1. Data Controller Information
This Privacy Policy explains how HostMods.com ("HostMods", "We", "Us") collects, stores, and protects personal data when you use our website, game server management panel, and associated digital services.
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679 - "GDPR"), the Data Controller is HostMods Cloud Operations. For any privacy-related questions or data subject access requests, contact us at hostmods.com/contact or open a ticket at hostmods.com/tickets.
2. Information We Collect
- Account Information: Username, email address, password hash (encrypted via modern one-way cryptographic algorithms), and registration timestamp.
- Billing & Invoicing Details: Full name, billing address, phone number, payment transaction ID, and currency. We do not store raw credit card numbers on our servers; payments are processed securely through certified gateways such as PayPal.
- Technical & Telemetry Data: IP address, browser User-Agent, operating system, session cookies, and login timestamps.
- Server Audit Logs: Command console inputs, file manager actions, sub-user permission grants, and power state toggles recorded for administrative and security auditing.
3. Legal Grounds for Processing (GDPR Art. 6)
We process personal data solely on legitimate legal bases:
- Performance of a Contract (Art. 6(1)(b)): To provision, configure, and maintain your game servers, execute payments, and provide customer support.
- Compliance with Legal Obligations (Art. 6(1)(c)): To comply with tax, invoicing, and corporate record-keeping requirements.
- Legitimate Interests (Art. 6(1)(f)): To defend our infrastructure against cyberattacks, mitigate DDoS floods, detect fraudulent transactions, and guarantee network stability.
4. Third-Party Service Providers
We may share necessary data with trusted third-party sub-processors solely for operational fulfillment:
- Payment Gateways: PayPal (Europe) S.à r.l. et Cie, S.C.A. for payment authorization and dispute management.
- Bare-Metal Data Centers: Tier-3 certified hosting providers located within the European Union (Germany, Italy, Bulgaria) providing isolated physical rack space and DDoS mitigation transit.
We do not sell, rent, or monetize your personal information to third parties or advertising brokers under any circumstances.
5. Your Rights Under GDPR
As an individual in the European Economic Area, you have extensive data rights:
- Right of Access (Art. 15): Request a copy of all personal data held concerning you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
- Right to Erasure / "To Be Forgotten" (Art. 17): Request deletion of your personal account, subject to mandatory tax retention laws.
- Right to Restriction (Art. 18): Restrict the processing of your data under specific conditions.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
To exercise any of these rights, simply submit a request via our Support Desk.
6. Data Security & Retention
All communication between your browser and our platform is encrypted with TLS 1.3. Server management nodes communicate across private encrypted tunnels. Access to database clusters is strictly limited to authenticated system daemons.
Account data is retained for the lifetime of your active profile. Financial records are retained in compliance with applicable statutory taxation requirements (typically 5 to 10 years). Temporary server audit logs are automatically rotated and purged after 30 to 90 days.