Legal
Hostwover Legal Center

Policies, agreements, and legal information for using Hostwover services.

Privacy / Data Protection Policy

Language note

The English version of Hostwover's legal agreements and policies is the authoritative version. Translated versions are provided for convenience. If there is any conflict between translations, the English version shall prevail.

Last updated: August 15, 2026

This Privacy & Data Protection Policy ("Policy") establishes the principles, responsibilities, safeguards, and procedures followed by Hostwover ("Hostwover," "we," "us," or "our") when processing Personal Data in connection with services provided, sold, resold, managed, or made available through Hostwover.

This Policy applies to Personal Data processed in connection with:

  • Hostwover websites.
  • Customer accounts.
  • domain services.
  • DNS services.
  • Web Hosting.
  • VPS.
  • VDS.
  • Professional Email.
  • Google Workspace.
  • SSL-related services.
  • payment and billing systems.
  • Customer support.
  • APIs.
  • artificial intelligence services.
  • security systems.
  • fraud-prevention systems.
  • marketing.
  • administrative operations; and
  • other Hostwover products and services.

This Policy should be read together with the:

  • Hostwover Privacy Policy.
  • Cookie Policy.
  • Terms of Service.
  • Acceptable Use Policy.
  • Acceptable Use Agreement.
  • Abuse Handling Policy.
  • Customer Service Policy.
  • Refund Policy.
  • applicable product agreements.
  • applicable Data Processing Agreement, where one exists; and
  • applicable third-party provider terms.

1. Purpose

The purpose of this Policy is to establish how Hostwover approaches the protection of Personal Data.

Hostwover seeks to process Personal Data in a manner that is:

  • lawful.
  • fair.
  • transparent.
  • proportionate.
  • secure.
  • purpose-specific.
  • limited to what is reasonably necessary.
  • retained only for appropriate periods; and
  • consistent with applicable data-protection requirements.

2. Relationship With the Hostwover Privacy Policy

The Hostwover Privacy Policy primarily explains to individuals:

  • what information Hostwover collects.
  • why it is collected.
  • how it is used.
  • who it may be shared with.
  • how long it may be retained; and
  • what privacy rights may be available.

This Privacy & Data Protection Policy establishes the broader operational and governance framework used by Hostwover to protect Personal Data.

Both documents may apply simultaneously.

3. Applicable Laws

Hostwover will seek to process Personal Data in accordance with data-protection and privacy laws applicable to the relevant processing activity.

Depending on the circumstances, these may include:

  • Egyptian data-protection requirements.
  • the General Data Protection Regulation ("GDPR") where applicable.
  • applicable national laws implementing or supplementing European data-protection requirements.
  • applicable electronic communications and cookie rules.
  • consumer-protection requirements.
  • contractual privacy obligations; and
  • other applicable privacy or data-protection laws.

4. Egyptian Data Protection Framework

Hostwover recognizes Egypt's Personal Data Protection Law No. 151 of 2020 and applicable implementing requirements where they apply to Hostwover's processing activities.

Hostwover will seek to implement applicable:

  • controller requirements.
  • processor requirements.
  • consent requirements.
  • security requirements.
  • data-subject rights.
  • breach-notification requirements.
  • cross-border transfer requirements.
  • licensing requirements.
  • registration requirements; and
  • Data Protection Officer requirements

as required by applicable Egyptian law and regulations.

Nothing in this Policy represents that Hostwover has obtained a particular government license, authorization, registration, certification, or approval unless Hostwover expressly confirms that fact separately.

5. GDPR

Where the GDPR applies to a Hostwover processing activity, Hostwover will process Personal Data according to applicable GDPR requirements.

These include principles concerning:

  • lawfulness, fairness, and transparency.
  • purpose limitation.
  • data minimization.
  • accuracy.
  • storage limitation.
  • integrity and confidentiality; and
  • accountability.

The GDPR also requires appropriate technical and organizational safeguards and incorporates data protection by design and by default.

6. Geographic Scope

The privacy rules applicable to a particular Customer or processing activity may depend on factors including:

  • Customer location.
  • Data Subject location.
  • Hostwover establishment.
  • processing location.
  • Service used.
  • type of Personal Data.
  • applicable contract.
  • applicable provider; and
  • relevant law.

The appearance of a particular law in this Policy does not mean that the law necessarily applies to every Hostwover Customer or transaction.

7. Data Protection Principles

Hostwover's handling of Personal Data is guided by the following principles:

  1. process data lawfully.
  2. explain processing transparently.
  3. collect data for identified purposes.
  4. avoid collecting unnecessary data.
  5. maintain reasonable accuracy.
  6. retain data only as long as appropriate.
  7. protect data against unauthorized access and loss.
  8. limit access based on legitimate need.
  9. respect applicable Data Subject rights.
  10. evaluate privacy risks in new systems.
  11. use processors and providers responsibly; and
  12. maintain reasonable evidence of compliance.

8. Accountability

Hostwover seeks to maintain appropriate policies, records, procedures, contracts, security controls, and operational processes to demonstrate responsible Personal Data handling.

Accountability measures may include:

  • privacy documentation.
  • processing records.
  • security controls.
  • vendor assessments.
  • access controls.
  • staff procedures.
  • incident records.
  • retention procedures.
  • privacy reviews.
  • contractual safeguards; and
  • Data Subject request procedures.

9. Privacy by Design

Hostwover seeks to consider privacy during the design and implementation of:

  • websites.
  • applications.
  • APIs.
  • databases.
  • checkout systems.
  • dashboards.
  • AI functionality.
  • Customer portals.
  • internal systems; and
  • new Services.

Where GDPR applies, privacy by design and default includes implementing safeguards based on the nature and risks of processing and ensuring that, by default, only data necessary for each specific purpose is processed.

10. Data Minimization

Hostwover seeks to collect and process only Personal Data reasonably relevant to the purpose for which it is needed.

Hostwover should avoid requesting Personal Data merely because it may potentially be useful in the future.

11. Purpose Limitation

Personal Data should be collected for identified and legitimate purposes.

Hostwover should not use Personal Data for materially incompatible new purposes without:

  • an appropriate legal basis.
  • additional notice.
  • consent where required; or
  • another lawful justification.

12. Accuracy

Hostwover seeks to maintain Personal Data accurately where reasonably necessary for the purposes for which the data is processed.

Customers are responsible for maintaining accurate:

  • account information.
  • contact information.
  • billing information.
  • domain information; and
  • other Customer-controlled data.

13. Storage Limitation

Hostwover seeks not to retain Personal Data indefinitely without justification.

Retention periods should reflect:

  • purpose.
  • account status.
  • contractual obligations.
  • financial requirements.
  • tax requirements.
  • security requirements.
  • dispute risks.
  • fraud prevention.
  • statutory obligations; and
  • applicable provider requirements.

The European Commission's GDPR guidance similarly describes storage limitation as keeping Personal Data for the shortest period appropriate to the processing purpose while accounting for applicable legal retention obligations.

14. Integrity and Confidentiality

Personal Data should be protected using safeguards appropriate to:

  • data sensitivity.
  • volume.
  • processing purpose.
  • potential risk.
  • infrastructure.
  • cost and feasibility.
  • available security technology; and
  • legal requirements.

