Privacy Policy
We believe transparency is a right, not a feature.
01 What We Collect
TL;DR: Four data categories, each with a purpose, a clock and a legal basis. Your server content is yours — we do not inspect it.
We collect only what operating the service requires. Every category below has a defined purpose, a retention period and a legal basis — and the content stored on your own servers is outside all of them: it belongs to you and is not read, scanned or profiled.
| Data type | Purpose | Retention period | Legal basis |
|---|---|---|---|
| Account data (name, email, hashed password) | Authentication & service management | Account lifetime + 30 days | Contract performance |
| Usage data (IP, browser, API requests) | Security, performance & support | 90 days | Legitimate interest |
| Payment data (last 4 digits, card type) | Billing & invoicing | 7 years (statutory) | Legal obligation |
| Communications (tickets, emails) | Support & dispute resolution | 3 years | Contract performance |
| Server logs | Diagnostics & incident response | 30 days | Legitimate interest |
| Analytics cookies | Service improvement | 12 months | Consent |
| Marketing cookies | Relevant offers | 6 months | Consent |
| Marketing data (opt-in only) | Newsletters & offers | Until unsubscribe | Consent |
* Data is deleted upon account cancellation unless legal requirements dictate otherwise.
02 How We Use Your Data
TL;DR: Four purposes — run the service, bill it, talk to you about it, improve it. Nothing else.
Your data is processed for exactly four purposes: operating the service (your account, servers, domains and panel), billing (invoices, payments, fraud prevention), operational communication (service notifications, security alerts, support replies) and improvement (aggregate, de-identified usage analysis).
We do not use your data to build advertising profiles, train models on your content, or target you on third-party platforms.
03 Data Sharing
TL;DR: Never sold, never rented. Shared only with the processors that make the service work, under contract.
Your personal data is never sold or rented to anyone. It is shared only with the processors strictly necessary to deliver the service — the payment gateway (which tokenizes card data so we never store full numbers), the transactional email provider, and the data-center operators hosting the infrastructure — each bound by data-processing agreements and confidentiality terms.
Beyond that, disclosure happens only when a legally binding order from a competent authority requires it, and only to the extent of that order.
04 Data Retention
TL;DR: Server content goes immediately on cancellation; account data after 30 days; invoices stay as long as the law says.
Retention follows the table in section 1. In summary: server content is deleted immediately when a service is cancelled; core account data is held 30 days to allow reactivation, then erased; support history is kept 3 years; security logs about 90 days; and invoices and payment records for the statutory period (typically 7 years).
You can request earlier deletion at any time — we honor it for everything the law does not oblige us to keep.
05 Your Rights
TL;DR: Access, correct, delete, object, port, withdraw consent — all free, all answered within 30 days.
Under PDPL and GDPR you hold the following rights, exercisable free of charge through the panel or the DPO contact in section 10:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion of your data where no legal duty requires retention.
- Objection & restriction — limiting processing based on legitimate interest.
- Portability — a machine-readable export of your account data.
- Withdrawal of consent — at any time, for consent-based processing such as marketing.
Requests receive an acknowledgment within 72 hours and a substantive response within 30 days.
06 Cookie Policy
TL;DR: Necessary cookies always on (honestly labeled); analytics and marketing are your call — right here.
Three cookie classes run on this site. Necessary cookies carry your login session and CSRF protection and cannot be switched off — the site does not function without them. Analytics and marketing cookies are optional and controlled below; your choice is stored in this browser only.
07 Security
TL;DR: TLS in transit, AES-256 at rest, 2FA, least-privilege access with audit logs, ISO 27001 audited.
Protection is layered: TLS encryption for all traffic, AES-256 encryption for sensitive stored data, two-factor authentication on accounts and mandatory hardware-backed 2FA for administrative access, least-privilege staff permissions with full audit logging, 24/7 security monitoring, regular tested backups, and network-level DDoS mitigation rated above 10 Tbps.
The whole program operates under ISO 27001 certification with recurring independent audits. Should a breach ever affect your personal data, you will be notified per the procedures PDPL and GDPR require.
08 Children's Privacy
TL;DR: 18+. Accounts found to belong to minors are closed and their data deleted.
Hostrena services are intended for adults aged 18 and over; registration asserts legal age. We do not knowingly collect data from minors. If an account is discovered to belong to a minor, it is suspended and its data deleted — parents or guardians can contact the DPO for immediate removal.
09 Policy Changes
TL;DR: Material changes are emailed 30 days ahead; the date at the top is always current.
When this policy changes materially — new purposes, new processors, changed retention — active accounts are notified by email at least 30 days before the change takes effect. The last-updated date in the header always identifies the current revision; minor editorial clarifications may ship without individual notice.
