Demos ↓

EU hosting and GDPR: the five questions a website owner should ask

Short answer: if your site collects even one name from a form, you are a controller of personal data and your host is a processor. The GDPR requires a written contract with the processor (Art. 28) and care when transferring data outside the EU (Chapter V). Here are the five questions and how we handle them.

Where are the servers physically?

Ours — in Hetzner data centres in Germany and Finland. Data never leaves the European Union, so you need no additional safeguards for transfers to third countries.

With “cloud” platforms outside the EU you must ask explicitly: where data is stored, where backups are made and whose servers the forms pass through.

Is there a data processing agreement?

Art. 28 of the GDPR requires the controller and the processor to have a written contract with specific content: subject matter, duration, types of data, security obligations, sub-processors. We provide such an agreement (DPA) on request with every hosting package.

If your provider cannot show such a document, that is an answer in itself.

Which cookies and tracking are there?

By default — none. The demos and the portfolio have no cookies, no Google Analytics and no external scripts; that is why they have no consent banner either. If you want analytics, we offer a privacy-first option that needs no consent, or the classic one with a proper banner.

The rule is simple: do not collect what you do not need, and you will have nothing to lose.

Who has access to the server and how?

Access is by SSH key only, no passwords, for a limited circle of people, with fail2ban against automated attempts. System updates are automatic, backups daily, kept for 30 days on a separate server.

These are the concrete measures under Art. 32 (security of processing) that you can also describe in your own record of processing activities.

What happens if you terminate?

You get all code and data as an archive, free of charge, and the site can run anywhere. Data on the server is deleted after your confirmation; backups expire on schedule.

This is not legal advice — for your own records and policies consult a lawyer. We provide the technical part and the documents for it.

// Sources
  1. Регламент (ЕС) 2016/679 (GDPR) — чл. 28 (обработващ) и глава V (предаване извън ЕС), EUR-Lex
  2. Hetzner — центрове за данни в Германия и Финландия

Quote configurator All articles

// More articles