Skip to content

PRIVACY POLICY

LAST UPDATED: FEBRUARY 2026

WHO.WE.ARE

ProClanHosting ("we", "us", "our") operates proclanhosting.com and provides game server hosting services. This policy describes how we collect, process, store, and protect your personal data in compliance with the General Data Protection Regulation (GDPR).

Applies to account holders, authorized users, and website visitors. We act as data controller for data collected directly from you and as data processor for data stored within your hosted game servers.

Where we act as data processor, our Data Processing Agreement governs how we handle that data on your behalf.

DATA.COLLECTED

ACCOUNT: Name, email, billing address, company name, phone number, payment details for service delivery and invoicing. Collected during registration and account management.

TECHNICAL: IP addresses, browser type, operating system, device identifiers, referring URLs, server access logs, API request metadata, game server connection logs. Collected automatically for diagnostics and security.

USAGE: Server resource consumption (CPU, RAM, bandwidth, storage, player slots), game server configurations, login timestamps, session durations, feature utilization. Used for maintenance, capacity planning, and optimization.

COMMS: Support tickets, emails, feedback — all correspondence with our team for issue tracking, quality assurance, and service improvement.

DATA.PURPOSE

  • → Delivering and maintaining game server hosting services
  • → Processing billing, payments, and invoicing
  • → Technical support and issue resolution
  • → Security monitoring and threat detection
  • → DDoS mitigation and abuse prevention
  • → Enforcing Terms of Service and Acceptable Use Policy
  • → Service updates and maintenance notifications
  • → Capacity planning and performance optimization
  • → Fraud prevention and unauthorized access detection
  • → Legal and regulatory compliance

No automated decision-making. No profiling. No advertising. Your data is never sold to marketers.

DATA.LEGAL

CONTRACT (Art. 6(1)(b)): Processing required to deliver purchased services — provisioning, server deployment, billing, support.

LEGITIMATE INTEREST (Art. 6(1)(f)): Security monitoring, fraud prevention, DDoS mitigation, service improvement, capacity planning. Your fundamental rights are never overridden.

LEGAL OBLIGATION (Art. 6(1)(c)): Tax records, financial reporting, regulatory compliance, lawful authority requests.

CONSENT (Art. 6(1)(a)): Where applicable. Withdrawable at any time. Prior processing remains lawful.

DATA.STORAGE

European Union data centers. AES-256 encryption at rest. TLS 1.3 in transit. Tenant isolation enforced at network and storage layers. Redundant power, environmental controls, physical access restrictions.

SECURITY STACK: Role-based access + mandatory MFA, network segmentation, multi-layer firewalls, DDoS protection with multi-Tbps mitigation, automated vulnerability scanning and patch management, 24/7 intrusion detection, physical biometric access controls, full audit logging.

BREACH PROTOCOL: Notification to affected users and supervisory authority within 72 hours per GDPR Article 33. Documented incident response for containment, investigation, and remediation.

DATA.RETENTION

ACCOUNT: Active + 30 days post-closure to handle outstanding matters.

BILLING: 7 years (tax/financial regulation compliance within the EU).

SERVER LOGS: 14 days for security monitoring and troubleshooting.

ACCESS LOGS: 90 days for security monitoring and abuse prevention.

SUPPORT: Duration of active account + 30 days for quality assurance.

GAME CONFIGS: Deleted upon account closure.

Post-retention: cryptographic erasure + multi-pass overwrite. Earlier deletion available on request, subject to legal retention obligations.

DATA.RIGHTS

  • ACCESS (Art. 15): Get a copy of your data and processing details.
  • RECTIFY (Art. 16): Correct inaccurate or incomplete data without undue delay.
  • ERASE (Art. 17): Request deletion when no longer necessary, subject to legal retention.
  • EXPORT (Art. 20): Receive data in machine-readable format (JSON/CSV) and transmit to another controller.
  • RESTRICT (Art. 18): Limit processing in specific circumstances, e.g. contested accuracy.
  • OBJECT (Art. 21): Object to processing based on legitimate interests or direct marketing.
  • WITHDRAW (Art. 7): Revoke consent at any time without affecting prior processing.
  • COMPLAINT: Lodge a complaint with your local data protection supervisory authority.

All requests acknowledged within 5 business days, processed within 30 days. Extensions up to 60 additional days for complex requests. Contact: [email protected].

DATA.COOKIES

Essential only. No tracking. No analytics. No advertising.

AUTH: Maintains login state and prevents unauthorized access. CSRF: Prevents forgery attacks and ensures form integrity.

SESSION: Load balancing across infrastructure. PREFS: Language/timezone settings for consistent experience.

No pixel trackers, web beacons, or fingerprinting. Cookies cannot be disabled without impairing functionality. Legal basis: legitimate interest (platform operation).

DATA.SHARING

PAYMENT PROCESSOR: PCI DSS-compliant. Card data never stored on our servers. Minimum data for transaction processing. We only receive transaction confirmations.

EMAIL PROVIDER: Transactional only — invoices, notifications, password resets. No marketing via third-party platforms.

All providers bound by GDPR-compliant data processing agreements. Regular compliance reviews conducted. We never sell, rent, or trade personal data. Disclosure only if required by law — you'll be notified where legally permitted.

DATA.TRANSFERS

Primary processing: EEA only. No routine transfers outside the EEA.

Where a third-party provider operates outside the EEA, safeguards enforced: EU adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or supplementary technical measures.

Request copies of transfer safeguards at any time by contacting our privacy team.

DATA.CHILDREN

Services not directed at individuals under 16. No data knowingly collected from minors.

Contact [email protected] for prompt deletion if you believe a child has provided personal data. If we become aware of collection without parental consent, data will be deleted within a reasonable timeframe.

DATA.UPDATES

Posted here with revised date. Material changes affecting data collection, use, or sharing notified via email at least 14 days before taking effect.

Continued use after changes constitutes acknowledgment. Previous versions available upon request.

DATA.CONTACT

[email protected]

We resolve all privacy inquiries promptly and transparently. If unsatisfied, lodge a complaint with your local data protection supervisory authority within the European Economic Area.