HOSTVDS · Legal documents

Annex 4. Personal Data Processing Policy

Version 1.0
Published: 17.09.2026
Effective from: 17.10.2026
sha256:e49f6dfe2780d1c6804f35871ba388a88ef59a10745b7da4b2053f9e413ec724 — hash of the document text: source.md · sha256.txt
First edition — no earlier versions

This is a translation. The authentic version is the Ukrainian one (https://www.zevshost.net/legal/privacy). In case of discrepancy, the Ukrainian text prevails.

1. Who processes the data

Controller: LLC «HOST VDS», identification code 37884379, 01021, м. Київ, вул. Мечникова, буд. 8, кімн. 22, Печерський район.

Data protection contact: admin@zevshost.net.

Applicable law: the Law of Ukraine «On Personal Data Protection» No. 2297-VI. For data subjects located in the European Union, Regulation (EU) 2016/679 (GDPR) applies additionally on the basis of Article 3(2) of the Regulation.


2. The Provider's two roles — the key distinction

This is the most important section of this Policy. It defines what the Provider is responsible for and what the Customer is responsible for.

2.1. The Provider as controller

In respect of the personal data of the Customer itself and its representatives: registration, contact and payment data, support requests, and Client Area access logs.

The Provider determines the purposes and means of processing this data, bears controller obligations and is answerable to data subjects.

2.2. The Provider as processor

In respect of personal data that the Customer itself hosts, collects or processes using the provided resources: data of visitors to the Customer's sites, customer databases, mailbox contents, and the Customer's application databases.

The Provider: - processes such data purely technically — storing it, keeping it available and transmitting it as part of providing the Service; - does not determine the purposes or means of its processing; - has no access to its content, save in the cases set out in clause 4.4; - acts solely on the Customer's instructions, the instruction being the very act of placing the data on the provided resources.

The Customer is the controller of that data and is solely responsible for: - ensuring a legal basis for processing; - discharging information duties towards data subjects; - responding to data subject requests; - notifying personal data breaches where required by law; - liability towards data subjects and supervisory authorities.

2.3. The provisions of this Annex concerning the processor role constitute an instruction to process personal data within the meaning of part four of Article 4 of the Law of Ukraine «On Personal Data Protection» (a controller «може доручити обробку персональних даних розпоряднику персональних даних відповідно до договору, укладеного в письмовій формі») and a processing agreement within the meaning of Article 28 GDPR.

Acceptance of the Agreement under Section 3 of the Agreement extends to this Annex. Where the Customer needs a document with the legal effect of one concluded in written form, the Provider will on request conclude a separate data processing agreement (DPA) signed in the manner set out in Article 12 of the Law of Ukraine «On Electronic Commerce» — in particular by electronic signature with a one-time identifier. Under part twelve of Article 11 of that Law such an electronic contract «за правовими наслідками прирівнюється до договору, укладеного у письмовій формі». Requests to admin@zevshost.net.


3. Customer data: what, why, on what basis

Category Content Purpose Legal basis Retention
Identification Name, identification code, address Conclusion and performance of the Agreement; compliance with part 1 of Art. 57 of the Law «On Copyright and Related Rights» Art. 11 of Law 2297-VI (performance of contract; compliance with a controller obligation); Art. 6(1)(b), 6(1)(c) GDPR Term of the Agreement + 3 years
Contact Email address, telephone Communication, notices, compliance with Art. 56 of the Law «On Copyright and Related Rights» Same Term of the Agreement + 3 years
Payment Payment details, transaction history, masked card number Settlements, accounting and tax records Performance of contract; compliance with tax obligations 1,095 days (limitation period under the Tax Code); accounting documents — per archival legislation
Verification A record of the check (date, ground, document type, outcome) and the purpose declaration. Document copies are not retained by default — they are deleted after the check (Section 7 of Annex 3) Verifying accuracy on the triggers in Section 3 of Annex 3; preventing unlawful use Performance of contract; compliance with part 1 of Art. 57 of the Law «On Copyright and Related Rights»; legitimate interest The record — term of the Agreement + 3 years. A document copy — only where retention is required by law or an authorised body, for the period of that requirement
Technical Client Area access IP addresses, time, device type, action logs Security, incident investigation, evidence The Provider's legitimate interest (service security) 12 months
Infrastructure logs Network connection logs, hypervisor logs Ensuring operability, incident investigation, responding to reports Legitimate interest; performance of obligations under Annex 2 12 months; under clause 8.5 of the Agreement — 90 days from suspension, and on an authorised body's demand — the period stated in the demand
Support requests Ticket text, attachments Providing support, evidence Performance of contract Term of the Agreement + 3 years
Marketing Email address Information about services and promotions Consent, revocable at any time Until consent is withdrawn

3.1. Provision of the data in rows 1–3 is a necessary condition for concluding the Agreement. Without it the Services cannot be provided.

3.2. The Provider does not carry out automated decision-making producing legal effects for a data subject without human involvement. Triggering of risk indicators under Annex 3 leads only to a request for a written explanation (the purpose declaration), not to an automated decision; the decision is taken by a member of the Provider's staff.

