Privacy Policy
This policy explains how personal data is processed for iHoster24 services offered to customers internationally. We follow applicable data protection laws, including the GDPR where it applies to you or to our processing.
1. Operator and contact
iHoster24 is operated by Dioartis Grup SRL (IDNO 1011600003727), registered in the Republic of Moldova at MD-2020, mun. Chișinău, sector Rîșcani, Calea Orheiului 109/3, ap. (of.) 211. Website: ihoster24.com. Client Area: clientarea.ihoster24.com.
Privacy requests: privacy@dioartis.com. General support: support@ihoster24.com. Abuse and security: abuse@dioartis.com.
We have not appointed a Data Protection Officer. Privacy requests are handled by our privacy contact above.
2. Two roles (important)
- Controller — for client accounts, billing, fraud prevention, security of our platforms, marketing (where consented), and the contractual relationship.
- Processor — for personal data that you (the customer) host on our servers as part of your websites, email, or applications, processed on your documented instructions under the DPA.
3. Categories of people
Customers and prospective customers; account users; billing contacts; website visitors; support chat/ticket participants; domain registrants/contacts you supply; reseller end-users (indirectly via reseller responsibility).
4. Categories of data
- Identity and contact (name, email, phone, address)
- Account and authentication data
- Billing and payment references (card data handled by payment providers)
- Service configuration, tickets, chat messages
- Technical logs (IP, timestamps, security events)
- Domain/WHOIS-related data you provide
- Cookie / consent preferences
5. Sources
You; your users when they interact with your hosted services; payment providers; registrars/registries; security tooling; analytics (only after consent); publicly available abuse/blocklists where used for security.
6. Purposes and legal bases
- Contract performance — provide hosting, support, billing, renewals
- Legal obligation — tax, accounting, responding to lawful requests
- Legitimate interests — securing platforms, preventing fraud/abuse, improving reliability (balanced against your rights)
- Consent — Analytics cookies; optional chat personalization; marketing emails where required
7. WHMCS, accounts, billing, payments, antifraud
Client Area runs on WHMCS. We process account and invoice data to deliver services and prevent fraud. Payment processors currently used include PayPal, maib card payments, Blockonomics (Bitcoin), and bank transfer, as offered at checkout.
8. Hosting, VPS, email, logs, backups
We process technical data needed to operate servers, email, and backups. Product catalog backup frequency for shared/business plans is weekly unless a specific product states otherwise. You remain responsible for application-level data and your own copies.
9. Ticketing, support, and Amevia
Tickets and optional Amevia chat messages are processed to provide support. Do not send passwords or sensitive secrets in chat. Amevia analytics/personalization/resume follow your cookie preferences (default deny). Authenticated identity is not enabled automatically for public visitors.
10. Domains, registrars, WHOIS
Domain registration requires sharing registrant data with the registrar/registry as required. Module integrations present include InternetBS/IBS. WHOIS/privacy proxy terms depend on TLD rules — see Domain Terms.
11. Analytics and cookies
Google Analytics (G-P6SBMT8Y5Y) loads only after Analytics consent. See the Cookie Policy and Cookie preferences.
12. Commercial communications
Marketing messages require a separate, unticked consent where consent is required. You may withdraw at any time.
13. Recipients and providers
Confirmed categories include: payment providers (PayPal, maib, Blockonomics, bank transfer); Amevia chat; Google (Analytics after consent; reCAPTCHA on protected forms); domain registrar integration (InternetBS/IBS); and infrastructure providers for EU and US locations as sold. See Subprocessors.
14. International transfers (EU / US and other locations)
Services may involve infrastructure in the EU and US as marketed, and support or vendors elsewhere. Where personal data is transferred internationally, we rely on lawful transfer mechanisms required by applicable law (for example adequacy decisions or standard contractual clauses). Details of subprocessors appear on the Subprocessors page.
15. Retention
We retain account and billing data while the account is active and afterwards as needed for legal, tax, accounting, and dispute purposes. Security and access logs are kept for a limited operational period. Support tickets and chat records are kept while useful for the support relationship and then deleted or anonymised. Platform backups follow the Backup Policy and are removed after service termination according to that schedule.
16. Automated decisions
Fraud and abuse systems may use automated signals (e.g. risk scoring, captcha). They do not produce solely automated legal effects about you without human review where required by law.
17. Your rights
Depending on applicable law (including the GDPR where it applies), you may request access, rectification, erasure, restriction, objection, and portability where available. We respond within one month, with lawful extensions where permitted. Submit requests to privacy@dioartis.com.
18. Complaints to a supervisory authority
You may lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova (CNPDCP), or with another competent supervisory authority (including your local authority in the EU/EEA where applicable).
19. Security and incident notification
We apply technical and organisational measures appropriate to risk. Personal data breach notification follows legal deadlines (including the 72-hour authority notification duty where applicable).
20. Children
Services are directed to adults and businesses. We do not knowingly collect data from children for marketing.
21. Updates
We will post updates with a new version and effective date. Material changes may also be notified by email or Client Area notice.