Data controller
Data we collect
We collect personal data necessary for providing our hosting and infrastructure services. The categories of data collected include:
User-supplied data
Collected when you register an account, place an order, or contact support:
- -First and last name
- -Email address
- -Password — stored only as a bcrypt hash; we never hold the plaintext
- -Phone number
- -Company name (optional, for business accounts)
- -Billing address — street, city, country
- -Two-factor authentication secret, if you enable 2FA
- -Messages, attachments and correspondence submitted through the support system
Business (B2B) verification data
If you register as a company and request business invoicing, we additionally process your VAT/registration number (CUI), company registry details and, where verification is required, supporting company documents you provide.
This data is used to issue legally valid fiscal documents and to verify that the business exists. See our Terms and conditions for the circumstances in which we may request further documentation or decline a business account.
Service and billing records
Operating the services you order produces records tied to your account:
- -Orders, subscriptions, invoices and payment status
- -Services provisioned to you and their configuration
- -IP addresses assigned to your servers
- -Resource and bandwidth usage measured for the purpose of applying plan limits
- -Record of your acceptance of our policies at checkout — the policy version accepted, together with the date, IP address and browser user agent, retained as proof of agreement
Technical & security data
We automatically collect technical data to secure our infrastructure and prevent attacks.
- -IP address
- -HTTP requests (methods, URLs, response codes)
- -Device type
- -Browser and operating system
- -Timestamps
- -Server logs
- -Outbound traffic monitored by our IDS
- -WAF (Web Application Firewall) events
Payment data
Payments are processed via third-party payment service providers (Stripe, Paysafecard, bank transfer). We do not store full credit or debit card data.
Billing data retained includes:
- -Cardholder name
- -Billing address
- -Last 4 digits of card (where applicable)
- -Transaction reference
Contact form data
When you submit the contact form on ench.ro, we collect:
- -Full name — to address your enquiry
- -Email address — to send you a reply
- -Subject (optional) — to route and categorise your message
- -Message body — the content of your enquiry
- -IP address — retained temporarily by our anti-abuse rate-limiting system; not stored with your message
This data is used solely to respond to your enquiry. It is not used for marketing purposes, not shared with third parties beyond the SMTP provider used to deliver email (Masterhost/any configured provider), and is not combined with any other data sets we hold.
Purposes of processing
- -Account creation and management
- -Providing and maintaining hosting services
- -Payment processing and transaction execution
- -Issuing invoices and accounting documents
- -Providing technical support
- -Infrastructure security monitoring, fraud and abuse detection and prevention
- -Managing commercial relationships with legal entity clients
- -Marketing communications to individuals (B2C)
- -Commercial communications to legal entities (B2B)
- -Responding to contact form enquiries
Legal basis for processing
Each processing activity is associated with a distinct legal basis under Art. 6 GDPR:
| Purpose / Activity | Legal basis | GDPR article |
|---|---|---|
| Account creation and management | Performance of a contract | Art. 6(1)(b) |
| Providing and maintaining hosting services | Performance of a contract | Art. 6(1)(b) |
| Payment processing and transaction execution | Performance of a contract | Art. 6(1)(b) |
| Issuing invoices and accounting documents | Legal obligation | Art. 6(1)(c) |
| Providing technical support | Performance of a contract | Art. 6(1)(b) |
| Infrastructure security monitoring, fraud and abuse detection and prevention | Legitimate interest | Art. 6(1)(f) |
| Managing commercial relationships with legal entity clients | Legitimate interest | Art. 6(1)(f) |
| Marketing communications to individuals (B2C) | Consent | Art. 6(1)(a) |
| Commercial communications to legal entities (B2B) | Legitimate interest | Art. 6(1)(f) |
| Responding to contact form enquiries | Legitimate interest | Art. 6(1)(f) |
Legitimate interest (Art. 6(1)(f)) — The processing of technical and security data, as well as the contact data of representatives of corporate clients, is based on the legitimate interest of the controller in securing infrastructure, preventing abuse, and maintaining commercial relationships. This interest has been assessed and does not override the fundamental rights and freedoms of data subjects. Data subjects have the right to object to this processing (Art. 21 GDPR).
Contact form (Art. 6(1)(f)) — When you submit the contact form, your name and email address are processed on the basis of our legitimate interest in responding to pre-contractual and general enquiries. You may request deletion of this data at any time by contacting [email protected].
