Privacy and cookies

VPS Hungary Privacy and Cookie Policy

This policy explains how VPS Hungary (“we”, “us”) collects, uses, stores and protects personal data when you visit www.vpshungary.com, create an account in our client area, order a virtual private server or dedicated server, or contact our support team. Because our infrastructure is located in a data centre in Budapest, Hungary, within the European Union, we handle personal data in line with the principles of the EU General Data Protection Regulation (GDPR).

We collect only what we need to run your services, bill for them, keep the network secure and meet legal obligations. We do not sell personal data. The sections below describe what we hold, why we hold it, who it is shared with, how long it is kept and how you can exercise your rights. The final section explains the cookies used on this site and how to change your consent at any time. Questions about privacy can be sent to info@vpshungary.com.

Personal Data We Collect

The personal data we process falls into three main groups. We collect most of it directly from you, and some is generated automatically when you use our website or services.

Account and contact information

When you register in the client area or place an order, we collect your name, email address, and the contact details you choose to provide, such as a company name, postal address for invoicing, country and, optionally, a VAT or tax number. If you contact us through a ticket, email or the contact form, we keep the content of that correspondence and any files you attach.

Billing information

We keep records of invoices, the services ordered, amounts, currencies, payment dates and transaction identifiers. Payments themselves are handled by PayPal or by cryptocurrency payment gateways. We do not receive or store your full card number or PayPal password. From PayPal we may receive your payer name, email address and payment status. For cryptocurrency payments we receive the transaction hash, amount and, where the gateway provides it, the sending wallet address.

Technical and usage data

  • Website and client area logs: IP address, browser type, operating system, pages requested, referring page, date and time, and login events.
  • Service data: the IP addresses, hostnames, reverse DNS records and resource usage associated with your VPS or dedicated server.
  • Network and security logs: traffic flow metadata, firewall and intrusion detection events, and records of DDoS mitigation, used to protect the platform and investigate abuse.
  • Cookies: small files described in the cookies section of this policy.

Data stored on your server

Files, databases, emails and other content you place on your VPS or dedicated server belong to you. You are the controller of that data and responsible for its lawful processing. We do not inspect the contents of customer servers as a matter of routine. Our engineers access them only when you ask us to, when required to investigate a credible abuse report, or when compelled by law.

How We Use Your Information

We use personal data only for clearly defined purposes connected with running a hosting business. We do not use it for automated decision-making that produces legal effects on you, and we do not sell it or rent it to anyone.

Providing and supporting services

  • Creating and managing your account in the client area.
  • Provisioning virtual machines and bare metal servers, assigning IP addresses and setting rDNS records you request.
  • Sending login details, service notifications and maintenance announcements.
  • Answering support tickets, carrying out reboots or reinstalls, and handling sales and quote requests.

Billing and accounting

We use billing data to issue invoices, match payments from PayPal or cryptocurrency gateways to the correct account, send renewal reminders and overdue notices, suspend or terminate unpaid services, process cancellations, and keep financial records required for tax and accounting purposes.

Security and fraud prevention

Technical logs help us detect and block attacks against our network, monitor for intrusion attempts, keep the platform stable for every customer and investigate reports of spam, malware or other abuse. We may review new orders for signs of fraud, such as mismatched details or known abusive addresses, before activating a service.

Legal obligations

We process data where the law requires it, for example to keep accounting records, to respond to valid requests from public authorities, or to report illegal content in accordance with legal duties.

Improving our website

If, and only if, you accept analytics cookies, we use aggregated statistics to understand which pages are useful, how visitors move through the site and where information is missing. This helps us improve content such as our VPS and dedicated server pages.

Service and marketing messages

Operational emails about your services, invoices and security are part of the service and cannot be switched off while you hold an active account. We send promotional messages only where you have agreed to receive them or where the law otherwise allows, and every such message includes a simple way to opt out. Marketing cookies are used only with your consent, as described below.

Payment Processors and Other Recipients

We share personal data only where necessary for the purposes described in this policy. We never sell it, and we do not share it with advertisers except through marketing cookies you have agreed to.

