Privacy Policy

Privacy Policy

Version 2.0 · in force from 5 September 2026

1. Introduction and scope

This Privacy Policy explains how IDA LIMITED ("IDA", "we", "us") collects, uses, shares, retains and protects personal data when you visit idaserver.net, order our services, or use the infrastructure and applications we operate.

It applies to:

  • Visitors to our website.
  • Customers using our domain, hosting, reseller, cloud VPS, VDS or dedicated server services.
  • Clients licensing our software or commissioning development work.
  • Users interacting with systems we build or operate for a client.
  • Business partners, suppliers and their staff.

By using the website or the services you confirm you have read this policy. It sits alongside our Terms of Service and forms part of them.

2. Who we are

IDA LIMITED is a company registered in Malta, operating since 2022, and is the controller of the personal data described in this policy unless a section says otherwise.

  • Website: https://idaserver.net
  • Written contact: [email protected], or a ticket in the client area.

Our services include:

  • Domain registration, transfer and DNS management.
  • Shared and reseller hosting on cPanel and CentOS Web Panel.
  • Cloud VPS and VDS, and physical dedicated servers, across our locations.
  • SSL certificates and related add-ons.
  • Infrastructure automation and provisioning systems.
  • Licensed enterprise software we develop in house, including idaFX (forex CRM) and idaGaming (casino and sportsbook platform).
  • Custom software, web and mobile application development, and integration work for business clients.

3. Definitions

Personal data

Any information relating to an identified or identifiable natural person.

Processing

Any operation performed on personal data: collection, storage, use, transmission, deletion and so on.

Controller

The party that decides why and how personal data is processed. For the data described here, that is normally IDA LIMITED.

Processor

A party that processes personal data on behalf of a controller and only on its instructions.

Client data

Data a customer stores in, or sends through, a service we provide. Where that data contains personal data of other people, the customer is the controller and we act as processor (see section 15).

4. Information we collect

What we hold depends on how you deal with us.

4.1 Identity and contact data

  • Full name, and company or organisation name where you order as a business.
  • Email address.
  • Billing address, and the registrant address a registry requires for a domain.
  • Job title or role, where you give it.
  • Telephone number where a domain registry requires one as a registrant contact detail, or where you choose to give it. We do not use it as a support channel — see section 14.

4.2 Account data

  • Username and password. Passwords are stored hashed, never in readable form.
  • Account and service identifiers, products held, and subscription details.
  • Service usage history and the record of changes made to your services.
  • Two-factor authentication settings, where enabled.

4.3 Billing data

  • Invoices, credit notes, payments, refunds and account credit movements.
  • The payment reference and status returned to us by the payment provider.
  • Tax identifiers where you supply them for invoicing.

We do not store full payment card numbers. Card details are entered with the payment provider and handled by it.

4.4 Technical data

  • IP address, browser type and version, device and operating system information.
  • Referring URLs, pages viewed, and date and time of access.
  • Server, application and error logs, authentication records and network diagnostics.

4.5 Infrastructure and hosting data

  • Server and account resource usage, traffic statistics and performance metrics.
  • Security logs, abuse reports and system access records.

This is used for operating the platform, capacity planning, and security. We do not inspect the contents of a customer's files or databases except where section 15 allows it.

4.6 Support data

  • The tickets you open, our replies, and anything you attach to them.
  • Notes we make about a fault or a change carried out on your service.

4.7 Project and development data

Clients commissioning development or integration work may pass us business requirements, specifications, architecture details, API access details, integration credentials and test datasets. We process this only to deliver the agreed work, and we ask clients not to send us production personal data where anonymised or sample data would do.

5. How we collect it

  • Directly from you: registration, orders, forms, tickets and email.
  • Automatically when you use the website or the services: logs, cookies and analytics.
  • From service provisioning: the systems that create hosting accounts, servers and domains.
  • From our payment providers, which confirm whether a payment succeeded.
  • From domain registrars and registries, in the course of registering or transferring a name.
  • From abuse and security reports sent to us by third parties about traffic from our network.

6. Why we use it, and our legal basis

Under the General Data Protection Regulation, every purpose below has a stated legal basis.

Providing the services you ordered

Creating and administering your account, provisioning hosting and servers, registering and renewing domains, managing DNS and SSL, and delivering licensed software or agreed development work.
Legal basis: performance of a contract with you, or steps taken at your request before entering one.

Billing and account administration

Issuing invoices, taking payment, applying credit, handling refunds, and administering renewals and cancellations.
Legal basis: performance of a contract; and legal obligation for the accounting and tax records we must keep.

Support

Answering tickets, diagnosing faults, and keeping the history attached to your account so a problem does not have to be explained twice.
Legal basis: performance of a contract.

