Privacy policy
How HOSTMYSERVERS collects, uses and protects your personal data, in accordance with the GDPR and the French Data Protection Act.
1 Who is responsible for your data?
The data controller for the processing described in this policy is the company operating the hostmyservers.fr website and the associated client area.
Data controller
Company: HOSTMYSERVERS SARL
Address: 71 rue Francis de Pressensé - 69100 Villeurbanne
SIRET: 842 789 000 000 10
VAT: FR 29842789000
Privacy contact
For any question about this policy or to exercise your rights:
Email: privacy@hostmyservers.fr
Mail: HOSTMYSERVERS SARL - 71 rue Francis de Pressensé - 69100 Villeurbanne
2 What data do we collect?
We only collect the data required to open your account, deliver the services you order, invoice them and keep our infrastructure secure.
Account and identification data
Last name and first name or company name, postal address, email address, phone number, VAT number for businesses, password (stored hashed), two-factor authentication data (TOTP secret, WebAuthn security keys), and the account identifier provided by Google or GitHub if you sign in with one of these providers.
Billing and payment data
Orders, invoices, credits and transactions, payment method used, and the references (tokens, mandate or agreement identifiers) returned by our payment providers. We never store your full card number or your banking credentials: those are handled directly by the payment providers listed in section 6.
Domain name contact data
When you register or transfer a domain name, the identity, postal address, email address and phone number of the holder and of the administrative and technical contacts are transmitted to the registrar and to the registry of the extension concerned. Depending on the rules of each extension, some of this data may be published in the public WHOIS/RDAP directories.
Technical and service data
IP addresses assigned to your services, connection and action logs in the client area, source IP address, browser and operating system, API keys, SSH public keys, DNS zones, configuration of your virtual machines and servers, and backup metadata.
Support and contact data
Support tickets and their attachments, messages sent through the contact form, emails exchanged with our teams, SMS and phone identification codes used to authenticate you when you call us.
Browsing data
Cookies and audience measurement data, detailed in section 11. Non-essential cookies are only placed after you consent.
Data we never ask for
We never ask you for so-called sensitive data (health data, biometric or genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or criminal convictions). Please do not include such data in your support tickets or in the messages you send us.
3 Data you host on our services
This policy covers the data we process as a data controller, that is to say the data of our customers and of the visitors of our website.
It does not cover the content you store or process on the services you rent from us (virtual machines, dedicated servers, hosted websites, mailboxes, backups). For that content, you remain the data controller and we only act as a processor, on your instructions.
We do not access the content of your services, except when strictly necessary to perform an operation you requested, to meet a legal obligation or a request from a competent authority, or to deal with a serious security incident.
4 Why do we process your data?
• Create and manage your account, and give you access to the client area.
• Deliver, provision, operate and renew the services you order.
• Issue invoices, collect payments and manage unpaid invoices and refunds.
• Register and manage your domain names with the relevant registries.
• Provide customer and technical support, and answer your requests.
• Send you service notifications: expiry and renewal reminders, incidents, scheduled maintenance, security alerts.
• Secure our infrastructure: fraud prevention, attack detection and mitigation, handling of abuse reports.
• Comply with our legal and regulatory obligations, in particular accounting obligations and the retention of connection data.
• Measure the audience of our website and improve it, subject to your consent.
5 Legal basis for each processing activity
Performance of the contract (article 6.1.b of the GDPR)
Account management, delivery and operation of the services, billing, support, domain name registration.
Legal obligation (article 6.1.c of the GDPR)
Retention of invoices and accounting records, retention of connection data, responses to requests from competent authorities.
Legitimate interest (article 6.1.f of the GDPR)
Security of our network and of our customers, fraud prevention, handling of abuse reports, improvement of our services.
Consent (article 6.1.a of the GDPR and article 82 of the French Data Protection Act)
Non-essential cookies, audience measurement and commercial communications. You may withdraw your consent at any time.
6 Who receives your data?
Your data is accessible to the HOSTMYSERVERS staff in charge of the services concerned, and is shared with the processors below, each one only for the data strictly needed for its task. We never sell your data and we never rent it out.
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Card payments and SEPA direct debit | Ireland (EU), transfers to the United States |
| PayPal | PayPal payments and recurring billing agreements | Luxembourg (EU), transfers to the United States |
| Paysafecard | Prepaid voucher payments | Austria (EU) |
| Postmark | Delivery of transactional emails | United States |
| OVHcloud | Sending SMS notifications | France (EU) |
| Netim | Domain name registrar | France (EU) |
| AFNIC and the registries of the extensions concerned | Domain name registration and WHOIS/RDAP publication | France (EU) and, depending on the extension, outside the European Union |
| Google, GitHub | Sign-in with a Google or GitHub account, only if you use this option | Ireland (EU), transfers to the United States |
| Google Analytics | Anonymised audience measurement, subject to your consent | Ireland (EU), transfers to the United States |
| nLighten (LYS1 Lyon) | Physical hosting of our servers: building infrastructure, power, cooling and site security | France (EU) |
| Telehouse (TH2 Paris) | Physical hosting of our servers: building infrastructure, power, cooling and site security | France (EU) |
Datacenter staff have no access to the inside of our racks: these are locked and only our authorised staff can open them. Their role is limited to the building infrastructure, and they never access your servers or your data.
