Skip to content
HostON

Legal · GDPR

Privacy policy

What personal data we process when you use hoston.ro, my.hoston.ro and our services, why, who we share it with and how you can exercise your rights.

Updated: 08.10.2026HOSTON SRL, Mărășești

The Romanian version of this document is the legally binding one; this translation is provided for information.

In brief

  • Only what is necessaryContact and billing details for the contract; the personal numeric code (CNP) is optional.
  • Data in RomaniaOur servers are in Vrancea, Romania (EU). Some providers may process data outside the EU, with safeguards.
  • Statistics only with consentGoogle Analytics and Ahrefs load only after you accept them in the cookie banner.
  • We do not sell dataWe do not sell personal data and do not give it to third parties for advertising.

01

Who processes the data

The controller of the data collected through hoston.ro, my.hoston.ro and the HostON services is:

Company name
HOSTON SRL (brand HostON)
Registered office
Str. I.L. Caragiale nr. 47, Mărășești, jud. Vrancea, 625200, România
Tax ID (CUI)
RO38066444
Trade Register No.
J2017000806390
Share capital
500 lei
Phone
+40 733 371 801 (Monday–Friday, 09:00–18:00)

We have not designated a data protection officer (DPO). For any question or request about your data, write to us at info@hoston.ro with the subject “GDPR request”.

For the data that customers store in their services (for example the customer data of an online shop hosted with us), HostON is the processor and the customer is the controller. For this data, the Data Processing Agreement applies.

02

What data we process

  • Identification and contactFirst name, last name, email address, phone number, postal address; for companies, the company name, tax ID (CUI) and contact person.
  • Billing and paymentsBilling details, order and invoice history, payment confirmation. Card data is processed by Netopia Payments; we only receive the result of the transaction.
  • DomainsDetails of the registrant and of the domain contacts, nameservers, registration history.
  • CommunicationsSupport tickets, emails, chat messages and messages sent through the website forms.
  • Technical dataIP address, date and time, browser, pages accessed, logins and security events.
  • Content of the servicesThe files, databases and emails stored in your services; we process them only as a processor.

The CNP (Romanian personal numeric code) is optional: you fill it in only if you want it to appear on the invoice. We do not intentionally collect special categories of data (health, political opinions, biometric data); these may, however, exist in the content customers store.

Contact and billing details are necessary to conclude and perform the contract and to issue invoices; without them we cannot deliver the services. The other data is optional or generated automatically when you use the services.

03

Purposes and legal bases

  • Contract

    ExamplesClient account, orders, service activation, domains, SSL, invoices, support

    Legal basis (GDPR)Performance of a contract, art. 6(1)(b)

  • Legal obligations

    ExamplesInvoicing, accounting, archiving, responding to requests from authorities, DSA obligations

    Legal basis (GDPR)Legal obligation, art. 6(1)(c)

  • Security

    ExamplesProtection against abuse, fraud, spam and attacks; access logs

    Legal basis (GDPR)Legitimate interest, art. 6(1)(f)

  • Communication

    ExamplesAnswers to questions, the reporting form, chat

    Legal basis (GDPR)Pre-contractual steps or legitimate interest, (b) / (f)

  • Visitor statistics

    ExamplesGoogle Analytics 4, Ahrefs Web Analytics

    Legal basis (GDPR)Consent, art. 6(1)(a)

  • Own aggregate statistics

    ExamplesUmami, hosted by HostON on its own servers, cookie-free

    Legal basis (GDPR)Legitimate interest, art. 6(1)(f)

  • Information about similar services

    ExamplesEmails about HostON services to customers, with an unsubscribe link in every message

    Legal basis (GDPR)Legitimate interest or consent, (f) / (a)

  • Defence of rights

    ExamplesDebt recovery, disputes

    Legal basis (GDPR)Legitimate interest, art. 6(1)(f)

Where processing is based on consent, you can withdraw it at any time, without affecting the lawfulness of processing carried out before. For cookies, use the “Cookie settings” button in the page footer.

