Server Pay Legal

GDPR Compliance

Last updated: July 29, 2026

This page describes how Server Pay approaches the EU General Data Protection Regulation (GDPR) and similar laws for users in the European Economic Area (EEA), UK, and Switzerland. It complements our Privacy Policy and is not legal advice.

1. Our role

For account, billing, and website data, Server Pay typically acts as a data controller. For content you store on your rented servers (websites, databases, files), you are generally the controller and Server Pay acts as a processor providing infrastructure. You must ensure you have a lawful basis to process personal data you place on our servers.

2. Lawful bases we rely on

Depending on the processing activity, we may rely on:

  • Contract — to create your account, take crypto payment, and deliver hosting.
  • Legitimate interests — network security, abuse prevention, service improvement, and fraud detection, balanced against your rights.
  • Legal obligation — accounting, tax, or responding to valid lawful requests.
  • Consent — where required (for example certain cookies or optional marketing).

3. Categories of personal data

Typical categories include email, technical logs (IP, device), payment transaction references on public blockchains, support correspondence, and service usage metadata. We do not require KYC identity documents for standard hosting signup.

4. Your GDPR rights

Subject to legal limits, you may have the right to:

  • Access — obtain a copy of personal data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion (“right to be forgotten”) where applicable.
  • Restriction — ask us to limit processing in certain cases.
  • Portability — receive structured data you provided to us.
  • Objection — object to processing based on legitimate interests or direct marketing.
  • Withdraw consent — where processing is consent-based, without affecting prior lawful processing.

5. How to exercise your rights

Email support@serverpay.com with the subject “GDPR Request” and enough detail to verify your account (e.g. registered email and request type). We aim to respond within one month, or longer where complexity requires and law allows. We may request additional information to confirm identity and prevent unauthorized disclosure.

6. International transfers

Infrastructure and vendors may be outside the EEA. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms, together with technical and organizational measures.

7. Security measures

We apply measures appropriate to risk, including access control, encryption in transit, logging, and abuse monitoring. Customers remain responsible for securing applications and data on their instances (patching, firewalls, credentials).

8. Breach notification

If a personal data breach affecting us as controller is likely to result in risk to individuals’ rights and freedoms, we will notify the competent supervisory authority and, where required, affected users, in line with GDPR timelines.

9. Children

Server Pay services are not directed at children under 16 (or the minimum age in your country). We do not knowingly collect personal data from children.

10. Supervisory authority

EEA users may lodge a complaint with their local data protection authority. We encourage contacting us first so we can try to resolve concerns directly.

11. Contact

Data protection inquiries: support@serverpay.com.

© 2026 Server Pay