other domain registries depending on the chosen TLD (e.g. Verisign for .com / .net, EURid for .eu)
- -Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Dublin, Ireland (payments for all services)
- -Microsoft Ireland Operations Ltd, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (email services on Microsoft 365 infrastructure, email customers only)
- -Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (Turnstile bot protection)
- -GitHub, Inc., 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA (only if you connect a repository for deployments)
- -Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland (web analytics)
- -Jan Smyrek (PawHost), Gerichtstr. 15, 58540 Meinerzhagen, Germany (server infrastructure and networking; we operate the services on it ourselves)
- -Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany (secondary nameserver)
- -Tax advisors and public authorities to the extent required by law
Transfers to third countries
Where personal data is transferred outside the EU/EEA - in particular to the United States in the context of Google Analytics, Cloudflare Turnstile, GitHub and, where applicable, Stripe - this is done on the basis of the EU-US Data Privacy Framework and/or Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Appropriate safeguards for your data are thereby ensured.
Retention periods
We retain personal data only for as long as is necessary for the relevant purposes or as required by statutory retention obligations:
- -Server log files: max. 14 days
- -Contact inquiries: until your request has been fully processed
- -Newsletter data: until you withdraw your consent
- -Customer account and contract data: for the duration of the business relationship plus statutory retention periods
- -Content data of booked services: deleted within 30 days after the service ends
- -Error diagnostics data (Sentry): 90 days
- -Invoicing data: 10 years pursuant to § 147 AO
- -Domain registration data: as required by the relevant registry
Automated decisions (Art. 22 GDPR)
We use automated decision-making only in the following cases:
- -Automated suspension of a service when a renewal payment fails; we notify you afterwards and the service is restored once payment succeeds
- -Automated deletion of services at the end of a cancelled subscription period
- -Automated flagging of unusual refund or withdrawal patterns for fraud prevention
Flagged cases are reviewed by a human before any decision with legal effect is made. You can always contest a decision via contact@headpat.space. Legal bases: Art. 6(1)(b) and (f) GDPR.
Your rights
You have the following rights regarding your personal data:
- -Right of access (Art. 15 GDPR)
- -Right to rectification (Art. 16 GDPR)
- -Right to erasure (Art. 17 GDPR)
- -Right to restriction of processing (Art. 18 GDPR)
- -Right to data portability (Art. 20 GDPR)
- -Right to object (Art. 21 GDPR)
- -Right to withdraw consent with effect for the future (Art. 7(3) GDPR)
- -Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise any of these rights, an informal message to contact@headpat.space is sufficient.
Competent supervisory authority: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany - poststelle@lfd.niedersachsen.de
Data security
We implement technical and organizational measures to protect your data against unauthorized access, loss, alteration or manipulation. All transmissions are encrypted via TLS. Our servers are located primarily in data centers within the European Union. Where you explicitly select a non-EU location for a service at order time, the content data of that service is processed in the selected region.
Changes to this policy
We reserve the right to amend this privacy policy where this becomes necessary due to new legal requirements or changes to our services. The current version is always available on this page.