SecureGate Hosting / Legal

Privacy Policy

Last updated: Version 0.1
Draft — this document is under legal review and is not yet in force.

This Privacy Policy explains how [LEGAL ENTITY NAME], operating as SecureGate Hosting ("we", "us"), collects and uses personal data when you use this client portal and our Services. We process personal data in line with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) where it applies to you.

1. Who is responsible

The data controller is [LEGAL ENTITY NAME], [COMPANY NUMBER], [ADDRESS]. Privacy contact: [privacy email].

2. What we collect

  • Account and contact data — name, company, email, phone, postal address, tax number.
  • Billing data — invoices, payment records and payment references. We do not store full card numbers.
  • Domain registrant data — the contact details that registries require for each domain (see section 5).
  • Service and technical data — IP addresses, login times, service logs, support ticket content.
  • Content you host — we process it only to provide the Service, on your instructions.

3. Why we use it (legal bases)

Purpose Legal basis
Creating your account, providing and billing the Services Performance of a contract
Keeping invoices and tax records Legal obligation
Security, fraud and abuse prevention, service logs Legitimate interest
Service and account notices by email Performance of a contract
Marketing emails, if you opt in Consent — you can withdraw it at any time

4. Who we share it with

We share personal data only with providers that help us deliver the Services, under contracts that protect your data:

  • Infrastructure and hosting — [e.g. Hetzner Online GmbH (Germany), cPanel hosting provider, Oracle Cloud Infrastructure].
  • Domain registrars — NameSilo (United States), DomainNameAPI (Türkiye), and the relevant registries.
  • Email delivery and payments — [providers to be listed].
  • Authorities, when the law requires it.

We never sell personal data.

5. Domain names and WHOIS

To register a domain we must pass your registrant details to the registrar and registry, as required by ICANN and ccTLD rules. Depending on the extension, some of this data may be published in public WHOIS/RDAP directories. Privacy protection is available for extensions that support it.

6. International transfers

Some providers above are located in other countries. When personal data is transferred internationally, we use the safeguards required by applicable law, such as standard contractual clauses.

7. How long we keep it

  • Account data: while your account is active, then [N] years.
  • Invoices and accounting records: for the period required by tax and accounting law ([N] years).
  • Service logs: up to [N] days.
  • Hosted content: deleted [N] days after a Service is terminated.

8. Your rights

You can ask to access, correct or delete your personal data, to restrict or object to its processing, and to receive a copy of it in a portable format. Where processing is based on consent, you can withdraw consent at any time. Send requests to [privacy email]; we reply within [30] days. You can also complain to the data protection authority where you live.

9. Security

We use encryption in transit, access controls, two-factor authentication for staff, and monitoring to protect personal data. No system is completely secure; if a breach affects your data, we will notify you and the authorities as required by law.

10. Cookies

This portal uses only cookies and browser storage that are strictly necessary: a session cookie to keep you signed in and protect forms, a language cookie, and local storage for your light/dark theme and for remembering that you have seen the cookie notice. We do not use advertising or tracking cookies. If this changes, we will ask for your consent first.

11. Changes

We will post any update on this page and change the version and date at the top. Material changes will also be announced by email.