# ANNEX 4
# PERSONAL DATA PROCESSING POLICY

to the Public Agreement (Offer) for the Provision of Hosting Services by LLC «HOST VDS»

Version **1.0** of **17 September 2026**

---

> **This is a translation.** The authentic version is the Ukrainian one
> (<https://www.zevshost.net/legal/privacy>). In case of discrepancy, the Ukrainian text prevails.

<!-- -->

## 1. Who processes the data

**Controller:** LLC «HOST VDS», identification code 37884379, 01021, м. Київ, вул. Мечникова, буд. 8, кімн. 22, Печерський район.

**Data protection contact:** admin@zevshost.net.

**Applicable law:** the Law of Ukraine «On Personal Data Protection» No. 2297-VI. For
data subjects located in the European Union, Regulation (EU) 2016/679 (GDPR) applies
additionally on the basis of Article 3(2) of the Regulation.

---

## 2. The Provider's two roles — the key distinction

> This is the most important section of this Policy. It defines what the Provider is
> responsible for and what the Customer is responsible for.

### 2.1. The Provider as **controller**

In respect of the personal data of **the Customer itself** and its representatives:
registration, contact and payment data, support requests, and Client Area access logs.

The Provider determines the purposes and means of processing this data, bears
controller obligations and is answerable to data subjects.

### 2.2. The Provider as **processor**

In respect of personal data that the **Customer itself hosts, collects or processes**
using the provided resources: data of visitors to the Customer's sites, customer
databases, mailbox contents, and the Customer's application databases.

The Provider:
- processes such data **purely technically** — storing it, keeping it available and
  transmitting it as part of providing the Service;
- **does not determine** the purposes or means of its processing;
- **has no access** to its content, save in the cases set out in clause 4.4;
- acts solely on the Customer's instructions, the instruction being the very act of
  placing the data on the provided resources.

**The Customer is the controller of that data** and is solely responsible for:
- ensuring a legal basis for processing;
- discharging information duties towards data subjects;
- responding to data subject requests;
- notifying personal data breaches where required by law;
- liability towards data subjects and supervisory authorities.

**2.3.** The provisions of this Annex concerning the processor role constitute an
instruction to process personal data within the meaning of **part four of Article 4**
of the Law of Ukraine «On Personal Data Protection» (a controller «може доручити
обробку персональних даних розпоряднику персональних даних відповідно до договору,
укладеного в письмовій формі») and a processing agreement within the meaning of
Article 28 GDPR.

Acceptance of the Agreement under Section 3 of the Agreement extends to this Annex.
Where the Customer needs a document with the legal effect of one concluded **in
written form**, the Provider will on request conclude a separate data processing
agreement (DPA) signed in the manner set out in Article 12 of the Law of Ukraine «On
Electronic Commerce» — in particular by electronic signature with a one-time
identifier. Under part twelve of Article 11 of that Law such an electronic contract
«за правовими наслідками прирівнюється до договору, укладеного у письмовій формі».
Requests to admin@zevshost.net.

---

## 3. Customer data: what, why, on what basis

| Category | Content | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| **Identification** | Name, identification code, address | Conclusion and performance of the Agreement; compliance with part 1 of Art. 57 of the Law «On Copyright and Related Rights» | Art. 11 of Law 2297-VI (performance of contract; compliance with a controller obligation); Art. 6(1)(b), 6(1)(c) GDPR | Term of the Agreement + 3 years |
| **Contact** | Email address, telephone | Communication, notices, compliance with Art. 56 of the Law «On Copyright and Related Rights» | Same | Term of the Agreement + 3 years |
| **Payment** | Payment details, transaction history, masked card number | Settlements, accounting and tax records | Performance of contract; compliance with tax obligations | **1,095 days** (limitation period under the Tax Code); accounting documents — per archival legislation |
| **Verification** | **A record of the check** (date, ground, document type, outcome) and the purpose declaration. **Document copies are not retained by default** — they are deleted after the check (Section 7 of Annex 3) | Verifying accuracy on the triggers in Section 3 of Annex 3; preventing unlawful use | Performance of contract; compliance with part 1 of Art. 57 of the Law «On Copyright and Related Rights»; legitimate interest | The record — term of the Agreement + 3 years. A document copy — only where retention is required by law or an authorised body, for the period of that requirement |
| **Technical** | Client Area access IP addresses, time, device type, action logs | Security, incident investigation, evidence | The Provider's legitimate interest (service security) | **12 months** |
| **Infrastructure logs** | Network connection logs, hypervisor logs | Ensuring operability, incident investigation, responding to reports | Legitimate interest; performance of obligations under Annex 2 | **12 months**; under clause 8.5 of the Agreement — **90 days** from suspension, and on an authorised body's demand — the period stated in the demand |
| **Support requests** | Ticket text, attachments | Providing support, evidence | Performance of contract | Term of the Agreement + 3 years |
| **Marketing** | Email address | Information about services and promotions | **Consent**, revocable at any time | Until consent is withdrawn |

**3.1.** Provision of the data in rows 1–3 is a necessary condition for concluding the
Agreement. Without it the Services cannot be provided.

**3.2.** The Provider **does not carry out automated decision-making** producing legal
effects for a data subject without human involvement. Triggering of risk indicators
under Annex 3 leads only to a request for a written explanation (the purpose
declaration), not to an automated decision; the decision is taken by a member of the
Provider's staff.

