GDPR Compliance Policy
The General Data Protection Regulation (GDPR) is a comprehensive European privacy law that took effect on May 25, 2018. It sets a high standard for how personal data is collected, handled, and protected. Hosticky ("we", "our", "us") is fully committed to compliance with the GDPR for all users accessing our hosting platform from the European Union (EU).
1. Your GDPR Rights
Under the GDPR, EU residents have specific rights regarding their personal data. We honor these rights for all our registered users:
- Right of Access: You can request a copy of all personal data we hold about you.
- Right to Rectification: You have the right to request updates or corrections to incomplete or inaccurate data.
- Right to Erasure (Right to be Forgotten): You can request the permanent deletion of your account and hosting data.
- Right to Restrict Processing: You can request that we pause or limit processing your data in certain conditions.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
2. Data Processor vs. Data Controller
Hosticky acts in two distinct capacities under the GDPR:
- Data Controller: We act as a Controller for data collected to manage your account and billing details (such as names, emails, and phone numbers).
- Data Processor: We act as a Processor for any client data, files, and databases that you upload and host on our servers. You remain the Controller of that data.
3. Sub-Processors
We utilize trusted third-party service providers (Sub-Processors) to assist with our billing and hosting infrastructure. These include payment processors (such as Cashfree/Stripe) and server control systems (like cPanel/WHM). All of our Sub-processors adhere to strict data transfer agreements to safeguard EU user data.
4. Data Transfer & Protection
To ensure maximum security, all communication between our servers and your device is encrypted using Let's Encrypt 256-bit SSL connections. We enforce strong administrative and technical controls to maintain data confidentiality, integrity, and availability.
5. Data Breaches
In the unlikely event of a data breach, we will notify affected users and the relevant regulatory authorities within 72 hours of becoming aware of the breach, in accordance with GDPR requirements.
6. GDPR Inquiries & Data Requests
If you wish to exercise any of your GDPR rights, or if you have any questions regarding your data protection, please contact our Data Protection Officer (DPO) by submitting a ticket in our support portal or emailing us at privacy@hosticky.com.