Privacy Policy
How ARA collects, uses and protects your personal data — and the rights you have over it.
On this page
- 1. Who we are
- 2. The data we collect
- 3. How and why we use your data
- 4. Cookies and analytics
- 5. Who we share your data with
- 6. Where your data is stored
- 7. How long we keep it
- 8. Data on your servers
- 9. How we protect your data
- 10. Your rights under the GDPR
- 11. Third-party links
- 12. Children’s privacy
- 13. Changes to this policy
- 14. How to contact us
1. Who we are
ARA (“we”, “us”, “our”) provides unmanaged virtual private servers, dedicated and GPU servers, and WordPress hosting to customers across the EU. We are the data controller responsible for the personal data described in this policy.
Our contact details:
- [*]
- Bochum, Deutschland
- Torronto, Canada
- Email: info@araservers.com
- Phone:
[If you have appointed a Data Protection Officer, add their contact details here.]
2. The data we collect
We collect only the data we need to provide our services:
- Account & contact data — your name, email address, postal address and phone number.
- Billing data — the details needed to take payment and issue invoices. Payments are handled by our payment provider; we do not store full card numbers.
- Order & service data — the products you order, your server configuration, and your client-area activity.
- Technical data — IP addresses, access and server logs, and basic device/browser information used to operate and secure the platform.
- Communications — the content of support tickets and emails you send us.
- Website data — cookies and usage information when you visit our website (see “Cookies and analytics” below).
3. How and why we use your data
We use your personal data for the purposes below, each with a legal basis under the GDPR:
- To provide and manage your services and client area — performance of our contract with you (Art. 6(1)(b)).
- To take payment and issue invoices — performance of a contract and compliance with legal (tax and accounting) obligations (Art. 6(1)(b) and (c)).
- To provide support and answer your enquiries — performance of a contract and our legitimate interests (Art. 6(1)(b) and (f)).
- To operate, secure and troubleshoot the platform, including logging and abuse prevention — our legitimate interests in running a secure service (Art. 6(1)(f)).
- To comply with legal obligations and respond to lawful requests — legal obligation (Art. 6(1)(c)).
- To send service-related notices — performance of a contract. For any marketing messages, only with your consent (Art. 6(1)(a)).
We do not sell your personal data, and we do not use it for automated decision-making that produces legal effects.
4. Cookies and analytics
Our website uses a small number of cookies:
- Essential cookies needed for the site and client area to function, such as login sessions.
- Analytics cookies [if used] to understand how the site is used — set only with your consent.
We keep tracking to a minimum. You can control or delete cookies in your browser settings; blocking essential cookies may stop parts of the site working. [If you use a specific analytics tool, name it here — ideally a privacy-friendly, EU-hosted option.]
5. Who we share your data with
We share personal data only with the parties needed to run our services, and only as far as necessary. These may include:
- Infrastructure providers — the data-centre and cloud providers whose hardware we use to deliver your servers (for example, [name your provider(s), e.g. Hetzner Online GmbH]). Your servers and data are hosted in EU data centres.
- Payment providers — to process payments securely (for example, [your payment processor(s)]).
- Our billing and client-area software — used to manage orders, invoices and support tickets.
- Professional advisers and authorities — where required by law, or to establish, exercise or defend legal claims.
Each provider acts as our processor under a data-processing agreement, or as an independent controller where it determines its own purposes (for example, payment providers). We do not share your data with anyone for their own marketing.
6. Where your data is stored
We host our services in data centres located within the European Union (Germany and Finland). Your account and server data are stored in the EU.
Where any provider we use would transfer personal data outside the EU/EEA, we ensure appropriate safeguards are in place, such as an adequacy decision or the European Commission’s Standard Contractual Clauses. [Confirm this matches your actual providers.]
7. How long we keep it
We keep personal data only as long as necessary:
- Account and service data — for the life of your account and for a reasonable period afterwards to handle queries and disputes.
- Invoicing and tax records — for the period required by law (in Germany, generally up to 10 years).
- Server logs and technical data — for a limited period for security and troubleshooting, then deleted or anonymised.
- Support communications — for as long as needed to assist you and for our records.
When your account is closed, your server and its contents are decommissioned and deleted after a short retention window — export anything you need before you cancel. [Set the specific retention periods that match how you operate.]
8. Data on your servers
Our services are unmanaged: you have full root or administrator access and full control of your server. For any personal data you store, process or transmit on your server or through your applications, you are the data controller and are responsible for handling it lawfully — including its security, its backups, and providing your own privacy notices to your users.
In providing the underlying infrastructure, we act as a processor for that data and access it only where you ask us to, or where strictly necessary to operate or protect the platform. This policy covers the data we collect from you to provide our services; it does not cover how you use your server.
9. How we protect your data
We protect the personal data we hold with appropriate technical and organisational measures, including encrypted connections (HTTPS) to our website and client area, access controls, and network-level protections such as DDoS mitigation at our providers.
No system is perfectly secure, but we work to keep your account data safe. Security inside your own server — its operating system, applications, users and backups — remains your responsibility under our unmanaged model.
10. Your rights under the GDPR
If you are in the EU/EEA, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, contact us at info@araservers.com. We will respond within the time limits set by the GDPR (generally one month).
You also have the right to lodge a complaint with a data protection supervisory authority. For a business established in North Rhine-Westphalia this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). [Confirm the authority that applies to your registered establishment.]
11. Third-party links
Our website and knowledge base may link to third-party websites. We are not responsible for the privacy practices or content of those sites; please review their own privacy policies.
12. Children’s privacy
Our services are intended for businesses and adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “last updated” date shown at the top. Where changes are significant, we will communicate them as appropriate.
14. How to contact us
If you have any questions about this policy or how we handle your data, or you want to exercise your rights, get in touch:
Email info@araservers.com
Phone +49
Post Bochum, Deutschland