Legal
GDPR Compliance
Effective date: 1 January 2025 · Last updated: 28 June 2025
1. Overview
HOSTSTACK (OPC) PVT LTD ("Hoststack", "we", "us") is committed to protecting the personal data of all customers, including those in the European Union and European Economic Area. While Hoststack is incorporated in India, we process data belonging to EU and EEA residents and acknowledge the obligations imposed by the General Data Protection Regulation (GDPR) (EU) 2016/679.
This page explains our GDPR posture, the rights available to EU data subjects, and how to contact our Data Protection Officer (DPO) with any requests or concerns.
2. Data We Collect
We collect and process the following categories of personal data from EU customers:
Identity & Contact Data
Full name, email address, phone number, company name, and billing address provided at registration.
Payment Data
Card type, last four digits, and payment method details. Full card data is handled exclusively by our PCI-DSS-certified payment processor — we do not store raw card numbers.
Technical Data
IP address, browser type, operating system, referring URLs, and server log data collected automatically during service use.
Service Usage Data
Domain names, resource consumption metrics (CPU, RAM, bandwidth, storage), and server configuration data.
Communication Data
Support tickets, live chat transcripts, and email correspondence you send to us.
3. Lawful Basis for Processing
Under Article 6 GDPR, we rely on the following lawful bases:
| Processing Activity | Lawful Basis (GDPR Art. 6) |
|---|---|
| Account creation and service provisioning | Art. 6(1)(b) — Performance of contract |
| Billing, invoicing and payment processing | Art. 6(1)(b) — Performance of contract |
| Fraud detection and security monitoring | Art. 6(1)(f) — Legitimate interests |
| Service communications and renewal notices | Art. 6(1)(b) — Performance of contract |
| Marketing and promotional emails | Art. 6(1)(a) — Consent (opt-in) |
| Legal compliance and law enforcement requests | Art. 6(1)(c) — Legal obligation |
| Analytics and service improvement | Art. 6(1)(f) — Legitimate interests |
4. Data Subject Rights
EU and EEA residents have the following rights under GDPR Chapter III:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you and information about how it is processed.
Right to Erasure (Art. 17)
Request deletion of your personal data where there is no compelling reason for its continued processing.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON or CSV) and transfer it to another controller.
Right to Restriction (Art. 18)
Request that we restrict processing of your data in certain circumstances, such as when you contest its accuracy.
Right to Rectification (Art. 16)
Ask us to correct inaccurate or complete incomplete personal data we hold about you.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including direct marketing and profiling.
Right to Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
Right to Lodge a Complaint
File a complaint with your local EU supervisory authority if you believe we are processing your data unlawfully.
We will respond to all verified data subject requests within 30 days. Complex or numerous requests may be extended by a further two months with notice. There is no fee for exercising your rights under normal circumstances.
5. Data Retention Periods
We retain personal data only for as long as necessary for the purposes for which it was collected:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of account + 5 years post-closure | Legal obligation |
| Billing records and invoices | 7 years | Tax and accounting law |
| Support communications | 3 years from last interaction | Legitimate interests |
| Server and access logs | 90 days | Security monitoring |
| Marketing consent records | Until opt-out + 1 year | Accountability (Art. 5(2)) |
| Analytics data | 26 months | Legitimate interests |
6. International Transfers (India–EU)
Hoststack's primary infrastructure is located in India. When EU customers use our services, their personal data is transferred to India — a country that does not currently hold an EU adequacy decision under GDPR Article 45.
To ensure GDPR-compliant transfers, we rely on:
- Standard Contractual Clauses (SCCs): Where applicable, we implement EU Commission-approved SCCs (Decision 2021/914) for transfers from the EU to India.
- Contractual necessity: For transfers necessary to perform the contract you have entered with us (e.g., providing hosting services from Indian data centres).
- Your explicit consent: Where you have been clearly informed and have provided unambiguous consent to the transfer.
You may request a copy of the applicable transfer safeguards by emailing our DPO at [email protected].
8. How to Exercise Your Rights
To submit a data subject request, please email our DPO with the following information:
- Your full name and email address associated with your Hoststack account
- The specific right(s) you wish to exercise
- Any relevant details that will help us locate your data
- A copy of a government-issued ID for identity verification (we will delete this after verification)
We will acknowledge your request within 72 hours and provide a full response within 30 days. Where we cannot fulfil your request, we will explain why and inform you of your right to complain to a supervisory authority.
9. Contact the DPO
Data Protection Officer — HOSTSTACK (OPC) PVT LTD
Email: [email protected]
Postal Address: 27/6, Brahmapur, Nathpara, Garia, South 24 Parganas, West Bengal 700084, India
Response time: Within 30 days of verified request
If you are unsatisfied with our response, you have the right to lodge a complaint with your local EU Data Protection Authority (e.g., the UK ICO, German BfDI, or your national supervisory authority).
Related Legal Documents