General
This Privacy Policy (the “Policy”) sets out how ExoHost (the “Provider”) collects, stores, protects and processes customers’ personal data.
This is a translation for convenience. In case of any discrepancy the Russian text prevails.
1.1. Using the control panel and ExoHost services constitutes acceptance of this Policy and of the processing conditions set out in it.
1.2. A customer who does not agree with the Policy should stop using the service.
2. What we collect
Only what is needed to perform the rental contract, process payments and keep the infrastructure secure.
Registration data: email address, name or login.
Technical data and cookies: IP address, browser type and language, access time, cookie files. A consent banner is shown on the first visit.
Card payment data: transaction records. ExoHost does not store full card details; they are handled by certified payment gateways (PCI DSS).
Cryptocurrency payments: for payments in cryptocurrency (Bitcoin, USDT and others) only the wallet address of the transaction and the amount are recorded. Blockchain transaction data is not linked to a real identity, except in the cases described in clause 5.2.
Identity documents (on request): where required by law or on suspicion of fraud, the Provider may ask for identity verification (a scan of a document).
3. Why we process it
Identifying the customer in the control panel and granting access to their servers.
Processing payments, issuing invoices and keeping accounts.
Communicating with the customer: support, notices about plan changes, warnings about abuse complaints.
Sending informational and marketing messages (news, promotions, special offers, discounts). A customer may opt out at any time via the unsubscribe link at the bottom of every such email or in the control panel settings.
Preventing fraud, DDoS attacks and other cybercrime.
4. Storage, security and deletion
4.1. Protection. The Provider applies current technical and organisational measures (TLS encryption, access control, firewalls) to protect data against loss, theft and unauthorised alteration.
4.2. Data inside the VPS. ExoHost has no access to the confidential information, source code or databases a customer places inside their rented server, unless the customer has given support access for configuration work.
4.3. Retention. Personal data is kept for as long as the account exists.
4.4. Deletion. A customer may request deletion of their account and personal data at any time through the ticket system, provided there are no active services or outstanding debts. Data is deleted irrecoverably within 30 calendar days.
5. Third parties and cryptocurrency payments
5.1. ExoHost does not sell or pass on customers’ personal data, except in response to official requests from law enforcement or courts made in accordance with the law of the country where the equipment is located or where the Provider is registered.
5.2. Cryptocurrency payments are handled by specialised gateways. ExoHost collects no personal data when processing them. However, if a transaction is blocked by the gateway’s AML monitoring on suspicion of a link to illegal activity (darknet, mixers, stolen funds), the Provider may suspend the services until the customer supplies documents showing the funds are of lawful origin (KYC).
6. Changes to this Policy
6.1. The Provider may amend this Policy unilaterally.
6.2. A new version takes effect when published on the ExoHost site. Customers are advised to check this document for updates.
