Privacy Policy

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Last Updated: August 22, 2026 · Version: 2.1

Introduction

1337 Services GmbH ("we", "us", or "our") operates RDP.sh and is committed to protecting your privacy. We are based in Hamburg, Germany and comply with the European Union General Data Protection Regulation (GDPR).

We process your personal data based on various legal grounds as described in this policy, including contract performance, legal obligations, and legitimate interests.

Data Controller

The data controller responsible for your personal data is:

1337 Services GmbH

Ludwig-Erhard-Str. 18

20459, Hamburg

Germany

[email protected]

Data Protection Officer

Based on the nature and scale of our data processing activities, a Data Protection Officer (DPO) is not required under Article 37 GDPR. For any privacy-related inquiries, please contact us at [email protected].

Information We Collect

Account Information

When you create an account, we collect:

  • Full Name - for account identification and billing purposes
  • Email Address - for account verification, notifications, and support
  • Password - stored securely using industry-standard hashing (bcrypt)

Billing Information

For invoicing and tax compliance, we may collect:

  • Billing address (street, city, postal code, country)
  • Company name (if applicable)
  • VAT identification number (if applicable)

Session and Security Data

For security and fraud prevention, we collect:

  • IP Address - for security, fraud prevention, and session management
  • Device Information - browser type, operating system, and device type
  • Location Data - approximate location derived from IP address (city/country level)
  • Login History - timestamps and session events for security auditing

How We Use Your Information

We use the collected information for the following purposes:

  • To provide and maintain our services
  • To process transactions and send invoices
  • To send service-related notifications (server status, billing reminders)
  • To detect and prevent fraud and abuse
  • To provide customer support
  • To comply with legal obligations (tax laws, court orders)

Cookies

We use essential cookies only. We do not use third-party analytics or tracking cookies.

  • Session Cookie - maintains your login session (expires after 2 hours of inactivity)
  • CSRF Token - protects against cross-site request forgery attacks

All cookies are encrypted and transmitted securely over HTTPS.

Payment Processing

We use third-party payment processors to handle payments. We do not store your credit card details. These processors act as recipients of your personal data within the meaning of Article 13(1)(e) GDPR, and each has its own privacy policy governing the use of your payment information.

  • Cryptomus - Cryptocurrency payments
  • DebloMassi (deblomassi.com) - Credit and debit card payments

Card payments

If you choose to pay by card, we open a checkout with DebloMassi and redirect you to their website to complete the payment. The only information we transmit to them is the invoice amount, the currency, your invoice number as the payment reference, a short description of the invoice and the address to return you to afterwards. We do not send them your name, your email address or any other account data.

You enter your card details, and any name and email address their checkout asks for, directly on DebloMassi's page. That information is collected by DebloMassi rather than by us, under their own privacy policy, and your card number is never transmitted to or stored on our systems.

Once the payment completes, DebloMassi notifies us with the payment reference, the amount, the currency, the payment status and the name and email address you entered at their checkout. We store that notification together with the invoice as proof of payment.

Legal basis: Article 6(1)(b) GDPR - the processing is necessary to perform our contract with you, namely to collect payment for the service you ordered. We additionally retain the stored payment confirmation under Article 6(1)(c) GDPR to satisfy our accounting and tax record-keeping obligations, as set out in Data Retention below.

Who they are: DebloMassi contracts under the name DebloMassi Inc. and is registered in the State of Delaware, United States, as DEBLOMASSI LIMITED LIABILITY COMPANY under file number 10111325. Its registered agent is Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States.

International transfer: Because DebloMassi is established in the United States, and states in its own privacy policy that it may transfer personal data on to further countries, paying by card involves a transfer of your personal data outside the European Economic Area. If you would like information about the safeguards that apply to this transfer, contact us at [email protected]. You can always avoid this transfer by paying with cryptocurrency or from your account balance instead.

Data Retention

We retain your data for the following periods:

  • Account Data - retained until you request account deletion
  • Session Data - automatically deleted after 2 hours of inactivity
  • Invoices and Billing Records - retained for 10 years as required by German tax law
  • Support Tickets - retained for 3 years after resolution

Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right to Access - request a copy of your personal data
  • Right to Rectification - request correction of inaccurate data
  • Right to Erasure - request deletion of your data ("right to be forgotten")
  • Right to Restriction - request limitation of processing of your data
  • Right to Data Portability - receive your data in a machine-readable format (JSON or CSV)
  • Right to Object - object to processing of your data
  • Right to Withdraw Consent - withdraw consent at any time
  • Right to Lodge a Complaint - file a complaint with a supervisory authority

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. Our lead supervisory authority is:

Hamburgische Beauftragte für Datenschutz und Informationsfreiheit

Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany

[email protected]

Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data transmitted over HTTPS/TLS encryption
  • Passwords hashed using bcrypt algorithm
  • Two-factor authentication available for all accounts
  • Regular security assessments and software updates
  • Data stored in EU-based data centers

Third-Party Services

We use the following third-party services to operate our platform. Each service processes data as described below:

  • Postmark - Transactional email delivery. Processes: email address, name. Location: USA (EU SCCs in place).
  • Cloudflare Turnstile - Bot protection during registration. Processes: IP address, browser data. Location: Global (EU SCCs in place).
  • Internet.bs - Domain registration services. Processes: contact information for WHOIS. Location: Bahamas.
  • Cryptomus - Cryptocurrency payment processing. Processes: transaction data. Location: Lithuania (EU).
  • DebloMassi - Credit and debit card payment processing. Processes: card details, cardholder name and email address you enter on their checkout, plus the invoice amount, currency and invoice reference. Location: Delaware, United States (transfer outside the EEA - see Payment Processing above).

International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA). However, some of our third-party service providers may process data outside the EEA.

When data is transferred outside the EEA, we rely on one or more of the following safeguards, depending on the provider:

  • Standard Contractual Clauses (SCCs) - approved by the European Commission
  • Adequacy Decisions - where the destination country ensures adequate protection
  • Data Processing Agreements - with our third-party processors

The transfer that takes place when you pay by card is described separately under Payment Processing above. You can avoid it by paying with cryptocurrency or from your account balance.

Children's Privacy

Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16 years of age.

If we become aware that a child under 16 has provided us with personal data, we will take steps to delete such information promptly. If you believe a child has provided us with their data, please contact us at [email protected].

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Inform affected individuals without undue delay if the breach is likely to result in high risk
  • Document all breaches and the remedial actions taken

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

1337 Services GmbH

Ludwig-Erhard-Str. 18

20459 Hamburg

Germany

[email protected]