Public testing phase We’re in a public testing phase — feel free to look around, but we’re not taking orders yet. Ordering opens 1 October 2026. See plans →

Trust centre

Everything an evaluator needs, on one page.

Built for market research, RFI and RFP answers, shortlisting and due diligence. Legal identity, data residency, security controls, contract terms, continuity and exit — quoted from the published documents, with what we do not have stated just as plainly.

Reviewed 2026-09-09 · Questionnaires and procurement questions answered within two business days · JSON · plain text

Start here

Pick your role. The links go straight to the evidence.

Procurement Who you contract with, on what terms, and how the money works.
Security Controls actually in place, and the ones we do not claim.
Legal & privacy GDPR roles, sub-processors, breach terms, deletion.
Technical evaluators Stacks, deploys, API, backups and how you would leave.
Decision-makers The honest summary, the risks, and the mitigations.
The short version

Small vendor. European end to end. Nothing borrowed.

veldhost is a young Dutch company that owns and operates its whole stack in EU datacenters. We publish our contracts, our sub-processors and our uptime, and we would rather tell you what we lack than wear a badge we have not earned. A risk assessment should weigh both columns.

What you get
  • EU-only infrastructure, no US hyperscaler or CDN in the path
  • Published Art. 28 DPA, 48-hour breach notice, versioned sub-processor register
  • Per-site container isolation, passkey-first accounts, hardware-key-only admin
  • Encrypted backups replicated nightly to a second region
  • Public status page with 90 days of measured uptime
  • Full exports and domain transfer-away at no charge — leaving is a download
What we do not have
  • ISO/IEC 27001 certification
  • SOC 2 report
  • Independent penetration-test report (published)
  • Cyber-liability insurance certificate (published)
  • Single sign-on (SAML / OIDC) for customer accounts
  • 24/7 staffed human support

If one of these is a hard requirement, tell us before you spend time on the rest — we will say straight away whether we can meet it.

Legal identity

ItemAnswerEvidence
Trading name Veldhost
Legal form Sole proprietorship (eenmanszaak) under Dutch law — a natural person trading under a registered trade name, not a B.V.
Owner Janis Berzins
Chamber of Commerce (KvK) 98167820
VAT number NL005311289B72
Registered office Piet Heinstraat 12, 7511 JE Enschede, Netherlands
Country of establishment Netherlands (EU)
Trade name registered August 2026 (Dutch Chamber of Commerce)
Governing law / venue Dutch law; competent Dutch courts, without prejudice to mandatory consumer rights Source →

Service & availability

ItemAnswerEvidence
Service Fully managed EU web hosting: WordPress, PHP, Laravel and static sites with domains, DNS on our own nameservers, email, backups, staging, monitoring, REST API and MCP server. Source →
Commercial availability Public testing phase — ordering opens 1 October 2026. Evaluation and quotes available now. Source →
Plans Starter €5/mo · Pro €15/mo · Business from €79/mo (dedicated server, quoted) Source →
Website https://veldhost.eu Source →
Customer portal https://manage.veldhost.eu Source →
Status page https://veldhost.eu/status Source →
API specification https://manage.veldhost.eu/api/v1/openapi.json (OpenAPI 3.1) Source →

Infrastructure & data residency

ItemAnswerEvidence
Hosting provider Hetzner Online GmbH (Germany) — servers operated entirely by veldhost Source →
Data locations Germany: Falkenstein (production), Nuremberg (nightly backup replication). The DPA also permits Hetzner Finland. All EU/EEA. Source →
Data leaves the EU? No — Customer Content, compute, storage and backups stay in the EU/EEA. Source →
US hyperscaler / CDN in the serving path? No. Served from our own infrastructure and our own authoritative nameservers. Source →
Tenant isolation One LXD system container per site; localhost-only databases; container-to-container traffic denied by default. Source →
Sub-processors Hetzner (DE), Stripe Payments Europe (IE), Openprovider (NL), OpenSRS/Tucows (CA, legacy, domain string only), self-hosted mail. Versioned register in the DPA. Source →

Compliance & certification status

ItemAnswerEvidence
GDPR Article 28 DPA published and incorporated by reference; countersigned copy on request. Source →
Breach notification Controller notified within 48 hours of awareness (DPA §10). Source →
NIS2 Measures mapped to the directive; no certification exists for a provider of our size. Source →
ISO/IEC 27001 Not held. Certification is on the public roadmap (later); not implied before a certificate exists. Source →
SOC 2 Not held. Source →
PCI DSS Card data is handled by Stripe (PCI DSS Level 1); no card data reaches veldhost systems. Source →
Independent penetration test No published report. Daily automated CVE scanning; responsible-disclosure programme. Source →
Cyber-liability insurance No certificate published; ask legal@veldhost.eu.
DNSSEC Available on our nameservers, enabled per domain from the dashboard. Source →

