Privacy Policy

Last updated: April 2026

Tandata attaches great importance to the protection of your personal data. This privacy policy applies to all Tandata services, including web hosting, WordPress hosting, email hosting, domain registration and related services. We process personal data in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

1. Identity of the Data Controller

Tandata (Tandata B.V.), registered in the Netherlands.
CoC (KvK): 57562938 Β· VAT: NL001125445B02
Email: [email protected] Β· Website: tandata.io

Tandata is the data controller within the meaning of the GDPR.

2. What personal data do we collect?

Account data: name, email, phone, company name, address, CoC/VAT number.
Payment data: processed by Mollie/Stripe β€” not stored by Tandata.
Technical data: IP address, browser, OS, referring URL, access times.
Communication data: emails, support tickets, WhatsApp messages.
Server data: access/error logs (may contain IP addresses).
Domain registration: ICANN/SIDN-required data forwarded to OpenProvider B.V.

3. Purposes and legal bases (Art. 6 GDPR)

Contract performance (Art. 6(1)(b)): service delivery, account management, invoicing, migration.
Legitimate interest (Art. 6(1)(f)): infrastructure security, fraud prevention, service improvement.
Legal obligation (Art. 6(1)(c)): fiscal retention (7 years), law enforcement cooperation.
Consent (Art. 6(1)(a)): newsletters, non-essential cookies.

4. Recipients and third parties

Payment: Mollie B.V. (NL). Registrar: Openprovider B.V. (NL). Data centres: EU only.

We never sell your data to third parties.

5. Transfers outside the EEA

Data is processed and stored within the EEA. If transfer outside the EEA is necessary, we use SCCs, adequacy decisions, or BCRs.

6. Retention periods

Account data: contract + 12 months. Invoices: 7 years. Server logs: max 90 days. Support: 24 months. Backups: per package (7–14 days), deleted within 30 days of account removal.

7. Security

TLS/SSL, DNSSEC, DANE, Imunify360, DDoS Shield, access controls, malware scanning, encrypted passwords, regular audits, physical data centre security, daily encrypted backups. Data breaches reported per Art. 33/34 GDPR.

8. Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7(3)). Contact: [email protected] (response within 30 days).

9. Automated decision-making

Tandata does not use automated decision-making per Art. 22 GDPR.

10. Data Processing Agreement

When using hosting services, Tandata acts as processor. DPA per Art. 28 GDPR available on request.

11. Minors

Services not aimed at persons under 16.

12. Complaints

Dutch DPA: www.autoriteitpersoonsgegevens.nl

13. Changes

Tandata may amend this policy. Active customers are notified of substantial changes by email.