15. Personal Data

"Personal Data" means information relating to an identified or identifiable natural person where that information falls within the applicable legal definition of personal data or personal information.

Examples may include:

  • name.
  • email address.
  • telephone number.
  • billing information.
  • IP address.
  • account identifiers.
  • authentication information.
  • domain registrant information; and
  • support communications.

16. Data Subject

A "Data Subject" means the individual to whom Personal Data relates.

A Data Subject may include:

  • Customer.
  • account administrator.
  • End User.
  • website visitor.
  • contact person.
  • domain registrant.
  • support requester.
  • employee of a Customer.
  • billing contact; or
  • another identifiable individual.

17. Controller

A "Controller" generally determines why and how Personal Data is processed.

Hostwover may act as a Controller for certain processing activities, including where Hostwover determines the purposes and means of processing Customer-account or business-administration information.

18. Processor

A "Processor" generally processes Personal Data on behalf of a Controller.

For some Services, Hostwover may process Customer-controlled Personal Data on behalf of the Customer.

The precise legal role depends on the specific Service and processing activity.

19. Different Roles for Different Data

Hostwover may act as:

  • Controller for one category of Personal Data.
  • Processor for another category; and
  • reseller or intermediary in relation to Personal Data processed independently by another provider.

The existence of one role does not automatically determine Hostwover's role for every processing activity.

20. Hostwover as Controller

Hostwover may generally act as Controller for information used to:

  • establish Customer accounts.
  • authenticate Customers.
  • process orders.
  • manage billing.
  • communicate with Customers.
  • prevent fraud.
  • secure Hostwover Services.
  • provide support.
  • comply with legal obligations.
  • manage subscriptions.
  • administer Hostwover operations; and
  • improve Hostwover Services.

21. Hostwover as Processor

Where Hostwover processes Personal Data solely on a Customer's documented instructions through a Service, Hostwover may act as Processor.

Examples may include certain processing performed within:

  • hosted applications.
  • hosting infrastructure.
  • server-management functionality; or
  • other Customer-controlled environments.

Whether Hostwover is legally a Processor will depend on the actual circumstances.

22. Customer as Controller

Customers commonly determine the purpose and means of processing Personal Data they collect through their own:

  • websites.
  • applications.
  • online stores.
  • databases.
  • mailing systems.
  • APIs.
  • VPS.
  • VDS.
  • forms.
  • customer portals; or
  • other hosted workloads.

In those circumstances, the Customer may be responsible as Controller.

23. Customer Privacy Obligations

Customers are responsible for determining whether their processing of Personal Data complies with applicable law.

This may include responsibility for:

  • privacy notices.
  • consent.
  • lawful processing.
  • retention.
  • security.
  • Data Subject requests.
  • cookie compliance.
  • marketing permissions.
  • cross-border transfers; and
  • appropriate contracts.

Providing infrastructure does not make Hostwover the Controller of all Personal Data stored through that infrastructure.

24. Data Processing Agreements

Where required by applicable law, Hostwover and a Customer may enter into an applicable Data Processing Agreement ("DPA").

A DPA may address matters including:

  • processing instructions.
  • confidentiality.
  • security.
  • subprocessors.
  • international transfers.
  • incident notification.
  • Data Subject requests.
  • audits.
  • deletion; and
  • return of Personal Data.

25. Priority of DPA

Where a valid DPA expressly conflicts with this general Policy regarding processing performed by Hostwover as Processor, the more specific DPA will govern that processing to the extent of the conflict.

26. Categories of Personal Data

Depending on how a person uses Hostwover, Hostwover may process categories including:

  • identity information.
  • contact information.
  • account information.
  • billing information.
  • transaction information.
  • domain information.
  • subscription information.
  • technical information.
  • device information.
  • IP addresses.
  • login information.
  • security information.
  • support information.
  • communication information.
  • usage information.
  • marketing preferences.
  • cookie information; and
  • compliance information.

27. Identity Information

Identity information may include:

  • name.
  • organization name.
  • authorized representative information.
  • account profile information; and
  • identity verification information where legitimately required.

28. Contact Information

Contact information may include:

  • email address.
  • telephone number.
  • postal information.
  • billing contact information.
  • technical contact information; and
  • domain-related contacts.

29. Account Information

Account information may include:

  • Customer ID.
  • account identifiers.
  • username.
  • language.
  • account status.
  • products.
  • subscriptions.
  • permissions.
  • login history; and
  • account preferences.

30. Authentication Information

Hostwover may process security information necessary to authenticate users.

This may include:

  • password hashes.
  • authentication tokens.
  • session identifiers.
  • recovery information.
  • multi-factor authentication information; and
  • security logs.

Hostwover should not intentionally store plain-text account passwords where secure one-way password storage is technically appropriate.

31. Billing Information

Billing information may include:

  • billing name.
  • billing address.
  • transaction identifiers.
  • invoice records.
  • currency.
  • tax information.
  • order history.
  • payment status; and
  • limited payment-method information.

32. Payment Card Information

Where payments are handled through an external payment processor, Hostwover may receive limited payment information rather than the complete payment-card details entered into the processor's payment environment.

Hostwover should not request Customers to transmit complete payment-card security information through ordinary support communications.

33. Domain Information

Domain Services may require processing information associated with:

  • registrant.
  • domain.
  • registration status.
  • contact information.
  • registration dates.
  • nameservers.
  • transfer information.
  • registrar information.
  • verification status; and
  • domain-management activity.

34. Domain Registration Data

Domain registration information may need to be shared with an upstream registrar, registry, escrow provider, or other domain-service participant according to applicable domain-industry requirements.

Hostwover should provide only data reasonably necessary for the relevant registration or domain-management purpose.

35. Technical Information

Technical information may include:

  • IP address.
  • browser.
  • operating system.
  • user agent.
  • device information.
  • request timestamps.
  • URLs.
  • server logs.
  • network information.
  • error information; and
  • security events.

36. Usage Information

Hostwover may process information concerning use of the Services for purposes such as:

  • Service operation.
  • security.
  • capacity management.
  • troubleshooting.
  • fraud prevention.
  • product improvement; and
  • Customer support.

37. Support Information

When a Customer contacts Hostwover, Hostwover may process:

  • support messages.
  • ticket history.
  • screenshots.
  • logs.
  • account information.
  • technical information.
  • call or chat information where applicable; and
  • troubleshooting records.

38. Customer Content

"Customer Content" may include content uploaded, stored, transmitted, processed, or made available by a Customer through a Hostwover Service.

Examples may include:

  • website data.
  • database records.
  • application data.
  • files.
  • emails.
  • server data.
  • API payloads; and
  • other hosted information.

Customer Content may contain Personal Data.

39. Customer Responsibility for Customer Content

The Customer is responsible for ensuring it has an appropriate legal basis to process Personal Data contained within Customer Content.

Hostwover does not independently determine whether every item of Customer Content was lawfully collected by the Customer.

40. Access to Customer Content

Hostwover personnel should not access Customer Content without a legitimate reason.

