Privacy Policy
Last updated: December 27, 2024 | Effective date: December 27, 2024
Quick Navigation
1. Introduction
PragmaticHost SRL ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our PRAHO Platform hosting services.
We comply with the General Data Protection Regulation (GDPR - EU 2016/679), Romanian Law 190/2018 implementing GDPR, and other applicable data protection legislation.
By using our services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller Information
Company Name: PragmaticHost SRL
Registration Number (CUI):
Registered Address:
Email: contact@pragmatichost.com
Phone:
Data Protection Officer (DPO)
Email: dpo@pragmatichost.com
For any privacy-related inquiries or to exercise your data protection rights, please contact our Data Protection Officer.
3. Personal Data We Collect
3.1 Information You Provide
- Account Information: Name, email address, phone number, password
- Billing Information: Company name, VAT number (CUI/CIF), billing address, payment details
- Service Configuration: Domain names, hosting preferences, technical settings
- Support Communications: Ticket content, emails, chat messages
3.2 Information Collected Automatically
- Technical Data: IP address, browser type, device information, operating system
- Usage Data: Pages visited, features used, session duration, click patterns
- Security Data: Login attempts, authentication events, security alerts
- Cookie Data: Session identifiers, preferences (see our Cookie Policy)
3.3 Special Categories of Data
We do not intentionally collect special categories of personal data (such as health data, religious beliefs, or political opinions). If you provide such data in support tickets or other communications, we will treat it with additional care.
4. Legal Basis for Processing
Under GDPR Article 6, we process your data based on the following legal grounds:
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Service provision | Contract performance | Art. 6(1)(b) |
| Invoicing and VAT compliance | Legal obligation | Art. 6(1)(c) |
| Security monitoring | Legitimate interest | Art. 6(1)(f) |
| Marketing communications | Consent | Art. 6(1)(a) |
| Analytics and improvement | Legitimate interest / Consent | Art. 6(1)(f) / (a) |
| Financial record retention (7 years) | Legal obligation (Romanian Law) | Art. 6(1)(c) |
5. How We Use Your Personal Data
5.1 Service Delivery
- Creating and managing your hosting account
- Provisioning and configuring hosting services
- Processing payments and generating invoices
- Providing technical support
5.2 Communication
- Sending service-related notifications (required)
- Responding to support requests
- Sending marketing emails (with your consent)
5.3 Security and Compliance
- Detecting and preventing fraud
- Protecting against security threats
- Complying with legal obligations
- Maintaining audit logs for compliance
6. Data Sharing and Third Parties
We do not sell your personal data. We may share your data with:
- Service Providers: Payment processors, email providers, infrastructure providers
- Domain Registrars: When you register domain names
- Legal Authorities: When required by law or court order
- Business Partners: With your explicit consent only
All third-party processors are bound by Data Processing Agreements (DPAs) ensuring GDPR compliance. View our Third-Party Data Processors
7. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights:
Right of Access (Art. 15)
Request a copy of your personal data we hold.
Right to Rectification (Art. 16)
Request correction of inaccurate personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data ("Right to be Forgotten").
Right to Restriction (Art. 18)
Request restriction of processing in certain circumstances.
Right to Data Portability (Art. 20)
Receive your data in a machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests or for marketing.
Right to Withdraw Consent (Art. 7)
Withdraw consent at any time for consent-based processing.
Exercise Your Rights
You can exercise your rights through our GDPR Privacy Dashboard or by contacting our DPO.
Login to Access GDPR Dashboard8. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account data | Duration of account + 2 years | Contract performance |
| Financial records (invoices) | 7 years | Romanian fiscal law |
| Security logs | 2 years | Legitimate interest |
| Support tickets | 5 years | Legitimate interest |
| Marketing consent records | Duration of consent + 3 years | Legal compliance |
9. Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
Encryption
- TLS/HTTPS for data in transit
- AES-256 encryption for sensitive data at rest
- Encrypted backups
Access Control
- Role-based access control (RBAC)
- Two-factor authentication (2FA)
- Account lockout protection
Monitoring
- Comprehensive audit logging
- Real-time security alerts
- Regular security assessments
Compliance
- Regular data protection training
- Incident response procedures
- Vendor security assessments
11. International Data Transfers
Your data is primarily processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure adequate safeguards through:
- EU-approved Standard Contractual Clauses (SCCs)
- EU-US Data Privacy Framework (where applicable)
- Binding Corporate Rules for processors
12. Contact Us
For questions about this Privacy Policy or to exercise your data protection rights:
Data Protection Officer
dpo@pragmatichost.com
General Inquiries
contact@pragmatichost.com
Supervisory Authority
You have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP):
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
anspdcp@dataprotection.ro | www.dataprotection.ro
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through our platform. The "Last updated" date at the top of this policy indicates when it was last revised.