Payment processors

PayPal. When you pay by PayPal, you are redirected to PayPal to complete the transaction. PayPal acts as an independent controller of the data it collects and processes it under its own privacy notice. We receive confirmation of payment, the transaction identifier, the payer name and email address, and the amount paid.

Cryptocurrency gateways. When you pay with Bitcoin or another supported cryptocurrency, the payment may be processed by a third-party gateway that generates the payment address and confirms the transaction. The gateway may collect your IP address, email address and transaction details under its own privacy terms.

Infrastructure and service providers

We rely on carefully chosen suppliers who help us operate the business, including the data centre operator in Budapest, network carriers, email delivery services, and the providers of our billing and client area software. Where these suppliers process personal data on our behalf, they act as processors under written agreements that require them to protect the data and use it only on our instructions.

Software vendors

If you order a licensed add-on such as a control panel, we may need to pass limited information, such as the server IP address and hostname, to the vendor in order to issue and validate the licence.

Authorities and legal requests

We may disclose personal data to law enforcement, courts, regulators or other public authorities when required by applicable law, or when necessary to protect our rights, our customers or the public from fraud, abuse or harm.

Abuse reports

When we receive an abuse complaint about a service, we pass relevant details of the complaint to the customer so the problem can be fixed. We do not disclose the customer’s identity to the person who filed the report unless the law requires it.

Data Retention, Security and International Transfers

How long we keep data

We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymise it. Typical periods are:

  • Account data: while your account is active, and for a limited period afterwards so that we can deal with queries, disputes or returning customers.
  • Invoices and payment records: for the period required by tax and accounting law, which may be several years.
  • Support tickets: for the life of the account plus a reasonable period, as they record what was agreed and done.
  • Technical and security logs: for a short period, usually measured in weeks or months, unless they are needed to investigate a specific incident or abuse case.
  • Server contents: deleted when a service is cancelled or terminated. Data on terminated services is not kept for later recovery.

How we protect data

We apply technical and organisational measures appropriate to the risk. The client area is served over encrypted HTTPS connections. Access to customer and billing records is restricted to staff who need it for their role. Our infrastructure is housed in a Tier III certified facility with physical access controls, and the network is protected by an internal firewall plus basic DDoS and intrusion protection. Payment card data never passes through our systems because payments are handled by PayPal or cryptocurrency gateways.

No system is perfectly secure. If a personal data breach occurs that is likely to put your rights at risk, we will notify the relevant supervisory authority and, where required, the affected individuals without undue delay.

Your part in security

Because our services are unmanaged, the security of the operating system and applications on your server is your responsibility. Use strong, unique passwords, keep software updated and maintain your own backups.

International transfers

Our servers are located in Hungary, within the European Economic Area. Some of our providers, including payment processors and support tools, may process data outside the EEA. Where personal data is transferred to a country that does not have an adequacy decision from the European Commission, we rely on appropriate safeguards such as Standard Contractual Clauses, or on another transfer mechanism permitted by the GDPR.

Shield representing layered protection

Your Data Protection Rights

Under the GDPR you have a set of rights over your personal data. Some depend on the legal basis we rely on, and some are subject to limits set by law, but we will always explain our decision if we cannot fully meet a request.

  • The rights available to you

    • Access. You can ask for confirmation of whether we process your data and receive a copy of it, along with information about how it is used.
    • Rectification. You can ask us to correct inaccurate data or complete incomplete data. Most account details can also be updated directly in the client area.
    • Erasure. You can ask us to delete your data where it is no longer needed, where you withdraw consent, or where processing is unlawful. We may need to keep certain records, such as invoices, to meet legal obligations.
    • Objection. You can object to processing based on legitimate interests. You can object to direct marketing at any time, and we will stop.
    • Portability. For data you provided to us under a contract or consent, you can receive it in a structured, commonly used, machine-readable format, or ask us to send it to another provider where technically feasible.
    • Withdrawal of consent. Where processing is based on consent, such as analytics or marketing cookies, you can withdraw it at any time.
  • How to make a request

    Email info@vpshungary.com or open a ticket from the client area, stating which right you wish to exercise. To protect your data, we may need to verify your identity before acting, usually by asking you to write from the email address registered on your account. We respond within one month, which may be extended by two further months for complex or numerous requests, in which case we will tell you why.

