GrandHosting is built from the ground up with European data protection principles at its core. Here’s how we uphold your privacy.
Our Approach
The General Data Protection Regulation is the world’s strongest framework for protecting personal data. As a European company hosting European customers, we don’t just comply with GDPR — we embrace it as a design principle.
Every architectural decision we make, from where we place our servers to how we structure our database, considers data protection first. We collect only what we need, store it only where it’s safe, and give you full control over it at all times.
Data Residency
All of your website data — files, databases, backups, and media — is stored exclusively within the European Union. Our servers are operated by EU infrastructure in Germany, home to some of the strictest data protection laws in the world. Our data centers are ISO 27001 certified.
This means your data never leaves the EU for core hosting operations. There are no US-based servers, no data mirroring to non-EU regions, and no “we’ll try to keep it in the EU” caveats. It’s EU-only by design.
Under the GDPR, you have powerful rights over your personal data. Here’s what they mean in plain language.
Request a complete copy of all personal data we hold about you. We’ll provide it in a structured, readable format within 30 days.
If any of your data is inaccurate or incomplete, let us know and we’ll correct it promptly.
Request deletion of your personal data. We’ll erase it from all systems, subject only to legal retention obligations (like tax records).
Receive your data in a machine-readable format (JSON, SQL, archives) so you can move to another provider with zero lock-in.
Ask us to pause certain processing activities while you verify accuracy or contest our legal basis.
Object to processing based on legitimate interest. We’ll stop unless we can demonstrate compelling grounds that override your rights.
If you gave consent for any specific processing, you can withdraw it at any time. Withdrawal doesn’t affect the lawfulness of prior processing.
Send a request to our Data Protection Officer. We respond within 30 days, free of charge.
dpo@grandhosting.grWe only share data with providers who are essential to running the platform. Each is bound by a Data Processing Agreement.
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| EU Infrastructure Provider | Servers, networking, compute infrastructure | Germany | EU-based, ISO 27001, SOC 1 Type II |
| GrandHosting CDN | Media file delivery and caching | EU edge nodes | EU company (Slovenia), GDPR compliant |
| GrandHosting Backup Storage | Backup storage | EU region | EU data region, encryption at rest |
| Supabase | User authentication, platform database | EU region | SOC 2 Type II, EU hosting option |
| Stripe | Payment processing | Ireland (EU) | PCI DSS Level 1, SCCs in place |
| GrandHosting SMTP | Transactional email delivery | US (with EU handling) | SCCs, minimal data (email + subject only) |
| Sentry | Error tracking and monitoring | EU data region | SOC 2, EU data residency, data scrubbing |
Security Measures
Security isn’t a feature we bolted on — it’s woven into our architecture. Every website runs in complete isolation, and we layer multiple defenses to keep your data safe.
TLS 1.2+ for all data in transit. Encrypted storage for data at rest. Automatic SSL certificates via Let’s Encrypt.
Every website runs in its own isolated environment with dedicated resources. No shared processes, no data leakage between sites.
Automated scanning runs nightly across all sites. Suspicious files are flagged and reported immediately.
Automated daily backups with 30-day retention. Stored encrypted on secure EU storage in the EU.
Least-privilege access policies. No shared credentials. Role-based access for all platform operations.
Prometheus metrics, Loki log aggregation, and 13 alert rules watching for anomalies 24/7.
Breach Notification
In the unlikely event of a personal data breach, we are committed to full transparency. In accordance with GDPR Article 33, we will:
We maintain an incident response plan that is tested and updated regularly. Our engineering team monitors for security events around the clock.
Contact
Whether you have a question, a request, or a concern about how we handle your data, our DPO is here to help.
Email dpo@grandhosting.grYou can also review our Privacy Policy and Data Processing Agreement for the full legal details.
Early access pricing stays yours forever. Create a free demo site — no credit card, no contracts.
Create Free Demo Site