Legal
Privacy Policy
Last updated: April 2026
Tandata attaches great importance to the protection of your personal data. This privacy policy applies to all Tandata services, including web hosting, WordPress hosting, email hosting, domain registration and related services. We process personal data in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
1. Identity of the Data Controller
Tandata (Tandata B.V.), registered in the Netherlands.
CoC (KvK): 57562938 Β· VAT: NL001125445B02
Email: [email protected] Β· Website: tandata.io
Tandata is the data controller within the meaning of the GDPR.
CoC (KvK): 57562938 Β· VAT: NL001125445B02
Email: [email protected] Β· Website: tandata.io
Tandata is the data controller within the meaning of the GDPR.
2. What personal data do we collect?
Account data: name, email, phone, company name, address, CoC/VAT number.
Payment data: processed by Mollie/Stripe β not stored by Tandata.
Technical data: IP address, browser, OS, referring URL, access times.
Communication data: emails, support tickets, WhatsApp messages.
Server data: access/error logs (may contain IP addresses).
Domain registration: ICANN/SIDN-required data forwarded to OpenProvider B.V.
Payment data: processed by Mollie/Stripe β not stored by Tandata.
Technical data: IP address, browser, OS, referring URL, access times.
Communication data: emails, support tickets, WhatsApp messages.
Server data: access/error logs (may contain IP addresses).
Domain registration: ICANN/SIDN-required data forwarded to OpenProvider B.V.
3. Purposes and legal bases (Art. 6 GDPR)
Contract performance (Art. 6(1)(b)): service delivery, account management, invoicing, migration.
Legitimate interest (Art. 6(1)(f)): infrastructure security, fraud prevention, service improvement.
Legal obligation (Art. 6(1)(c)): fiscal retention (7 years), law enforcement cooperation.
Consent (Art. 6(1)(a)): newsletters, non-essential cookies.
Legitimate interest (Art. 6(1)(f)): infrastructure security, fraud prevention, service improvement.
Legal obligation (Art. 6(1)(c)): fiscal retention (7 years), law enforcement cooperation.
Consent (Art. 6(1)(a)): newsletters, non-essential cookies.
4. Recipients and third parties
Payment: Mollie B.V. (NL). Registrar: Openprovider B.V. (NL). Data centres: EU only.
We never sell your data to third parties.
We never sell your data to third parties.
5. Transfers outside the EEA
Data is processed and stored within the EEA. If transfer outside the EEA is necessary, we use SCCs, adequacy decisions, or BCRs.
6. Retention periods
Account data: contract + 12 months. Invoices: 7 years. Server logs: max 90 days. Support: 24 months. Backups: per package (7β14 days), deleted within 30 days of account removal.
7. Security
TLS/SSL, DNSSEC, DANE, Imunify360, DDoS Shield, access controls, malware scanning, encrypted passwords, regular audits, physical data centre security, daily encrypted backups. Data breaches reported per Art. 33/34 GDPR.
8. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7(3)). Contact: [email protected] (response within 30 days).
9. Automated decision-making
Tandata does not use automated decision-making per Art. 22 GDPR.
10. Data Processing Agreement
When using hosting services, Tandata acts as processor. DPA per Art. 28 GDPR available on request.
11. Minors
Services not aimed at persons under 16.
12. Complaints
Dutch DPA: www.autoriteitpersoonsgegevens.nl
13. Changes
Tandata may amend this policy. Active customers are notified of substantial changes by email.