Your data may also be disclosed to the competent administrative or judicial authorities when we are legally required to do so, and to our accountants and auditors in the course of their duties.
7 How long do we keep your data?
• Account data: for the duration of the contractual relationship, then three years after your last activity.
• Invoices and accounting records: ten years, in accordance with article L.123-22 of the French Commercial Code.
• Connection data: one year, in accordance with the French regulations applicable to hosting providers.
• Support tickets and exchanges: for the duration of the contractual relationship, then three years.
• Domain name contact data: for the lifetime of the domain name, plus the retention period imposed by the registry concerned.
• Prospect data (contact form): three years after the last contact.
• Consent to cookies and audience measurement: thirteen months maximum, in accordance with the CNIL recommendation.
• Backups of your services: according to the retention period of the plan you subscribed to, then automatic overwriting.
At the end of these periods, the data is deleted or irreversibly anonymised.
8 Where is your data hosted and transferred?
Our infrastructure and our client area are hosted in France, in rack space we rent in datacenters operated by third parties, located in Lyon (nLighten LYS1) and Paris (TH2). Your account, billing and service data therefore remains in the European Union.
These datacenters are certified ISO/IEC 27001 and hold the French Health Data Host (HDS) approval for their hosting activities.
Some of the processors listed in section 6 are located outside the European Union or may transfer data there. These transfers are governed by the safeguards provided for in chapter V of the GDPR: adequacy decisions, in particular the EU-US Data Privacy Framework, or standard contractual clauses adopted by the European Commission.
9 How do we protect your data?
We implement technical and organisational measures suited to the risk: encryption of traffic in transit, hashing of passwords, two-factor authentication and passwordless authentication available on every account, network filtering and anti-DDoS protection, strict access control for our staff, logging of administrative actions and regular backups.
Should a personal data breach occur, we notify the CNIL within seventy-two hours in accordance with article 33 of the GDPR, and we inform the individuals concerned where the breach is likely to result in a high risk to their rights and freedoms, in accordance with article 34.
10 What are your rights?
In accordance with the GDPR and the French Data Protection Act, you have the following rights over your data:
• Right of access: obtain a copy of the data we hold about you.
• Right to rectification: correct inaccurate or incomplete data; most of it can be updated directly in your client area.
• Right to erasure: request the deletion of your data, subject to the retention periods we are legally required to observe.
• Right to restriction of processing: request that the use of your data be temporarily frozen.
• Right to object: object to processing based on our legitimate interest, and to commercial communications at any time.
• Right to data portability: receive the data you provided to us in a structured, commonly used and machine-readable format.
• Right to withdraw your consent: at any time, for processing based on consent, without affecting the lawfulness of processing carried out beforehand.
• Directives after death: define how your data should be handled after your death, in accordance with article 85 of law no. 78-17 of 6 January 1978.
To exercise these rights, write to privacy@hostmyservers.fr from the email address associated with your account. We reply within one month of receiving your request; this period may be extended by two months where the request is complex, in which case we will inform you.
We do not make any decision producing legal effects concerning you based solely on automated processing. Automated checks may be run for security or anti-fraud purposes (for instance the temporary restriction of a payment method), and you may always ask for a human review by contacting our support.
11 Cookies
When you arrive on the site, a banner asks for your consent before any non-essential cookie is deposited. You can accept all, reject all, or customize your choice purpose by purpose. You may withdraw or modify your consent at any time via the "Manage cookies" link in the footer.
Essential cookies
Required for the site to function (session, authentication, cart). Always active, no consent required.
Audience measurement (Google Analytics)
Anonymized traffic statistics (truncated IP) to understand how the site is used and improve it. Subject to your consent.
Legal basis: your consent (article 82 of the French Data Protection Act and articles 6.1.a and 7 of the GDPR). Your choice is stored locally in your browser for 13 months maximum (CNIL recommendation), then the banner is shown again. No consent data is sent to our servers.
12 Changes, contact and complaints
This policy may be updated to reflect changes in our services or in the applicable regulations. The date of the last update is shown at the top of this page, and any significant change is announced on the site or by email.
For any question relating to your personal data, contact us at privacy@hostmyservers.fr.
Our other legal documents remain available: legal notices and terms and conditions of sale.
Lodging a complaint
If you consider, after contacting us, that your rights have not been respected, you may lodge a complaint with the CNIL: 3 place de Fontenoy - TSA 80715 - 75334 Paris Cedex 07, or on www.cnil.fr.
In case of discrepancy, the French version prevails.