Privacy Policy
Cloudhosting.lu privacy policy and how we handle personal data.
Important notice: The English version of this Privacy Policy is the legally binding version. Any translations are provided for convenience only. In case of any discrepancy, the English version shall prevail.
1. Introduction
352 Digital Sarl, operating as cloudhosting.lu (“we”, “us”, “our”, or “cloudhosting.lu”), is committed to protecting the privacy and personal data of our customers, website visitors, and all individuals whose data we process.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Luxembourg data protection law, specifically the Law of 1 August 2018 on the organisation of the National Data Protection Commission and the general data protection framework.
By using our services or website, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
352 Digital S.Ã r.l.
29 Boulevard de la Grande Duchesse Charlotte
L-1331 Luxembourg
Grand Duchy of Luxembourg
- RCS: B212612
- VAT: LU29182886
- Email: [email protected]
- Phone: +352 2020 3352
For data protection enquiries, please contact our Data Protection Contact at [email protected].
3. Data We Collect
3.1 Information You Provide Directly
Account Registration Data:
- Full name (first name, last name)
- Email address
- Postal address
- Telephone number
- Company name (if applicable)
- VAT number (if applicable)
- Username and password
Payment Information:
- Credit/debit card details (processed by our payment providers)
- Bank account details (for SEPA direct debit)
- PayPal account information
- Billing address
- Transaction history
Domain Registration Data:
- Registrant contact information
- Administrative contact details
- Technical contact details
- Organisation details (for business registrations)
- Documentation for restricted TLDs (identity documents, business registrations)
Support and Communication Data:
- Support ticket content
- Email correspondence
- Chat transcripts
- Phone call records (if applicable)
- Feedback and survey responses
3.2 Information Collected Automatically
Technical Data:
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Time zone and language settings
- Screen resolution
Usage Data:
- Pages visited on our website
- Time and date of visits
- Duration of visits
- Click patterns
- Referring website addresses
- Search queries on our site
Service Usage Data:
- Login times and frequency
- Control panel actions
- Resource usage statistics
- Error logs
- Security events
3.3 Information from Third Parties
Domain Registries:
- WHOIS verification data
- Registry transfer information
- Dispute-related information
Payment Providers:
- Transaction confirmations
- Fraud prevention data
- Payment method validation
Public Sources:
- Company registry information
- VAT validation services (VIES)
- Publicly available business information
4. Purposes and Legal Bases
We process your personal data for the following purposes and legal bases:
4.1 Contract Performance (Article 6(1)(b) GDPR)
| Purpose | Data Used |
|---|---|
| Account creation and management | Name, email, address, phone |
| Service provisioning | Account data, technical requirements |
| Domain registration | Registrant details, contact information |
| Billing and payments | Payment details, billing address |
| Customer support | Communication data, account information |
| Service notifications | Email address, phone number |
4.2 Legal Obligations (Article 6(1)(c) GDPR)
| Purpose | Data Used |
|---|---|
| Tax compliance and invoicing | Name, address, VAT number, transactions |
| ICANN/Registry compliance | WHOIS data, registrant verification |
| Response to legal requests | As required by authorities |
| Anti-money laundering checks | Identity verification data |
| Record keeping requirements | Transaction and communication records |
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
| Purpose | Legitimate Interest | Data Used |
|---|---|---|
| Security monitoring | Protecting our infrastructure and customers | IP addresses, access logs, security events |
| Fraud prevention | Preventing financial losses | Payment patterns, account activity |
| Service improvement | Enhancing customer experience | Usage analytics, feedback |
| Network maintenance | Ensuring service availability | Technical logs, performance data |
| Business communications | Maintaining customer relationships | Contact details, service history |
4.4 Consent (Article 6(1)(a) GDPR)
Where required, we obtain your explicit consent for marketing communications, non essential cookies, processing of special category data (if applicable), and transfers to third countries beyond contractual necessity. You may withdraw consent at any time by contacting [email protected] or using unsubscribe links in communications.
5. Data Location and Sovereignty
5.1 Luxembourg Data Hosting Guarantee
For all hosting services (Shared Hosting, VPS, Dedicated Servers):
- All infrastructure is physically located in Luxembourg
- Data at rest is stored exclusively within Luxembourg borders
- Processing occurs under Luxembourg jurisdiction
- EU data protection laws apply fully
- No transfer outside the EU without explicit consent
Data Centres:
- Primary: Luxembourg City, Luxembourg
- Secondary: Bettembourg, Luxembourg
- Backup: Luxembourg (off site facility)
5.2 Third Party Services with External Data Processing
The following services involve data processing outside Luxembourg. By using these services, you acknowledge and consent to the relevant data transfers:
| Service | Provider | Data Location | Safeguards |
|---|---|---|---|
| Basekit Website Builder | Basekit Platform Ltd | United Kingdom | UK Adequacy Decision |
| Microsoft 365 Email | Microsoft Corporation | EU/Global | Standard Contractual Clauses, EU Data Boundary |
| Zoho Mail | Zoho Corporation | EU (Netherlands) | EU Data Centres, SCCs |
| Mailprovider.com | Mailprovider | Provider infrastructure | Contractual safeguards |
| Domain Registries | Various (ICANN, ccTLD operators) | International | Registry agreements, SCCs where applicable |
| Payment Processors | Stripe, PayPal | EU/US | SCCs, certified frameworks |
5.3 Domain Name Data
Domain registration inherently involves international data flows, including WHOIS databases (public or gated, depending on TLD), registry operators in various jurisdictions, ICANN (for gTLDs) in the United States, and ccTLD registries in respective countries. This processing is necessary for domain registration and operation and is governed by registry policies.
6. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
6.1 Retention Periods
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data | Duration of account plus 10 years | Luxembourg commercial law requirements |
| Transaction records | 10 years from transaction | Tax and accounting obligations |
| Invoices | 10 years | Luxembourg tax law |
| Support tickets | 5 years after closure | Service quality and dispute resolution |
| Server logs | 12 months | Security and troubleshooting |
| Access logs | 6 months | Security monitoring |
| Marketing consent records | Duration of consent plus 3 years | Proof of consent |
| Domain WHOIS data | Duration of registration plus per registry requirements | Registry obligations |
| Backup data | 14 days (rolling) | Disaster recovery |
6.2 Post Termination Retention
Upon account termination:
- Service data: deleted within 60 days
- Backups: purged within 30 days after service deletion
- Legal records: retained per statutory requirements
- Anonymised analytics: may be retained indefinitely
6.3 Data Deletion Requests
You may request deletion of your personal data subject to no ongoing contractual relationship, no outstanding legal obligations, completion of mandatory retention periods, and no overriding legitimate interests.
7. Data Sharing
7.1 Categories of Recipients
We may share your personal data with:
Service Providers (Data Processors):
- Payment processors (Stripe, PayPal)
- Domain registrars (EuroDNS, Realtime Register, OpenProvider)
- Data centre operators
- Email service providers (for transactional emails)
- Customer support tools
- Analytics providers
Third Parties (Joint or Independent Controllers):
- Domain registries (ICANN, ccTLD operators)
- SSL certificate authorities
- Tax authorities (upon legal request)
- Law enforcement (upon valid legal process)
Professional Advisors:
- Legal counsel
- Accountants and auditors
- Insurance providers
7.2 No Sale of Personal Data
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
7.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, subject to the same privacy protections.
8. International Transfers
8.1 Transfer Mechanisms
When personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards through:
- Adequacy decisions: Transfers to countries with EU adequacy decisions (UK, Switzerland, etc.)
- Standard Contractual Clauses (SCCs): EU approved contractual clauses with recipients
- Binding Corporate Rules: Where applicable with corporate groups
- Explicit consent: For specific, informed transfers with your consent
8.2 Domain Related Transfers
Domain registration necessarily involves transfers to:
- ICANN (United States) for gTLD administration
- Various ccTLD registries worldwide
- Registrar partners for domain processing
These transfers are necessary for contract performance and are governed by registry specific policies and ICANN’s data protection framework.
9. Data Security
9.1 Technical Measures
We implement comprehensive security measures including:
Encryption:
- TLS 1.2+ for all data in transit
- AES 256 encryption for data at rest
- Encrypted backup storage
- Secure key management
Access Controls:
- Role based access control (RBAC)
- Multi factor authentication for administrative access
- Regular access reviews
- Privileged access management
- Unique user credentials
Infrastructure Security:
- Firewalls and intrusion detection/prevention systems
- DDoS protection
- Network segmentation
- Regular security patching
- Vulnerability scanning
Physical Security:
- 24/7 manned security at data centres
- Biometric access controls
- CCTV surveillance
- Environmental controls
9.2 Organisational Measures
- Staff confidentiality agreements
- Regular security awareness training
- Data protection impact assessments
- Incident response procedures
- Business continuity planning
- Regular audits and assessments
9.3 Incident Response
In the event of a personal data breach that poses a risk to your rights and freedoms:
- We will notify the CNPD within 72 hours of becoming aware
- We will notify affected individuals without undue delay if there is high risk
- We maintain a breach register for all incidents
10. Your Rights
Under GDPR, you have the following rights regarding your personal data:
10.1 Right of Access (Article 15)
You may request a copy of the personal data we hold about you.
10.2 Right to Rectification (Article 16)
You may request correction of inaccurate or incomplete personal data.
10.3 Right to Erasure (Article 17)
You may request deletion of your personal data where:
- Data is no longer necessary for original purpose
- You withdraw consent (where consent is the legal basis)
- You object to processing and no overriding legitimate grounds exist
- Data has been unlawfully processed
- Legal obligation requires erasure
This right does not apply where processing is necessary for:
- Compliance with legal obligations
- Establishment, exercise, or defence of legal claims
- Archiving in the public interest
10.4 Right to Restriction (Article 18)
You may request restriction of processing where:
- You contest the accuracy of data (pending verification)
- Processing is unlawful but you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing (pending verification)
10.5 Right to Data Portability (Article 20)
You may receive your personal data in a structured, commonly used, machine readable format and transmit it to another controller, where:
- Processing is based on consent or contract
- Processing is carried out by automated means
10.6 Right to Object (Article 21)
You may object to processing based on legitimate interests. We must cease processing unless we demonstrate compelling legitimate grounds. You have an absolute right to object to direct marketing at any time.
