Our Commitment to Data Protection and Privacy
At Visuan Web Services, we recognize that data privacy is an essential part of providing reliable hosting, server, and technology services. Businesses entrust their websites, applications, databases, and business information to their hosting provider, and protecting that information is a responsibility we take seriously.
We follow GDPR-aligned data protection and security practices where the General Data Protection Regulation (GDPR) applies to our services and customers. Our approach focuses on responsible data handling, appropriate security controls, access management, transparency, and contractual obligations relating to the processing and protection of personal data.
Our objective is to help customers operate their online infrastructure with greater confidence while maintaining responsible practices around the collection, processing, storage, and protection of customer information.
What Is GDPR?
The General Data Protection Regulation (GDPR) is a European Union privacy and data protection regulation designed to strengthen individuals’ rights concerning their personal data and establish requirements for organizations that process such information.
GDPR can apply to organizations located within the European Economic Area as well as organizations outside the region when they process personal data in circumstances covered by the regulation.
For hosting and technology companies, GDPR considerations can become particularly important because infrastructure may be used to store or process information such as customer records, website user information, IP addresses, account information, application data, and other personal data.
Our GDPR-Aligned Approach
Visuan Web Services takes a structured approach to privacy and information security. Depending on the services being provided and the customer’s specific requirements, our practices may include appropriate technical and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
1. Secure Data Handling
We aim to ensure that customer information is handled responsibly throughout its lifecycle. This includes considering how information is collected, accessed, processed, stored, transferred, and ultimately removed when it is no longer required.
Our data-handling approach is designed around the principle that access to customer information should be limited to legitimate business and technical requirements.
2. Access Controls
Access control is an important component of protecting customer information and infrastructure.
We use appropriate administrative and technical controls to help restrict access to systems and information. Access should be provided based on business requirements and operational responsibilities rather than unnecessarily granting broad access.
Where applicable, security practices may include account authentication controls, restricted administrative access, server-level security configurations, and other measures appropriate to the environment.
3. Infrastructure and Server Security
For hosting and server environments, security is an important part of protecting customer data.
Depending on the service and configuration, security measures may include server hardening, firewall configuration, monitoring, access restrictions, system updates, malware protection, and other security controls.
Customers using VPS, dedicated servers, cloud infrastructure, or hosting environments are also encouraged to maintain appropriate application-level security, strong passwords, access controls, software updates, backups, and other security measures.
Security is a shared responsibility, and the specific responsibilities of Visuan Web Services and the customer may vary depending on the service being provided.
4. Data Processing
Where Visuan Web Services processes personal data on behalf of a customer, the nature and purpose of that processing depend on the services being provided and the customer’s instructions.
We seek to process customer data only for legitimate purposes associated with providing, maintaining, securing, and supporting the contracted services, subject to applicable law and contractual requirements.
Customers remain responsible for ensuring that they have an appropriate legal basis for collecting and processing personal data through their own websites, applications, systems, or services.
5. Data Protection Agreements
For customers whose activities require additional contractual data protection provisions, Visuan Web Services can discuss an appropriate Data Processing Agreement (DPA) where applicable.
A DPA can establish important responsibilities between the parties, including matters relating to:
- Categories of personal data
- Categories of data subjects
- Purpose and nature of processing
- Data protection responsibilities
- Security measures
- Confidentiality requirements
- Sub-processors, where applicable
- Data breach and incident procedures
- Data retention and deletion
- Assistance with applicable data protection obligations
Customers with specific GDPR or contractual requirements are encouraged to contact us so that the requirements can be reviewed before or during the provision of services.
Privacy and Customer Information
Protecting customer information is an important part of our overall privacy approach.
The information collected from customers may depend on the services they purchase and how they interact with Visuan Web Services. This may include account information, billing information, contact information, technical information, support communications, and information required to deliver and maintain services.
We seek to collect and use information for legitimate business and operational purposes, including account management, service provisioning, billing, technical support, security, service communications, and compliance with applicable legal requirements.
Our privacy practices are further described in our applicable Privacy Policy.
Data Security Is a Shared Responsibility
While Visuan Web Services takes appropriate measures to protect the infrastructure and services we operate, customers also have important responsibilities when using hosting and server services.
For example, customers should consider:
- Using strong and unique passwords
- Enabling multi-factor authentication where available
- Keeping operating systems and applications updated
- Restricting administrative access
- Regularly reviewing user permissions
- Maintaining appropriate backups
- Securing databases and application credentials
- Using HTTPS/TLS for applicable websites and applications
- Monitoring suspicious account or server activity
- Removing unnecessary accounts and access permissions
- Implementing appropriate security controls within their applications
The exact security responsibilities depend on the hosting product and level of management provided.
Data Retention and Deletion
Data retention is another important consideration under modern privacy regulations.
Customer and service information may need to be retained for legitimate operational, contractual, financial, security, or legal reasons. When information is no longer required and there is no legitimate reason to retain it, appropriate deletion or disposal procedures may apply, subject to applicable requirements and technical limitations.
Customers may contact us regarding specific data-retention or deletion requirements associated with their services.
Handling Security Incidents
Security incidents can occur in any technology environment, which is why incident management is an important component of responsible infrastructure operations.
Visuan Web Services maintains operational procedures for identifying, investigating, and responding to service and security-related issues. Where an incident involving personal data creates obligations under applicable law or contractual agreements, notification and response procedures will be handled in accordance with those requirements.
Customers should also maintain their own incident-response procedures for applications and data under their control.
GDPR Does Not Mean Every Customer Has the Same Requirements
GDPR requirements can vary depending on the nature of a customer’s business, the type of personal data being processed, the role of each party, the geographic scope of the processing, and the services being used.
For example, a company using a VPS only to host a public website may have different privacy requirements from a company using infrastructure to process customer accounts, employee information, healthcare-related information, financial information, or other sensitive business data.
For this reason, we encourage customers with specific regulatory or contractual requirements to discuss their requirements with us.
Transparency and Customer Communication
We believe transparency is an important part of responsible data management.
Customers may request additional information relating to our applicable:
- Privacy practices
- Data processing activities
- Security measures
- Data handling procedures
- Data retention practices
- Subprocessor information, where applicable
- Data Processing Agreement requirements
- GDPR-related contractual requirements
We will review such requests based on the services involved, the customer’s requirements, and applicable legal and contractual obligations.
Our Ongoing Commitment
Data protection is not a one-time activity. Technology, security threats, regulations, and business requirements continue to evolve.
Visuan Web Services is committed to continually reviewing its data protection and security practices and improving them where appropriate. Our goal is to provide customers with dependable hosting and server infrastructure while maintaining responsible standards for privacy, security, and data handling.
We understand that trust is an important part of any technology relationship. Our commitment is therefore not limited to infrastructure performance—we also recognize the importance of protecting the information entrusted to our services.
Need to Discuss Your GDPR Requirements?
If your organization operates in the EU/EEA, serves European customers, or has contractual GDPR requirements, we encourage you to contact Visuan Web Services before deploying your infrastructure so that we can understand your requirements and identify the appropriate contractual and technical measures.
We can review questions relating to privacy, data processing, security controls, hosting infrastructure, and Data Processing Agreements (DPA) based on the services you use.
Visuan Web Services — Reliable Hosting, Server Infrastructure and Technology Services with a strong focus on security, privacy, and responsible data management.
Disclaimer: This article describes Visuan Web Services’ general approach to GDPR-aligned data protection practices and is not legal advice. GDPR applicability and specific compliance obligations depend on the circumstances of each organization. Customers should obtain independent legal advice where necessary.