Legitimate reasons may include:

  • Customer-requested support.
  • security.
  • abuse investigation.
  • infrastructure maintenance.
  • fraud investigation.
  • legal compliance.
  • Service restoration; or
  • another legitimate operational requirement.

41. Web Hosting Data

Web Hosting may process Personal Data contained in:

  • websites.
  • forms.
  • databases.
  • CMS systems.
  • ecommerce stores.
  • server logs; and
  • email-related functions.

The Customer is responsible for privacy compliance concerning information collected by the Customer's website or application.

42. VPS and VDS Data

VPS and VDS Customers generally control the software and data placed on their server environments.

Hostwover does not ordinarily determine the purposes for which a Customer uses Personal Data inside a self-managed server.

Customers remain responsible for their own applications and databases.

43. Professional Email Data

Professional Email may process:

  • mailbox-account information.
  • messages.
  • attachments.
  • address books.
  • administrative information.
  • email metadata; and
  • authentication information.

The underlying email provider may also process Personal Data according to applicable provider terms.

44. Google Workspace Data

Google Workspace is operated by Google.

For subscriptions purchased through Hostwover, Hostwover may process limited information necessary for:

  • ordering.
  • provisioning.
  • license management.
  • billing.
  • Customer support.
  • reseller administration; and
  • domain verification.

Google's independent processing of Google Workspace content and account information is governed by applicable Google terms and privacy/data-processing documentation.

45. AI Services

Where Hostwover provides artificial intelligence functionality, Personal Data may be included in:

  • user prompts.
  • attached content.
  • conversation history.
  • generated responses.
  • logs.
  • account context; and
  • feedback.

Customers should avoid submitting unnecessary sensitive Personal Data to AI functionality.

46. AI Providers

AI functionality may depend on external infrastructure or model providers.

Where an external provider processes information on Hostwover's behalf or in connection with an integrated Service, Hostwover should evaluate applicable:

  • contractual protections.
  • security.
  • retention.
  • permitted use.
  • transfer requirements; and
  • confidentiality obligations.

47. No Assumption of AI Confidentiality Beyond Terms

Customers should not assume that every AI interaction has the same confidentiality or retention characteristics as a private database or dedicated server.

Applicable AI-specific terms and notices should be reviewed before submitting highly sensitive information.

48. Cookies

Hostwover may use cookies and similar technologies in accordance with the Hostwover Cookie Policy.

Where required, optional technologies should be subject to appropriate consent or preference controls.

49. Sources of Personal Data

Hostwover may obtain Personal Data:

  • directly from the Data Subject.
  • from a Customer administrator.
  • from another authorized user.
  • through Hostwover systems.
  • from payment processors.
  • from domain providers.
  • from service providers.
  • from security providers.
  • from public sources.
  • through integrations; or
  • through lawful third-party sources.

50. Information Provided by Customers About Others

A Customer may provide Personal Data relating to another person, such as:

  • employee.
  • administrator.
  • domain registrant.
  • technical contact.
  • billing contact; or
  • End User.

The Customer is responsible for ensuring it is authorized to provide that Personal Data where required.

51. Processing Purposes

Hostwover may process Personal Data for legitimate purposes including:

  • creating accounts.
  • providing Services.
  • fulfilling orders.
  • processing payments.
  • provisioning products.
  • registering domains.
  • authenticating users.
  • securing accounts.
  • providing Customer support.
  • communicating about Services.
  • renewing Services.
  • preventing fraud.
  • detecting abuse.
  • responding to legal requirements.
  • maintaining records.
  • improving Services.
  • measuring performance; and
  • marketing where lawfully permitted.

52. Lawful Bases

Where applicable law requires Hostwover to identify a lawful basis, processing may rely on one or more applicable bases such as:

  • consent.
  • contractual necessity.
  • compliance with legal obligations.
  • legitimate interests.
  • protection of vital interests.
  • public-interest grounds where applicable; or
  • another basis permitted by law.

The relevant basis depends on the specific processing activity.

53. Contractual Necessity

Hostwover may process information necessary to:

  • create a Customer account.
  • deliver an ordered Service.
  • register a domain.
  • provision infrastructure.
  • issue an invoice.
  • manage a subscription.
  • provide support; or
  • perform another contractual obligation.

54. Legal Obligations

Hostwover may process or retain information where necessary to comply with legal obligations concerning:

  • accounting.
  • taxation.
  • domain registration.
  • law enforcement.
  • court orders.
  • fraud.
  • financial compliance.
  • data protection.
  • security; or
  • other applicable requirements.

55. Legitimate Interests

Where permitted, Hostwover may rely on legitimate interests for activities such as:

  • protecting Services.
  • preventing abuse.
  • preventing fraud.
  • securing accounts.
  • improving products.
  • maintaining business records.
  • defending legal claims; and
  • operating Hostwover efficiently.

Where required, Hostwover will consider the impact of such processing on the rights and interests of Data Subjects.

56. Consent

Where Hostwover relies on consent, Hostwover seeks to ensure that the consent is:

  • appropriately informed.
  • sufficiently specific.
  • freely given where legally required.
  • demonstrable; and
  • capable of withdrawal where required.

57. Withdrawal of Consent

Where processing relies solely on consent, the Data Subject may withdraw consent through the available mechanism.

Withdrawal does not retroactively make prior lawful processing unlawful.

Hostwover may continue processing where another valid legal basis applies.

58. Marketing

Hostwover may send marketing communications where legally permitted.

Where consent or another specific authorization is required, Hostwover will seek to comply with that requirement.

59. Marketing Opt-Out

Recipients should be given a reasonable method of opting out of optional marketing communications.

Opting out of marketing does not prevent Hostwover from sending necessary:

  • invoices.
  • security notices.
  • renewal notices.
  • domain notices.
  • order confirmations.
  • support responses; or
  • other transactional communications.

60. Direct Electronic Marketing

Hostwover will seek to maintain marketing practices consistent with applicable consent and electronic-communications requirements.

Marketing preferences should be respected across applicable systems within a reasonable operational period.

61. Sensitive Personal Data

Certain laws provide enhanced protection for sensitive categories of Personal Data.

Hostwover should process Sensitive Personal Data only where:

  • genuinely necessary.
  • permitted by applicable law.
  • appropriate safeguards are implemented; and
  • any additional legal conditions are satisfied.

62. Customer Sensitive Data

Customers should not upload Sensitive Personal Data to a Hostwover Service unless:

  • the Service is appropriate for that data.
  • the Customer is legally permitted to process it.
  • appropriate security is implemented; and
  • any required contractual arrangements are in place.

63. Passwords and Authentication Secrets

Hostwover treats passwords, API secrets, private keys, authentication tokens, recovery codes, and similar credentials as security-sensitive information.

Customers should not transmit such information through ordinary support channels unless specifically required through an appropriate secure process.

64. Children's Personal Data

Hostwover's primary Services are directed toward businesses, professionals, developers, organizations, and persons legally capable of entering into applicable agreements.

Hostwover does not intentionally design its core infrastructure Services for young children.

65. Children and Customer Content

A Customer may operate a website or application used by children.

The Customer is responsible for determining and complying with applicable requirements governing children's Personal Data.

Providing infrastructure does not transfer that responsibility to Hostwover.

