🔥 Limited time: 50% off annual hosting + 30-day money-back + free migration. Code:
50OFFSTACK
🔒 GDPR & Data Protection
HostStack is committed to protecting the privacy and personal data of all customers — including those in the European Union, United Kingdom, and other regulated markets.
Last updated: May 4, 2026. This page explains how HostStack handles personal data for international customers, with a specific focus on EU/UK GDPR compliance. For our full Privacy Policy, see hoststack.in/privacy/. To request a Data Processing Agreement (DPA), visit hoststack.in/dpa/.
The General Data Protection Regulation (GDPR) is an EU law (Regulation 2016/679) that governs the processing of personal data of individuals located in the European Economic Area (EEA). The UK GDPR is the post-Brexit version that applies in the United Kingdom.
Although HostStack is incorporated and operates in India, GDPR applies to us when we offer services to people in the EU or UK, or monitor their behaviour. By providing web hosting to EU/UK customers, we are subject to GDPR's requirements.
This statement applies to:
When you sign up for a HostStack account, we act as the data controller for your personal information (name, email, billing details, support communications). We determine the purposes and means of processing your data.
When you host your website or application with us and your end-users interact with it, we act as a data processor on your behalf. You are the controller of your end-users' data; we only process it to provide the hosting service. A formal Data Processing Agreement (DPA) governs this relationship.
If you are a business customer and need us to sign a DPA for GDPR compliance, download our DPA template or email [email protected] with subject "DPA Request".
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, phone, address | Service delivery, billing, support |
| Billing data | Card type, last 4 digits, invoice history | Payment processing (via Razorpay/Stripe) |
| Usage data | Pages visited, plan selected, login times | Service improvement, fraud prevention |
| Technical data | IP address, browser type, OS | Security, uptime monitoring, abuse prevention |
| Support data | Ticket content, chat logs | Resolving support requests |
| Cookie data | Session ID, preferences | Essential site function; analytics with consent |
We rely on the following legal bases under Article 6 GDPR:
If you are an EU or UK resident, you have the following rights regarding your personal data:
Request a copy of all personal data we hold about you (Art. 15).
Correct inaccurate or incomplete personal data (Art. 16).
Request deletion of your data ("right to be forgotten") (Art. 17).
Ask us to pause processing of your data in certain circumstances (Art. 18).
Receive your data in a structured, machine-readable format (Art. 20).
Object to processing based on legitimate interests (Art. 21).
To exercise any of these rights, email us at [email protected] with subject line "GDPR Data Request". We will respond within 30 days (and sooner in most cases).
You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU) if you believe we have not handled your data correctly.
HostStack is based in India, which means personal data from EU/UK customers is transferred to a third country (India is not on the EU's adequacy list). We ensure such transfers are protected by:
Our primary data center is located in Kolkata, India. We are actively working to add EU-region server options to allow EU customers to keep their data within the EEA.
We use the following trusted third-party sub-processors who may access your personal data in the course of providing our services:
| Sub-processor | Purpose | Location |
|---|---|---|
| Razorpay | Payment processing | India (Mumbai) |
| Stripe | International card payments | USA (with EU DPA) |
| PayPal | International payment method | USA (with EU DPA) |
| WHMCS (client.hoststack.pro) | Billing & client portal | India |
| Cloudflare | DDoS protection, DNS, CDN | USA (with EU SCC) |
| Google Analytics | Website analytics (opt-in only) | USA (with EU SCC) |
| Tawk.to | Live chat support | USA (with GDPR DPA) |
| UptimeRobot | Infrastructure monitoring | USA |
All sub-processors are required to maintain appropriate GDPR-level data protection standards. We review this list quarterly.
Upon account deletion, we will erase all personal data within 30 days, unless retention is required by law.
We implement the following technical and organisational measures (TOMs) to protect your data:
In the event of a personal data breach affecting EU/UK customers, we will notify the relevant supervisory authority within 72 hours and affected customers without undue delay.
We use a granular cookie consent system that lets you control which cookies are set. On your first visit you will see our cookie preference panel.
For full details, see our Cookie Policy.
For all data protection enquiries, GDPR requests, or DPA requests, please contact:
Privacy & Data Protection
📧 [email protected] — Subject: "GDPR Data Request"
📍 HostStack, Bramapur Nath Para, Kolkata 700084, West Bengal, India
Response time: within 30 days (typically 3-5 business days)
You may also contact the relevant supervisory authority in your country:
Business customers can request our DPA — required for GDPR Article 28 compliance.
View our DPA Contact usFrom ₹149/mo • Shared • Cloud • VPS
✔ 30-day money-back • Free migration