Legal
Privacy Policy
This Privacy Policy explains how veldhost ("we", "us") processes personal data when you use veldhost.eu, create or manage a hosting account, request support, or order managed hosting services. We are established in the Netherlands and process this controller-side data under the EU GDPR.
Controller
The controller is Veldhost, a Dutch sole proprietorship (eenmanszaak) of Janis Berzins, established in Netherlands (EU).
- Registered office: Piet Heinstraat 12, 7511 JE Enschede, Netherlands
- Chamber of Commerce (KvK): 98167820
- VAT number: NL005311289B72
- Privacy / legal contact: legal@veldhost.eu
Controller and processor roles
For your account, billing, support, website-visit, security, and abuse-prevention data, we are the controller and this policy applies. For the websites, files, mailboxes, databases, backups, and other content you host with us, you are the controller and we act as your processor under our Data Processing Agreement. If your personal data appears inside a customer's hosted content, please contact that customer first; we assist them where required by the DPA.
Summary
- We do not use analytics, tracking pixels or advertising cookies, and we never sell personal data. If you arrive through one of our Google ads and agree when we ask, we tell Google whether that visit led to a sign-up or an enquiry (see Google Ads measurement).
- We use only essential/session cookies required to run the website, portal, and security controls.
- Account data is hosted in the EU. Customer content is handled under the separate DPA.
- We do not sell domains. If you ask us to register one, it is registered in your name and your registrant details go to the registrar and registry, as they require.
What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account data: name, email, company, KvK/VAT details, address, login credentials, ordered domains and services | Create, secure, and run your account and provide the service | Contract |
| Billing data: billing address, VAT number, plan, invoices, payment reference and payment status | Bill you, collect payment, and keep required accounting records | Contract and legal obligation |
| Support data: emails, tickets, messages, and troubleshooting details you provide | Answer questions, diagnose issues, and provide support | Contract and legitimate interests |
| Technical and security logs: IP address, user-agent, timestamps, requests, error logs, audit events, and rate-limit signals | Keep the website and service secure, prevent abuse, troubleshoot, and maintain reliability | Legitimate interests |
| Registrant data, only where you ask us to register a domain: name, address, email, telephone, VAT number or identity-check result | Register and maintain domains and meet registry or ICANN requirements | Contract and legal or registry obligation |
| Google Ads click ID, only if you arrived through one of our ads and agreed to measurement | Tell Google Ads which ad visits led to a sign-up or an enquiry, so we pay only for ads that work | Consent (Art. 6(1)(a) GDPR), which you can withdraw at any time |
| Essential cookies and session data | Operate sessions, security, authentication, and forms | Legitimate interests; consent is not required for strictly necessary cookies |
How we collect data
- Directly from you through forms, account setup, support, email, and service configuration.
- Automatically through server logs, audit logs, session cookies, and security controls when you use the website or portal.
- From domain registries or registrars when a domain is registered or managed through the service.
Recipients and service providers
We share personal data only where needed to run the service, comply with law, or establish, exercise, or defend legal claims.
- Hetzner Online GmbH, Germany/Finland: core EU hosting infrastructure for the platform, account data, hosted files, backups, and authoritative DNS nodes.
- Openprovider / Hosting Concepts B.V., Netherlands: domain registrar, used only where you ask us to register a domain for you. Because you are the registrant, it receives your registrant details (name, address, email, telephone, and a VAT number or identity-verification result where the registry requires one) and passes them to the registry. Both are in the EU.
- Stripe Payments Europe, Ltd.: payment processing. Stripe acts as an independent controller for card and payment data under its own privacy terms; we receive payment references and statuses, not full card numbers.
- Google Ireland Limited: only with your consent, and only when you arrived through one of our Google ads: we send Google the ad's click ID, which conversion it led to (sign-up or enquiry) and when. Google acts as an independent controller for that data under its own privacy terms. Nothing else about you or your account is sent.
- Mail-in-a-Box (self-hosted): mailbox/email service when enabled, run by us on our own Hetzner EU infrastructure rather than a third-party email SaaS.
- No edge, CDN or third-party DNS provider: this website and the veldhost portal are served directly from our own EU infrastructure and our own authoritative nameservers, so visitor request metadata is not shared with an edge network.
- Providers not yet enabled: off-node backups, transactional email, and workspace tooling are added to the DPA sub-processor register and pinned to an EU region before they are used for customer data.
The complete, versioned sub-processor register — including each provider's role, location, and transfer basis — is maintained in our Data Processing Agreement. Where we act as your processor, we will notify you before adding or replacing a sub-processor and you may object on reasonable data-protection grounds.
Domain registration and WHOIS/RDAP
We are not a domain retailer: normally your domain stays at your own registrar and only its DNS points at us, so no registrant data of yours passes through us at all.