66. Data Sharing

Hostwover does not treat Personal Data as information that may be freely disclosed.

Hostwover may share Personal Data only where there is an appropriate business, contractual, security, legal, or operational purpose.

67. Service Providers

Hostwover may use external providers for functions such as:

  • infrastructure.
  • hosting.
  • domain registration.
  • email.
  • payment processing.
  • security.
  • fraud prevention.
  • analytics.
  • support.
  • communications.
  • AI processing.
  • productivity services.
  • backup.
  • monitoring; and
  • software operations.

68. Subprocessors

Where Hostwover acts as Processor, certain external providers may act as subprocessors.

Where required, Hostwover may maintain or provide information concerning subprocessors through:

  • a DPA.
  • subprocessor list.
  • provider documentation; or
  • another appropriate mechanism.

69. Provider Selection

When reasonably appropriate, Hostwover may consider factors including:

  • provider security.
  • privacy practices.
  • reliability.
  • contractual safeguards.
  • geographic processing.
  • confidentiality.
  • incident management; and
  • legal requirements

when selecting providers that process Personal Data.

70. Provider Access

Service providers should be permitted access only to information reasonably necessary for the services they perform.

Provider relationships may be subject to:

  • confidentiality.
  • data-processing provisions.
  • security requirements; and
  • other contractual safeguards.

71. Domain Registrars and Registries

Domain-registration information may need to be shared with:

  • registrar.
  • registry.
  • registry service providers.
  • domain escrow providers.
  • dispute-resolution providers; or
  • other domain-industry participants

where applicable to domain registration or management.

72. Payment Providers

Hostwover may share transaction-related information with payment providers for purposes including:

  • payment authorization.
  • settlement.
  • fraud prevention.
  • refunds.
  • chargebacks; and
  • financial compliance.

73. Fraud and Security Providers

Hostwover may share relevant information with security or fraud-prevention providers where reasonably necessary to identify:

  • compromised accounts.
  • stolen payment methods.
  • malicious activity.
  • attacks.
  • fraudulent transactions.
  • abuse; or
  • other security threats.

74. Professional Advisers

Hostwover may disclose relevant Personal Data to professional advisers such as:

  • lawyers.
  • accountants.
  • auditors.
  • insurers; or
  • consultants

where reasonably necessary and subject to appropriate confidentiality obligations.

75. Legal Disclosures

Hostwover may disclose Personal Data where reasonably necessary to:

  • comply with applicable law.
  • respond to valid legal process.
  • comply with a court order.
  • protect legal rights.
  • investigate fraud.
  • address security threats; or
  • protect persons from serious harm.

76. Government Requests

Hostwover may assess government or law-enforcement requests before disclosure where legally permitted.

Hostwover may consider:

  • requesting authority.
  • legal basis.
  • scope.
  • authenticity.
  • jurisdiction.
  • necessity; and
  • applicable confidentiality restrictions.

77. No Informal Disclosure

Hostwover should not disclose non-public Customer information merely because a person claims to be:

  • law enforcement.
  • a lawyer.
  • a trademark holder.
  • a Customer's employer.
  • a family member.
  • a business partner; or
  • another interested party.

Appropriate verification or legal authority may be required.

78. Business Transfers

If Hostwover undergoes a:

  • merger.
  • acquisition.
  • restructuring.
  • financing transaction.
  • sale of business.
  • asset transfer; or
  • similar corporate event,

Personal Data may be transferred where reasonably necessary as part of that transaction and subject to appropriate confidentiality and legal requirements.

79. International Processing

Hostwover Services may involve providers, infrastructure, or systems located in multiple countries.

Personal Data may therefore be processed outside the country where the Data Subject is located.

80. International Transfer Safeguards

Where applicable law restricts international transfers, Hostwover will seek to use an appropriate transfer mechanism.

Potential mechanisms may include:

  • adequacy decisions.
  • Standard Contractual Clauses.
  • contractual safeguards.
  • regulatory permits.
  • approved transfer mechanisms.
  • legally permitted exceptions; or
  • another mechanism recognized by applicable law.

Under the GDPR, transfers outside the applicable protected area must comply with Chapter V requirements, including adequacy mechanisms or appropriate safeguards where applicable.

81. Egyptian Cross-Border Requirements

Where Egyptian data-protection rules apply to a cross-border transfer, Hostwover will seek to satisfy applicable:

  • licensing.
  • permit.
  • approval.
  • equivalent-protection.
  • contractual.
  • technical; and
  • regulatory requirements.

Hostwover will not claim that a particular transfer authorization has been obtained unless it has actually been obtained.

82. Data Localization

Where applicable law requires particular Personal Data to be stored, processed, or retained within a specified jurisdiction, Hostwover may:

  • implement appropriate technical arrangements.
  • restrict Service availability.
  • select appropriate providers.
  • require Customer configuration; or
  • otherwise take reasonable steps to comply.

83. Customer-Selected Regions

Where a Service permits Customers to select a server or processing region, that selection may affect where Customer Content is primarily stored.

It may not prevent limited processing in other locations for purposes such as:

  • billing.
  • support.
  • security.
  • backups.
  • abuse prevention.
  • provider administration; or
  • legal compliance.

84. Data Retention

Hostwover will seek to retain Personal Data for no longer than reasonably necessary for the relevant purpose, subject to applicable legal, contractual, security, and business requirements.

85. Retention Factors

Retention periods may be based on:

  • duration of the Customer relationship.
  • type of Service.
  • legal limitation periods.
  • tax requirements.
  • accounting requirements.
  • fraud-prevention needs.
  • security.
  • dispute history.
  • provider obligations.
  • domain requirements; and
  • applicable law.

86. Account Data Retention

Some account records may be retained after account closure where necessary for:

  • financial records.
  • fraud prevention.
  • security.
  • legal claims.
  • transaction history.
  • compliance; or
  • regulatory obligations.

Account closure therefore does not necessarily result in immediate deletion of every record.

87. Billing Records

Invoices and transaction records may be retained for periods required by:

  • tax law.
  • accounting law.
  • financial compliance.
  • dispute resolution; and
  • fraud prevention.

88. Support Records

Support communications may be retained where reasonably necessary for:

  • service history.
  • troubleshooting.
  • quality assurance.
  • security.
  • disputes.
  • training.
  • compliance; and
  • Customer support.

89. Security Logs

Security logs may be retained for periods appropriate to:

  • detecting attacks.
  • investigating compromises.
  • preventing fraud.
  • identifying repeated abuse.
  • resolving incidents; and
  • meeting legal obligations.

90. Domain Records

Certain domain-related records may need to be retained according to applicable:

  • registrar requirements.
  • registry requirements.
  • contractual requirements.
  • dispute procedures.
  • fraud-prevention requirements; and
  • law.

91. Customer Content Retention

Customer Content retention depends on the applicable Service.

Customer Content may be deleted after:

  • cancellation.
  • expiration.
  • suspension.
  • account closure.
  • backup expiration.
  • server deletion; or
  • another applicable termination event.

Customers should maintain independent backups where appropriate.

92. Backup Data

Deletion from an active production system may not immediately remove Personal Data from every backup copy.

