Privacy policy
What data we collect and why, who we share it with, and how long we keep it.
1. What we collect
We collect only what is needed to provide the service. The list below is complete; we do not collect categories that are not named here.
- Account details: name, email address, and an irreversible hash of your password.
- Billing details: legal name, address, tax or identity number, country and city. These are legally required on an invoice.
- Order and payment records: what you bought, the amount, the currency, the payment status and the provider’s transaction reference.
- Service details: your domain, your server’s IP address and the technical settings of the service.
- Technical logs: request time, IP address, browser information and a request identifier. These exist for debugging and for detecting abuse.
2. What we do not collect
We never see or store your card number, expiry date or CVV. Payment is taken in the provider’s own hosted form; those details never reach our servers.
We do not read your site’s content or your email. Access to your data on the servers happens only to the extent a support ticket you opened requires, and it is logged.
We do not profile you for advertising and we do not sell your data to third parties.
3. Why we process it
- To form and perform the contract: opening the account, provisioning the service, renewing it and providing support.
- Legal obligation: issuing invoices and retaining them for the period tax law requires.
- Legitimate interest: detecting fraud and abuse, keeping the infrastructure secure, debugging faults.
- Consent: for marketing emails only. You can withdraw it at any time; notices about your service are separate and continue regardless.
4. Who we share it with
We share data only with the parties required to deliver the service, and only as much as needed:
- The payment provider: name, email and amount, in order to take the payment.
- The e-invoicing provider: the details on your billing profile, in order to issue the invoice.
- The domain registry: name, address, email and phone, in order to register the domain. Some of this may appear in the WHOIS record; on extensions that support it you can enable privacy protection.
- The licence supplier: your server’s IP address, in order to issue the licence.
- Infrastructure providers: the companies supplying server and storage capacity.
- Authorities: only on a properly made request, and limited to its scope.
5. Where your data is kept
We offer our services in more than one region. We tell you in writing, before you buy, which region your data will be kept in.
Where a transfer abroad is involved, we apply the safeguards the law requires (an undertaking or standard contractual clauses).
6. How long we keep it
- Account and service records: for as long as the service runs, plus a reasonable archive period afterwards.
- Invoices and accounting records: for the retention period tax law requires. Because that period is a legal obligation, a deletion request cannot shorten it.
- Technical logs: for a limited period for debugging and security review, then deleted.
- After a service ends, your data on the server remains for a further window during which you can download it; at the end of that window it is permanently deleted.
7. Cookies
We use strictly necessary cookies: the one that keeps you signed in and the one that remembers your language. Without them you could not sign in or browse in your chosen language.
We use no advertising or tracking cookies, which is why you see no consent banner. If that changes, this text will change with it and your consent will be asked.
8. Security
Passwords are stored irreversibly. Access to the admin panel requires two-step verification and administrator actions are logged.
Confidential data such as licence keys and server access details is stored encrypted in the database, so it cannot be read in plain text even if a backup is obtained.
No single measure is sufficient on its own. We recommend using a strong password and enabling two-step verification on your side too.
9. Your rights
You have the right to access your data, to have it corrected, to request its deletion, to object to processing, and to receive your data in a portable format.
Open a support ticket from your customer panel to make a request. We respond within 30 days at the latest. If we cannot meet a request we write out why — for example, invoice records cannot be deleted because tax law requires us to retain them.
10. Contact
Write to us through support with any question about this text. If you have a concern about how we process data, we ask you to raise it with us first; if we cannot resolve it, your right to apply to the relevant supervisory authority is reserved.