Privacy Policy

Last updated: December 27, 2024 | Effective date: December 27, 2024

1. Introduction

PragmaticHost SRL ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our PRAHO Platform hosting services.

We comply with the General Data Protection Regulation (GDPR - EU 2016/679), Romanian Law 190/2018 implementing GDPR, and other applicable data protection legislation.

By using our services, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller Information

Company Name: PragmaticHost SRL

Registration Number (CUI):

Registered Address:

Email: contact@pragmatichost.com

Phone:

Data Protection Officer (DPO)

Email: dpo@pragmatichost.com

For any privacy-related inquiries or to exercise your data protection rights, please contact our Data Protection Officer.

3. Personal Data We Collect

3.1 Information You Provide

  • Account Information: Name, email address, phone number, password
  • Billing Information: Company name, VAT number (CUI/CIF), billing address, payment details
  • Service Configuration: Domain names, hosting preferences, technical settings
  • Support Communications: Ticket content, emails, chat messages

3.2 Information Collected Automatically

  • Technical Data: IP address, browser type, device information, operating system
  • Usage Data: Pages visited, features used, session duration, click patterns
  • Security Data: Login attempts, authentication events, security alerts
  • Cookie Data: Session identifiers, preferences (see our Cookie Policy)

3.3 Special Categories of Data

We do not intentionally collect special categories of personal data (such as health data, religious beliefs, or political opinions). If you provide such data in support tickets or other communications, we will treat it with additional care.

5. How We Use Your Personal Data

5.1 Service Delivery

  • Creating and managing your hosting account
  • Provisioning and configuring hosting services
  • Processing payments and generating invoices
  • Providing technical support

5.2 Communication

  • Sending service-related notifications (required)
  • Responding to support requests
  • Sending marketing emails (with your consent)

5.3 Security and Compliance

  • Detecting and preventing fraud
  • Protecting against security threats
  • Complying with legal obligations
  • Maintaining audit logs for compliance

6. Data Sharing and Third Parties

We do not sell your personal data. We may share your data with:

  • Service Providers: Payment processors, email providers, infrastructure providers
  • Domain Registrars: When you register domain names
  • Legal Authorities: When required by law or court order
  • Business Partners: With your explicit consent only

All third-party processors are bound by Data Processing Agreements (DPAs) ensuring GDPR compliance. View our Third-Party Data Processors

7. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights:

Right of Access (Art. 15)

Request a copy of your personal data we hold.

Right to Rectification (Art. 16)

Request correction of inaccurate personal data.

Right to Erasure (Art. 17)

Request deletion of your personal data ("Right to be Forgotten").

Right to Restriction (Art. 18)

Request restriction of processing in certain circumstances.

Right to Data Portability (Art. 20)

Receive your data in a machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests or for marketing.

Right to Withdraw Consent (Art. 7)

Withdraw consent at any time for consent-based processing.

Exercise Your Rights

You can exercise your rights through our GDPR Privacy Dashboard or by contacting our DPO.

Login to Access GDPR Dashboard

8. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Data Type Retention Period Legal Basis
Account data Duration of account + 2 years Contract performance
Financial records (invoices) 7 years Romanian fiscal law
Security logs 2 years Legitimate interest
Support tickets 5 years Legitimate interest
Marketing consent records Duration of consent + 3 years Legal compliance

9. Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

Encryption

  • TLS/HTTPS for data in transit
  • AES-256 encryption for sensitive data at rest
  • Encrypted backups

Access Control

  • Role-based access control (RBAC)
  • Two-factor authentication (2FA)
  • Account lockout protection

Monitoring

  • Comprehensive audit logging
  • Real-time security alerts
  • Regular security assessments

Compliance

  • Regular data protection training
  • Incident response procedures
  • Vendor security assessments

10. Cookies and Tracking

We use cookies and similar technologies to operate our service and improve your experience. For detailed information, please see our Cookie Policy.

View Cookie Policy

11. International Data Transfers

Your data is primarily processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure adequate safeguards through:

  • EU-approved Standard Contractual Clauses (SCCs)
  • EU-US Data Privacy Framework (where applicable)
  • Binding Corporate Rules for processors

12. Contact Us

For questions about this Privacy Policy or to exercise your data protection rights:

Data Protection Officer

dpo@pragmatichost.com

General Inquiries

contact@pragmatichost.com

Supervisory Authority

You have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP):

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
anspdcp@dataprotection.ro | www.dataprotection.ro

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through our platform. The "Last updated" date at the top of this policy indicates when it was last revised.