Backup copies may remain until:

  • backup rotation.
  • expiration.
  • overwrite.
  • secure deletion; or
  • another applicable retention event.

Hostwover should not restore deleted Personal Data from backups except where operationally necessary and legally appropriate.

93. Anonymization

Where appropriate, Hostwover may anonymize information so that it no longer identifies an individual.

Properly anonymized information may be used for purposes such as:

  • statistics.
  • capacity planning.
  • product development.
  • security analysis; and
  • business analysis.

94. Pseudonymization

Hostwover may use pseudonymization or similar techniques to reduce privacy risks where technically appropriate.

Pseudonymized information may still constitute Personal Data where an individual can be reidentified using additional information.

95. Data Deletion

When Personal Data is no longer required and no legal basis requires continued retention, Hostwover may:

  • delete.
  • erase.
  • anonymize.
  • aggregate.
  • overwrite; or
  • otherwise render the data unavailable

according to applicable technical processes.

96. Security Program

Hostwover seeks to maintain reasonable administrative, technical, and organizational security measures appropriate to its Services.

97. Security Measures

Depending on the Service and risk, safeguards may include:

  • encryption.
  • secure communications.
  • authentication.
  • authorization controls.
  • password hashing.
  • multi-factor authentication.
  • network controls.
  • firewalls.
  • monitoring.
  • logging.
  • backups.
  • access restrictions.
  • patch management.
  • malware protection.
  • vulnerability management.
  • security testing; and
  • incident-response procedures.

98. Security Is Risk-Based

Security measures may differ depending on:

  • data sensitivity.
  • product.
  • infrastructure.
  • Customer configuration.
  • threat model.
  • provider.
  • technical feasibility; and
  • risk.

No single security control is appropriate for every system.

99. No Absolute Security Guarantee

No internet-based service or storage system can guarantee complete protection against every possible security incident.

Hostwover therefore does not represent that unauthorized access or data loss can never occur.

100. Access Controls

Access to Personal Data should be restricted based on:

  • legitimate operational need.
  • role.
  • authorization.
  • security level; and
  • relevant responsibilities.

101. Least Privilege

Where reasonably practicable, Hostwover should apply least-privilege principles so personnel and systems receive only the access necessary for their functions.

102. Personnel Confidentiality

Personnel with access to Personal Data should be subject to appropriate:

  • confidentiality expectations.
  • access restrictions.
  • security procedures; and
  • privacy responsibilities.

103. Privileged Access

Administrative access to:

  • servers.
  • databases.
  • payment systems.
  • Customer systems.
  • domain systems; and
  • internal platforms

should be limited to authorized personnel.

104. Logging of Sensitive Actions

Hostwover may log sensitive administrative actions for:

  • security.
  • fraud prevention.
  • accountability.
  • troubleshooting; and
  • incident investigation.

105. Customer Security Responsibilities

Customers are responsible for securing their own:

  • passwords.
  • administrator accounts.
  • API keys.
  • servers.
  • websites.
  • applications.
  • databases.
  • devices.
  • access permissions; and
  • Customer Content.

106. Shared Responsibility

Data protection in hosting and cloud environments often requires both Hostwover and the Customer to perform appropriate security responsibilities.

Hostwover's responsibilities concerning infrastructure do not eliminate the Customer's responsibilities concerning:

  • application security.
  • user permissions.
  • software updates.
  • data collection.
  • Customer passwords; and
  • application configuration.

107. Security Reviews

Hostwover may perform or commission reasonable:

  • vulnerability assessments.
  • configuration reviews.
  • penetration tests.
  • risk assessments.
  • code reviews.
  • infrastructure audits; or
  • similar security evaluations.

108. Data Protection Impact Assessments

Where required or appropriate, Hostwover may perform a Data Protection Impact Assessment ("DPIA") or equivalent privacy-risk assessment before conducting processing likely to create significant privacy risks.

Under the GDPR, a DPIA is required for certain processing likely to result in high risk to individuals' rights and freedoms.

109. Vendor Assessments

Hostwover may conduct reasonable due diligence concerning third-party providers that process significant Personal Data.

Assessment may consider:

  • security.
  • processing purpose.
  • data location.
  • contractual protections.
  • subprocessors.
  • incident handling.
  • access controls; and
  • provider reputation.

110. Personal Data Breach

A "Personal Data Breach" generally means a security incident resulting in accidental or unlawful:

  • destruction.
  • loss.
  • alteration.
  • unauthorized disclosure; or
  • unauthorized access

to Personal Data.

111. Breach Response

When Hostwover becomes aware of a suspected Personal Data Breach, Hostwover may:

  1. contain the incident.
  2. investigate what occurred.
  3. identify affected systems.
  4. determine affected data.
  5. assess potential risk.
  6. preserve appropriate evidence.
  7. take remediation measures.
  8. document the incident.
  9. notify relevant Customers.
  10. notify authorities where required; and
  11. notify affected Data Subjects where required.

112. Regulatory Notification

Hostwover will seek to notify the applicable data-protection authority within any legally required timeframe when the relevant notification threshold is met.

For example, where GDPR Article 33 applies, a Controller must generally notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after awareness of a qualifying breach unless the breach is unlikely to create a risk to individuals' rights and freedoms.

113. Egyptian Breach Requirements

Where Egyptian data-protection requirements apply, Hostwover will follow applicable Personal Data Breach notification procedures and deadlines established by the Egyptian data-protection framework.

Current Egyptian requirements include specified regulatory and Data Subject notification obligations for qualifying Personal Data infringements.

114. Customer Notification When Hostwover Is Processor

Where Hostwover acts as Processor and becomes aware of a Personal Data Breach affecting Customer-controlled Personal Data, Hostwover will seek to notify the relevant Controller in accordance with:

  • applicable law.
  • applicable DPA; and
  • the circumstances of the incident.

Under GDPR Article 33, a Processor must notify its Controller without undue delay after becoming aware of a Personal Data Breach.

115. Data Subject Breach Notice

Where applicable law requires Hostwover to notify affected Data Subjects, Hostwover will seek to provide information reasonably required by applicable law.

Such information may include:

  • nature of the incident.
  • categories of information affected.
  • potential consequences.
  • measures taken.
  • recommended precautions; and
  • contact information.

116. Incident Confidentiality

During a security investigation, Hostwover may temporarily restrict disclosure of detailed technical information where disclosure could:

  • compromise containment.
  • expose security controls.
  • affect another Customer.
  • prejudice an investigation.
  • facilitate additional attacks; or
  • violate legal restrictions.

117. Data Subject Rights

Depending on applicable law, individuals may have rights concerning their Personal Data.

These may include rights to:

  • information.
  • access.
  • correction.
  • deletion.
  • restriction.
  • objection.
  • portability.
  • withdrawal of consent.
  • challenge certain automated decisions; and
  • complain to a supervisory authority.

Under GDPR, these rights include access, rectification, erasure in qualifying circumstances, restriction, portability, objection, and protections concerning certain automated decision-making.

118. Right to Information

Where applicable, Data Subjects may have the right to know information such as:

  • identity of the Controller.
  • processing purposes.
  • categories of Personal Data.
  • legal basis.
  • recipients.
  • retention.
  • international transfers; and
  • applicable rights.

