GDPR Compliance
GDPR Compliance at VeerHost
At VeerHost, protecting the privacy and personal information of our customers is one of our highest priorities. We understand that trust is essential when you choose a hosting provider, and we are committed to maintaining the highest standards of security, transparency, and regulatory compliance.
This page explains how VeerHost complies with the European Union General Data Protection Regulation (EU Regulation 2016/679), commonly known as the GDPR.
Our services are designed with privacy, security, and data protection in mind, ensuring that personal information is handled lawfully, fairly, and transparently.
Our Commitment to Privacy
VeerHost is committed to:
- Protecting customer privacy
- Processing personal data lawfully
- Maintaining strict security controls
- Being transparent about data processing
- Respecting customer rights
- Following internationally recognized privacy practices
- Continuously improving our security and compliance programs
We regularly review our internal procedures to ensure our services continue to meet applicable privacy regulations and industry best practices.
VeerHost’s Role Under GDPR
Depending on the services provided, VeerHost may act as either a Data Controller or a Data Processor.
When We Act as a Data Controller
We act as the Data Controller when processing information necessary to operate our business, including:
- Customer account registration
- Billing
- Support requests
- Sales inquiries
- Security monitoring
- Fraud prevention
- Marketing communications (where consent applies)
In these situations, VeerHost determines the purposes and means of processing personal data.
When We Act as a Data Processor
For hosting services, VeerHost generally acts as a Data Processor.
This means that our customers remain the Data Controllers of the websites, databases, applications, emails, and files they host with us.
We process customer-hosted data only:
- According to customer instructions
- To provide hosting services
- To maintain platform security
- To ensure service availability
- To perform backups where applicable
- To comply with legal obligations
We never access customer content unless necessary for technical support, security investigations, or when legally required.
Personal Data We May Process
Depending on the services you use, VeerHost may process information such as:
Account Information
- Full name
- Company name
- Email address
- Phone number
- Billing address
- Country
- VAT or tax information (if applicable)
Technical Information
- IP addresses
- Browser information
- Device information
- Operating system
- Login timestamps
- Security logs
- Authentication records
Payment Information
Payments are securely processed by trusted third-party payment providers.
VeerHost does not store full credit card numbers or sensitive payment credentials on its servers.
Support Information
When contacting support, we may process:
- Support tickets
- Emails
- Live chat conversations
- Uploaded files
- Diagnostic information
Only authorized personnel may access this information.
Legal Basis for Processing
VeerHost processes personal data under one or more of the following legal bases established by GDPR:
- Performance of a contract
- Compliance with legal obligations
- Legitimate business interests
- Customer consent
- Protection against fraud and abuse
We process only the minimum amount of information necessary for each purpose.
How We Use Personal Data
Personal information may be used to:
- Create customer accounts
- Deliver hosting services
- Register domain names
- Process payments
- Respond to support requests
- Maintain platform security
- Detect fraud
- Improve service performance
- Notify customers about maintenance or security events
- Meet legal and regulatory obligations
We do not sell customer personal information to third parties.
Data Security
Protecting customer information is a fundamental part of our operations.
VeerHost employs multiple technical and organizational security measures, including:
- SSL/TLS encryption
- Encrypted administrative connections
- Firewalls
- Network monitoring
- Intrusion detection systems
- Access control policies
- Multi-factor authentication where available
- Secure password hashing
- Routine software updates
- Vulnerability monitoring
- Malware scanning
- Automated backups
- Infrastructure monitoring
- Principle of least privilege for internal staff access
Only authorized personnel with legitimate business needs are permitted to access customer information.
Infrastructure Security
Our infrastructure is designed to provide high levels of availability, confidentiality, and integrity.
Security practices include:
- Continuous infrastructure monitoring
- Server hardening
- DDoS protection
- Network segmentation
- Secure data centers
- Redundant systems where applicable
- Physical access controls at data center facilities
Data Retention
We retain personal data only for as long as necessary to:
- Provide our services
- Fulfill contractual obligations
- Comply with legal requirements
- Resolve disputes
- Enforce our agreements
When information is no longer required, it is securely deleted or anonymized where appropriate.
International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), VeerHost ensures that appropriate safeguards are in place.
These safeguards may include:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions issued by the European Commission
- Other legally recognized transfer mechanisms
Data Processing Agreement (DPA)
Customers who require a Data Processing Agreement may request one at any time.
Our DPA outlines:
- Processing responsibilities
- Security obligations
- Confidentiality commitments
- International transfer safeguards
- Customer rights
- Subprocessor obligations
Subprocessors
VeerHost may work with carefully selected third-party service providers to operate our services.
Examples may include:
- Cloud infrastructure providers
- Payment processors
- Email delivery providers
- Monitoring platforms
- Customer support software
- Domain registries
All subprocessors are evaluated for appropriate security and privacy practices before being engaged.
Your GDPR Rights
If you are located within the European Economic Area, you may exercise the following rights:
Right of Access
Request confirmation of whether we process your personal information and receive a copy of that data.
Right to Rectification
Request correction of inaccurate or incomplete information.
Right to Erasure
Request deletion of your personal data where legally applicable.
Right to Restrict Processing
Ask us to temporarily restrict processing under certain circumstances.
Right to Object
Object to processing based on legitimate interests.
Right to Data Portability
Request a machine-readable copy of your personal data.
Right to Withdraw Consent
Where processing relies on consent, you may withdraw that consent at any time.
Right to Lodge a Complaint
You may file a complaint with your local data protection authority if you believe your rights have been violated.
Data Breach Notification
VeerHost maintains documented procedures for responding to security incidents.
If a personal data breach is likely to result in a risk to individuals’ rights and freedoms, we will:
- Investigate immediately
- Contain the incident
- Notify relevant supervisory authorities where required
- Inform affected customers when legally required
- Implement corrective measures
Customer Responsibilities
Customers using VeerHost services are responsible for ensuring that their own websites and applications comply with applicable privacy laws.
This includes:
- Publishing a Privacy Policy
- Obtaining consent where required
- Managing cookies appropriately
- Responding to data subject requests
- Ensuring lawful collection of personal information
Cookies and Analytics
Our websites may use cookies and similar technologies to:
- Maintain user sessions
- Improve website performance
- Analyze traffic
- Enhance user experience
- Protect against abuse
Where required by law, users will be provided with options to manage cookie preferences.
Contact Our Privacy Team
If you have any questions regarding GDPR, privacy, or personal data processing, please contact us.
VeerHost
Email: [email protected]
Support: [email protected]
Website: https://veerhost.com
Updates to This Policy
We may update this GDPR Compliance Statement periodically to reflect changes in legislation, technology, or our business practices.
The latest version will always be available on this page, and the “Last Updated” date will indicate when changes were made.