How We Use Your Information
We use personal data only for clearly defined purposes connected with running a hosting business. We do not use it for automated decision-making that produces legal effects on you, and we do not sell it or rent it to anyone.
Providing and supporting services
- Creating and managing your account in the client area.
- Provisioning virtual machines and bare metal servers, assigning IP addresses and setting rDNS records you request.
- Sending login details, service notifications and maintenance announcements.
- Answering support tickets, carrying out reboots or reinstalls, and handling sales and quote requests.
Billing and accounting
We use billing data to issue invoices, match payments from PayPal or cryptocurrency gateways to the correct account, send renewal reminders and overdue notices, suspend or terminate unpaid services, process cancellations, and keep financial records required for tax and accounting purposes.
Security and fraud prevention
Technical logs help us detect and block attacks against our network, monitor for intrusion attempts, keep the platform stable for every customer and investigate reports of spam, malware or other abuse. We may review new orders for signs of fraud, such as mismatched details or known abusive addresses, before activating a service.
Legal obligations
We process data where the law requires it, for example to keep accounting records, to respond to valid requests from public authorities, or to report illegal content in accordance with legal duties.
Improving our website
If, and only if, you accept analytics cookies, we use aggregated statistics to understand which pages are useful, how visitors move through the site and where information is missing. This helps us improve content such as our VPS and dedicated server pages.
Service and marketing messages
Operational emails about your services, invoices and security are part of the service and cannot be switched off while you hold an active account. We send promotional messages only where you have agreed to receive them or where the law otherwise allows, and every such message includes a simple way to opt out. Marketing cookies are used only with your consent, as described below.
Legal Bases for Processing Under GDPR
The GDPR requires every processing activity to rest on a lawful basis. We rely on the following four bases, depending on the purpose.
- Performance of a contract
Most of what we do with your data is necessary to deliver the services you have ordered under our Terms of Service, or to take steps you request before entering into that contract. This covers creating your account, provisioning servers, assigning IP addresses, invoicing, processing payments and providing support.
- Legal obligation
We keep invoices and payment records for the periods required by tax and accounting law, and we may need to disclose information to competent authorities when legally obliged to do so. We also process data to meet obligations relating to illegal content and network abuse.
- Legitimate interests
Some processing is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. These interests include:
- protecting our network, servers and customers from attacks, fraud and abuse;
- keeping logs needed to diagnose faults and investigate complaints;
- verifying identity before acting on sensitive account requests;
- establishing, exercising or defending legal claims;
- remembering technical preferences needed for the website to work properly.
We have weighed these interests against the impact on you and limit the data and retention periods accordingly. You have the right to object to processing based on legitimate interests, as explained in the section on your rights.
- Consent
We ask for your consent before setting analytics or marketing cookies, and before sending promotional emails where consent is required. Consent is freely given, specific and recorded. You can withdraw it at any time, and withdrawal is as easy as giving it: for cookies, use the “Cookie settings” link in the website footer; for emails, use the unsubscribe link or contact us. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
- Where you are the controller
For personal data that you store or process on your own server, for example details of your website visitors or your customers, you act as the controller and we act only as the infrastructure provider. You are responsible for having a lawful basis for that processing and for meeting your own obligations to the people concerned.
Data Retention, Security and International Transfers
How long we keep data
We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymise it. Typical periods are:
- Account data: while your account is active, and for a limited period afterwards so that we can deal with queries, disputes or returning customers.
- Invoices and payment records: for the period required by tax and accounting law, which may be several years.
- Support tickets: for the life of the account plus a reasonable period, as they record what was agreed and done.
- Technical and security logs: for a short period, usually measured in weeks or months, unless they are needed to investigate a specific incident or abuse case.
- Server contents: deleted when a service is cancelled or terminated. Data on terminated services is not kept for later recovery.
How we protect data
We apply technical and organisational measures appropriate to the risk. The client area is served over encrypted HTTPS connections. Access to customer and billing records is restricted to staff who need it for their role. Our infrastructure is housed in a Tier III certified facility with physical access controls, and the network is protected by an internal firewall plus basic DDoS and intrusion protection. Payment card data never passes through our systems because payments are handled by PayPal or cryptocurrency gateways.
No system is perfectly secure. If a personal data breach occurs that is likely to put your rights at risk, we will notify the relevant supervisory authority and, where required, the affected individuals without undue delay.
Your part in security
Because our services are unmanaged, the security of the operating system and applications on your server is your responsibility. Use strong, unique passwords, keep software updated and maintain your own backups.
International transfers
Our servers are located in Hungary, within the European Economic Area. Some of our providers, including payment processors and support tools, may process data outside the EEA. Where personal data is transferred to a country that does not have an adequacy decision from the European Commission, we rely on appropriate safeguards such as Standard Contractual Clauses, or on another transfer mechanism permitted by the GDPR.
Your Data Protection Rights
Under the GDPR you have a set of rights over your personal data. Some depend on the legal basis we rely on, and some are subject to limits set by law, but we will always explain our decision if we cannot fully meet a request.
The rights available to you
- Access. You can ask for confirmation of whether we process your data and receive a copy of it, along with information about how it is used.
- Rectification. You can ask us to correct inaccurate data or complete incomplete data. Most account details can also be updated directly in the client area.
- Erasure. You can ask us to delete your data where it is no longer needed, where you withdraw consent, or where processing is unlawful. We may need to keep certain records, such as invoices, to meet legal obligations.
- Objection. You can object to processing based on legitimate interests. You can object to direct marketing at any time, and we will stop.
- Portability. For data you provided to us under a contract or consent, you can receive it in a structured, commonly used, machine-readable format, or ask us to send it to another provider where technically feasible.
- Withdrawal of consent. Where processing is based on consent, such as analytics or marketing cookies, you can withdraw it at any time.
How to make a request
Email info@vpshungary.com or open a ticket from the client area, stating which right you wish to exercise. To protect your data, we may need to verify your identity before acting, usually by asking you to write from the email address registered on your account. We respond within one month, which may be extended by two further months for complex or numerous requests, in which case we will tell you why.
Complaints
If you are unhappy with how we have handled your data, please contact us first so that we can try to put it right. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live, work or where an alleged infringement took place. Hungary’s authority is the National Authority for Data Protection and Freedom of Information (NAIH).