Privacy Policy
Transparent information about the processing of personal data on hts-hosting.com, in the client portal my.hts-hosting.com and in connection with requests for IT, hosting and security services.
Last updated: 07 July 2026
1. Controller
The controller responsible for the processing of personal data on this website and in the customer portal is:
HTS Europa / HTS Hosting
Owner: Mustapha Haouili
Kirchstraße 27
65620 Waldbrunn (Westerwald)-Hausen
Germany
Email: mustapha@hts-hosting.com
Support: support@hts-hosting.com
Phone: +49 1575 699 2825
2. General information on data processing
We process personal data only where this is necessary to provide our website, process enquiries, take steps prior to entering into a contract, perform contracts, provide customer support, secure our systems or comply with legal obligations.
The processing is based in particular on Art. 6(1)(b) GDPR where it is required for pre-contractual measures or contract performance, on Art. 6(1)(f) GDPR where we have a legitimate interest in secure operation, communication, documentation and improvement of our services, and on Art. 6(1)(c) GDPR where legal retention or documentation obligations apply.
3. Website access and server log files
When you access our website or customer portal, technical data transmitted by your browser may be processed. This may include IP address, date and time of access, requested page, referrer URL, browser type, operating system, transferred data volume and technical status codes.
This processing is carried out to provide the website, analyse errors, defend against attacks, detect misuse and ensure stable and secure operation. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our website, customer portal and IT systems.
4. Customer portal, WHMCS and support tickets
We use a WHMCS-based customer portal at my.hts-hosting.com for enquiries, support, offers, orders, customer accounts and ongoing customer communication.
When you use the customer portal, contact form or ticket system, the following categories of personal data may be processed:
- first and last name
- company name, where provided
- email address
- phone number, where provided
- ticket subject
- message content and ticket history
- selected department, priority and ticket status
- uploaded attachments
- technical information you provide for processing the request
- customer account and login data, where an account is created
- orders, booked services and contract data
- invoice data and payment status, where a paid service is ordered
- IP address, timestamps and technical log data for portal security
We process this data to handle enquiries, prepare offers, provide services, deliver support, perform contracts, enable invoicing, prevent misuse and maintain the security of the customer portal.
Please do not submit passwords, access credentials, confidential customer data or other sensitive information through the ticket system unless this has been explicitly agreed. If sensitive information is required for a technical review, we will, where possible, agree on a suitable secure transfer method.
5. Email, telephone and business communication
When you contact us by email, telephone or other communication channels, we process the data you provide to handle your request, ask follow-up questions, prepare offers and document the communication. The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
6. Infrastructure Security Assessment and technical evidence
If you request or order an Infrastructure Security Assessment or a comparable security review, additional technical and organisational information may be processed where this is necessary to assess your IT infrastructure. This may include information about servers, workstations, Active Directory, user and administrator accounts, Group Policy, network services, backup status, security measures, technical contacts and planned remediation measures.
The processing is carried out exclusively for defensive purposes, in particular to analyse the security posture, create reports, prioritise measures, provide technical advice and document the agreed services. We do not perform destructive actions, password spraying, credential theft or unauthorised offensive testing.
7. Cookies and technical functions
Our static marketing website currently does not use non-essential tracking cookies and does not use cloud AI functions to process customer data. The customer portal may use technically necessary cookies, in particular for login, session handling, language settings, shopping cart, form protection and security functions. These cookies are required to provide the customer portal securely and properly.
If analytics, marketing or tracking services are used in the future, this Privacy Policy will be updated accordingly and consent will be obtained where required.
8. Recipients and processors
Personal data is shared only where this is necessary to provide our services, where there is a legal obligation, where you have given consent or where another legal basis applies.
Depending on the service used, technical service providers, hosting providers, domain registrars, payment service providers, email service providers or IT service providers may be involved. Where these providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
9. Retention period
We store personal data only for as long as this is required for the respective purposes or as long as legal retention obligations apply.
Enquiries and support tickets are generally stored for as long as necessary for processing, documentation and customer support. Contract, order and invoice data is stored in accordance with statutory retention periods. Server log files are stored only for as long as required for security, error analysis and operation, unless longer retention is required due to a security incident.
10. Your rights
Subject to the statutory requirements, you have the right to obtain access to your personal data, rectification, erasure, restriction of processing, data portability and the right to object to certain processing activities.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority may be the authority at your place of residence, your workplace or the place of the alleged data protection infringement.
12. Security and data minimisation
We take technical and organisational measures to protect personal data against loss, misuse, unauthorised access and unauthorised disclosure. For security assessments, we work with data minimisation and process only the evidence required for the agreed purpose.
13. Updates to this Privacy Policy
This Privacy Policy may be updated if the website, customer portal, service providers, legal requirements or processing activities change.
14. Privacy contact
If you have any questions about privacy or wish to exercise your rights, please contact us:
Mustapha Haouili
mustapha@hts-hosting.com
support@hts-hosting.com