Data protection

GDPR & Data Protection

How the GDPR applies to ARA’s hosting services — and how we support your own compliance.

Last updated: September 2026
Draft template — review before publishing. This data-protection page is a starting point for an EU hosting business. Complete the items marked [in brackets] — especially your sub-processor list and DPA — make sure it reflects how you operate, and have it reviewed by a qualified professional before you publish. Delete this note once done.

1. Our commitment to data protection

ARA is committed to protecting personal data and complying with the EU General Data Protection Regulation (GDPR). We are based in the EU, host in EU data centres, and keep data collection to a minimum.

This page explains how the GDPR applies to our services and how we support your own compliance. For the personal data we collect about you as our customer, please see our Privacy Policy.

2. Controller and processor: who is responsible

Under the GDPR it matters who decides why and how personal data is processed. With our services there are two distinct roles:

ARA is the controller

Your account data

For the personal data we collect to run our services — your name, contact details, billing and account data — ARA is the data controller. How we handle it is set out in our Privacy Policy.

You are the controller · ARA is your processor

Data on your server

For personal data you store or process on your server or applications, you are the controller and ARA acts as a processor. As our service is unmanaged, we process it only to provide the hosting — we don’t access or manage your server’s contents except on your instruction or to protect the platform.

Understanding this split is important: we look after the platform and the account data we hold, while you remain responsible for the personal data you choose to run on your server.

3. Data Processing Agreement (DPA)

If you process personal data on our infrastructure, GDPR Article 28 requires a data processing agreement (DPA) between us. We make a DPA available that covers the subject-matter and duration of processing, its nature and purpose, the types of personal data and categories of data subjects, and our obligations as your processor.

To request or sign our DPA, contact us at info@araservers.com. [If you have a standard DPA document, link it here for customers to download.]

4. Sub-processors

To deliver our services we use a limited number of sub-processors. Each is bound by a data processing agreement and processes data only as needed to provide our services:

Sub-processor Purpose Location
[Data-centre provider, e.g. Hetzner Online GmbH] Server hosting & infrastructure Germany / Finland / Niederland (EU)
[Payment provider] Payment processing [EU, or with SCCs/adequacy]
[Billing & client-area software] Orders, invoices & support tickets [EU, or with SCCs/adequacy]

We keep this list current and will inform customers of material changes to our sub-processors so you can raise any objection. [Keep this list accurate and up to date.]

5. Where your data is processed

We process and store data within the European Union (Germany and Finland). Where any sub-processor would transfer personal data outside the EU/EEA, we rely on appropriate safeguards such as an adequacy decision or the European Commission’s Standard Contractual Clauses. [Confirm this matches your actual providers.]

6. Security measures

We apply appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS/TLS) to our website and client area, access controls and authentication, network-level DDoS protection, and physical security at our data-centre providers.

Security inside your own server — its operating system, applications, encryption and backups — is your responsibility under our unmanaged model.

7. Data subject rights

Individuals have rights under the GDPR, including access, rectification, erasure, restriction, portability and objection. Where a request goes depends on who controls the data:

  • If it concerns data ARA holds as controller (your account data), contact us and we’ll handle it — see our Privacy Policy.
  • If it concerns data held on a customer’s server, the customer is the controller and is responsible for responding. As your processor, we will assist you, so far as reasonably possible, in responding to data subject requests relating to data on your server.

8. Data breaches

We maintain procedures to detect and respond to personal data breaches. If a breach affecting personal data we control is likely to result in a risk to individuals, we will notify the relevant supervisory authority and affected individuals as required by the GDPR.

Where we act as your processor, we will notify you without undue delay after becoming aware of a breach affecting personal data you process on our infrastructure, so that you can meet your own notification obligations as controller.

9. Your responsibilities as a controller

When you process personal data on our infrastructure, you are the controller and remain responsible for:

  • having a valid legal basis for your processing;
  • providing your own privacy notices to your users;
  • configuring and securing your server, applications and access;
  • maintaining your own backups and records of processing;
  • responding to data subject requests relating to your data.

We provide the infrastructure; lawful use of it is down to you.

10. Complaints & supervisory authority

If you believe we have not handled your personal data properly, please contact us first so we can put it right. You also have the right to lodge a complaint with a data protection supervisory authority.

For a business established in North Rhine-Westphalia this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). [Confirm the authority that applies to your registered establishment.]

11. Contact

For any data protection or GDPR question, or to request our DPA, get in touch. [If you have appointed a Data Protection Officer, add their details here.]

Email   info@araservers.com

Phone   +49

Post   Bochum, Deutschland