Last updated: August 2026

Privacy policy

How we process your personal data, for what purpose, for how long and what rights you have over it, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD).

Data controller

The controller of your data is Hostemy. You can contact us at any time at [email protected].

Data we process

We process only the data necessary to provide and invoice our services:

  • Identification and contact data: name and surname or company name, tax ID, address, email address and telephone number.
  • Billing data: orders, invoices, payment cycle and the last digits and identifier of the card returned to us by the payment gateway. We do not store full card numbers.
  • Technical usage data: IP addresses, panel access logs, sessions and activity of the contracted services.
  • Support data: the content of the tickets, quotes and communications you send us.
  • Browsing data: that collected through cookies, as detailed in the Cookie policy.

Purposes and legal bases

Each processing activity rests on a specific legal basis:

  • Providing and managing the contracted services, including billing and support: performance of the contract.
  • Complying with accounting, tax and traffic-data retention obligations: legal obligation.
  • Preventing fraud and abuse and ensuring the security of the infrastructure: legitimate interest.
  • Sending commercial communications about our services to customers: legitimate interest, with the right to object at any time.
  • Sending commercial communications to non-customers and using analytics cookies: consent, which may be withdrawn at any time.

Retention periods

We keep your data for the duration of the contractual relationship and, afterwards, blocked for the applicable limitation periods: six years for accounting and tax records, four years for employment and administrative matters, and the periods set by sector regulations for connection logs. Data processed on the basis of your consent is kept until you withdraw it.

Recipients and processors

We do not sell or transfer your data. Only the providers needed to deliver the service have access to it, and we have signed the corresponding data processing agreement with each of them:

  • Payment gateways that process payments and act as independent controllers of card data.
  • Infrastructure and data centre providers where the servers are hosted.
  • Transactional and commercial email delivery providers.
  • Web analytics providers, only if you have consented to analytics cookies.
  • Public authorities, courts and law enforcement where there is a legal obligation.
  • For domain registration, the registrar and the registry of the extension, as required by ICANN.

International transfers

Our main infrastructure is located in the European Union. Some providers may process data outside the European Economic Area; in that case the transfer relies on an adequacy decision of the European Commission or on standard contractual clauses, together with any additional measures that may be necessary.

Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing, portability and not to be subject to automated decisions by writing to [email protected], stating the right you are exercising and proving your identity. We will respond within one month. If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

Information security

We apply technical and organisational measures to protect data against unauthorised access, loss or alteration: encryption in transit, access control, two-step verification in the panel, activity logging and backups. No system is infallible, but in the event of a security breach posing a risk to your rights we will notify you and report it to the supervisory authority in accordance with the GDPR.

Third-party data hosted by the customer

Where a customer hosts third-party personal data on our services, the customer is the controller and Hostemy acts as processor, processing that data solely in accordance with their instructions and with article 28 of the GDPR.

Minors

Our services are not directed at children under fourteen. We do not knowingly collect data from children of that age; if we find that we have, we will delete it.

Changes to this policy

We may update this policy to reflect legal changes or changes in how we provide the service. We will always publish the current version on this page with its update date and, where the change is material, we will notify you by email.