Privacy Policy
Last updated: [DD/MM/YYYY]
1. Data controller
The controller of your personal data is [Company name], with registered office at [Full address], tax ID [Tax ID], operating under the brand Anthares Host ("we").
Contact: [email protected] · WhatsApp +351 914 800 132.
Data Protection Officer (if appointed): [DPO name / email, or remove this line].
2. What data we process
- Identity and contact: name, email, phone, address, tax ID and company details.
- Billing and payment: order history, invoices and payment method reference. Full card details are handled by the payment provider, not by us.
- Technical service data: assigned IP addresses, control panel access logs, network and security logs (e.g. intrusion attempts, DDoS attack traffic).
- Communications: messages exchanged with us by email, WhatsApp, Telegram or support tickets.
- Website browsing: IP address and technical browser data needed to serve the pages; and, only with your consent, analytics or marketing cookies (see Cookie Policy).
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating your account, activating and providing the services, technical support | Performance of a contract — (b) |
| Billing, accounting and tax obligations | Legal obligation — (c) |
| Network security, fraud prevention, attack mitigation and handling abuse reports | Legitimate interest — (f) |
| Answering enquiries made via WhatsApp, Telegram or email before you sign up | Pre-contractual steps — (b) |
| Sending news and promotions | Consent — (a) (or legitimate interest for existing customers, with an opt-out in every message) |
| Analytics and marketing cookies | Consent — (a) |
| Responding to requests from competent authorities | Legal obligation — (c) |
4. How long we keep data
- Customer data: while the account is active and then for as long as needed to handle any claims.
- Billing documents: 10 years, as required by Portuguese tax law.
- Technical and security logs: up to [e.g. 12 months], unless needed to investigate an incident.
- Data on your servers and hosting accounts: deleted within [e.g. 30 days] after the contract ends.
- Consents: until you withdraw them.
5. Who we share data with
We only share data with parties that help us provide the services, bound by a data processing agreement (Art. 28 GDPR):
- Data centers, network and DDoS protection providers: [names / country]
- Payment provider: [e.g. Stripe, PayPal]
- Billing software and client panel: [e.g. WHMCS + certified invoicing software]
- Communication channels you choose to use: WhatsApp (Meta Platforms Ireland Ltd.) and Telegram.
- Website technical resources: Google Fonts (Google Ireland Ltd.), cdnjs (Cloudflare, Inc.), jsDelivr and Unsplash images. These services receive your IP address in order to deliver the files.
- Google Analytics and Google Ads (Google Ireland Ltd.), only if you accept analytics or marketing cookies, to measure visits and ad effectiveness.
- Authorities, where required by law.
6. Transfers outside the European Economic Area
Some providers (e.g. Meta, Google, Cloudflare) may process data outside the EEA, notably in the US. In those cases, transfers rely on the EU-US Data Privacy Framework or on standard contractual clauses approved by the European Commission (Art. 46 GDPR).
7. Your rights
Under Articles 15 to 22 of the GDPR, you have the right to:
- access your data and obtain a copy;
- rectify inaccurate data;
- request erasure (the "right to be forgotten"), where applicable;
- restrict or object to processing, including direct marketing (at any time);
- portability of the data you provided to us;
- withdraw consent, without affecting the lawfulness of prior processing.
To exercise any right, write to [email protected]. We reply within one month and may ask for proof of identity.
8. Data you host on our servers
For personal data the customer stores on the services (websites, databases, email), the customer is the data controller and Anthares Host acts as processor. We only process that data to provide the service and in line with the customer's instructions, under Art. 28 GDPR and the Terms of Service.
9. Security
We are cybersecurity specialists and apply appropriate technical and organizational measures: encryption in transit, access control, firewalls, continuous monitoring, backups and incident logging. In the event of a data breach that risks your rights, we notify the CNPD within 72 hours and, if the risk is high, the affected individuals as well.
10. Automated decisions and minors
We do not make solely automated decisions with legal effects on you. Our services are intended for people aged 18 or over and for businesses.
11. Changes
We may update this policy. The date of the latest version appears at the top. Significant changes will be communicated to customers by email.