Contractual commitments (quoted)

ItemAnswerEvidence
Availability Starter best effort · Pro 99.5% monthly target (no credits) · Business 99.9% monthly with credits of 10% / 25% / 50% of the monthly hosting fee, capped at one month, once the dedicated setup is confirmed in the order. Source →
Support first response (P1) Starter 1 business day · Pro 4 business hours · Business 2 business hours. Source →
Backups Weekly on every plan; daily with 30-day retention on Business or as an add-on; nightly encrypted replication to a second region. Source →
RPO / RTO targets RPO 7 days (weekly) or 24 hours (daily). RTO 2 business days / 1 business day / 8 business hours (Business). Objectives, not guarantees. Source →
Maintenance window Sunday 22:00–02:00 CET/CEST, max 2 hours per month; notice 3 / 5 / 7 business days by plan. Source →
Liability cap Fees paid for the affected service in the preceding 12 months, never below one billing period; negotiable in a Business order form. Source →
Sub-processor changes At least 14 days’ notice; right to object and terminate the affected service. Source →
Audit rights Once per 12 months on reasonable notice, or after a breach affecting you. Source →
Data return & deletion Export of files, database, DNS and mail plus domain transfer codes on termination; deletion of all copies within the export window; 7-year fiscal retention of invoices only. Source →
Cancellation & refunds Cancel any time, effective end of paid period. 14-day withdrawal with full refund on hosting for consumers and sole traders; domain registrations non-refundable. Pro-rata refund if we terminate for convenience. Source →

Billing

ItemAnswerEvidence
Currency EUR
Payment Card via Stripe, monthly or annual. Business orders: written quote and order form; purchase-order references and invoice-based payment discussed per order. Source →
VAT Dutch VAT; EU business customers with a valid VAT number are reverse-charged (0%). Source →
Invoices Issued for every charge; listed in the dashboard with PDF download. Purchase-order references on Business orders. Source →
Continuity and exit

What happens if something goes wrong — including with us.

Your site goes down

Health checks run every five minutes; the status page and dashboard show it; P1 first response is 2 business hours on Business. Business availability below 99.9% earns service credits.

SLA →
Data is lost or corrupted

Restore any nightly or weekly restore point yourself in one click, or download the backup. Every backup is replicated nightly to a second region.

Backups & restore →
A personal-data breach

You are notified within 48 hours of our awareness with the facts you need for your own Art. 33/34 reporting. We assist; you remain the controller.

DPA §10 →
You want to leave

Export files, databases, DNS zones and mail at any time. Managed domains transfer away on request — EPP code and lock removal within five business days, no fee. Standard stacks run anywhere.

Terms §6 and §8 →
We stop trading

Stated plainly because we are a sole proprietorship: your mitigation is that nothing here is proprietary. Standard WordPress, PHP, Laravel, MariaDB and IMAP; exports and transfer codes available at all times; backups in two regions you can download.

Questionnaire →
A sub-processor changes

At least 14 days’ notice, a right to object on data-protection grounds, and a right to terminate the affected service if the objection cannot be resolved.

DPA §6 →
How to evaluate us

A shortlist-to-signature path that costs you nothing.

Most evaluations finish in two conversations. Send what you already have — your own questionnaire, your DPA template, your order-form requirements — and we answer in writing rather than on a call you have to transcribe.

  1. Read the fact sheet. The vendor profile is one page and also comes as JSON and plain text for your supplier register.
  2. Map your questionnaire. The pre-answered questionnaire follows the usual SIG-Lite / CAIQ sections. Send the remainder to security@veldhost.eu; first response within two business days.
  3. Pilot on a real site. A staging copy or a trial site on the plan you would buy — no sales-only demo environment.
  4. Paper it. The DPA is incorporated by reference; a countersigned copy, a Business order form with negotiated availability and liability terms, and purchase-order references are handled by legal@veldhost.eu.
  5. Migrate for free. We move files, database, DNS and mailboxes on a written plan, typically with no downtime.

Document library

Two documents still carry a “pending final review by counsel” note (the DPA and the SLA). It stays visible on purpose until licensed NL/EU review is complete; the commitments in them are what we operate to today.

Evaluating us for a tender or a regulated project?

Send the questionnaire, the DPA template or the requirement you are not sure we meet. You get a written answer, not a sales call.

Contact us Request a Business quote