Skip to content
HostOn

Legal

Privacy policy

We only process the data we genuinely need for our services – without advertising tracking, with statistics only if you consent and without selling data. Here you can find out in detail what happens to your data.

This translation is provided for convenience. The German version is legally binding. German version

Last updated: 5 October 2026HostOn · Alin Ghiorghiu, Kloten

The key points

  • Statistics only with consent

    We only load Google Analytics and Google Tag Manager if you agree in the cookie banner. We do not use advertising cookies and do not sell data.

  • Storage location

    Customer data is stored in a data centre in the EU (Romania), which is recognised as providing adequate data protection.

  • Few recipients

    Only where necessary: domain registries, certification authorities, Cloudflare and Google reCAPTCHA.

  • Your rights

    Access, rectification, erasure and objection – simply by email to datenschutz@hoston.ch.

01

Controller and contact

Controller
Alin Ghiorghiu, sole proprietorship (HostOn)
Address
Schürbungertweg 10, 8302 Kloten, Switzerland
UID
CHE-250.946.601
Data protection contact
datenschutz@hoston.ch

This privacy policy applies to the websites hoston.ch and my.hoston.ch, our services (web hosting, WordPress hosting, VPS, email, domains, SSL), support and any other contact with us. It is based on the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

We are a small business and have not appointed a data protection advisor; requests are handled personally by the owner.

02

When we are responsible – and when you are

We are responsible for the data about you as a prospective or existing customer (account, contracts, invoices, support).

You are responsible for data that you as a customer store in your websites, databases, mailboxes or servers – for example data of visitors to your website or of your online shop customers. We process this data only on your behalf (processing on your behalf in accordance with section 14 of the Terms and Conditions). Visitors to a website hosted with us should address any questions to the operator of that website.

03

What data we process

  • Master dataName, company, address, email, telephone, language, customer number.
  • Contract and payment dataOrders, services, invoices, payments received, payment method (we do not hold full card numbers).
  • CommunicationContents of emails, support tickets, forms and migration requests.
  • Domain dataRegistrant, admin and technical contacts, name servers, registration data.
  • Technical dataIP address, date and time, browser, operating system, pages accessed, logins and security events.
  • Content dataEverything you store in your services (we process this data only on your behalf).

We do not specifically collect sensitive personal data. However, such data may be contained in content that customers store in their services.

04

Where the data comes from

We receive most data directly from you, for example when you place an order, register or make an enquiry. Technical data is generated automatically when you use our websites and services. Data may also come from public sources (e.g. the commercial register, public domain directories), from registries and payment providers, or from persons who report misuse to us.

05

Purposes and legal bases

  • Contract

    ExamplesAccount, provisioning, domains, SSL, invoices, support

    Legal basis (GDPR)Performance of contract (Art. 6(1)(b))

  • Communication

    ExamplesReplies to enquiries, migration requests, notices concerning the contract

    Legal basis (GDPR)Contract or legitimate interest (lit. b/f)

  • Security

    ExamplesProtection against misuse, spam, attacks and fraud, logging

    Legal basis (GDPR)Legitimate interest, legal obligation (lit. f/c)

  • Legal obligations

    ExamplesAccounting, VAT, retention, orders from authorities

    Legal basis (GDPR)Legal obligation (lit. c)

  • Enforcement of rights

    ExamplesDebt collection, enforcement or defence of claims

    Legal basis (GDPR)Legitimate interest (lit. f)

  • Information about our own services

    ExamplesInformation on similar products to customers (can be unsubscribed at any time)

    Legal basis (GDPR)Legitimate interest or consent (lit. f/a)

Under the Swiss FADP, a legal basis is not generally required; however, we process data only for the purposes stated and in a proportionate manner. Where we obtain your consent, you can withdraw it at any time with effect for the future.

06

Website, server logs and cookies

When you visit our websites, technical data (IP address, time, page accessed, browser) is stored in server logs to ensure operation and security. These logs are deleted after 30 days at the latest, unless they are needed to investigate an incident.

We set necessary cookies without consent because the website, the client area and the cart would not work otherwise. Statistics cookies (Google Analytics 4, see below) are only set if you click “Accept statistics” in the cookie banner. We do not use marketing or social media cookies. Fonts and images are loaded from our own servers.

