GDPR Compliance

GDPR Compliance at VeerHost

At VeerHost, protecting the privacy and personal information of our customers is one of our highest priorities. We understand that trust is essential when you choose a hosting provider, and we are committed to maintaining the highest standards of security, transparency, and regulatory compliance.

This page explains how VeerHost complies with the European Union General Data Protection Regulation (EU Regulation 2016/679), commonly known as the GDPR.

Our services are designed with privacy, security, and data protection in mind, ensuring that personal information is handled lawfully, fairly, and transparently.

Our Commitment to Privacy

VeerHost is committed to:

  • Protecting customer privacy
  • Processing personal data lawfully
  • Maintaining strict security controls
  • Being transparent about data processing
  • Respecting customer rights
  • Following internationally recognized privacy practices
  • Continuously improving our security and compliance programs

We regularly review our internal procedures to ensure our services continue to meet applicable privacy regulations and industry best practices.

VeerHost’s Role Under GDPR

Depending on the services provided, VeerHost may act as either a Data Controller or a Data Processor.

When We Act as a Data Controller

We act as the Data Controller when processing information necessary to operate our business, including:

  • Customer account registration
  • Billing
  • Support requests
  • Sales inquiries
  • Security monitoring
  • Fraud prevention
  • Marketing communications (where consent applies)

In these situations, VeerHost determines the purposes and means of processing personal data.

When We Act as a Data Processor

For hosting services, VeerHost generally acts as a Data Processor.

This means that our customers remain the Data Controllers of the websites, databases, applications, emails, and files they host with us.

We process customer-hosted data only:

  • According to customer instructions
  • To provide hosting services
  • To maintain platform security
  • To ensure service availability
  • To perform backups where applicable
  • To comply with legal obligations

We never access customer content unless necessary for technical support, security investigations, or when legally required.

Personal Data We May Process

Depending on the services you use, VeerHost may process information such as:

Account Information

  • Full name
  • Company name
  • Email address
  • Phone number
  • Billing address
  • Country
  • VAT or tax information (if applicable)

Technical Information

  • IP addresses
  • Browser information
  • Device information
  • Operating system
  • Login timestamps
  • Security logs
  • Authentication records

Payment Information

Payments are securely processed by trusted third-party payment providers.

VeerHost does not store full credit card numbers or sensitive payment credentials on its servers.

Support Information

When contacting support, we may process:

  • Support tickets
  • Emails
  • Live chat conversations
  • Uploaded files
  • Diagnostic information

Only authorized personnel may access this information.

Legal Basis for Processing

VeerHost processes personal data under one or more of the following legal bases established by GDPR:

  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate business interests
  • Customer consent
  • Protection against fraud and abuse

We process only the minimum amount of information necessary for each purpose.

How We Use Personal Data

Personal information may be used to:

  • Create customer accounts
  • Deliver hosting services
  • Register domain names
  • Process payments
  • Respond to support requests
  • Maintain platform security
  • Detect fraud
  • Improve service performance
  • Notify customers about maintenance or security events
  • Meet legal and regulatory obligations

We do not sell customer personal information to third parties.

Data Security

Protecting customer information is a fundamental part of our operations.

VeerHost employs multiple technical and organizational security measures, including:

  • SSL/TLS encryption
  • Encrypted administrative connections
  • Firewalls
  • Network monitoring
  • Intrusion detection systems
  • Access control policies
  • Multi-factor authentication where available
  • Secure password hashing
  • Routine software updates
  • Vulnerability monitoring
  • Malware scanning
  • Automated backups
  • Infrastructure monitoring
  • Principle of least privilege for internal staff access

Only authorized personnel with legitimate business needs are permitted to access customer information.

Infrastructure Security

Our infrastructure is designed to provide high levels of availability, confidentiality, and integrity.

Security practices include:

  • Continuous infrastructure monitoring
  • Server hardening
  • DDoS protection
  • Network segmentation
  • Secure data centers
  • Redundant systems where applicable
  • Physical access controls at data center facilities

Data Retention

We retain personal data only for as long as necessary to:

  • Provide our services
  • Fulfill contractual obligations
  • Comply with legal requirements
  • Resolve disputes
  • Enforce our agreements

When information is no longer required, it is securely deleted or anonymized where appropriate.

International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), VeerHost ensures that appropriate safeguards are in place.

These safeguards may include:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions issued by the European Commission
  • Other legally recognized transfer mechanisms

Data Processing Agreement (DPA)

Customers who require a Data Processing Agreement may request one at any time.

Our DPA outlines:

  • Processing responsibilities
  • Security obligations
  • Confidentiality commitments
  • International transfer safeguards
  • Customer rights
  • Subprocessor obligations

Subprocessors

VeerHost may work with carefully selected third-party service providers to operate our services.

Examples may include:

  • Cloud infrastructure providers
  • Payment processors
  • Email delivery providers
  • Monitoring platforms
  • Customer support software
  • Domain registries

All subprocessors are evaluated for appropriate security and privacy practices before being engaged.

Your GDPR Rights

If you are located within the European Economic Area, you may exercise the following rights:

Right of Access

Request confirmation of whether we process your personal information and receive a copy of that data.

Right to Rectification

Request correction of inaccurate or incomplete information.

Right to Erasure

Request deletion of your personal data where legally applicable.

Right to Restrict Processing

Ask us to temporarily restrict processing under certain circumstances.

Right to Object

Object to processing based on legitimate interests.

Right to Data Portability

Request a machine-readable copy of your personal data.

Right to Withdraw Consent

Where processing relies on consent, you may withdraw that consent at any time.

Right to Lodge a Complaint

You may file a complaint with your local data protection authority if you believe your rights have been violated.

Data Breach Notification

VeerHost maintains documented procedures for responding to security incidents.

If a personal data breach is likely to result in a risk to individuals’ rights and freedoms, we will:

  • Investigate immediately
  • Contain the incident
  • Notify relevant supervisory authorities where required
  • Inform affected customers when legally required
  • Implement corrective measures

Customer Responsibilities

Customers using VeerHost services are responsible for ensuring that their own websites and applications comply with applicable privacy laws.

This includes:

  • Publishing a Privacy Policy
  • Obtaining consent where required
  • Managing cookies appropriately
  • Responding to data subject requests
  • Ensuring lawful collection of personal information

Cookies and Analytics

Our websites may use cookies and similar technologies to:

  • Maintain user sessions
  • Improve website performance
  • Analyze traffic
  • Enhance user experience
  • Protect against abuse

Where required by law, users will be provided with options to manage cookie preferences.

Contact Our Privacy Team

If you have any questions regarding GDPR, privacy, or personal data processing, please contact us.

VeerHost

Email: [email protected]

Support: [email protected]

Website: https://veerhost.com

Updates to This Policy

We may update this GDPR Compliance Statement periodically to reflect changes in legislation, technology, or our business practices.

The latest version will always be available on this page, and the “Last Updated” date will indicate when changes were made.

Launchpad