Visuan Web Services LLC & Its Associated Brands
GDPR Compliance & Data Protection Documentation
Visuan Web Services LLC
Parent Company of Our Hosting, Server & Technology Brands
Document Version: 1.0
Effective Date: August 31, 2026
Document Owner: Visuan Web Services
Review: Periodic and whenever material changes are made to applicable privacy, security, infrastructure, or processing practices
1. Introduction
Visuan Web Services LLC (“Visuan Web Services”, “VWS”, “we”, “us”, or “our”) recognizes the importance of privacy, information security, and responsible processing of personal data.
As a provider of hosting, VPS, server, infrastructure, technical support, and related technology services, we understand that our customers may use our services to host websites, applications, databases, business systems, and other information that may contain personal data.
We therefore maintain a data protection and security framework designed to support responsible handling of customer and personal information.
Where the General Data Protection Regulation (GDPR) applies to our activities or to a customer’s use of our services, Visuan Web Services seeks to process personal data in accordance with applicable GDPR requirements, contractual obligations, and appropriate technical and organizational measures.
The GDPR requires organizations to consider appropriate security measures based on the nature, scope, context, purpose, and risks associated with processing personal data.
This document describes our general approach to GDPR and data protection and is intended to provide customers, prospective customers, partners, and other stakeholders with greater transparency regarding our practices.
2. Corporate and Brand Structure
Visuan Web Services LLC is the parent organization responsible for the operation and management of its technology and hosting businesses and brands.
This GDPR and Data Protection framework applies, where relevant, to services provided by Visuan Web Services and its associated brands operated under the Visuan Web Services organization.
Depending on the service or customer relationship, a customer may interact with a specific VWS brand while the underlying contractual, operational, technical, support, billing, or infrastructure functions may be provided by Visuan Web Services or an applicable service provider.
For privacy and data-protection purposes, the relevant contracting entity and service arrangement should be identified in the applicable order, service agreement, invoice, Terms of Service, Privacy Policy, or Data Processing Agreement.
3. Our Commitment to Data Protection
Visuan Web Services takes data protection seriously.
Our approach is based on the following principles:
- Responsible collection and use of information
- Appropriate access controls
- Confidentiality of customer information
- Appropriate technical and organizational security measures
- Secure administration of infrastructure
- Responsible handling of support information
- Appropriate data retention and deletion practices
- Security incident management
- Transparency regarding applicable third-party service providers
- Appropriate contractual arrangements where required
- Continuous review and improvement of security and privacy practices
We recognize that privacy and security are ongoing processes rather than one-time activities.
4. GDPR Applicability
GDPR applicability depends on the nature of the organization, its activities, the individuals involved, and the processing of personal data.
Visuan Web Services does not assume that every customer or every service is subject to exactly the same GDPR requirements.
Where GDPR applies, the responsibilities of Visuan Web Services and the customer may also differ depending on the nature of the processing.
For example, a customer may determine the purposes and means of processing personal data within its website or application, while Visuan Web Services may provide hosting or infrastructure services used to process or store that information.
The specific controller/processor relationship should therefore be assessed based on the actual services and processing activities involved.
5. Controller and Processor Responsibilities
Depending on the circumstances, Visuan Web Services may act as a data controller, data processor, or service provider in relation to particular categories of information.
For customer-hosted data, the customer will generally determine what information is collected through its website, application, or business system and why that information is processed.
Where Visuan Web Services processes personal data on behalf of a customer, the applicable contractual arrangements may establish processor-related responsibilities.
Where required, these responsibilities may be documented through a Data Processing Agreement (DPA).
The European Commission provides standard contractual clauses for controller-processor relationships under Article 28 of the GDPR.
6. Data Processing Agreement (DPA)
Customers that require a formal Data Processing Agreement may contact Visuan Web Services to discuss their requirements.