3.3. The Provider does not process special categories of Customers' personal data and does not request them.


4. Recipients of data

4.1. Categories of recipients:

Recipient What is shared Basis
Payment providers and banks Payment data, payer name Performance of contract
Domain registrars and registries Registrant data per registry rules Performance of contract, registry rules
Infrastructure Operators (OVHcloud, Hetzner, Scaleway, WorldStream, MevSpace, myLoc (WIIT AG) and others per the list at /legal/infrastructure) Technical data needed to host equipment; upon the Operator's demand when processing a complaint — the Customer's identification and contact details Performance of contract; legitimate interest (abuse prevention)
Connectivity providers Network data Performance of contract
Billing and support system vendor Registration, contact and payment data, tickets Performance of contract, processing agreement
Auditors, legal advisers Where necessary, to the minimum extent Legitimate interest
State authorities Under Section 16 of the Agreement and Annex 6 Compliance with a legal obligation
Claimant under Article 56 of the Law «On Copyright and Related Rights» Customer contact details to the extent set out in part 12 of Art. 56 Express statutory requirement

4.2. The Provider does not sell personal data and does not share it with third parties for their own independent marketing purposes.

4.3. Cross-border transfers. A substantial part of the Services is delivered using Infrastructure Operators' equipment located outside Ukraine — primarily in European Union member states (in particular Germany, France, the Netherlands and Poland). The current list of Operators and countries is at /legal/infrastructure.

Basis for transfers. Part three of Article 29 of the Law of Ukraine «On Personal Data Protection» expressly provides that states party to the European Economic Area, and states that have signed the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, «визнаються такими, що забезпечують належний рівень захисту персональних даних». Germany, France, the Netherlands, Poland and Finland are EEA states, so transfers to them are made without additional conditions.

Transfers to countries not recognised as ensuring an adequate level of protection are made on the basis of the safeguards provided by Article 29 of that Law and Chapter V GDPR. The Provider does not place equipment in such countries without giving the Customer prior notice under clause 5.11 of the Agreement. The list of countries where infrastructure is located is published on the website and provided on request to admin@zevshost.net.

4.4. Access to Customer Content. The Provider's staff access Content solely:
1) at the Customer's direct request to technical support — to the extent necessary to resolve the request;
2) to perform obligations under Article 56 of the Law «On Copyright and Related Rights» — to the extent identified in the notice;
3) to verify a report under Annex 2 — to the extent necessary to confirm or refute the infringement;
4) to remedy an incident threatening the infrastructure;
5) to comply with a binding decision of an authorised body.

Every such access is logged with the staff member, time, ground and scope. The access log is provided to the Customer on request.


5. Data subject rights

5.1. A data subject has the right:

Right Content Response time
To information To know the composition and content of their data, the purposes and the recipients 30 calendar days
Of access To obtain a copy of their data 30 calendar days
To rectification To have inaccurate data corrected 10 business days
To erasure To have data erased where no basis for further processing exists 10 business days
To restriction To have processing restricted pending review of an objection 10 business days
To object To object to processing based on legitimate interest 30 calendar days
To withdraw consent To withdraw consent to marketing messages Immediately
To portability (GDPR) To receive data in a structured, machine-readable format 30 calendar days
To complain To apply to the Ukrainian Parliament Commissioner for Human Rights or an EU supervisory authority

5.2. Requests are sent to admin@zevshost.net. The Provider verifies the requester's identity before disclosing data.

5.3. The right to erasure does not apply to data the Provider is required by law to retain (tax and accounting records) or that is necessary for defence in a dispute — until the relevant periods expire.

5.4. In respect of data hosted by the Customer on the provided resources, the data subject should approach the Customer directly as controller. On receiving such a request the Provider forwards it to the Customer within 5 business days and informs the requester accordingly.


6. Security

6.1. The Provider applies organisational and technical safeguards:

6.2. Personal data breach. Where a breach creates a risk to data subjects' rights, the Provider:
1) remedies the cause and contains the consequences;
2) notifies affected Customers — within 72 hours of detection;
3) for data subjects in the EU — notifies the competent supervisory authority within the period set by Article 33 GDPR;
4) records the circumstances, consequences and measures taken.

6.3. Where a breach occurs within the Customer's area of responsibility (on its resources), the notification duty rests with the Customer. The Provider supplies the technical information needed for the investigation.


7. Cookies

7.1. The website and Client Area use:

Category Purpose Basis
Strictly necessary Session, authentication, security, language and currency selection Necessary to provide the service
Analytics Anonymised visit statistics Consent
Marketing Measuring advertising effectiveness Consent

7.2. Consent for analytics and marketing cookies is requested separately and may be withdrawn at any time in the website settings.


8. Children

8.1. The Services are not intended for persons under 18. The Provider does not knowingly collect such persons' data. Where identified, such data is deleted.


9. Amendments

9.1. Amendments are published and take effect in the manner set out in Section 21 of the Agreement.

9.2. Customers are separately notified of material changes (expansion of processing purposes, new categories of recipients) at least 30 calendar days in advance.