Consent (Art. 6(1)(a)) — Marketing communications addressed to individuals are sent solely on the basis of explicit consent, which may be withdrawn at any time without affecting the contracted services.
B2B marketing — Commercial communications addressed to legal entities are sent on the basis of legitimate interest, with the possibility to opt out at any time.
Sharing of data
We do not sell your personal data. Data may be shared with:
- -Payment processors (Stripe, Paysafecard) — solely to complete transactions
- -Infrastructure providers — to operate services (data centres, networks)
- -Competent authorities — when required by law or court order
International data transfers
Some service providers may process data outside the European Economic Area (EEA). Where such transfers occur, we ensure that appropriate safeguards are in place, including standard contractual clauses approved by the European Commission.
Data security
- -TLS/SSL encryption for all data in transit
- -Bcrypt hashing for passwords
- -IDS/WAF systems for intrusion detection & prevention
- -Continuous access logging and monitoring
- -Regular security audits
- -Role-based access control (RBAC)
Data retention
We retain personal data for as long as necessary for the purpose for which it was collected:
- -Account data — for the duration of account activity and 90 days after closure
- -Unverified accounts — deleted automatically 30 days after registration if the email address is never confirmed, which also frees the address for re-registration
- -Security logs — up to 12 months from the time of recording
- -Accounting and tax records — 10 years under Romanian law
- -Policy acceptance records — retained for as long as the related order and accounting records, as proof of the agreement you entered into
- -Business verification documents — retained only as long as needed to verify the business, then deleted unless accounting law requires otherwise
- -Communication data (support) — 24 months from the last interaction
- -Contact form submissions — 12 months from the date of submission, or until the enquiry is resolved, whichever is sooner
Data you store on your services
A distinction worth stating plainly: for your account — your name, billing details, invoices, support tickets — we decide why and how the data is processed, and we are the controller.
For whatever you place on the servers you rent — your websites, databases, game server data, and any personal data of your own users — you remain the controller and we act only as a processor. We process that content solely to run the service, on your instructions. We do not inspect, access or use it for any other purpose, except where strictly necessary to investigate a reported abuse, resolve a support request you raised, or comply with a legal obligation.
If you process personal data of others on our infrastructure, you are responsible for having a lawful basis to do so. Business customers requiring a written data processing agreement under Art. 28 GDPR can request one at [email protected].
Backups and erasure
Backups exist so that data can be restored after failure, and they necessarily contain copies of personal data as it stood when the backup ran.
When you ask us to erase data, we remove it from live systems immediately. Copies held in backups are not individually edited — doing so would compromise the integrity of the backup — and instead age out on the ordinary backup rotation, after which the deletion is complete. In the meantime those copies are not used for any purpose other than disaster recovery.
Security incidents
If a personal data breach occurs, we notify the supervisory authority (ANSPDCP) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR.
Where a breach is likely to result in a high risk to your rights and freedoms, we will also inform you directly and without undue delay, describing what happened, the likely consequences and the measures taken (Art. 34 GDPR).
Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you, nor do we profile you in that sense (Art. 22 GDPR).
Automated systems are used only for security and abuse prevention — rate limiting, anti-bot checks and intrusion detection — and for applying the resource limits of the plan you purchased. Where such a system restricts your access, you can contest it and obtain a human review by contacting support.
Cookies and local storage
This site uses cookies and browser storage entries (localStorage and sessionStorage). Each one is described individually — name, purpose, type, lifetime and legal basis — in our Cookie policy.
Storage that is strictly necessary for the site to work does not require consent. Everything else, including analytics and the anti-bot check, is activated only after you explicitly accept it, and consent can be withdrawn at any time from the cookies page. On withdrawal, data stored on the basis of consent is deleted from your browser.
User rights
As a data subject, you have the right to:
- -Access — request a copy of the personal data we hold
- -Rectification — request correction of inaccurate or incomplete data
- -Erasure — request removal of data, subject to legal obligations
- -Restriction — limit how we process your data
- -Portability — receive your data in a structured, machine-readable format
- -Objection — object to processing based on our legitimate interest
To exercise these rights, contact us using the details listed in section 01 above.
Supervisory authority
You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) if you believe the processing of your data infringes applicable regulations.
ANSPDCP — www.dataprotection.ro