Service messages

Renewal and expiry notices, invoices, maintenance windows, incident notifications and security advisories.
Legal basis: performance of a contract. These messages are part of the service and cannot be switched off while you hold an active service.

Security, abuse prevention and platform integrity

Detecting malicious activity, preventing unauthorised access and fraud, rate limiting, filtering traffic, investigating abuse reports, and protecting our network and our customers.
Legal basis: our legitimate interest in keeping the platform and its users safe, balanced against your rights; and, where applicable, a legal obligation.

Operating and improving the platform

Monitoring performance, capacity planning, troubleshooting, and developing features.
Legal basis: our legitimate interest in running a reliable service. Aggregated or anonymised data is used wherever it is sufficient.

Legal compliance and defence of claims

Meeting obligations under Maltese and EU law, responding to lawful requests, and establishing, exercising or defending legal claims.
Legal basis: legal obligation; and legitimate interest in defending our rights.

Marketing

Occasional messages about new services or offers.
Legal basis: consent, which you can withdraw at any time; where we write to an existing customer about services similar to those already bought, our legitimate interest, with an opt-out in every message.

Analytics cookies

Understanding, in aggregate, which pages are used.
Legal basis: consent. See section 13.

7. Domain registration data, WHOIS and RDAP

This section matters if you register a domain with us, and it is outside our control.

  • Registering, transferring or renewing a domain requires us to send registrant, administrative, technical and billing contact details to the registrar and to the registry that operates the extension.
  • Depending on the extension, some of that data may be published in public WHOIS or RDAP records, or held by the registry and disclosed under its own rules and, for gTLDs, under ICANN policy.
  • Registries and registrars keep their own copies of this data and retain it under their own retention rules, including after a domain leaves us. We cannot delete data from a registry.
  • Registry data may be escrowed with a third-party escrow agent, as ICANN and several country registries require.
  • Registrant details must be accurate. A registry can suspend a domain if a verification message is not answered or the details are shown to be false.
  • Where an extension offers WHOIS privacy, it hides contact data from public lookups. It does not hide it from the registrar, the registry, or from lawful requests.

Legal basis: performance of your contract with us, and compliance with registry and ICANN requirements that apply to holding a domain name.

8. Who we share data with

We do not sell personal data, and we do not share it for anyone else's marketing. We share it only where it is needed to deliver a service, or where the law requires it.

  • Domain registrars and registries — as described in section 7.
  • Data centre, network and cloud infrastructure providers that host the servers your services run on.
  • Payment providers, which process the transaction and return a reference and status to us.
  • Certificate authorities, for issuing and validating SSL certificates.
  • Email delivery providers, for the notices and ticket replies we send.
  • A content delivery and security provider that sits in front of our website and filters traffic.
  • Subcontractors and development partners who work on our infrastructure or on client projects, under written confidentiality and data processing terms.
  • Professional advisers — accountants and lawyers — where necessary.

Suppliers acting as our processors may use the data only on our instructions, for the purpose we set, and must protect it under a written agreement.

Lawful requests and regulatory disclosure

We may disclose data where we are required to by applicable law, a regulatory authority, a court order, a valid law enforcement request, or a registry acting under its own rules. We check that a request is valid and lawful before responding, and we disclose no more than the request requires. Where we are permitted to tell you about a request, we will.

If our business or part of it is transferred to another entity, customer data may transfer with it. You would be told in advance and this policy would continue to apply until replaced by one no less protective.

9. Third-party services and integrations

Our services and the platforms we build may connect to external systems: cloud providers, payment gateways, domain registrars, mobile ecosystems, mapping and analytics APIs, and other API providers. Those parties operate under their own privacy policies and, where they act as independent controllers, we are not responsible for how they handle data once it reaches them. Where we choose a supplier, we assess it before use and put a data processing agreement in place where it acts for us.

10. International transfers

Our platform is operated from the European Union, and we prefer suppliers inside the EEA. Some parties we must deal with — registries in particular, and some infrastructure and API providers — are located outside it, so personal data may be processed in more than one jurisdiction.

Where data is transferred outside the EEA, we rely on:

  • An adequacy decision of the European Commission covering the destination country; or
  • Standard Contractual Clauses, together with any additional safeguards the transfer requires; and
  • Written data processing terms with the recipient.

You can ask us which safeguard applies to a particular transfer.

11. Security

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit for the website, the client area and administrative access.
  • Network firewalls, traffic filtering and intrusion detection.
  • Server hardening, patching and vulnerability management.
  • Restricted administrative access on a need-to-know basis, with individual accounts and logging.
  • Separation between customer environments, and per-account resource allocation.
  • Monitoring, logging and periodic security review.

