Short version: this site sets no advertising or tracking cookies, profiles nobody, and sends nothing about you to an advertising network.
Who is responsible for your data
The data controller is Sustainable Hosting, an eenmanszaak registered in Belgium under company number (KBO) 1032.400.791, at Tabakvest 87 / 4687, 2000 Antwerpen, Belgium. For any question about your data, or to exercise any of the rights below, write to support@sustainablehosting.com.
What this website collects
Browsing these pages requires no account and sets no tracking cookies. The web server keeps ordinary access logs — the requesting IP address, the page requested, the time, and the browser’s user-agent string — which we need in order to keep the service running and to investigate abuse or attacks. That is the legitimate-interest basis under Article 6(1)(f) of the GDPR. Those logs are rotated and deleted on a short cycle, keeping only the anonymous statistics.
If you write to us, we receive what you send, so that we can answer you. The same applies to any contact form we may add in future. We keep that correspondence for as long as it is useful to the relationship, and no longer.
If you leave a comment, we store what the comment form collects, plus your IP address and user-agent string, to help detect spam. You may choose to have your name, email address and website saved in cookies for your own convenience; those are entirely optional.
Cookies this site does set
- A cookie recording whether you chose dark or light mode. This is stored in your own browser, is not sent to us, and contains nothing but the word “dark” or “light”.
- If you log in to WordPress here (and normal visitors can’t), the standard WordPress session cookies. Login cookies last two days, or two weeks if you tick “remember me”, and screen-preference cookies last a year. Logging out removes them.
- A temporary cookie set when you visit a login page, purely to check that your browser accepts cookies. It contains no personal data and is discarded when you close the browser.
There are no external analytics, advertising, social or fingerprinting cookies. If there is no consent banner, it’s because there is nothing to consent to!
The two things loaded from another site
The Green Web Foundation badge in the footer is an image served from their servers, which means your browser makes one request to them and they can see your IP address in doing so. It is there because the value of an independent verification badge is precisely that it comes from the independent party. Nothing else on these pages is loaded from a third party. The fonts, scripts and images are all served from this site.
The carbon figure shown next to it is fetched by our server once a day and cached, specifically so that your browser does not have to contact anyone else for it.
Embedded content from other sites
Articles may occasionally include embedded content such as a video. Embedded content behaves exactly as if you had visited that other website, and those sites may collect data about you, set cookies and track your interaction with the embed. We keep embeds to a minimum for this reason, and at the time of writing, there are none.
If you upload images
Avoid uploading images containing embedded location data (EXIF GPS). Visitors can download images from a website and extract that data. That goes for your site(s) as well.
Where your data is, and who else sees it
This website and our customers’ sites and mailboxes run on renewable-powered servers in the European Union. We do not sell data and we do not share it with advertisers or data brokers.
Billing and support ticketing are handled in a separate system (WHMCS at time of writing, and eventual FOSSBilling) which we operate ourselves. If you follow a link to the client portal you are moving into that system, and the data you enter there is processed for the purpose of providing and billing your service. Comments may be checked by an automated spam-detection service. If you request a password reset, your IP address is included in the reset email.
How long we keep things
- Web server access logs: a short rotation, then deleted.
- Correspondence with you: as long as the relationship makes it useful, with possible permanence in eventual recipients’ mailboxes.
- Comments and their metadata: retained so that follow-up comments can be recognised and approved automatically rather than held in a queue.
- Account and billing records: as long as we are legally required to keep them for accounting and tax purposes, and no longer.
- Backups are harder to define, and it would be insecure to do so, but any data we keep is encrypted at rest.
Your rights
Under the GDPR you have the right to ask us for a copy of the personal data we hold about you, to have inaccurate data corrected, to have data erased, to receive it in a portable form, to restrict or object to our processing of it, and to withdraw any consent you have given. Erasure does not extend to data we are obliged to keep for legal, accounting or security reasons.
Ask by writing to support@sustainablehosting.com. We will answer as quickly as possible, and comply within one month.
If you are not satisfied with how we handle it, you have the right to complain to the Belgian data protection authority, the Gegevensbeschermingsautoriteit / Autorité de protection des données, in Brussels — or to the supervisory authority in your own EU country of residence. Are you in the USA? Then technically speaking, the rules there don’t apply to us… but European rules are much stricter, so don’t worry.
Thank you for your trust and understanding!