Where applicable, a DPA may address:
- Subject matter of processing
- Duration of processing
- Nature and purpose of processing
- Categories of personal data
- Categories of data subjects
- Documented processing instructions
- Confidentiality obligations
- Security measures
- Subprocessor arrangements
- Assistance with data-subject requests
- Security incident procedures
- Data deletion or return
- Audit and compliance assistance
- International data transfers
- Other applicable contractual requirements
A DPA should be evaluated in conjunction with the customer’s specific services and processing activities.
7. Privacy Policy
Visuan Web Services maintains privacy practices intended to provide transparency regarding information collected through our websites, customer accounts, service provisioning systems, support channels, billing processes, and other business operations.
Our Privacy Policy may address:
- Information collected
- Purposes of processing
- Legal bases where applicable
- Customer and account information
- Billing information
- Technical information
- Support communications
- Cookies and similar technologies
- Information sharing
- Data retention
- Security measures
- Privacy rights
- Data-related requests
- Contact information
The applicable Privacy Policy should be reviewed together with this document.
8. Technical and Organizational Security Measures
Visuan Web Services recognizes that protecting personal data requires appropriate technical and organizational measures.
Depending on the service and infrastructure involved, our security practices may include:
Infrastructure Security
- Server hardening
- Firewall configuration
- Network access controls
- Administrative access restrictions
- Operating system security updates
- Security monitoring
- Service monitoring
- Malware and threat protection where applicable
- Configuration management
Account Security
- Restricted administrative access
- Authentication controls
- Permission management
- Principle of least privilege where applicable
- Administrative access review
Data Security
Depending on the service and technical environment:
- Protection of stored information
- Secure transmission mechanisms
- Access restrictions
- Backup and recovery measures
- Data restoration procedures
- Security monitoring and logging
GDPR Article 32 specifically identifies measures such as encryption/pseudonymization where appropriate, confidentiality, integrity, availability and resilience of systems, restoration capability, and regular testing of security measures.
The specific security measures applicable to an individual customer depend on the product, infrastructure, management level, and services purchased.
9. Customer Security Responsibilities
Data protection is a shared responsibility.
While Visuan Web Services is responsible for the infrastructure and services under its control, customers remain responsible for securing systems, applications, credentials, and information that they control.
Customers should, where applicable:
- Use strong passwords
- Enable multi-factor authentication
- Keep applications and operating systems updated
- Restrict administrative access
- Regularly review user permissions
- Secure database credentials
- Protect API keys and authentication tokens
- Maintain appropriate backups
- Use HTTPS/TLS where appropriate
- Monitor application activity
- Remove unnecessary accounts
- Implement appropriate application-level security
- Comply with applicable privacy laws for data collected through their services
A secure hosting environment cannot compensate for an insecure customer application or improperly configured customer system.
10. Data Subprocessors and Third-Party Providers
Visuan Web Services may rely on third-party infrastructure, technology, payment, communications, security, support, or other service providers in order to operate and deliver services.
Where a third party is involved in processing personal data on behalf of Visuan Web Services, its role should be evaluated under the applicable service and contractual arrangements.
Where appropriate, customers may request information concerning relevant subprocessors, including:
- Provider name
- Service provided
- Processing purpose
- Categories of information involved
- Applicable processing location
- Relevant data protection arrangements
Subprocessor information may change as our infrastructure and service ecosystem develops.
Where international transfers are relevant, appropriate transfer mechanisms may need to be considered. The European Commission has adopted Standard Contractual Clauses for certain transfers of personal data to third countries.
11. Data Retention
Visuan Web Services seeks to retain information only for as long as reasonably necessary for legitimate business, operational, contractual, security, accounting, or legal purposes.
Retention periods may differ depending on the nature of the information.
Examples may include:
- Customer account information
- Billing records
- Service records
- Support communications
- Security logs
- Technical records
- Abuse-prevention information
- Backup data
- Legal and regulatory records
Where information is no longer required and there is no legitimate reason for continued retention, appropriate deletion or disposal procedures may be applied.