  • WHMCS…

    ProviderHostOn (my.hoston.ch)

    PurposeSession in the client area and cart

    Durationuntil the browser is closed

  • hoston_cart

    ProviderHostOn

    PurposeDisplays the number of items in the cart on hoston.ch (only a number, deleted when the cart is empty)

    Duration7 days

  • hoston_vat

    ProviderHostOn

    PurposeRemembers whether prices are shown incl. or excl. VAT (on hoston.ch and my.hoston.ch)

    Duration1 year

  • hoston_cart_n (sessionStorage)

    ProviderHostOn

    PurposeStores the number of items in the cart for a few seconds so that it is not queried again on every page

    Durationuntil the tab is closed

  • __cf_bm, cf_clearance

    ProviderCloudflare

    PurposeProtection against bots and attacks

    Duration30 minutes to 1 year

  • _GRECAPTCHA

    ProviderGoogle

    PurposeSpam protection (reCAPTCHA) for forms

    Durationup to 6 months

  • hoston_consent

    ProviderHostOn

    PurposeStores your choice in the cookie banner (on hoston.ch and my.hoston.ch)

    Duration6 months

  • _ga, _ga_<ID>

    ProviderGoogle (Google Analytics 4)

    PurposeStatistics: distinguishes visitors and sessions – only after your consent

    Duration2 years

You can change your choice at any time via “Cookie settings” at the bottom of every page. You can also delete or block cookies in your browser. Without the necessary cookies, however, the client area and the cart will not work.

07

Google Analytics and Google Tag Manager (only with consent)

If you agree in the cookie banner, we use Google Analytics 4 and Google Tag Manager from Google Ireland Ltd. (Ireland), with Google LLC (USA) as sub-processor, on hoston.ch and my.hoston.ch. Google Analytics analyses in pseudonymised form how our websites are used (e.g. pages viewed, time on site, device type, approximate region and steps in the ordering process such as cart, checkout and completed order with the amount in CHF). Google Tag Manager is a tool we use to integrate such services; it does not set any cookies itself.

Without your consent, neither Google Analytics nor Google Tag Manager is loaded and no data is sent to Google (Google Consent Mode, advertising signals always denied). Google Analytics 4 does not store IP addresses by default. The data is retained for 14 months and then deleted.

Data may be transferred to the USA in the process. Google LLC is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework; standard contractual clauses also apply. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time via “Cookie settings”; the statistics cookies are then deleted. More information: policies.google.com/privacy

08

Google reCAPTCHA

To protect our forms (e.g. migration request, registration in the client area) against automated misuse, we use Google reCAPTCHA v3 from Google Ireland Ltd. or Google LLC (USA). reCAPTCHA evaluates characteristics such as IP address, browser information and interactions with the page and returns an assessment to us of whether a human or a program is submitting the form. Google’s privacy policy (policies.google.com/privacy) and terms of service (policies.google.com/terms) apply.

The processing is based on our legitimate interest in protection against spam and misuse. Google LLC is certified under the Swiss-U.S. Data Privacy Framework.

09

Cloudflare

Our websites and some services (e.g. hoston.ch, my.hoston.ch, cpanel.hoston.ch) are delivered via the network of Cloudflare, Inc. (USA). Cloudflare routes the data traffic, speeds up delivery and protects against attacks. In doing so, IP addresses and technical data of the requests are processed, including on servers outside Switzerland. Cloudflare is certified under the Swiss-U.S. Data Privacy Framework; standard contractual clauses also apply.

10

Client area, orders and payments

For orders and contract management, we use the WHMCS software, which we operate ourselves on our own servers. For payments by card or online payment, the payment data is processed directly by the respective payment provider; we only receive the confirmation and, where applicable, part of the card number. The data protection provisions of the payment provider apply to that processing.

To protect against fraud, we may check orders for plausibility (e.g. whether country, IP address and means of payment match). No automated individual decision within the meaning of Art. 21 FADP or Art. 22 GDPR takes place; conspicuous orders are reviewed by us personally.

11

Domains, public directories and SSL

To register a domain, we must transmit the registrant and contact data to our registration partner Hosting Concepts B.V. (Openprovider, Netherlands) and to the competent registry. For .ch and .li, this is the registry under the Ordinance on Internet Domains (Switzerland); for other extensions, it is the respective registry, which may also be based outside Switzerland and the EU (e.g. USA for .com).

Depending on the extension and the registrant (individual or organisation), certain data is displayed in the public directory (RDAP/WHOIS). Registries are also obliged to disclose data to authorities and to persons with a legitimate interest. The transmission is strictly necessary for the registration (performance of contract).

For SSL certificates, we transmit the domain and, for OV/EV certificates, the organisation and contact data to the certification authority that issues the certificate. Issued certificates are published in public Certificate Transparency logs.

12

Recipients and processors

  • Data centre for our servers

    PurposeHosting, email, client area, backups

    CountryRomania (EU)

  • Cloudflare, Inc.