No system connected to the internet can be guaranteed perfectly secure. Where a personal data breach is likely to result in a risk to your rights, we notify the supervisory authority and, where the risk is high, you as well, in the time frames the GDPR sets.

Keeping your own credentials safe is your responsibility. Enable two-factor authentication where it is offered.

12. How long we keep data

  • Account records — for as long as the account is open, and for a limited period afterwards to handle disputes and reactivation requests.
  • Billing and accounting records — for the period Maltese accounting and tax law requires, currently at least ten years, regardless of whether the account is closed.
  • Service data — until the service is terminated, after which it is deleted with the service and cannot be recovered.
  • Domain records — as long as we are the sponsoring provider, plus the retention the registry and ICANN require. Registry-held data is outside our control.
  • Support tickets — kept with the account so that history is available, and removed when the account is closed unless a legal obligation or a dispute requires otherwise.
  • Technical and access logs — kept for a short operational period and then rotated out, other than records retained for a specific security investigation or a legal obligation.

When data is no longer needed it is securely deleted or anonymised.

13. Cookies and tracking technologies

  • Necessary cookies keep you signed in, hold your cart, remember your language, and protect forms against abuse. The site cannot work without them, and they are set on the basis of our legitimate interest in delivering the site you asked for.
  • Analytics cookies tell us, in aggregate, which pages are used and where errors occur. These are set only where you accept them, and you can change your choice at any time.

We do not use advertising cookies, and we do not carry out cross-site tracking, profiling for advertising, or ad-network retargeting. We do not sell or share browsing data with advertisers.

You can also control cookies through your browser settings. Blocking necessary cookies will stop parts of the client area from working.

14. How we communicate with you

  • Support runs through the ticket system in the client area. Every request is written down, routed to the engineer responsible, and kept attached to your account with its full history.
  • We do not operate a telephone support line, and we do not provide support over the phone. A written record of what was asked, what was changed and when protects both sides.
  • Notices about invoices, renewals, maintenance and incidents are sent by email and are also available in the client area.
  • We will never ask you for your password, a two-factor code, or full payment card details in a message. If you receive a message that appears to come from us and does so, do not answer it — open a ticket instead.

15. When you host other people's data

If you use our hosting, servers or software to process personal data belonging to your own users, customers or staff, you are the controller of that data and we act as your processor. In that role:

  • We process that data only to run the service, to fix a fault, where you ask us to, or where the law requires it.
  • We do not use it for our own purposes, and we do not disclose it except as set out in section 8.
  • We keep the staff who can access it limited and under confidentiality obligations.
  • We will help you, so far as we reasonably can, to answer a request from one of your own users or to notify a breach.

You are responsible for having a lawful basis for the data you put on our platform, for informing your own users, for the security of the applications you install, and for the configuration of an unmanaged server. Where a written data processing agreement is required, open a ticket and we will put one in place.

16. Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have data deleted where we no longer have a basis for holding it.
  • Restriction — have processing limited while a matter is resolved.
  • Portability — receive data you gave us in a structured, machine-readable form.
  • Object — object to processing based on our legitimate interest, and to object to direct marketing at any time, without giving a reason.
  • Withdraw consent — where processing is based on consent, without affecting what was done before.
  • Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. We do not make such decisions about you.

To exercise a right, open a ticket or write to [email protected]. We answer within one month, and tell you if a complex request needs longer. We may need to confirm your identity first. Exercising a right is free; we may charge only where a request is manifestly unfounded or excessive.

Some data cannot be deleted on request — an invoice we must keep for tax purposes, a record needed to defend a claim, or registrant data a registry holds under its own rules.

17. Complaints

If you are unhappy with how we have handled your data, tell us first: open a ticket or write to [email protected], and we will look into it.

You also have the right to complain to a supervisory authority. Ours is the Information and Data Protection Commissioner (IDPC) in Malta. You may instead complain to the supervisory authority in the EU or EEA country where you live, where you work, or where the matter you are complaining about took place. Complaining to an authority does not affect any other legal remedy available to you.

18. Children's privacy

Our services are sold for professional and commercial use. We do not knowingly collect personal data from anyone under 18, and accounts may not be opened by minors. If we learn that we hold such data without a proper basis, we delete it.

19. Changes and contact

We may update this policy to reflect changes in the law, in our services, or in how we operate. The version and date at the top always show the current one. Material changes are announced in the client area, and the current version is always published on idaserver.net. Please review this page from time to time.

Contact: [email protected], or open a ticket in the client area · IDA LIMITED, a company registered in Malta.

The English version of this policy is the binding one. Translations are provided for convenience.