Specific retention periods may also depend on contractual obligations, legal requirements, backup cycles, infrastructure architecture, and security requirements.
12. Data Deletion
Where applicable, customers may request deletion of personal information or customer data subject to:
- Applicable law
- Contractual requirements
- Legitimate retention requirements
- Security requirements
- Billing and accounting obligations
- Backup retention cycles
- Technical limitations
For hosted infrastructure, customers may have direct control over the deletion of information stored within their own applications, websites, databases, or servers.
Where Visuan Web Services is responsible for specific processing activities, applicable deletion procedures will be evaluated according to the service and contractual relationship.
13. Data Subject Rights
Where GDPR applies, individuals may have rights concerning their personal data.
Depending on the circumstances, these may include:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Rights relating to certain automated decision-making
The European Commission identifies these rights as part of the GDPR framework for individuals.
Where a customer is the controller of personal data, the customer will generally be responsible for responding to requests relating to information that it controls.
Where Visuan Web Services is required to provide reasonable assistance as a processor, such assistance will be handled in accordance with the applicable agreement and applicable law.
14. Security Incident Management
Visuan Web Services recognizes that effective incident management is an important part of data protection.
Our approach to security incidents may include:
- Identification of the incident
- Initial assessment
- Containment
- Investigation
- Risk assessment
- Remediation
- Recovery
- Documentation
- Customer communication where applicable
- Preventive measures and review
Where a security incident involves personal data and notification obligations apply, the applicable contractual and legal requirements will be followed.
Under GDPR Article 33, a processor is required to notify the controller without undue delay after becoming aware of a personal-data breach. The controller may have a separate obligation to notify the relevant supervisory authority within the applicable timeframe, including the GDPR’s 72-hour requirement where applicable.
15. Breach Notification
If Visuan Web Services becomes aware of a confirmed personal-data breach affecting information processed on behalf of a customer, we will assess the incident and follow the applicable contractual and legal requirements.
Where notification to a customer is required, information may include, where reasonably available:
- Description of the incident
- Date or estimated timeframe
- Systems or services affected
- Categories of information affected
- Potential impact
- Containment measures
- Remediation measures
- Recommended customer actions
- Additional relevant information
Notifications may be provided through appropriate customer communication channels.
16. International Data Transfers
Customers subject to GDPR may have requirements concerning where personal data is stored or processed.
Depending on the selected hosting location, infrastructure provider, support arrangements, third-party services, and other operational factors, information may potentially be processed in different jurisdictions.
Customers requiring specific geographic restrictions, EU/EEA hosting, data residency, or international-transfer safeguards should communicate these requirements before service deployment.
Where required, appropriate contractual mechanisms and safeguards should be evaluated.
The European Commission provides Standard Contractual Clauses for certain international transfers of personal data from the EU/EEA to third countries.
17. Access to Customer Data
Access to customer information and infrastructure is restricted according to operational and technical requirements.
Where administrative or technical access is necessary for service delivery, troubleshooting, maintenance, security, abuse prevention, or support, access should be limited to authorized personnel and appropriate circumstances.
Customers should understand that the level of access available to Visuan Web Services can vary depending on whether the customer uses:
- Shared hosting
- Managed hosting
- VPS
- Cloud infrastructure
- Dedicated servers
- Managed server services
- Technical support services
Customers using unmanaged infrastructure generally retain greater responsibility for their own system configuration and application-level data.
18. Confidentiality
Visuan Web Services recognizes the confidential nature of customer information.
Information obtained through customer relationships, service provisioning, technical support, or infrastructure management should be handled appropriately and accessed only for legitimate business, operational, security, legal, or support purposes.
Confidentiality obligations may also be established through applicable Terms of Service, contracts, DPAs, employment arrangements, vendor agreements, or other contractual instruments.
19. Data Protection by Design and Responsible Operations
Privacy and security considerations should be incorporated into the design and operation of services where appropriate.
