Applies to: All plans
This article summarises how we handle your personal data under the EU General Data Protection Regulation (GDPR), where we host it, and how to exercise your data rights. It is a plain-English overview — the authoritative versions are the full Privacy Policy, Data Processing Agreement (DPA) and Subprocessors list published on maxinodes.com. Where those documents and this summary ever differ, the documents on maxinodes.com apply.
Where is my data hosted?
Your websites, databases and mailboxes are hosted in the Netherlands (EU) on infrastructure provided by Worldstream, and your sites are served straight from those servers — no CDN or proxy sits in front of them. Our hosting nodes run CloudLinux 9 with cPanel, LiteSpeed and a ModSecurity web application firewall; malware scanning on the node matches local signatures only, and no file of yours is uploaded anywhere for analysis. Incoming mail is scored for spam on the node itself (ImunifyEmail), and spam is filtered into your Junk folder; before that, mail from known spam sources is refused by looking up the sending server's IP address on a DNS blocklist, and only that IP address is sent for the check, never the message. For more on the platform, see Datacentres and infrastructure (Worldstream, CloudLinux 9).
Several services we rely on sit outside those hosting nodes. This is where each of them is:
- DNS is managed by us, on our own nameservers, running on the global anycast network of BunnyWay d.o.o. (Bunny.net), a company established in Slovenia (EU). Your zone is created automatically, and you manage records in the client area.
- Backups are taken with JetBackup and stored with Backblaze in Amsterdam (EU). They include your mailboxes, and they are encrypted at rest (AES-256) by the storage provider.
- Outgoing mail from your mailboxes and websites is relayed to its recipients through MailChannels Corporation, a company established in Canada, whose relay infrastructure is in the United States. It receives each message in full and filters it for spam and abuse on the way; it deletes the content once the message is delivered and keeps delivery metadata (sender, recipient, subject, sending IP address and account) for logging and abuse handling. Mail you receive, and the mail stored in your mailboxes, does not pass through it.
- Professional Email, the optional upgrade, runs on Microsoft 365 or Google Workspace — those mailboxes and their contents live in your own tenant with Microsoft or Google, not on our servers.
- Support — tickets, chat, this Help Center, the contact form on maxinodes.com, and mail to support@, privacy@ and abuse@maxinodes.com — runs on a helpdesk operated by Zendesk, Inc., a Delaware corporation in the United States. Our account's data currently sits in Zendesk's Europe (Ireland) region, but we have not bought the option that would turn that into a contractual commitment, and Zendesk's US operations and its own US providers can reach it. Nothing from your hosting account is sent there — only what you write to us, and anything you choose to attach. This Help Center is served by Zendesk's own edge network, which is Cloudflare, so pages here set cookies that are not ours.
- Our own websites and the client area at my.maxinodes.com are served through Microsoft Azure Front Door, a global edge network that terminates the connection, caches our marketing pages and logs request metadata — IP address, user agent, URL — into a Microsoft workspace in West Europe for 30 days. It sets no cookies. The websites we host for you are not behind it. Microsoft also answers DNS for our own maxinodes domains and runs our own mail platform in the EU. Microsoft Corporation, the group parent, is established in the United States.
- The rest: invoices and account email from the client area are sent through Postmark, a transactional-email service run from the United States; domains you register through us are handled by Key-Systems GmbH (Germany); our status page and monitoring run on UptimeRobot (Slovakia); and cryptocurrency payments are taken on NOWPayments' own hosted page, which collects your payment data directly from you under its own policy rather than on our instructions.
The short version: what you host with us, including your mailboxes, is stored in the EU. Email you send passes through our relay provider, MailChannels (Canada, with relay infrastructure in the United States), on its way to the recipient. What you send us in a support message goes into a helpdesk run by a US company — its data for our account currently sits in Zendesk's Ireland region, but that is today's arrangement rather than a commitment we have bought, and Zendesk's US side can reach it. That is why we ask you never to paste passwords or identity documents into it.
Every provider we rely on to deliver the service is named on our Subprocessors page on maxinodes.com, with what it does, where it processes data and, where that is outside the EEA, the safeguard we rely on for the transfer.
What is the difference between the Privacy Policy and the DPA?
The Privacy Policy covers data we process about you as a customer; the Data Processing Agreement (DPA) covers personal data you process about your visitors and users that passes through our platform. In GDPR terms, for your own customer data we act as a controller, and for the data inside your hosting account we act as a processor on your instructions.
- The Privacy Policy explains what we collect when you sign up and use the client area (for example your account, billing and support details), why, and who we share it with.
- The DPA sets out how we process the personal data inside your hosting account on your behalf, including security measures and the use of subprocessors. If your business needs a signed DPA, the terms are published on maxinodes.com — contact us if you need a copy on file.
Who are your subprocessors?
A subprocessor is a third party we use to help deliver the service that may process personal data — for example the infrastructure, DNS, backup, outgoing-mail relay, helpdesk, edge, transactional-email and registrar providers named above. The current, authoritative list is on the Subprocessors page on maxinodes.com, where each one is named individually, rather than described by category. We keep it there so it stays up to date as providers change; the same page explains how we notify you of a change and how to object to a new provider.
How do I exercise my data rights?
Under the GDPR you have rights over your personal data — including access, rectification, erasure, restriction, portability and objection. To exercise any of them, email privacy@maxinodes.com, which is the route set out in our Privacy Policy. Tell us what you want and which account it relates to. We may need to verify your identity before we act, but please do not attach identity documents unless we ask for them: mail to privacy@ is forwarded into our helpdesk at Zendesk — a US company, however its regions are configured — exactly like an ordinary support message.
If you would rather your request did not pass through a third-party helpdesk, email billing@maxinodes.com, which reaches us directly, or write to us by post at the address in our company information. We answer within one month either way. The full process, including how we handle requests and the time limits that apply, is described in the Privacy Policy on maxinodes.com.
If you want to update your own account details directly, you can do so any time in client area -> account/profile menu (top right). See How to manage your contacts and sub-users on your account.
Where do I read the full policies?
All of our data-protection documents — the Privacy Policy, Data Processing Agreement, Subprocessors list and Cookie Policy — are published in full on maxinodes.com. Our company and contact details are on the Imprint page; see Company details and imprint.
Comments
0 comments
Please sign in to leave a comment.