What we collect
Your email address, which you provide. Your invoices and payment references, which are generated when you buy. The servers on your account and their addresses. The tickets you open and our replies. Web server access logs containing IP addresses, timestamps and requested paths. That is the complete list.
What we do not collect
We do not ask for or store identity documents, phone numbers, physical addresses, dates of birth, card details or bank account numbers. We do not run analytics scripts, we do not embed third-party trackers, we set no advertising cookies and we do not build behavioural profiles. The only cookie we set is a session cookie after you sign in.
How long we keep it
Access logs rotate after seventy-two hours. Hypervisor event logs rotate after fourteen days. Account data, invoices and tickets are kept while the account exists and for the period tax law in the Netherlands requires for invoices, which is seven years. Everything else is deleted within twenty-four hours of account deletion.
Who we share it with
Our payment processor receives an invoice amount and reference, never your identity, because we do not have one. Our transactional email provider receives your address to deliver mail. Nobody else receives anything, and we sell nothing to anybody under any circumstances.
Legal disclosure
We disclose data only in response to valid legal process from the jurisdiction where the relevant hardware sits, and only what that process compels. We publish the number of requests received, complied with and refused every six months in our transparency report. Where we are legally permitted to notify you of a request, we do.
Your rights
You may request a copy of everything we hold, correct it, or have it erased, from the dashboard or by ticket. Erasure requests are executed within twenty-four hours except for invoices we are required to retain. There is no verification step because there is nothing to verify against: control of the email address is the identity.
Security
Data at rest on our management systems is encrypted. Access to production requires hardware tokens and is logged. Customer volumes are encrypted at rest at the storage layer by default, and you can add your own LUKS layer that we hold no key for.
CrestVPS B.V. · AS204871 · [email protected]