Our ongoing approach includes consideration of:
- Data minimization
- Access limitation
- Security controls
- Appropriate retention
- Secure disposal
- System availability
- Business continuity
- Incident management
- Customer transparency
The specific controls applied will depend on the nature and risk of the relevant processing activity.
20. Data Protection Officer (DPO)
GDPR does not require every organization to appoint a Data Protection Officer.
The requirement depends on the organization’s activities and circumstances. For example, the European Commission notes that a DPO is required in certain situations involving large-scale processing of sensitive data or large-scale, regular and systematic monitoring of individuals.
Visuan Web Services will assess DPO requirements based on the nature and scale of its processing activities and applicable legal requirements.
Where a formal DPO is not legally required, privacy-related matters may be handled through an appropriate designated privacy or compliance contact.
21. Customer Due Diligence
We understand that businesses may need to assess their hosting and infrastructure providers before entering into a service relationship.
Customers may request reasonable information concerning our data protection and security practices, including:
- Privacy Policy
- Data Processing Agreement
- Security measures
- Data retention
- Data deletion
- Subprocessor information
- Incident response
- Breach notification
- Processing locations
- International transfers
- Applicable contractual protections
Requests will be evaluated based on the customer’s services, contractual requirements, security considerations, and information that can appropriately be disclosed.
22. GDPR Documentation Available to Clients
Where applicable, Visuan Web Services can provide or make available relevant documentation for customer review, including:
Privacy Documentation
- Privacy Policy
- Cookie Policy, where applicable
- Data Protection documentation
Contractual Documentation
- Data Processing Agreement (DPA)
- Applicable Terms of Service
- Data protection clauses
- International transfer provisions where applicable
Security Documentation
- Security controls overview
- Technical and organizational measures
- Incident-response procedures
- Business continuity and recovery information where applicable
Data Management Documentation
- Data retention practices
- Data deletion procedures
- Subprocessor information
- Data processing information
The availability of particular documents may depend on the service, customer requirements, and contractual relationship.
23. Continuous Improvement
Data protection is an ongoing process.
Visuan Web Services periodically reviews its operational, technical, and organizational practices and seeks to improve its security and privacy framework as our business, infrastructure, services, and regulatory environment evolve.
Our objective is to provide customers with dependable hosting and server infrastructure while maintaining responsible standards for:
Security | Privacy | Confidentiality | Availability | Transparency | Responsible Data Processing
24. Contact Us Regarding GDPR Requirements
Customers with GDPR, privacy, security, data residency, or contractual requirements are encouraged to contact Visuan Web Services before deploying their infrastructure.
Our team can review the requirements and determine the appropriate documentation, contractual arrangements, technical considerations, and service configuration.
Visuan Web Services LLC
Hosting • VPS • Dedicated Servers • Cloud Infrastructure • Technical Support • IT Services
Parent organization: Visuan Web Services LLC
Brands: Services and brands operated under the Visuan Web Services organization
For GDPR or data protection inquiries, please contact our business/support team through the applicable official customer support channel.
25. Important Legal Disclaimer
This document describes the general data protection and security approach of Visuan Web Services and its applicable brands.
It is not legal advice, does not constitute a legal opinion, and should not be interpreted as a guarantee that every customer or service is subject to, or automatically compliant with, every requirement of the GDPR.
GDPR applicability and compliance obligations depend on the specific circumstances of an organization, its processing activities, the categories of personal data involved, the roles of the parties, the geographic scope of processing, and applicable contractual and legal requirements.
Where necessary, customers should obtain independent legal or professional advice regarding their own GDPR obligations.
This document should also be read together with the applicable Privacy Policy, Terms of Service, Data Processing Agreement, security documentation, and other contractual documents.
Document Control
Organization: Visuan Web Services LLC
Document: GDPR Compliance & Data Protection Documentation
Version: 1.0
Effective: August 31, 2026
Status: Public / Client-Facing
Owner: Visuan Web Services
Next Review: As required following material changes to services, infrastructure, processing activities, or applicable data protection requirements.