10 Contact the DPO
TL;DR: One named contact for every privacy matter — acknowledgment in 72 hours.
Data Protection Officer
For any inquiry about your data or to exercise your rights, contact us directly — we respond within 72 hours.
If our response does not satisfy you, you retain the right to lodge a complaint with the Saudi Data & AI Authority (SDAIA) or the supervisory authority of your own jurisdiction.
Privacy questions, answered
What personal data does Hostrena collect about me?
Four categories only: account data (name, email, phone), payment data (tokenized by the payment gateway — full card numbers never touch our servers), usage data (login history, resource consumption, API requests) and communication data (tickets and messages). The content stored on your own servers is yours and is not inspected.
How does Hostrena use my personal data?
For four purposes: operating the service (your account, servers and panel), billing and invoicing, operational communication (service notifications, security alerts, support replies) and aggregate product improvement. Profiling for third-party advertising is not one of them — your data is never used to target you elsewhere.
Does Hostrena sell my data to third parties?
No — never, in any form, at any price. Data is shared only with the processors strictly required to run the service (payment gateway, email delivery provider, data-center operators), each bound by contractual confidentiality and processing agreements, and only to the minimum extent the specific function requires.
Where is my data stored geographically?
Account and billing records live in Hostrena's primary infrastructure, while your server content lives in whichever region you deploy to — Frankfurt, Helsinki, Ashburn or Singapore today, with Riyadh and Dubai next. The platform is designed around PDPL data-residency requirements as in-Kingdom infrastructure comes online.
How does Hostrena protect my data from breaches?
Layered controls: TLS for everything in transit, AES-256 encryption for sensitive data at rest, two-factor authentication, least-privilege staff access with full audit logging, 24/7 security monitoring, regular backups and DDoS mitigation above 10 Tbps. ISO 27001 certification keeps the whole program independently audited.
What cookies does Hostrena use?
Three classes. Necessary cookies power login sessions and CSRF protection and cannot be disabled. Analytics cookies measure aggregate site usage and can be switched off. Marketing cookies measure campaigns and are opt-in. The cookie preferences panel on this page controls the last two, saved locally in your browser.
How do I delete my account and all my data?
Request deletion from the client panel (Settings → Delete Account) or by writing to the DPO email. Processing stops and data is erased within 30 days. The only exceptions are records the law obliges us to keep — primarily invoices and payment records under financial regulations, typically for 7 years.
Can I get a copy of all data Hostrena holds about me?
Yes — data portability is your right under both PDPL and GDPR. Use the export option in the client panel or email the DPO, and you will receive a complete, machine-readable copy of your account data within 30 days, free of charge for reasonable requests.
Is this policy compliant with GDPR and Saudi PDPL?
The policy is built on both frameworks: PDPL as the home regulation and GDPR for international clients. In practice that means documented legal bases for every processing purpose, honored rights of access, correction, deletion, objection and portability, breach-notification procedures and a named Data Protection Officer.
Who inside Hostrena can access my account data?
Access follows least privilege. Support engineers see only what is needed for your specific ticket, finance staff see billing records only, and infrastructure engineers work with systems rather than personal data. Every access is logged in an audit trail, and administrative access requires hardware-backed two-factor authentication.
Does Hostrena use my data for marketing?
Only its own, and only with an exit. Registered clients may receive product news and offers from Hostrena itself, and every such message carries a one-click unsubscribe that is honored immediately. Your data is never shared with external advertisers, and unsubscribing never affects operational notices like invoices or security alerts.
How long is my data kept after I cancel?
Server content is deleted immediately at cancellation. Core account data is held 30 days in case you reactivate, then erased. Support history is kept 3 years, security logs about 90 days, and invoices and payment records for the legally mandated period (typically 7 years). Earlier deletion can be requested where the law allows it.
Does Hostrena knowingly collect data from minors?
No. The services are intended for adults aged 18 and over, and registration asserts legal age. If an account is discovered to belong to a minor, it is suspended and its data deleted. Parents or guardians who believe a minor has registered can contact the DPO for immediate removal.
How do I file a privacy complaint?
Write to the Data Protection Officer with the details — you will get an acknowledgment within 72 hours and a substantive answer within 30 days. If the outcome does not satisfy you, you retain the right to escalate to the Saudi Data & AI Authority (SDAIA) or the supervisory authority in your own jurisdiction.
How do I update my personal information?
Directly from the client panel: profile data (name, phone) under Profile, billing and company details under Account Settings. Changing the account email requires confirmation from the new address to prevent hijacking. Anything you cannot edit yourself, the support team or DPO will correct on request — correction is a guaranteed right.