**3.3.** The Provider does not process special categories of Customers' personal data
and does not request them.

---

## 4. Recipients of data

**4.1. Categories of recipients:**

| Recipient | What is shared | Basis |
|---|---|---|
| Payment providers and banks | Payment data, payer name | Performance of contract |
| Domain registrars and registries | Registrant data per registry rules | Performance of contract, registry rules |
| **Infrastructure Operators** (OVHcloud, Hetzner, Scaleway, WorldStream, MevSpace, myLoc (WIIT AG) and others per the list at `/legal/infrastructure`) | Technical data needed to host equipment; upon the Operator's demand when processing a complaint — the Customer's identification and contact details | Performance of contract; legitimate interest (abuse prevention) |
| Connectivity providers | Network data | Performance of contract |
| Billing and support system vendor | Registration, contact and payment data, tickets | Performance of contract, processing agreement |
| Auditors, legal advisers | Where necessary, to the minimum extent | Legitimate interest |
| State authorities | Under Section 16 of the Agreement and Annex 6 | Compliance with a legal obligation |
| Claimant under Article 56 of the Law «On Copyright and Related Rights» | Customer contact details to the extent set out in part 12 of Art. 56 | **Express statutory requirement** |

**4.2.** The Provider does not sell personal data and does not share it with third
parties for their own independent marketing purposes.

**4.3. Cross-border transfers.** A substantial part of the Services is delivered
using Infrastructure Operators' equipment located outside Ukraine — primarily in
European Union member states (in particular Germany, France, the Netherlands and
Poland). The current list of Operators and countries is at `/legal/infrastructure`.

**Basis for transfers.** Part three of Article 29 of the Law of Ukraine «On Personal
Data Protection» expressly provides that states party to the European Economic Area,
and states that have signed the Council of Europe Convention for the Protection of
Individuals with regard to Automatic Processing of Personal Data, «**визнаються
такими, що забезпечують належний рівень захисту персональних даних**». Germany,
France, the Netherlands, Poland and Finland are EEA states, so transfers to them are
made **without additional conditions**.

Transfers to countries not recognised as ensuring an adequate level of protection are
made on the basis of the safeguards provided by Article 29 of that Law and Chapter V
GDPR. The Provider does not place equipment in such countries without giving the
Customer prior notice under clause 5.11 of the Agreement.
The list of countries where infrastructure is located is published on the website and
provided on request to admin@zevshost.net.

**4.4. Access to Customer Content.** The Provider's staff access Content solely:
1) at the Customer's direct request to technical support — to the extent necessary to
   resolve the request;
2) to perform obligations under Article 56 of the Law «On Copyright and Related
   Rights» — to the extent identified in the notice;
3) to verify a report under Annex 2 — to the extent necessary to confirm or refute the
   infringement;
4) to remedy an incident threatening the infrastructure;
5) to comply with a binding decision of an authorised body.

Every such access is logged with the staff member, time, ground and scope. The access
log is provided to the Customer on request.

---

## 5. Data subject rights

**5.1.** A data subject has the right:

| Right | Content | Response time |
|---|---|---|
| To information | To know the composition and content of their data, the purposes and the recipients | 30 calendar days |
| Of access | To obtain a copy of their data | 30 calendar days |
| To rectification | To have inaccurate data corrected | 10 business days |
| To erasure | To have data erased where no basis for further processing exists | 10 business days |
| To restriction | To have processing restricted pending review of an objection | 10 business days |
| To object | To object to processing based on legitimate interest | 30 calendar days |
| To withdraw consent | To withdraw consent to marketing messages | Immediately |
| To portability (GDPR) | To receive data in a structured, machine-readable format | 30 calendar days |
| To complain | To apply to the Ukrainian Parliament Commissioner for Human Rights or an EU supervisory authority | — |

**5.2.** Requests are sent to admin@zevshost.net. The Provider verifies the requester's
identity before disclosing data.

**5.3.** The right to erasure does not apply to data the Provider is required by law to
retain (tax and accounting records) or that is necessary for defence in a dispute —
until the relevant periods expire.

**5.4. In respect of data hosted by the Customer on the provided resources**, the data
subject should approach **the Customer directly** as controller. On receiving such a
request the Provider forwards it to the Customer within 5 business days and informs the
requester accordingly.

---

## 6. Security

**6.1.** The Provider applies organisational and technical safeguards:

- encryption of transmission channels (TLS) for the Client Area, mail and ticket
  system;
- encryption of the verification document store;
- access segregation on a least-privilege basis;
- mandatory two-factor authentication for staff with access to personal data;
- logging of access to personal data;
- regular software updates and vulnerability management;
- written confidentiality undertakings by staff;
- backups of the Provider's own systems with restore testing.

**6.2. Personal data breach.** Where a breach creates a risk to data subjects' rights,
the Provider:
1) remedies the cause and contains the consequences;
2) notifies affected Customers — **within 72 hours** of detection;
3) for data subjects in the EU — notifies the competent supervisory authority within
   the period set by Article 33 GDPR;
4) records the circumstances, consequences and measures taken.

**6.3.** Where a breach occurs within the Customer's area of responsibility (on its
resources), the notification duty rests with the Customer. The Provider supplies the
technical information needed for the investigation.

---

## 7. Cookies

**7.1.** The website and Client Area use:

| Category | Purpose | Basis |
|---|---|---|
| Strictly necessary | Session, authentication, security, language and currency selection | Necessary to provide the service |
| Analytics | Anonymised visit statistics | Consent |
| Marketing | Measuring advertising effectiveness | Consent |

**7.2.** Consent for analytics and marketing cookies is requested separately and may be
withdrawn at any time in the website settings.

---

## 8. Children

**8.1.** The Services are not intended for persons under 18. The Provider does not
knowingly collect such persons' data. Where identified, such data is deleted.

---

## 9. Amendments

**9.1.** Amendments are published and take effect in the manner set out in Section 21
of the Agreement.

**9.2.** Customers are separately notified of material changes (expansion of processing
purposes, new categories of recipients) at least 30 calendar days in advance.
