Skip to content
/ PrivacyLegal

Privacy policy

How we collect, process and protect your personal data. ViaHost Networks, LLC is the data controller. Regulation (EU) 2016/679 (GDPR) applies to clients in the European Economic Area.

Last updated: 5 September 2026 · ViaHost Networks, LLC

  1. 01Data controller

    The controller of your data is ViaHost Networks, LLC, EIN 32-0862114, with its address at 7345 W Sand Lake Rd, Ste 210, Office 3344, Orlando, FL 32819, United States.

    For any data-protection matter, including exercising your rights, write to [email protected] with the subject line "Data protection".

  2. 02Data we collect

    We only process the data needed to provide the service, bill it and keep it secure:

    • Account data: first and last name, email address, password (stored only as a hash) and, if you enable two-step verification, the associated TOTP secret.
    • Billing data: name or company name, postal address, country and tax identifier if you provide it, together with your history of orders, proforma invoices and invoices.
    • Payment data: card payments are processed by Stripe and bank transfers are received in our Wise account. We do not store card numbers; we only keep the transaction identifier and its status.
    • Service data: server name, assigned IP addresses, plan, operating system, status and tasks run from the panel (power, reinstall, backups, plan changes). If you install our metrics agent, we receive CPU, memory, disk and network usage series from the server.
    • Support data: the messages you send us through the ticket system or by email and any data you include in them.
    • Technical browsing data: IP address, date and time, requested pages, browser and operating system, collected in the web server logs and by our delivery and protection network (Cloudflare).
    • Cookies and local storage: as described in the Cookie policy.
  3. 03Purposes and legal basis

    We process your data for the following purposes and on the following legal bases:

    • Providing the services you purchase, managing your account and handling your support requests (performance of the contract).
    • Issuing proforma invoices and invoices, collecting payment, reconciling payments and managing renewals and non-payment (performance of the contract and compliance with legal obligations, in particular tax and accounting).
    • Sending you necessary service communications: expiry notices, payment confirmations, alerts about your server, maintenance or security notices (performance of the contract).
    • Keeping the platform secure: preventing unauthorised access, attacks, fraud and abuse, and keeping technical logs (legitimate interest).
    • Responding to requests from authorities and third-party complaints about abusive use (legal obligations and legitimate interest).
    • Sending you commercial information about our services only if you have authorised it; you can withdraw consent at any time (consent).

    We do not make automated decisions with legal effects on you, nor do we build profiles for advertising purposes.

  4. 04Data retention

    We keep each category of data only for as long as its purpose requires:

    • Account data: while the account is active and for up to 12 months after it is closed, unless a legal obligation or a pending claim requires keeping it longer.
    • Proforma invoices, invoices and payment records: for the period required by the applicable tax and accounting rules.
    • Server data: while the service is active. A cancelled service, including deletion for non-payment, is removed from the infrastructure together with its disk; a reference may remain in the platform backups for up to 30 days.
    • Agent metrics: raw data is aggregated by the hour and the aggregated series are kept for 46 days.
    • Web server logs: 14 days. System and security logs: 90 days.
    • Support tickets and emails: up to 24 months after they are closed, so that recurring issues can be handled.
  5. 05Recipients and processors

    We do not sell or share your data. Only the providers essential to delivering the service receive it, acting either as processors or as independent controllers with their own policies:

    • Stripe (card payments) and Wise (bank account for transfers).
    • Cloudflare (content delivery network, DNS and attack protection for the website and the panel).
    • The operators of the data centres where our servers are hosted in the European Union (Netherlands, Germany and the other locations indicated on each product).
    • The accredited registrar through which purchased domains are managed.
    • Email providers and encrypted backup storage providers.
    • Public authorities, courts or law enforcement when the law requires it.
  6. 06International transfers

    Our servers and the services you purchase are located in data centres in the European Union. However, ViaHost Networks, LLC is a US company, so your account and billing data may be accessed from the United States by our staff to manage the service. Some providers (Stripe, Cloudflare) may also process data outside the EEA.

    In those cases we apply the safeguards provided for in the GDPR, in particular the standard contractual clauses approved by the European Commission and, where the provider is certified, the EU-US Data Privacy Framework.

  7. 07Your rights

    You may at any time exercise your rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw any consent you have given, by writing to [email protected] from the email address linked to your account. We will reply within one month at most.

    Much of your data can be viewed and changed directly in the client area (profile, billing details, two-step verification, notifications).

    If you believe we have not handled your rights properly, you may lodge a complaint with the supervisory authority of your country of residence. In Spain this is the Agencia Española de Protección de Datos (www.aepd.es).

  8. 08Security

    We apply technical and organisational measures appropriate to the risk: TLS encryption on all communications with the website, the panel and the API; passwords stored only as hashes; two-step verification available to every account and mandatory for administrators; web application firewall and attack mitigation at the network edge; regular hardening and updating of the servers; security logs; encrypted backups; and access to data restricted to the staff who need it.

    Remember that the security of whatever you install inside your server (operating system, applications, access passwords) is your responsibility.

For any question about this document, write to [email protected].