04

The website, logs and cookies

When you visit the website, the server records the IP address, date and time, the page requested and the browser, for operation and security. Logs are deleted after 90 days at most, except those needed to investigate an incident.

The website uses strictly necessary cookies (your cookie choice, the currency and price display mode, the language). Google Analytics 4 and Ahrefs Web Analytics load only if you accept them. Ahrefs Web Analytics does not use cookies. For our own statistics we also use Umami, hosted on our servers, without cookies and without sending data to third parties. The full list is in the Cookie policy.

The website’s fonts and images are served from our servers. The website is delivered through the Cloudflare network, which processes the IP address for protection against attacks.

05

Chat and AI assistant

The chat window on the website first answers you through an automated assistant based on artificial intelligence. The answers are generated with the Claude model of Anthropic PBC (USA).

  • What is sent: the messages you write, the previous messages in the same conversation and the page you are on. We do not send your name or the details of your account.
  • Where it is kept: the conversation is kept in the browser (sessionStorage) until you close the tab and on our server for 7 days, so that we can follow up on a request and improve the answers; it is then deleted automatically.
  • Anthropic processes the messages as a provider, in order to generate the answer, and does not use them to train models. The transfer to the USA is based on the standard contractual clauses approved by the European Commission.
  • Legal basis: our legitimate interest in answering questions about the services quickly and, where applicable, the pre-contractual steps you request (art. 6(1)(f) and (b) GDPR).
  • The AI assistant does not make decisions with legal effects on you and has no access to the client account.

Do not write passwords, card details, your CNP or other sensitive data in the chat. For account-related issues, open a ticket from my.hoston.ro.

If you choose to talk to an operator, only then is the tawk.to chat service (tawk.to inc., USA) loaded. tawk.to processes the messages, your name and email address if you enter them, the IP address and browser information, and sets its own cookies. If you do not start the chat with an operator, the tawk.to script is not loaded.

06

Who we share data with

  • Netopia Payments SRL

    PurposeProcessing online card payments

    CountryRomania

  • Brevo (Sendinblue SAS)

    PurposeSending notification emails and the messages from the website forms

    CountryFrance (EU)

  • Cloudflare, Inc.

    PurposeDelivery and protection of websites (IP address, technical data)

    CountryUSA, global network

  • Google Ireland Ltd. / Google LLC

    PurposeGoogle Analytics 4, only with your consent

    CountryIreland, USA

  • Ahrefs Pte. Ltd.

    PurposeCookie-free visitor statistics, only with your consent

    CountrySingapore

  • Umami (installed and hosted by HostON)

    PurposeAggregate visitor statistics without cookies; the data stays on our servers

    CountryRomania (EU)

  • HostAdvice Ltd.

    PurposeThe widget with the HostON rating in the page footer, only with your consent

    CountryIsrael (country with an EU adequacy decision)

  • Anthropic PBC

    PurposeThe AI assistant in the chat

    CountryUSA

  • tawk.to inc.

    PurposeChat with an operator, only when you start it

    CountryUSA

  • Partner registrars (for .ro, TES Euro Media SRL) and domain registries

    PurposeRegistration and management of domains (for example RoTLD for .ro, EURid for .eu, Verisign for .com)

    CountryRomania, EU, USA and others, depending on the extension

  • Certificate authorities (CA)

    PurposeIssuing SSL certificates

    CountryEU, USA

  • Chartered accountant, lawyers, debt collectors

    PurposeAccounting, defence of rights

    CountryRomania

  • Public authorities and courts

    PurposeOnly when the law requires us to (for example ANAF, the police, ANCOM, courts)

    CountryRomania

For domains, the registrant’s data is sent to the registry of the extension; some of it may appear in the public WHOIS/RDAP database, according to the registry’s rules. Details in the Domain terms.

Providers that process data on our behalf have contractual confidentiality and security obligations. We do not sell personal data and do not share it for marketing purposes.

