Your data. Your rights.
Our commitment.
Grandhosting is built from the ground up with European data protection principles at its core. Here’s how we uphold your privacy.
Last updated: June 30, 2026
Our Approach
GDPR isn’t a checkbox for us — it’s how we build.
The General Data Protection Regulation is the world’s strongest framework for protecting personal data. As a European company hosting European customers, we don’t just comply with GDPR — we embrace it as a design principle.
Every architectural decision we make, from where we place our servers to how we structure our database, considers data protection first. We collect only what we need, store it only where it’s safe, and give you full control over it at all times.
Data Residency
100% EU infrastructure. No exceptions for core data.
All of your website data — files, databases, backups, and media — is stored exclusively within the European Union, primarily in Germany — home to some of the strictest data protection laws in the world — with redundancy in other EU locations such as Finland. Our data centers are ISO 27001 certified.
Your core hosting data stays in the EU: our servers and storage run within the European Union (primarily Germany), and your databases, backups and media are kept in EU regions. A small number of supporting services (such as the dashboard host, error-tracking, and our analytics and advertising tools) are operated by companies headquartered in the US; where that is the case, data is kept in EU regions wherever available and protected by Standard Contractual Clauses (SCCs). The complete list is in our sub-processor table below.
- Compute and networking — Hetzner, EU (Germany and Finland)
- Storage and media — Hetzner, EU (Germany and Finland)
- Backups — Cloudflare R2, EU storage region
- DNS and CDN — Bunny.net, Slovenia (EU)
- Authentication and platform database — Supabase, EU region
- Payments — Stripe, Ireland (EU)
Seven rights. Zero friction.
Under the GDPR, you have powerful rights over your personal data. Here’s what they mean in plain language.
Right to Access
Request a complete copy of all personal data we hold about you. We’ll provide it in a structured, readable format within 30 days.
Right to Rectification
If any of your data is inaccurate or incomplete, let us know and we’ll correct it promptly.
Right to Erasure
Request deletion of your personal data. We’ll erase it from all systems, subject only to legal retention obligations (like tax records).
Right to Data Portability
Receive your data in a machine-readable format (JSON, SQL, archives) so you can move to another provider with zero lock-in.
Right to Restrict Processing
Ask us to pause certain processing activities while you verify accuracy or contest our legal basis.
Right to Object
Object to processing based on legitimate interest. We’ll stop unless we can demonstrate compelling grounds that override your rights.
Right to Withdraw Consent
If you gave consent for any specific processing, you can withdraw it at any time. Withdrawal doesn’t affect the lawfulness of prior processing.
How to exercise your rights
Send a request to our Data Protection Officer. We respond within 30 days, free of charge.
dpo@grandhosting.grWho handles your data — and why
We only share data with providers who are essential to running the platform. Each is bound by a Data Processing Agreement.
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Servers, networking, compute, and object storage for website media | EU (Germany and Finland) | EU-based, ISO 27001 data centres |
| Bunny.net (BunnyWay d.o.o.) | CDN, DNS and web application firewall (WAF) | Slovenia (EU) | EU company, GDPR compliant |
| Cloudflare, Inc. (R2) | Encrypted backup and snapshot storage | EU storage region (company US) | SCCs, encryption at rest |
| Supabase, Inc. | User authentication, platform database | EU hosting region (company US) | SOC 2 Type II, SCCs in place |
| Stripe Payments Europe Ltd | Payment processing | Ireland (EU) | PCI DSS Level 1, SCCs in place |
| Resend | Transactional and authentication email delivery | Ireland (EU) | EU data region, minimal data (email + subject only) |
| Sentry (Functional Software, Inc.) | Error and exception tracking | EU data region (company US) | SOC 2, EU data residency, data scrubbing, SCCs |
| Vercel, Inc. | Hosting and delivery of the customer dashboard | US | SCCs in place |
| Featurebase | In-app feedback and support widget (name, email, country) | EU data region | GDPR compliant, identity via signed token |
| Google LLC (Google Analytics) | Website usage analytics | US | SCCs, loaded only after consent |
| Meta Platforms, Inc. (Meta Pixel) | Advertising, retargeting, conversion measurement | US | SCCs, loaded only after consent |
| Termly, Inc. | Cookie consent management | US | SCCs, stores consent records |
| Hosting Concepts B.V. (OpenProvider) | Domain registration/transfer for non-.gr domains | Netherlands (EU) | EU company, registrant data only |
| ICS-FORTH (.gr/.el registry) | Registration of .gr / .el domains | Greece (EU) | EU national registry, registrant data only |
Security Measures
How we protect your data
Security isn’t a feature we bolted on — it’s woven into our architecture. Every website runs in complete isolation, and we layer multiple defenses to keep your data safe.
Encryption everywhere
TLS 1.2+ for all data in transit. Encrypted storage for data at rest. Automatic SSL certificates via Let’s Encrypt.
Complete site isolation
Every website runs in its own isolated environment with dedicated resources. No shared processes, no data leakage between sites.
Automated malware scanning
Automated scanning runs nightly across all sites. Suspicious files are flagged and reported immediately.
Daily backups
Automated daily backups with 30-day retention. Stored encrypted on secure EU storage in the EU.
Access controls
Least-privilege access policies. No shared credentials. Role-based access for all platform operations.
Continuous monitoring
Prometheus metrics, Loki log aggregation, and 13 alert rules watching for anomalies 24/7.
Breach Notification
If something goes wrong, you’ll know within 72 hours
In the unlikely event of a personal data breach, we are committed to full transparency. In accordance with GDPR Article 33, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms
- Provide a clear description of the nature of the breach, the data involved, likely consequences, and the measures taken to address it
- Document the breach and our response for accountability purposes
We maintain an incident response plan that is tested and updated regularly. Our engineering team monitors for security events around the clock.
Contact
Talk to our Data Protection Officer
Whether you have a question, a request, or a concern about how we handle your data, our DPO is here to help.
Email dpo@grandhosting.grYou can also review our Privacy Policy and Data Processing Agreement for the full legal details.
Founding Member pricing.
Yours forever.
From €3.49/mo — pay only for the compute you use. Every feature included. Founding-member prices lock forever — they only increase at public launch.
Early access means direct access to our team. You’re not a ticket number. You’re a founding partner.
No commitment. Start free. Go live when you’re ready.
Already hosted elsewhere? Managed migration, zero downtime →