10.7 Rights Related to Automated Decision Making (Article 22)
We do not currently engage in solely automated decision making that produces legal or similarly significant effects on you.
10.8 Exercising Your Rights
To exercise any of these rights, contact us at:
- Email: [email protected]
- Post: 352 Digital S.Ã r.l., 29 Boulevard de la Grande Duchesse Charlotte, L-1331 Luxembourg
- Through your Customer Account portal
We will respond within one month, extendable by two months for complex requests. We may request identity verification before processing requests.
10.9 Right to Lodge a Complaint
If you believe we have violated your data protection rights, you have the right to lodge a complaint with:
Commission Nationale pour la Protection des Donnees (CNPD)
Service des plaintes
15 Boulevard du Jazz
L-4370 Belvaux
Luxembourg
Phone: (+352) 26 10 60 1
Email: [email protected]
Website: www.cnpd.lu
We encourage you to contact us first so we can address your concerns directly.
11. Cookies and Tracking
11.1 Cookie Policy
Our website uses cookies and similar technologies. Categories include:
Strictly Necessary Cookies:
- Session management
- Security functions
- Load balancing
- Shopping cart functionality
These cookies are essential and do not require consent.
Functional Cookies:
- Language preferences
- User interface customisation
- Previously entered information
Analytics Cookies:
- Website usage statistics
- Performance monitoring
- User journey analysis
Marketing Cookies:
- Advertising effectiveness
- Remarketing (if applicable)
- Social media integration
11.2 Cookie Management
Upon first visit, you will be presented with a cookie consent banner allowing you to accept all cookies, reject non essential cookies, or customise your preferences. You may change your preferences at any time via the cookie settings link in our website footer or by clearing your browser cookies.
11.3 Third Party Cookies
We may use cookies from:
- Google Analytics (analytics)
- Payment providers (functional)
- Customer support tools (functional)
Each provider is subject to their own privacy policy.
12. Marketing Communications
12.1 Marketing Consent
We will only send marketing communications where:
- You have given explicit opt in consent, or
- You are an existing customer and the communications relate to similar products/services (soft opt in), and you have not opted out
12.2 Service Communications
We will send non marketing service communications without consent where necessary for:
- Account notifications
- Security alerts
- Renewal reminders
- Service changes
- Legal updates
These are not considered marketing and cannot be opted out of while you maintain an account.
12.3 Opting Out
You may opt out of marketing communications at any time by:
- Clicking the unsubscribe link in any email
- Updating preferences in your Customer Account
- Contacting [email protected]
13. Childrens Privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children under 18.
If we become aware that we have collected personal data from a child under 18 without parental consent, we will take steps to delete that information promptly.
If you believe we may have collected data from a child, please contact [email protected].
14. Third Party Links
Our website and services may contain links to third party websites, products, or services. We are not responsible for the privacy practices of these third parties.
We encourage you to read the privacy policies of any third party sites you visit.
15. Updates to This Policy
15.1 Notification of Changes
We may update this Privacy Policy periodically. We will notify you of material changes through:
- Email notification to your registered address
- Prominent notice on our website
- Notification in your Customer Account
15.2 Effective Date
Changes become effective:
- 30 days after notification for material changes
- Immediately for minor clarifications or legally required changes
Continued use of our services after the effective date constitutes acceptance of the updated policy.
15.3 Version History
| Version | Date | Description |
|---|---|---|
| 1.0 | November 2025 | Initial release |
16. Specific Provisions for DORA Regulated Entities
For customers qualifying as Financial Entities under the Digital Operational Resilience Act (DORA), the following additional provisions apply:
16.1 Enhanced Transparency
We provide Financial Entities with:
- Detailed processing registers upon request
- Subprocessor information and changes
- ICT incident notifications per agreed thresholds
- Regular compliance reporting
16.2 Competent Authority Access
We will cooperate fully with competent authorities conducting supervisory activities on Financial Entities, including providing access to personal data processing information as required.
16.3 DORA Specific Contact
For DORA related data protection enquiries: [email protected]
17. Contact Us
For any questions about this Privacy Policy or our data protection practices:
Data Protection Contact
352 Digital S.Ã r.l.
Attn: Data Protection
29 Boulevard de la Grande Duchesse Charlotte
L-1331 Luxembourg
Grand Duchy of Luxembourg
- Email: [email protected]
- Phone: +352 2020 3352
- Business Hours: Monday to Friday, 09:00 to 18:00 CET
Governing Law
This Privacy Policy is governed by Luxembourg law and the GDPR. The courts of Luxembourg City have jurisdiction for any disputes relating to data protection.