    PurposeDelivery and protection of the websites

    CountryUSA / global network

  • Google Ireland Ltd. / Google LLC

    PurposereCAPTCHA (spam protection)

    CountryIreland, USA

  • Google Ireland Ltd. / Google LLC

    PurposeStatistics (Google Analytics 4, Google Tag Manager) – only with consent

    CountryIreland, USA

  • Hosting Concepts B.V. (Openprovider)

    PurposeDomain registration

    CountryNetherlands

  • Domain registries

    PurposeRegistration and management of domains

    CountrySwitzerland, EU, USA and others depending on the extension

  • Certification authorities (CA)

    PurposeIssuing SSL certificates

    CountryEU, USA

  • Payment providers and banks

    PurposeProcessing of payments

    CountrySwitzerland, EU

  • Fiduciary, debt collection, legal advice

    PurposeAccounting, enforcement of claims

    CountrySwitzerland

  • Authorities and courts

    Purposewhere required by law or order

    CountrySwitzerland

Our processors are contractually obliged to process the data only in accordance with our instructions and with appropriate security. We do not sell personal data and do not pass it on to third parties for advertising purposes.

13

Disclosure abroad

Our servers are located in a data centre in Romania and therefore in the European Union. The Swiss Federal Council has determined that all EU states provide an adequate level of data protection (Annex 1 to the Data Protection Ordinance (DPO)).

Data is disclosed to the USA to Cloudflare and Google; both are certified under the Swiss-U.S. Data Privacy Framework, which the Federal Council recognises as adequate. For domain registries and certification authorities in countries without an adequate level of data protection, disclosure is based on Art. 17(1)(b) FADP or Art. 49(1)(b) GDPR, because it is necessary for the performance of the contract with you, or on standard contractual clauses.

14

How long we keep data

  • Server and access logs

    Retentionup to 30 days, longer in the event of security incidents

  • Content in hosting, mailboxes, servers

    Retentionuntil the end of the contract, then deletion no earlier than 14 days later (VPS 7 days); backups until their retention period expires

  • Account and contract data

    Retentionduration of the customer relationship, then 10 years

  • Invoices and accounting records

    Retention10 years (Art. 958f CO)

  • Support tickets and emails

    Retentionup to 3 years after closure, up to 10 years if related to the contract

  • Migration and contact requests without a contract

    Retentionup to 12 months

If retention is necessary because of ongoing proceedings or to safeguard claims, the period may be longer. Thereafter, the data is deleted or anonymised.

15

Data security

We take appropriate technical and organisational measures: encrypted connections (TLS), isolated customer accounts (CloudLinux), firewall and malware protection, daily backups, access restrictions on a need-to-know basis, regular updates and logging of security-relevant events. No one can guarantee absolute security. Where required by law, we report data security breaches to the FDPIC and to the persons concerned.

16

Your rights

  • AccessWhat data we process about you and for what purpose.
  • RectificationCorrection of inaccurate data – much of it directly in the client area.
  • ErasureProvided there is no obligation to retain the data.
  • ObjectionTo processing based on legitimate interest and to direct marketing.
  • Data portabilityYour data in a common electronic format.
  • WithdrawalOf consent given, with effect for the future.

Write to datenschutz@hoston.ch or to our postal address. We may request proof of identity and usually reply within 30 days. The rights may be restricted, for example where statutory retention obligations or the rights of third parties stand in the way.

You can lodge a complaint with the supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch), in the EU with the authority of your country of residence.

17

Changes

We adapt this privacy policy when our processing activities or the legal situation change. The version published on hoston.ch applies. Last updated: 05.10.2026.

Frequently asked questions

We do not use advertising or marketing cookies. Statistics cookies (Google Analytics 4 via Google Tag Manager) are only set if you agree in the cookie banner; you can change your choice at any time under “Cookie settings”. We do not sell personal data.

Customer data is stored in a data centre in the European Union, for which the Federal Council recognises an adequate level of data protection. Cloudflare and Google are certified under the Swiss-U.S. Data Privacy Framework.

You are responsible for the data you store in your websites, databases and mailboxes. HostOn only processes this data on your behalf as a processor.

Server logs containing the IP address, time, page requested and browser are deleted after 30 days at the latest, unless they are needed to investigate an incident.

Holder and contact details are passed to our registration partner and to the responsible registry. Depending on the extension, certain data appears in the public RDAP/WHOIS directory, but not for .ch and .li.

You have the right to access, rectification, erasure, objection, data portability and withdrawal of consent. Write to the data protection address in the legal notice; we usually reply within 30 days.

In Switzerland, with the Federal Data Protection and Information Commissioner (FDPIC); in the EU, with the supervisory authority of your country of residence.

We are here for you

Whether before you order or in the middle of a project: you reach real specialists who understand what you need.

Workstations with headsets and laptops in a bright office