Scroll to top
Legal

Privacy Policy

Draft — not yet in force. Takes effect once the identification below is completed and the document is reviewed. Last updated: 15 July 2026.

This policy explains what personal data ServerSpark collects, why, and what rights you have. We keep this deliberately short and specific: we collect as little as possible, because data we don't hold can't be lost.

1. Who is responsible (controller)

  • ServerSpark, a registered trade name of [LEGAL_NAME]
  • Address: [BUSINESS_ADDRESS]
  • KvK: [KVK_NUMBER]
  • Privacy contact: [SUPPORT_EMAIL]

We are not required to appoint a Data Protection Officer, and have not done so.

2. What we collect, why, and on what legal basis

DataWhyLegal basis (GDPR Art. 6)
NameTo identify you as a customer and issue invoicesContract (6(1)(b))
Email addressAccount, support, service noticesContract (6(1)(b))
Billing addressLegally required on invoices; VATLegal obligation (6(1)(c))
Payment referenceTo match your payment to your orderContract (6(1)(b))
IP address & server logsSecurity, abuse prevention, diagnosing faultsLegitimate interest (6(1)(f))
Support messagesTo answer you and keep a record of what was agreedContract (6(1)(b))

We do not collect your gender or date of birth. We do not need them. We never receive or store your card details — those go directly to our payment provider. We do not sell your data, and we do not send marketing email unless you ask us to.

3. Children

Our services are not directed at children under 16. If you believe we hold data about a child without parental consent, contact [SUPPORT_EMAIL] and we will delete it.

4. Who we share data with (processors)

We use a small number of providers. Each processes data only on our instructions, under a data processing agreement:

ProviderPurposeWhere
Hetzner Online GmbHServer infrastructureGermany / Finland (EU). Also USA & Singapore only if you choose that location.
Mollie B.V.Payment processingNetherlands (EU)
CloudflareDNS and website protectionEU / global network

Where a provider processes data outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses. If you pick an EU server location, your server data stays in the EU.

5. How long we keep it

  • Invoices and accounting records: 7 years — required by Dutch tax law.
  • Account and contact data: for as long as you are a customer, then deleted within 6 months.
  • Server logs / IP addresses: maximum 90 days, unless needed for an active abuse or security investigation.
  • Your server content: deleted 7 days after a service ends (see Terms clause 6).
  • Support tickets: 2 years.

6. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you;
  • Rectification — have inaccurate data corrected;
  • Erasure — have your data deleted, where we have no legal duty to keep it;
  • Restriction — ask us to pause processing while a dispute is resolved;
  • Data portability — receive your data in a machine-readable format;
  • Object — object to processing based on our legitimate interests;
  • Withdraw consent at any time, where processing is based on consent.

Email [SUPPORT_EMAIL]. We respond within one month. It is free, unless a request is manifestly unfounded or excessive.

7. Complaints

If you are unhappy with how we handle your data, tell us first — we would rather fix it. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

8. Automated decision-making

We do not make decisions with legal or similarly significant effects about you by automated means. Automated systems may provision or suspend a server based on payment status; a human reviews any suspension or deletion before it happens, and you can always reach a person.

9. Cookies

We use only functional cookies needed for the site and your account to work. We do not use advertising or tracking cookies, and we do not embed third-party advertising.

10. How we protect your data

Access is limited to what is necessary. Credentials are never stored in application code, no end-of-life software is exposed to the internet, systems are monitored for tampering, and card data never touches our systems. If a breach occurs that is likely to put your rights at risk, we will notify the Autoriteit Persoonsgegevens within 72 hours and tell you directly and honestly.

11. Changes

We will announce material changes to this policy at least 30 days in advance.