20% off your first order with code APEX20 00:00:00 See deals

Legal

GDPR Compliance

Effective date: 1 January 2025  ·  Last updated: 28 June 2025

1. Overview

HOSTSTACK (OPC) PVT LTD ("Hoststack", "we", "us") is committed to protecting the personal data of all customers, including those in the European Union and European Economic Area. While Hoststack is incorporated in India, we process data belonging to EU and EEA residents and acknowledge the obligations imposed by the General Data Protection Regulation (GDPR) (EU) 2016/679.

This page explains our GDPR posture, the rights available to EU data subjects, and how to contact our Data Protection Officer (DPO) with any requests or concerns.

2. Data We Collect

We collect and process the following categories of personal data from EU customers:

Identity & Contact Data

Full name, email address, phone number, company name, and billing address provided at registration.

Payment Data

Card type, last four digits, and payment method details. Full card data is handled exclusively by our PCI-DSS-certified payment processor — we do not store raw card numbers.

Technical Data

IP address, browser type, operating system, referring URLs, and server log data collected automatically during service use.

Service Usage Data

Domain names, resource consumption metrics (CPU, RAM, bandwidth, storage), and server configuration data.

Communication Data

Support tickets, live chat transcripts, and email correspondence you send to us.

3. Lawful Basis for Processing

Under Article 6 GDPR, we rely on the following lawful bases:

Processing Activity Lawful Basis (GDPR Art. 6)
Account creation and service provisioning Art. 6(1)(b) — Performance of contract
Billing, invoicing and payment processing Art. 6(1)(b) — Performance of contract
Fraud detection and security monitoring Art. 6(1)(f) — Legitimate interests
Service communications and renewal notices Art. 6(1)(b) — Performance of contract
Marketing and promotional emails Art. 6(1)(a) — Consent (opt-in)
Legal compliance and law enforcement requests Art. 6(1)(c) — Legal obligation
Analytics and service improvement Art. 6(1)(f) — Legitimate interests

4. Data Subject Rights

EU and EEA residents have the following rights under GDPR Chapter III:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you and information about how it is processed.

Right to Erasure (Art. 17)

Request deletion of your personal data where there is no compelling reason for its continued processing.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON or CSV) and transfer it to another controller.

Right to Restriction (Art. 18)

Request that we restrict processing of your data in certain circumstances, such as when you contest its accuracy.

Right to Rectification (Art. 16)

Ask us to correct inaccurate or complete incomplete personal data we hold about you.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including direct marketing and profiling.

Right to Withdraw Consent

Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

Right to Lodge a Complaint

File a complaint with your local EU supervisory authority if you believe we are processing your data unlawfully.

We will respond to all verified data subject requests within 30 days. Complex or numerous requests may be extended by a further two months with notice. There is no fee for exercising your rights under normal circumstances.

5. Data Retention Periods

We retain personal data only for as long as necessary for the purposes for which it was collected:

Data Category Retention Period Basis
Account and identity data Duration of account + 5 years post-closure Legal obligation
Billing records and invoices 7 years Tax and accounting law
Support communications 3 years from last interaction Legitimate interests
Server and access logs 90 days Security monitoring
Marketing consent records Until opt-out + 1 year Accountability (Art. 5(2))
Analytics data 26 months Legitimate interests

6. International Transfers (India–EU)

Hoststack's primary infrastructure is located in India. When EU customers use our services, their personal data is transferred to India — a country that does not currently hold an EU adequacy decision under GDPR Article 45.

To ensure GDPR-compliant transfers, we rely on:

  • Standard Contractual Clauses (SCCs): Where applicable, we implement EU Commission-approved SCCs (Decision 2021/914) for transfers from the EU to India.
  • Contractual necessity: For transfers necessary to perform the contract you have entered with us (e.g., providing hosting services from Indian data centres).
  • Your explicit consent: Where you have been clearly informed and have provided unambiguous consent to the transfer.

You may request a copy of the applicable transfer safeguards by emailing our DPO at [email protected].

7. Cookie Categories

Under the ePrivacy Directive and GDPR, we categorise our cookies as follows:

Strictly Necessary

Required for the website to function. These include session management, login state and security tokens. No consent required — these cannot be disabled.

Analytics & Performance

Help us understand how visitors interact with our site. Set only with your consent via the cookie banner. Includes Google Analytics (anonymised IP) and similar tools.

Functionality

Remember your preferences such as currency selection and language. Set with your consent.

Marketing & Targeting

Used to deliver relevant advertisements. Set only with explicit consent. Includes conversion tracking pixels.

Full details including specific cookies, their purposes, providers and lifetimes are available in our Cookie Policy.

8. How to Exercise Your Rights

To submit a data subject request, please email our DPO with the following information:

  • Your full name and email address associated with your Hoststack account
  • The specific right(s) you wish to exercise
  • Any relevant details that will help us locate your data
  • A copy of a government-issued ID for identity verification (we will delete this after verification)

Submit Your Data Request

Email our Data Protection Officer directly:

[email protected]

We will acknowledge your request within 72 hours and provide a full response within 30 days. Where we cannot fulfil your request, we will explain why and inform you of your right to complain to a supervisory authority.

9. Contact the DPO

Data Protection Officer — HOSTSTACK (OPC) PVT LTD

Email: [email protected]

Postal Address: 27/6, Brahmapur, Nathpara, Garia, South 24 Parganas, West Bengal 700084, India

Response time: Within 30 days of verified request

If you are unsatisfied with our response, you have the right to lodge a complaint with your local EU Data Protection Authority (e.g., the UK ICO, German BfDI, or your national supervisory authority).

Deploy today

Online in 60 seconds. Supported around the clock.

Hosting, VPS and game servers on Mumbai infrastructure — INR billing, GST invoices, and code APEX20 for 20% off your first order.

5,000+ customers served
99.9% uptime SLA
<8ms ping across India
24/7 expert support
WhatsApp Discord