Applies to: All plans
This article summarises how we handle your personal data under the EU General Data Protection Regulation (GDPR), where we host it, and how to exercise your data rights. It is a plain-English overview — the authoritative versions are the full Privacy Policy, Data Processing Addendum (DPA) and Subprocessors list published on maxinodes.com. Where those documents and this summary ever differ, the documents on maxinodes.com apply.
Where is my data hosted?
Your websites and databases are hosted in the EU on infrastructure provided by Worldstream. Our hosting nodes run AlmaLinux 9 with cPanel, CloudLinux, LiteSpeed and a ModSecurity web application firewall. For more on the platform, see Datacentres and infrastructure (Worldstream, AlmaLinux 9).
A few related services sit outside our hosting nodes and may process data on your behalf:
- DNS is managed by us, on our own nameservers, running on a global anycast DNS network (provided by Bunny.net). Your zone is created automatically, and you manage records in the client area.
- Backups are taken with JetBackup and stored in Backblaze B2.
- Professional Email is resold Microsoft 365 or Google Workspace — your mailboxes and their contents live with Microsoft or Google, in their environments, not on our servers.
These providers, and any others we rely on to deliver the service, are listed on our Subprocessors page on maxinodes.com.
What is the difference between the Privacy Policy and the DPA?
The Privacy Policy covers data we process about you as a customer; the Data Processing Addendum (DPA) covers personal data you process about your visitors and users that passes through our platform. In GDPR terms, for your own customer data we act as a controller, and for the data inside your hosting account we act as a processor on your instructions.
- The Privacy Policy explains what we collect when you sign up and use the client area (for example your account, billing and support details), why, and who we share it with.
- The DPA sets out how we process the personal data inside your hosting account on your behalf, including security measures and the use of subprocessors. If your business needs a signed DPA, the terms are published on maxinodes.com — contact us if you need a copy on file.
Who are your subprocessors?
A subprocessor is a third party we use to help deliver the service that may process personal data — for example our infrastructure, DNS, backup and email providers named above. The current, authoritative list is on the Subprocessors page on maxinodes.com. We keep it there so it stays up to date as providers change.
How do I exercise my data rights?
Under the GDPR you have rights over your personal data — including access, rectification, erasure, restriction, portability and objection. To exercise any of them, start a chat or email support from your client area with your request and your account details, so we can verify your identity before we act. The full process, including how we handle requests and the time limits that apply, is described in the Privacy Policy on maxinodes.com.
If you want to update your own account details directly, you can do so any time in client area -> account/profile menu (top right). See How to manage your contacts and sub-users on your account.
Where do I read the full policies?
All of our data-protection documents — the Privacy Policy, Data Processing Addendum, Subprocessors list and Cookie Policy — are published in full on maxinodes.com. Our company and contact details are on the Imprint page; see Company details and imprint.
Comments
0 comments
Please sign in to leave a comment.