119. Right of Access

Where applicable, a Data Subject may request confirmation of whether Hostwover processes Personal Data concerning that person and request access to relevant information.

GDPR Article 15 provides an access right that includes information concerning processing purposes, categories, recipients, and applicable retention.

120. Right to Correction

Where applicable, individuals may request correction of inaccurate Personal Data.

Customers may be able to update certain information directly through their Hostwover account.

121. Right to Deletion

Where applicable, individuals may request deletion of Personal Data.

Deletion rights are not absolute.

Hostwover may retain information where continued processing is necessary for reasons such as:

  • contractual obligations.
  • legal obligations.
  • fraud prevention.
  • dispute resolution.
  • security.
  • legal claims; or
  • another lawful ground.

122. Right to Restriction

Where applicable, a Data Subject may request restriction of certain processing.

Hostwover will evaluate such requests according to the relevant legal requirements.

123. Right to Object

Where applicable, individuals may object to certain processing.

An objection may not prevent processing where Hostwover has a valid overriding or mandatory legal basis to continue.

124. Direct Marketing Objections

Where applicable, Hostwover will respect a valid objection or opt-out concerning optional direct marketing.

125. Data Portability

Where applicable, a Data Subject may have the right to receive certain Personal Data in a structured, commonly used, machine-readable form.

The scope of portability depends on the applicable law and processing basis.

126. Automated Decision-Making

Hostwover may use automated systems for purposes such as:

  • fraud screening.
  • abuse detection.
  • security.
  • spam prevention.
  • ticket routing.
  • risk assessment; and
  • Service automation.

Hostwover will seek to provide applicable safeguards where automated decisions create legal or similarly significant effects and applicable law requires additional protections.

127. Human Review

Where required by applicable law, qualifying automated decisions may be subject to:

  • human review.
  • Customer explanation.
  • challenge.
  • correction of inaccurate information; or
  • another legally required safeguard.

128. Profiling

Hostwover may use limited profiling or risk indicators where appropriate for:

  • fraud prevention.
  • security.
  • abuse prevention.
  • Service personalization; or
  • marketing where legally permitted.

Hostwover will seek to apply applicable legal requirements to such processing.

129. Exercising Privacy Rights

Privacy requests may currently be submitted to:

Hostwover Support

Email: [email protected]

Website: hostwover.com

The request should clearly identify the privacy right the individual wishes to exercise.

130. Identity Verification for Privacy Requests

Hostwover may require reasonable verification before disclosing, correcting, exporting, or deleting Personal Data.

Verification protects against:

  • identity theft.
  • account takeover.
  • unauthorized disclosure; and
  • fraudulent deletion requests.

131. Proportional Verification

Verification requirements should be proportionate to:

  • sensitivity of the information.
  • nature of the request.
  • available account information.
  • risk of unauthorized disclosure; and
  • applicable law.

Hostwover should not intentionally request significantly more Personal Data than reasonably necessary to verify the requester.

132. Authorized Agents

Where permitted, a Data Subject may authorize another person to submit a request on their behalf.

Hostwover may require evidence of:

  • identity.
  • authority; and
  • authenticity of the authorization.

133. Privacy Request Response Times

Hostwover will seek to respond within the period required by applicable law.

Where GDPR applies, action on qualifying Data Subject requests generally must be communicated without undue delay and ordinarily within one month, subject to permitted extensions for complexity or volume.

134. Complex Requests

Where legally permitted, Hostwover may extend a response deadline if a request is:

  • complex.
  • unusually broad; or
  • one of a significant number of requests,

provided any required notice concerning the extension is given.

135. Manifestly Unfounded or Excessive Requests

Where applicable law permits, Hostwover may:

  • charge an appropriate fee; or
  • decline to act

on requests that are manifestly unfounded or excessive.

Hostwover will not treat an ordinary privacy request as abusive merely because exercising the right is inconvenient.

136. Rights of Others

A Data Subject request must not improperly expose Personal Data belonging to another individual.

Hostwover may redact or withhold information where necessary to protect:

  • another person's privacy.
  • trade secrets.
  • security.
  • intellectual property; or
  • other legally protected interests.

137. Processor Data Subject Requests

Where Hostwover holds Personal Data solely as Processor for a Customer, Hostwover may direct the requesting individual to the Customer acting as Controller.

Where required, Hostwover may reasonably assist the Customer in responding to the request.

138. Complaints

Individuals who believe Hostwover has handled their Personal Data improperly may contact Hostwover.

Hostwover will seek to investigate legitimate privacy complaints.

139. Supervisory Authority Complaints

Where applicable law provides such a right, a Data Subject may lodge a complaint with an appropriate data-protection or supervisory authority.

Under GDPR, individuals have a right to lodge complaints with a competent data-protection authority.

140. Data Protection Contact

Until Hostwover publishes a separate privacy contact, privacy and data-protection requests may be directed to:

Hostwover Support

Email: [email protected]

Hostwover may establish a dedicated address such as a privacy or data-protection contact channel in the future.

141. Data Protection Officer

Where Hostwover is legally required to appoint, register, or maintain a Data Protection Officer ("DPO"), Hostwover will seek to satisfy the applicable requirement.

Hostwover will publish appropriate DPO contact information where legally required.

This Policy does not represent that a particular person is currently a legally registered DPO unless Hostwover separately confirms that appointment.

142. DPO Independence

Where an applicable DPO function exists, the DPO should be enabled to perform the responsibilities required by applicable law without improper interference or conflicts of interest.

143. Processing Records

Where required or appropriate, Hostwover may maintain records describing processing activities, including:

  • processing purpose.
  • data categories.
  • Data Subjects.
  • recipients.
  • retention.
  • international transfers.
  • security measures.
  • processors; and
  • other legally required information.

144. Consent Records

Where consent is relied upon, Hostwover may maintain records concerning:

  • consent status.
  • consent date.
  • consent method.
  • applicable purpose.
  • withdrawal; and
  • policy version.

145. Privacy Training

Personnel handling Personal Data may receive appropriate guidance or training relating to:

  • confidentiality.
  • security.
  • phishing.
  • privacy.
  • account verification.
  • Data Subject requests; and
  • incident reporting.

146. Internal Reporting

Personnel should report suspected:

  • Personal Data Breaches.
  • unauthorized disclosures.
  • lost credentials.
  • security incidents.
  • privacy complaints; or
  • unauthorized access

through the appropriate Hostwover internal process.

147. Privacy Risk Assessments

Hostwover may conduct privacy-risk assessments for significant changes involving:

  • new providers.
  • new technologies.
  • Sensitive Personal Data.
  • large-scale processing.
  • AI systems.
  • new tracking technologies.
  • major integrations; or
  • international transfers.

148. Change Management

Privacy and security considerations should be incorporated into material changes affecting Personal Data where reasonably appropriate.

149. New Vendors

Before onboarding significant providers with access to Personal Data, Hostwover may evaluate relevant:

  • contractual.
  • technical.
  • security.
  • privacy.
  • transfer; and
  • operational considerations.

150. Provider Changes

Hostwover may change providers where necessary for:

  • performance.
  • pricing.
  • availability.
  • security.
  • legal compliance.
  • feature improvements; or
  • business requirements.