Where you ask us to register a domain for you, you are the registrant. Registries require the real registrant's identity, so we collect and pass on your name, postal address, email address and telephone number, plus your VAT number (validated against the EU VIES register) for an organisation, or the result of an identity check for an individual. That data goes to Openprovider in the Netherlands and onward to the registry for your extension, and parts of it may be published through WHOIS/RDAP under that registry's own rules — most registries withhold an individual registrant's contact details by default. You can correct your registrant details at any time from the portal, and we push corrections on to the registry. A registry may also contact you directly to verify them; if it does and you do not respond, it can suspend the domain.
International transfers
We keep Account Data and Customer Content in the EU/EEA. Domain registration is mostly inside it too: our registrar, Openprovider, is in the Netherlands, and the registries for .nl, .eu and most European extensions are in the EU. The registries for generic extensions such as .com, .net and .org, and the data-escrow agents ICANN requires for them, are outside the EEA — so if you ask us to register one of those, your registrant data is transferred there under Article 49(1)(b) GDPR, because the transfer is necessary to perform the registration you asked us to make. We tell you which registry applies before you pay. Google Ireland Limited, which receives the ad click IDs described under Google Ads measurement, may transfer them to Google LLC in the United States; Google LLC is certified under the EU-US Data Privacy Framework (Article 45 GDPR). If a future service requires your personal data to leave the EEA, we will use an appropriate GDPR Chapter V safeguard, such as an adequacy decision or the EU Standard Contractual Clauses, and disclose that before enabling the flow.
Retention
- Account data: for the life of your account and up to 24 months after closure, unless longer retention is needed for legal claims.
- Billing and invoice data: seven years to meet Dutch statutory fiscal retention obligations.
- Support data: up to 24 months after a ticket closes, unless needed for legal claims or an ongoing service issue.
- Google Ads click IDs: 90 days, Google's own import window, then deleted automatically.
- Server logs and anti-abuse data: up to 12 months, unless extended for a specific security investigation.
- Archived mailboxes: when you remove a mailbox, disconnect its domain or delete its site, the mailbox stops receiving and sending mail and the mail in it is kept for 90 days so you can restore it, then deleted. Copies in our encrypted backups expire with the backup cycle.
We delete or anonymise personal data when the applicable retention period ends.
Deletion on account closure or termination. When you close your account or the service ends, we give you a reasonable opportunity to export your website/app files, database, and DNS information, and deleting your account triggers automated teardown of the associated hosting container and resources. Personal data inside your hosted content is returned and/or deleted under our Data Processing Agreement. We then delete or anonymise account and support data on the schedule above, keeping only the minimum records the law requires — for example invoices for the seven-year Dutch fiscal retention period.
Your rights
You may request access, rectification, erasure, restriction, objection to processing based on legitimate interests, and data portability. Where we rely on consent, you may withdraw it at any time without affecting prior processing. We respond within one month unless GDPR permits an extension. You may complain to the Autoriteit Persoonsgegevens or your local supervisory authority.
Security
We apply appropriate technical and organisational measures for the service, including TLS in transit, multi-factor authentication, role-based access control, customer separation, audit logging, and abuse monitoring. No transmission or storage method is completely secure. Where GDPR requires it, we notify affected customers and the Autoriteit Persoonsgegevens of personal-data breaches.
Children
The service is not directed to children under 16. We do not knowingly collect their personal data.
Google Ads measurement
We advertise on Google. No Google script, pixel or cookie runs on our website. When you arrive by clicking one of our ads, the address carries a click ID from Google, and a small notice asks whether we may tell Google if the visit leads to a sign-up or an enquiry.
- If you say no, or ignore it, nothing is kept and nothing is sent. The click ID is removed from the address bar either way.
- If you say yes, the click ID is kept in your browser's session storage for that tab only, and passed to us when you start a checkout or send an enquiry form. We store it with the type of conversion and the time, and send those three things to Google Ads. A sign-up counts only once its free trial has actually started.
- We tell Google that you consented to this measurement and that you did not consent to personalised advertising.
- You can withdraw consent at any time by emailing us; we then delete the stored click ID and stop sending it. Withdrawal does not affect what was sent before.
Cookies
We use only essential/session cookies needed for the website, portal, authentication, security, and forms. We do not use analytics, advertising, or tracking cookies. The only other thing we keep in your browser is the Google Ads click ID described above, and only after you agree; it is cleared when you close the tab.
Changes
We may update this policy for legal or operational reasons. The current version is posted here with the review date shown above. For material changes affecting how we use your personal data, we will give notice where appropriate.
Contact
For privacy enquiries or rights requests, email legal@veldhost.eu.