1. Introduction
HostYourAI B.V. ("we", "us", "our") respects the privacy of all users of its services and website. This privacy policy applies to all services of HostYourAI B.V. and describes what personal data we collect, how we process it, and what rights you have.
HostYourAI B.V. is established in the Netherlands and falls under the General Data Protection Regulation (GDPR). We are responsible for the processing of personal data as described in this privacy policy.
2. Contact Details
HostYourAI B.V.
Email: privacy@hostyourai.com
Website: https://hostyourai.com
Chamber of Commerce: [Number]
VAT Number: [Number]
3. What Personal Data Do We Collect?
3.1 Account Data
When registering for our services, we collect:
- Name (first and last name)
- Email address
- Company name (optional)
- Country
- Password (stored encrypted)
3.2 Payment Data
For processing payments, we collect:
- Billing address
- VAT number (for business customers)
- Payment history
Credit card and bank details are never stored by us. These are processed directly by our payment processor Stripe, which is PCI-DSS Level 1 certified.
3.3 Usage Data
When using our services, we collect:
- API calls and logs (anonymized after 30 days)
- IP addresses
- Browser type and version
- Time of access
- Features and services used
4. Why Do We Process This Data?
4.1 Contract Execution
We process data to:
- Create and manage your account
- Provide access to our AI hosting services
- Process payments and send invoices
- Provide technical support
4.2 Legitimate Interests
Based on legitimate interests, we process data for:
- Security and fraud prevention
- Improvement of our services
- Analysis of usage patterns (anonymized)
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Up to 2 years after account termination |
| Payment data | 7 years (legal requirement) |
| API logs | 30 days (then anonymized) |
| Support communication | 3 years after last contact |
6. Who Do We Share Data With?
6.1 Processors
We use the following processors:
- Stripe (Ireland): Payment processing
- Hetzner (Germany): Server hosting
- Mailgun (EU): Email services
We have Data Processing Agreements (DPAs) in place with all these parties.
6.2 No Transfer Outside the EU
Important: We never transfer your personal data to parties outside the European Union.
7. Your Rights
Under the GDPR, you have the following rights:
- Right of access: Know what data we process about you
- Right to rectification: Correct inaccurate data
- Right to erasure: Request deletion of your data
- Right to restriction: Limit processing of your data
- Right to data portability: Receive your data in a structured format
- Right to object: Object to processing based on legitimate interests
8. Security
We take the security of your data very seriously:
- Encryption: AES-256 for data at rest, TLS 1.3 for data in transit
- Compliance: GDPR compliant
- Data centers: Tier III+ certified EU data centers
9. Contact
For questions about this privacy policy or to exercise your rights:
Email: privacy@hostyourai.com
Response time: Within 30 days