Material privacy implications should be addressed as appropriate.

151. Sale of Personal Data

Hostwover does not treat Personal Data as unrestricted merchandise.

Hostwover will not intentionally sell Personal Data where such sale would violate applicable law or Hostwover's stated privacy commitments.

Where an applicable law provides a specific statutory definition of "sale," Hostwover will address applicable rights according to that law.

152. Advertising Data

Where Hostwover uses optional advertising or behavioral technologies, relevant processing must comply with:

  • Cookie Policy.
  • consent requirements.
  • opt-out rights.
  • applicable privacy law; and
  • applicable provider terms.

153. Public Information

Information being publicly available does not automatically mean Hostwover may use it for any purpose.

Hostwover should still consider:

  • purpose.
  • applicable law.
  • privacy expectations.
  • source restrictions; and
  • proportionality.

154. Third-Party Links

Hostwover Services may contain links to external websites.

Hostwover is not responsible for independent Personal Data processing performed solely by unrelated third-party websites after a user leaves Hostwover's Services.

155. Third-Party Accounts

Where Customers connect Hostwover Services to a third-party platform, the third party may independently process Personal Data.

Customers should review the provider's applicable privacy terms.

156. Account Closure

Closing a Hostwover account may trigger deletion or deactivation processes.

Certain information may remain where necessary for:

  • invoices.
  • taxation.
  • fraud prevention.
  • security.
  • domain records.
  • provider records.
  • legal claims; or
  • other lawful retention purposes.

157. Service Cancellation

Cancelling one Service does not necessarily delete all Personal Data associated with the Customer's Hostwover account.

A Customer may have:

  • other active Services.
  • unpaid invoices.
  • support records.
  • legal obligations.
  • domain records; or
  • other continuing account information.

158. Domain Transfer

Transferring a domain away from Hostwover does not necessarily result in immediate deletion of historical transaction or registration records.

Hostwover may retain appropriate records where legally or operationally necessary.

159. Server Deletion

When a VPS or VDS is deleted, Customer data stored on the active server may be scheduled for deletion according to the applicable technical process.

Customers must export required data before deletion.

160. Backup Expiry

Server deletion does not necessarily mean that every backup copy is immediately overwritten.

Backup copies may remain until normal retention or rotation processes complete.

161. Data Return

Where Hostwover acts as Processor and applicable law or a DPA requires return of Personal Data following termination, Hostwover will seek to provide an appropriate mechanism where technically feasible and contractually required.

162. Data Destruction

Where appropriate, deletion procedures may involve:

  • logical deletion.
  • cryptographic erasure.
  • overwrite.
  • backup expiration.
  • media destruction; or
  • provider-managed deletion.

The method depends on the relevant infrastructure.

163. Legal Holds

Hostwover may suspend normal deletion where Personal Data must be preserved because of:

  • litigation.
  • investigation.
  • legal process.
  • fraud.
  • security incident.
  • regulatory requirement; or
  • another legally justified hold.

164. Abuse Investigations

Hostwover may process relevant Personal Data when investigating suspected violations involving:

  • phishing.
  • malware.
  • fraud.
  • spam.
  • network attacks.
  • account compromise.
  • illegal activity; or
  • other abuse.

Such processing will be subject to applicable law and Hostwover's Abuse Handling Policy.

165. Domain Disputes

Hostwover may process and preserve Personal Data relevant to:

  • ownership disputes.
  • transfer disputes.
  • UDRP.
  • URS.
  • court proceedings.
  • registry matters; and
  • registrar disputes.

Disclosure of non-public domain information remains subject to applicable legal and contractual requirements.

166. Fraud Prevention

Hostwover may process information necessary to identify and prevent:

  • stolen payment methods.
  • account takeover.
  • false identities.
  • fraudulent registrations.
  • promotional abuse.
  • chargeback abuse; and
  • related misconduct.

167. Security Monitoring

Hostwover may monitor systems for indicators of:

  • unauthorized access.
  • malware.
  • brute force.
  • unusual login patterns.
  • network attacks.
  • abuse.
  • fraud; and
  • other threats.

Security monitoring should be proportionate to the legitimate protection purpose.

168. Communications Monitoring

Hostwover does not intend to routinely read private Customer communications merely because it provides underlying infrastructure.

Limited review may occur where necessary for:

  • Customer-requested support.
  • abuse investigation.
  • security.
  • legal obligations; or
  • another legitimate and permitted reason.

169. Employee and Contractor Access

Personnel and contractors should access Personal Data only where required for authorized Hostwover work.

Access rights should be removed or updated when the person no longer requires access.

170. Termination of Personnel Access

When a person leaves a role or no longer requires system access, Hostwover should reasonably:

  • revoke accounts.
  • remove permissions.
  • invalidate credentials; and
  • recover Hostwover-controlled access mechanisms

appropriate to that role.

171. Data Exports

When fulfilling a legitimate Personal Data export request, Hostwover should seek to transmit the export through an appropriately secure method.

172. Privacy Request Security

Hostwover should avoid emailing highly sensitive Personal Data in an insecure form where a more appropriate delivery mechanism is reasonably available.

173. Data Quality

Where Personal Data is material to a Service, Hostwover may ask the Customer to verify or update it.

This may be necessary for:

  • billing.
  • domain registration.
  • account recovery.
  • compliance.
  • fraud prevention; or
  • Service delivery.

174. Customer Updates

Customers should promptly update inaccurate Personal Data through available account controls or Hostwover Support.

175. Notifications

Hostwover may communicate important privacy or security matters through:

  • email.
  • account dashboard.
  • support tickets.
  • website notices.
  • Service notifications; or
  • another appropriate channel.

176. Data Protection Documentation

Hostwover may maintain internal or external documents including:

  • Privacy Policy.
  • Cookie Policy.
  • Data Processing Agreements.
  • subprocessor information.
  • security policies.
  • incident procedures.
  • retention rules.
  • access-control procedures; and
  • privacy-request procedures.

177. Certification Claims

Hostwover will not represent that it holds a particular:

  • ISO certification.
  • government privacy license.
  • security certification.
  • regulatory approval.
  • compliance seal; or
  • other formal accreditation

unless that status has actually been obtained and remains applicable.

178. Compliance Claims

Statements that Hostwover "supports compliance" or uses privacy-oriented practices should not be interpreted as a guarantee that every Customer automatically complies with:

  • GDPR.
  • Egyptian law.
  • healthcare laws.
  • financial laws.
  • sector-specific rules; or
  • other regulatory requirements.

179. Customer Compliance

Customers remain responsible for assessing whether their configuration and use of Hostwover Services satisfy their own privacy obligations.

180. Special Regulatory Environments

Customers processing highly regulated Personal Data should determine independently whether the relevant Hostwover Service is appropriate.

This may include sectors involving:

  • healthcare.
  • banking.
  • financial services.
  • government.
  • children.
  • biometrics.
  • criminal records; or
  • other sensitive information.

181. No Legal Advice

This Policy describes Hostwover's data-protection framework.

It does not constitute legal advice to Customers or Data Subjects.