07

Transfers outside the EU

Customer data and the content of the services are stored on our servers in Vrancea, Romania (EU). Some of the providers in the table above (Cloudflare, Google, Anthropic, tawk.to, Ahrefs, HostAdvice, some registries and certificate authorities) may process data outside the European Economic Area. In these cases, the transfer is based on the EU–US adequacy decision (Data Privacy Framework), for certified providers, or on the European Commission’s standard contractual clauses. You can ask us for a copy of the safeguards at info@hoston.ro.

08

How long we keep the data

  • Client account and contractual data

    Retention periodFor the duration of the contract and 5 years after it ends (limitation periods and legal obligations)

  • Invoices and accounting documents

    Retention period10 years, in accordance with the Accounting Law no. 82/1991 (Legea contabilității nr. 82/1991)

  • Technical server logs

    Retention period90 days at most, except those needed for an incident

  • Conversations with the AI assistant

    Retention period7 days on our server, then automatic deletion

  • Withdrawal statements and notices of illegal content

    Retention periodFor the general limitation period (3 years), as evidence

  • Domain data

    Retention periodFor the duration of the domain registration and 1 year after expiry

  • Data for information messages

    Retention periodUntil you unsubscribe or withdraw your consent

  • Identity documents sent for account recovery

    Retention periodDeleted once the request has been resolved

09

Your rights

  • the right of access (art. 15 GDPR): a copy of the data we hold about you;
  • the right to rectification (art. 16): you can correct most of the data directly in my.hoston.ro;
  • the right to erasure (art. 17), with the exceptions provided by law (for example invoices);
  • the right to restriction of processing (art. 18);
  • the right to data portability (art. 20): the data in a structured format (JSON or CSV);
  • the right to object (art. 21), including to commercial information messages, with immediate effect;
  • the right to withdraw your consent at any time (art. 7(3)).

Send your request to info@hoston.ro with the subject “GDPR request”, or by post to our registered office. We reply within one month at most; for complex requests the period may be extended by a further two months, and we will inform you. We do not charge fees, except for manifestly unfounded or excessive requests. Details on the GDPR – your rights page.

10

Complaint to the supervisory authority

If you believe that the processing of your data infringes the GDPR, you can lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru nr. 28–30, sector 1, Bucharest, www.dataprotection.ro. Please write to us first, so that we can resolve the issue directly.

11

Automated decisions

We do not make decisions based solely on automated processing that produce legal effects concerning you (art. 22 GDPR). Orders may be checked automatically for signs of fraud (for example the country, IP address and payment method), but flagged orders are reviewed by a person.

12

Data security

We apply appropriate technical and organisational measures: TLS encryption for all connections, isolation of web hosting accounts (CloudLinux CageFS), firewall and malware scanning on the servers, daily backups (JetBackup), protection against attacks through Cloudflare, and restricted staff access, only as far as necessary. If a security incident poses a high risk to your rights, we will inform you in accordance with art. 34 GDPR.

13

Changes to this policy

We may update this policy when the services or providers change. Important changes are communicated to you by email or through a notice on the website before they take effect. The date of the last update appears at the top of the page.

Other legal documents

Frequently asked questions

No. The CNP (Romanian personal numeric code) is optional and you fill it in only if you want it to appear on the invoice. For the contract, we only need your contact and billing details.

Messages to the AI assistant are processed by Anthropic to generate the answer and are kept on our server for 7 days, then deleted automatically. Do not write passwords or card details in the chat.

Only if you accept statistics in the cookie banner. Without your consent, the Google Analytics script is not loaded and the _ga cookies are not set.

Customer data and the content of the services are on our servers in Vrancea, Romania. Some providers, such as Cloudflare or Google, may process data outside the EU, with the safeguards provided by the GDPR.

We have not designated a DPO. Requests regarding personal data are sent to info@hoston.ro with the subject “GDPR request”.

Send a request to info@hoston.ro. We delete the data that does not have to be kept by law; invoices, for example, are kept for 10 years. Deleting the account also means terminating the active services, so make a backup first.

Have a question? Write to us.

Whether you are about to order or already have a site with us, the people who manage the servers will answer you.

HostON technical support team member wearing a headset and answering a customer