HTProtect.app ← Home

Privacy Policy

This is a convenience translation. Only the German version of this privacy policy is legally binding. In the event of any discrepancy between the two language versions, the German text prevails. You can find the authoritative version at Datenschutzerklärung (German).

This privacy policy informs you, in accordance with Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR), which personal data we process when operating the HTProtect.app service, for which purposes and on which legal basis this takes place, and which rights you are entitled to. Personal data means any information relating to an identified or identifiable natural person.

1. Controller and contact details

The controller within the meaning of Art. 4(7) GDPR is:

ControllerPascal Lohmann (sole proprietorship / Einzelunternehmen)
Business nameHTProtect
AddressPlitscharder Str. 62, 52134 Herzogenrath, Germany
E-mailmail@htprotect.app
VAT identification number (USt-IdNr.)DE275411097

We have not appointed a statutory data protection officer, as there is no legal obligation to do so. For any matter concerning data protection, you can reach us at the e-mail address given above. Further details can be found in our imprint / legal notice (Impressum).

2. General information and legal bases

We process personal data only to the extent necessary for providing our service and where a valid legal basis exists. Depending on the processing activity, we rely on one of the following legal bases under Art. 6(1) GDPR:

3. Server log data

Each time HTProtect.app is accessed, the server automatically records access data and stores it in what are known as log files. The data recorded includes in particular:

This processing takes place on the basis of our legitimate interest in technically faultless operation, in system security and in investigating and defending against attacks (Art. 6(1)(f) GDPR). Log data is stored only for as long as is necessary for these purposes and is subsequently deleted or anonymised.

Hosting is provided by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, in data centres located within the European Union (Germany). A data processing agreement (Auftragsverarbeitungsvertrag, AVV) pursuant to Art. 28 GDPR is in place with IONOS SE.

4. Cookies

We use exclusively technically necessary cookies that are required for the operation and the security of the service. These include, in particular, session and security cookies for signing in, protection against cross-site request forgery (CSRF) and storing your language selection. The language cookie htp_locale merely remembers the display language you have chosen; it is not evaluated on a personal basis.

We use no analytics, statistics, tracking or marketing cookies, and we do not integrate any third-party services of that kind. Because we use only strictly necessary cookies within the meaning of Section 25(2) TDDDG, no consent is required for this; a consent banner is therefore not needed. The legal basis is our legitimate interest in proper and secure operation (Art. 6(1)(f) GDPR) and the performance of the contract (Art. 6(1)(b) GDPR) respectively.

5. Registration, account and workspace

To use the service, you set up an account. In doing so, and during ongoing use, we process in particular the following data:

The purpose of this processing is to provide, administer and secure your account and to deliver the agreed service. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

6. Payment processing via Stripe

We use the payment service provider Stripe to process payments. The payment process runs through a checkout hosted by Stripe: you are redirected to a Stripe payment page for this purpose. Your full payment details, in particular credit card numbers, are not processed or stored by HTProtect.app but are collected exclusively by Stripe.

The data transmitted to Stripe, or processed there in connection with your payment, includes in particular your name, your e-mail address, billing and address data, where applicable your VAT identification number (USt-IdNr.), and the invoice amount. Stripe processes this data partly as a processor and partly as a payment service provider acting as controller in its own right.

The providers are Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA). This may involve a transfer of data to a third country (USA). Such transfers are safeguarded by the standard contractual clauses adopted by the EU Commission (Art. 46 GDPR). The legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations, in particular retention obligations under commercial and tax law (Art. 6(1)(c) GDPR). Further information on data processing by Stripe can be found in Stripe's privacy policy at stripe.com/privacy.

7. Sending e-mails

In the course of performing the contract, we send you system e-mails, for example to confirm a cancellation, to communicate security-relevant information or to report on the status of the service. The purpose is the performance of the contract and compliance with legal obligations (Art. 6(1)(b) and (c) GDPR); for purely informational messages we rely on our legitimate interest in keeping our customers informed (Art. 6(1)(f) GDPR).

For sending e-mails (e.g. cancellation confirmations, system messages) we use Amazon Simple Email Service (Amazon SES) provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, with processing in the Frankfurt region (eu-central-1) within the EU. A data processing agreement is in place (AWS Data Processing Addendum pursuant to Art. 28 GDPR). The data transmitted comprises the recipient's e-mail address and the content of the message. Legal basis: performance of the contract and legal obligation (Art. 6(1)(b) and (c) GDPR).

8. Site metadata reported by the connector

The HTProtect connector, which you install on the websites you manage, reports security-relevant metadata about those websites outbound to HTProtect.app. This includes, in particular, the security level determined, installed software versions, the URLs of the websites managed, and the respective update and scan status.

Passwords, access credentials, keys and other secrets are expressly not transmitted. The purpose of this processing is the provision of the security service, that is, the monitoring and protection of your websites. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). Insofar as this metadata contains personal data (for example within URLs), this privacy policy applies accordingly.

9. Community forum

At forum.htprotect.app we operate a community forum based on the Flarum software. The forum runs on our own infrastructure within the EU; no transfer to third parties takes place in this context.

If you open the forum while signed in to your account, a forum account is automatically created for you or linked to your existing one (single sign-on). The data transmitted in this process consists of an immutable, pseudonymous identifier of your account in the form htp{ID}, your display name and your e-mail address. Your password is not transmitted.

Posts, topics and reactions that you write there are visible to other signed-in users and remain stored until they are deleted. Please do not publish any personal data of third parties or any credentials in plain text in the forum. End-to-end encryption is available for exchanging confidential information; we, as the operator, cannot read the content of such messages in plain text.

The purpose of the processing is professional exchange and support relating to the service. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in a functioning user community (Art. 6(1)(f) GDPR). The forum account exists independently of your customer account; if you would like it to be deleted, a message to mail@htprotect.app is sufficient. Posts already published may be retained in anonymised form so that ongoing discussions remain comprehensible.

10. Retention period and erasure

As a matter of principle, we store personal data only for as long as is necessary for the respective purposes or for carrying out the contractual relationship. The data is deleted thereafter, unless statutory retention obligations preclude this. Retention periods under tax and commercial law in particular (as a rule six to ten years) remain unaffected; for the duration of those periods, the processing of the data concerned is restricted.

11. No automated decision-making

Automated decision-making in individual cases, including profiling within the meaning of Art. 22 GDPR, does not take place.

12. Your rights as a data subject

Under the GDPR, you are entitled to the following rights:

To exercise these rights, an informal message to mail@htprotect.app is sufficient.

Irrespective of the above, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Because our place of business is in North Rhine-Westphalia, the competent authority for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen). You may, however, also contact the supervisory authority of your habitual residence.

13. Amendments to this privacy policy

We update this privacy policy whenever the actual processing activities or the legal framework change. The current version published on this page applies in each case. Supplementary information can be found in our imprint / legal notice (Impressum), our Terms and Conditions (AGB) as well as in the information on withdrawal (Widerruf) and on cancellation (Kündigung).

As of: July 2026