182. Legal Requests for Customer Data

Hostwover may establish a separate process governing:

  • subpoenas.
  • court orders.
  • law-enforcement requests.
  • emergency disclosure requests; and
  • other government requests.

Until such a separate policy is published, applicable law and Hostwover's privacy procedures will govern.

183. Emergency Disclosure

Where legally permitted, Hostwover may disclose limited information when reasonably necessary to address an imminent risk of:

  • death.
  • serious physical injury; or
  • comparable emergency harm.

Such disclosures should be limited to what is reasonably necessary.

184. Transparency

Hostwover seeks to provide clear information about material Personal Data processing.

Transparency may be provided through:

  • Privacy Policy.
  • Cookie Policy.
  • checkout disclosures.
  • product terms.
  • account notices.
  • consent interfaces.
  • Data Processing Agreements; and
  • other appropriate notices.

185. Changes in Processing

If Hostwover materially changes how Personal Data is processed, Hostwover may:

  • update the Privacy Policy.
  • update this Policy.
  • update the Cookie Policy.
  • provide additional notice.
  • obtain new consent where necessary; or
  • amend contractual documentation.

186. Changes to This Policy

Hostwover may update this Policy to reflect:

  • legal changes.
  • regulatory guidance.
  • new Services.
  • security developments.
  • new providers.
  • infrastructure changes.
  • operational improvements; and
  • changes in Hostwover's privacy practices.

187. Material Changes

Where required by applicable law, Hostwover will provide appropriate notice of material changes.

188. Effective Version

The Last Updated date identifies the current published version of this Policy.

189. External Legal Changes

Applicable privacy laws may change independently of this Policy.

Mandatory applicable law will control where this Policy has not yet been updated to reflect a new legal requirement.

190. Relationship With Terms of Service

This Policy forms part of Hostwover's broader privacy, security, and operational framework.

Where incorporated into the Hostwover Terms of Service or a product agreement, applicable Customers agree to comply with relevant responsibilities described in this Policy.

191. Relationship With Cookie Policy

The Cookie Policy provides additional information concerning:

  • cookies.
  • browser storage.
  • analytics.
  • optional tracking.
  • consent.
  • cookie preferences; and
  • similar technologies.

192. Relationship With Abuse Handling Policy

Personal Data processed in connection with abuse investigations remains subject to this Policy, applicable law, and the Abuse Handling Policy.

193. Relationship With Customer Service Policy

Personal Data supplied through support requests is handled according to this Policy, the Privacy Policy, and applicable Customer Service procedures.

194. Relationship With Product Agreements

Specific product agreements may contain additional privacy or data-processing provisions.

Where a product-specific provision is more specific, it will govern that Service to the extent of an actual conflict.

195. Relationship With Third-Party Provider Terms

Certain Hostwover Services depend on independent providers.

Those providers may maintain separate:

  • privacy policies.
  • Data Processing Agreements.
  • security terms.
  • retention practices; and
  • international-transfer mechanisms.

Those terms govern processing performed independently by the relevant provider.

196. Severability

If any provision of this Policy is invalid or unenforceable, the remaining provisions will continue to apply to the maximum extent permitted by applicable law.

197. No Waiver

Hostwover's failure to enforce or apply a provision in one circumstance does not waive its ability to apply that provision later.

198. Language

Hostwover may provide translations of this Policy.

Where permitted by applicable law and unless expressly stated otherwise, the English version will control in the event of a material inconsistency between translations.

199. Definitions

For purposes of this Policy:

  • "Controller" means a person or entity that determines the purposes and means of processing Personal Data, as defined by applicable law.
  • "Customer" means a person or entity purchasing, administering, accessing, or using Hostwover Services.
  • "Customer Content" means data, files, communications, applications, databases, or other information submitted, stored, transmitted, or processed by a Customer through a Service.
  • "Data Processing Agreement" or "DPA" means an agreement regulating processing of Personal Data where one party processes data on behalf of another.
  • "Data Protection Officer" or "DPO" means a data-protection officer appointed or registered where applicable legal requirements call for such a role.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "GDPR" means Regulation (EU) 2016/679 where applicable.
  • "Personal Data" means information relating to an identified or identifiable natural person or equivalent information protected under applicable privacy law.
  • "Personal Data Breach" means a security incident involving unauthorized or unlawful destruction, loss, alteration, disclosure of, or access to Personal Data where defined by applicable law.
  • "Processor" means a person or entity processing Personal Data on behalf of a Controller, as defined by applicable law.
  • "Processing" includes operations performed on Personal Data such as collection, recording, organization, storage, use, disclosure, alteration, transmission, restriction, deletion, or destruction.
  • "Sensitive Personal Data" means Personal Data subject to enhanced protection under applicable law.
  • "Service" means a product or service provided, sold, resold, managed, or made available through Hostwover.
  • "Subprocessor" means a third party engaged by a Processor to perform Personal Data processing on behalf of a Controller.

200. Hostwover Data Protection Principles

Hostwover's data-protection framework is based on the following commitments:

  1. Personal Data should be processed lawfully and transparently.
  2. Data should be collected for legitimate identified purposes.
  3. Hostwover should collect no more Personal Data than reasonably necessary.
  4. Personal Data should be protected with appropriate security.
  5. Access should be limited according to legitimate operational need.
  6. Personal Data should not be retained indefinitely without justification.
  7. Applicable Data Subject rights should be respected.
  8. Privacy should be considered when new Services are designed.
  9. Vendors processing Personal Data should be subject to appropriate review and safeguards.
  10. International transfers should use appropriate legal mechanisms where required.
  11. Personal Data Breaches should be investigated and addressed promptly.
  12. Regulators and affected persons should be notified where legally required.
  13. Customers should remain responsible for Personal Data they control through their own applications.
  14. Hostwover should distinguish its Controller, Processor, and reseller roles according to the actual processing activity.
  15. Hostwover should not claim certifications, licenses, DPO registrations, or regulatory approvals that have not actually been obtained.
  16. Customer Content should not be accessed without legitimate reason.
  17. Sensitive Personal Data should receive appropriate additional protection.
  18. Privacy requests should be authenticated appropriately.
  19. Security monitoring should remain proportionate to legitimate security purposes.
  20. Hostwover should continually review and improve its privacy and data-protection framework.

201. Contact

Questions, concerns, or requests relating to privacy or Personal Data may currently be directed to:

Hostwover Support

Email: [email protected]

Website: hostwover.com

When submitting a privacy request, please clearly identify:

  • your name.
  • relevant Hostwover account, where applicable.
  • the privacy right or concern involved.
  • relevant Service.
  • enough information for Hostwover to locate the relevant records; and
  • any supporting information reasonably necessary to process the request.

Do not send:

  • passwords.
  • authentication codes.
  • private keys.
  • full payment-card numbers; or
  • unnecessary sensitive information

through ordinary support email.

Hostwover may establish a dedicated privacy contact or Data Protection Officer contact address as its data-protection program develops or where required by applicable law.

202. Effective Date

This Privacy & Data Protection Policy becomes effective on the date stated above and applies to Hostwover processing activities and Services that reference or incorporate this Policy.

END OF PRIVACY & DATA PROTECTION POLICY