Legal

Privacy Policy

Last Updated: 20.09.2026

1. Introduction

This Privacy Policy describes how Tranquila-Host Ltd. (registered in the United Kingdom, Company Number: 16847459, Registered Address: 124 City Road, London, EC1V 2NX) (“we,” “us,” or “our”) collects, uses, and shares your personal data when you use our virtual private server (VPS) hosting services, website, and related applications (collectively, the “Services”).

Tranquila-Host Ltd. acts as the Data Controller for your personal data.

Age Limitation: Our Services are strictly designed for users who are eighteen (18) years of age or older. We do not knowingly collect personal data from anyone under the age of 18.

2. Data We Collect

We collect data necessary to provide our hosting services, process payments, and ensure the security of our infrastructure.

  • 2.1. Information You Provide to Us (Account Data): When you register, you may provide your email address, name, phone number, and a custom username/login. You only provide the information you choose to fill in, though an email address is strictly required for account creation.
  • 2.2. Financial and Billing Information (Payment Data): We do not collect, process, or store raw credit card details on our servers. All sensitive payment data is securely handled directly by our certified third-party payment gateways (Platega, 2328). Data is routed seamlessly from our isolated financial services to these gateways to ensure strict separation of concerns and maximum security.
  • 2.3. Automatically Collected Technical Data (Access Logs): We collect your IP address, User-Agent strings, and login timestamps to secure your account and monitor active sessions.

3. Cookies and Analytics

We use tracking technologies to ensure the functionality of our Services and understand how our website is used.

  • Strictly Necessary Cookies: Required for user authentication, session management, and navigating our control panel.
  • Analytics: We use Plausible Analytics to track aggregate website usage. Plausible is a privacy-focused analytics tool that helps us understand our traffic sources and user behavior without heavily compromising individual privacy.

4. How We Use Your Data & Legal Basis for Processing

Under the UK GDPR and EU GDPR, we process your personal data based on the following legal grounds:

  • Service Provisioning (Performance of a Contract): To create and manage your account, deploy your VPS, and provide technical support.
  • Security & Fraud Prevention (Legitimate Interests): To detect and prevent fraudulent transactions, unauthorized access, and network abuse.
  • Accounting & Tax (Legal Obligation): To maintain accurate financial records as required by UK law.
  • Marketing & Communications (Consent): To send you service updates, billing alerts, and promotional marketing emails. Note: You can opt-out of marketing emails at any time via the “unsubscribe” link or within your account settings.

5. Traffic Analysis and Content Liability (Network Security)

  • User-Generated Content: You retain full ownership and sole liability for all files, databases, and software deployed on your virtual servers. Tranquila-Host Ltd. does not possess administrative (root) access to guest operating systems and does not inspect the payload of your stored data.
  • Network Monitoring: To ensure infrastructure stability, prevent network anomalies, and protect against abuse (including DDoS attacks), we deploy automated network flow monitoring systems. These systems analyze routing vectors and technical connection telemetry (metadata) strictly to secure the platform. We do not perform deep packet inspection (DPI), inspect data payloads, or interfere with user content hosted on virtual servers.

6. Data Sharing and Third-Party Processors

To provide our Services, we share strictly necessary data with trusted third-party service providers (Data Processors), who are bound by data processing agreements:

  • Infrastructure Partners: Hetzner (providing physical server hosting located in Frankfurt, Germany).
  • Network Protection: Cloudflare (for DNS management, CDN, and Web Application Firewall capabilities).
  • Payment Gateways: Platega and 2328 (for secure payment processing).
  • Email Delivery: Mailtrap (for routing and delivering transactional and marketing emails).
  • Law Enforcement: We will disclose user data or server logs to law enforcement agencies only when presented with a valid, legally binding warrant, subpoena, or court order under applicable UK or international law.

7. Cross-Border Data Transfers

Our primary infrastructure is located in Frankfurt, Germany (within the EEA) and our company is registered in the UK. Your data may be accessed by our authorized technical support and administrative staff. We ensure that any cross-border transfers are protected by appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the UK ICO and the European Commission, ensuring your data rights remain fully protected. Users residing in the European Union can address any privacy inquiries directly to our UK office via the contact details provided in Section 12.

8. Data Security

We implement robust, industry-standard security measures, including state-of-the-art cryptographic hashing (using algorithms such as Argon2id) for all user passwords, preventing exposure even in the event of database compromise. Communications between you and our services are strictly encrypted using TLS/SSL.

9. Data Retention and Deletion

  • Active Accounts: Data is kept as long as your account remains active.
  • Financial Records: Under UK law (HMRC regulations), we are legally required to retain billing and financial transaction records for a period of six (6) years.
  • Access Logs: Technical access logs (IPs, User-Agents) are retained for a maximum of 90 days.
  • Abuse and Violations: In the event your account is suspended for violating our Terms of Service (e.g., spam, malware hosting, phishing), or if we have reasonable grounds to expect an imminent request from law enforcement, a forensic backup (snapshot) of your server and associated account data will be preserved in quarantine for 90 days to facilitate investigation.

10. Your Privacy Rights (UK GDPR & EU GDPR)

Under applicable data protection laws, you possess the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct any inaccurate or incomplete data.
  • Erasure (Right to be Forgotten): Request deletion of your account and personal data (subject to our legal obligations to retain financial records).
  • Objection & Restriction: Opt-out of data processing for marketing purposes or request restriction of processing.
  • Data Portability: Receive your data in a structured, machine-readable format.
  • Lodge a Complaint: You have the right to lodge a complaint regarding our data processing with the UK Information Commissioner’s Office (ICO) or your local data protection authority.

To exercise any of these rights, please contact our privacy team.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. If we make material changes, we will notify you via email or a prominent notice on our website at least 14 days before the changes take effect.

12. Contact Us

If you have any questions about this Privacy Policy, your rights, or our data practices, please contact us at:

  • Email: [email protected]
  • Mailing Address: Tranquila-Host Ltd., 124 City Road, London, EC1V 2NX