1.0 Scope & Data Controller
This Privacy Policy explains how HostBrr (operating under PFWeb Solutions, CVR DK44002698, Denmark — hereinafter "HostBrr", "we", "us") collects, uses, and protects personal data when you visit this website (hostbrr.com), use our client portal at my.hostbrr.com, or purchase and use our hosting services.
PFWeb Solutions is the data controller for the personal data described in this policy. As a business established in Denmark, we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law.
Our client portal and billing system run on Blesta, billing software that we host and operate ourselves. Data you enter in the client portal is processed on our own infrastructure; it is not shared with the software vendor.
This policy does not cover data that you or your users store on services you purchase from us (websites, virtual servers, storage). For that data you act as the data controller, and we act solely as a hosting provider processing it on your instructions.
2.0 Data Collected by This Website
Server and security logs. When you visit hostbrr.com, our web servers and Cloudflare (our CDN and DDoS-protection provider) automatically record technical data such as your IP address, browser user agent, the pages requested, referring page, and timestamps. We use these logs exclusively to keep the website secure, prevent abuse, and diagnose technical problems.
Browser preferences. Your currency choice (EUR/USD) and light/dark theme preference are stored in your browser's localStorage. These values never leave your device, are not transmitted to us, and cannot be used to track you.
No analytics or advertising trackers. This website does not use analytics platforms, advertising pixels, fingerprinting, or any third-party tracking cookies.
Embedded third-party resources. Some pages load resources from third parties: web fonts from Google Fonts and, on our status page, an uptime widget from HetrixTools. When your browser fetches these resources, your IP address and user agent are disclosed to the respective provider. Please refer to the privacy policies of Google and HetrixTools for how they handle this data.
3.0 Data Collected via the Client Portal
Account information. When you register or place an order at my.hostbrr.com, we collect the details needed to create and manage your account: your name, company name (if applicable), postal address, country, email address, phone number, and a password (stored only in hashed form).
Technical and usage data. The portal records the IP addresses and timestamps of logins and orders, and uses session cookies to keep you signed in securely. This information helps us secure accounts, investigate unauthorized access, and screen orders for fraud.
Billing records. We keep records of your orders, services, invoices, transactions, account credits, and applicable taxes for the duration required by accounting law.
Support communications. When you open a support ticket or email us, we store the correspondence and any attachments you provide so we can resolve your request and reference past issues.
4.0 Payment Information
Card and PayPal payments are processed by external payment gateways. Your full card number or PayPal credentials are submitted directly to the processor and never touch our servers; we receive only a payment confirmation and a transaction reference.
Cryptocurrency payments are processed through blockchain payment gateways. We store the transaction reference associated with your invoice. Please note that blockchain transactions are public and immutable by design.
Order details, including your IP address and billing information, may be screened against fraud-prevention checks before a service is activated. Orders flagged as high-risk may be reviewed manually.
5.0 How We Use Data & Legal Bases
Performance of a contract (Art. 6(1)(b) GDPR): we process your account, billing, and support data to provision the services you order, collect payment, and provide technical support.
Legal obligations (Art. 6(1)(c) GDPR): we retain invoicing and transaction records to comply with Danish bookkeeping and tax legislation.
Legitimate interests (Art. 6(1)(f) GDPR): we process log and technical data to secure our network, prevent fraud and abuse, and maintain service quality. You may object to processing based on legitimate interests at any time.
Consent (Art. 6(1)(a) GDPR): where we rely on consent — for example for optional product announcements — you can withdraw it at any time without affecting the lawfulness of prior processing.
We do not sell personal data, and we do not use automated decision-making that produces legal or similarly significant effects on you.
6.0 Sharing & International Transfers
Infrastructure providers. Our services run in datacenters in Germany, the United States, and Luxembourg. Technical data necessary to operate your services resides in the location associated with the service you purchase.
Cloudflare processes website traffic (including visitor IP addresses) to deliver this website and protect it against attacks.
Payment processors receive the data required to complete your payment, as described in Section 4.
Authorities. We disclose personal data to law enforcement or other authorities only where we are legally required to do so.
Where personal data is transferred outside the European Economic Area (for example to US-based providers), we rely on appropriate safeguards such as the EU Standard Contractual Clauses or the provider's certification under the EU–US Data Privacy Framework.
7.0 Cookies & Local Storage
The hostbrr.com website itself sets no cookies. Your currency and theme preferences are kept in localStorage, a browser feature that stores data only on your device; this data is functional, is never sent to our servers, and is not used for tracking.
The client portal at my.hostbrr.com sets strictly necessary session cookies used to keep you logged in and to protect forms against cross-site request forgery. These cookies are essential for the portal to function and are deleted or invalidated when your session ends.
We do not set third-party advertising cookies and we do not participate in cross-site tracking. Because we use only strictly necessary cookies and functional localStorage, no cookie consent banner is required.
8.0 Data Retention
Account information is retained for as long as your account exists. When you close your account, personal data is deleted or anonymized unless a legal obligation requires us to keep it longer.
Invoices and transaction records are retained for five (5) years after the end of the financial year they relate to, as required by the Danish Bookkeeping Act.
Server and security logs are kept for a short, rolling period — typically no more than 90 days — unless a specific security incident requires longer preservation.
Support tickets are retained while your account is active so that we can reference the history of your services, and are removed together with your account data upon closure.
9.0 Your Rights
Under the GDPR you have the right to access the personal data we hold about you, to have inaccurate data rectified, to request erasure ("right to be forgotten"), to restrict processing, to receive your data in a portable format, and to object to processing based on our legitimate interests.
Where processing is based on consent, you have the right to withdraw that consent at any time.
To exercise any of these rights, open a support ticket via the client portal at my.hostbrr.com. We may need to verify your identity before acting on a request, and we will respond within one month as required by the GDPR.
If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or with the supervisory authority in your EU member state of residence.
10.0 Security, Changes & Contact
We protect personal data with technical and organizational measures appropriate to the risk, including TLS encryption for all connections, hashed password storage, isolation between customer environments, access controls, and timely security patching of our systems.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, the affected users, in accordance with Articles 33 and 34 GDPR.
We may update this Privacy Policy from time to time. Changes take effect when posted on this page, and the "Last Updated" date above will be revised accordingly. Material changes will be announced via the client portal or email.
For any questions about this policy or how we handle your data, contact us by opening a support ticket at my.hostbrr.com.