  • Complaints

    If you are unhappy with how we have handled your data, please contact us first so that we can try to put it right. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live, work or where an alleged infringement took place. Hungary’s authority is the National Authority for Data Protection and Freedom of Information (NAIH).

Cookies and Consent Choices on This Website

Cookies are small text files that a website stores in your browser. When you first visit www.vpshungary.com, a consent banner lets you choose which categories of cookies to allow. Only necessary cookies are active until you make a choice.

Necessary cookies

These are essential for the website and client area to function and cannot be switched off in the banner. They do not track you across other sites. They include:

  • Theme preference: remembers whether you chose the light or dark display mode, so the site looks the way you set it on your next visit.
  • Consent choice: stores the decision you made in the cookie banner, so we respect it and do not ask again on every page.
  • WHMCS session: keeps you logged in to the client area, holds the contents of your cart while you order, and protects forms against cross-site request forgery.

The legal basis for necessary cookies is our legitimate interest in providing a working website, and the performance of the contract when you use the client area.

Frequently asked questions

Still unsure about something? Our team answers sales and technical tickets around the clock.

Ask a question
Do you sell my personal data?

No. VPS Hungary does not sell or rent personal data to anyone. We share information only where necessary to provide our services, such as with payment processors, infrastructure suppliers and licence vendors, where required by law, or with advertising partners through marketing cookies if you have chosen to accept them in the consent banner.

Do you store my credit card details?

No. Payments are handled by PayPal or by cryptocurrency payment gateways, so your card number and PayPal login never pass through our systems. We keep only the information needed for accounting, such as the transaction ID, amount, date and payer name or email address, so that we can match the payment to your invoice and account.

Can you see the files on my server?

We do not routinely inspect the contents of customer servers. Data you store on your VPS or dedicated server is yours, and you act as its controller. Our engineers access a server only at your request, when needed to investigate a credible abuse report, or when legally compelled. Because services are unmanaged, securing that data is your responsibility.

Where is my data stored?

Customer servers and their contents are located in a Tier III certified data centre in Budapest, Hungary, inside the European Union. Some suppliers, such as payment processors, may process limited data outside the EEA. In those cases we rely on safeguards permitted by the GDPR, such as Standard Contractual Clauses, to protect the transfer.

How can I get a copy of my data?

Send a request to info@vpshungary.com or open a ticket from the client area. We may ask you to confirm your identity, usually by writing from your registered email address. We aim to respond within one month. Where the portability right applies, we can supply the data in a structured, machine-readable format suitable for reuse elsewhere.

Can I ask you to delete my account data?

Yes. You can request erasure once you no longer use our services. We will delete or anonymise your data except for records we must keep by law, such as invoices and payment records needed for tax and accounting. Server contents are deleted when a service is cancelled or terminated, so take your own backups before you leave.

Which cookies are set if I ignore the banner?

Only necessary cookies. These remember your theme preference, store your consent choice once you make one, and keep the WHMCS client area session working when you log in or order. Analytics and marketing cookies are never loaded unless you actively accept them, so ignoring or declining the banner keeps tracking switched off.

How do I change my cookie choice later?

Click the “Cookie settings” link in the footer of any page on the site. The consent banner reopens, and you can switch analytics or marketing cookies on or off. The change takes effect straight away. Clearing cookies in your browser also resets your choice, and the banner will appear again on your next visit.

How long do you keep server logs?

Technical and security logs, such as website access logs and network events, are kept for a short period, usually weeks or months. They help us diagnose faults, defend against attacks and investigate abuse reports. Logs linked to a specific incident or legal claim may be retained longer until the matter is resolved, then deleted in the normal way.

Who can I complain to about data handling?

Please contact info@vpshungary.com first, as most concerns can be resolved directly. You also have the right to complain to a data protection supervisory authority, particularly in the EU country where you live, work or where the issue arose. In Hungary this is the National Authority for Data Protection and Freedom of Information, known as NAIH.

Need help choosing a server?

Our team answers sales and technical tickets around the clock.

Submit a ticket
Submit a ticket