Privacy Policy
Last updated: 28 July 2026 · Version 1.4
This policy explains what personal data we process when you use yiorashost.com and panel.yiorashost.com, why, who we share it with and what rights you have under the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.
1. Who is responsible (controller)
Georgios Koikas, sole trader (ελεύθερος επαγγελματίας)
Olympionikon 19, 20200 Kiato, Korinthia, Greece
Tax ID (ΑΦΜ): 171419432
Email: support@yiorashost.com · Phone: +30 694 735 3025 ·
Support: yiorashost.com/tickets
2. What we collect
- Account data — name, email address, country, password (stored only as a cryptographic hash).
- Billing data — orders, invoices, payment status and payment-method metadata (for example card brand and last four digits). Full card details go directly to our payment provider and never touch our servers.
- Tax-location evidence — the country you declare on your account, and, from our payment provider, the country of your payment method and the transaction identifier. We compare these to determine the correct VAT jurisdiction for each sale and keep the outcome, including any mismatch review, with our tax records.
- Service data — the servers you run and their configuration; the files, worlds, databases and backups you store with us.
- Support data — tickets and emails you send us.
- Technical data — IP addresses, timestamps, requested paths, HTTP status, referrer and browser user agent in web-server, panel, authentication and security logs. We discard query strings when producing site reports.
3. Why we process it (legal bases)
- To provide the Service (contract, Art. 6(1)(b) GDPR): account management, provisioning your servers, billing, support, and service emails such as invoices, renewal reminders and "your server is ready" notices.
- Legal obligations (Art. 6(1)(c)): keeping invoices and tax records as Greek tax law requires, and determining and evidencing the correct VAT jurisdiction for each sale as EU VAT law requires (Art. 24b of Implementing Regulation (EU) 282/2011).
- Legitimate interests (Art. 6(1)(f)): security logging, abuse and fraud prevention, service reliability, aggregate measurement of public-page demand and the sales funnel, and defending legal claims. Reporting is limited to what helps us operate and improve the hosting service and does not create visitor profiles.
- Consent (Art. 6(1)(a)): advertising and analytics measurement through Google, which only runs if you accept it in the cookie banner. You can refuse without losing anything, and you can withdraw at any time from the Cookie Policy — withdrawing does not affect the lawfulness of what was measured before.
We do not send marketing email without your consent and we do not sell personal data.
4. Who we share it with (processors)
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Data-center infrastructure our servers run on | Germany (EU) | Processing in the EU — no transfer |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU); some data processed by Stripe Inc. in the US | EU–US Data Privacy Framework (certified) and SCCs |
| Viva.com | Hosted IRIS payment processing | Greece / EEA | GDPR and the safeguards described in Viva.com's privacy notice |
| Cloudflare, Inc. | DNS and network services for our domains | EU/US | EU–US Data Privacy Framework (certified) and SCCs |
| Resend, Inc. | Sending transactional email (invoices, service notices) | US | Standard Contractual Clauses |
| Google Ireland Ltd. | Advertising and analytics measurement — only if you accept it in the cookie banner | Ireland (EU); some data processed by Google LLC in the US | EU–US Data Privacy Framework (certified) and SCCs |
Stripe, Viva.com, Cloudflare and Google act as our processors for some operations and as independent controllers for others — for example payment-provider fraud prevention and regulatory compliance — as described in their own privacy notices. Where a provider processes data outside the EU/EEA, transfers rest on an EU adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) and/or the European Commission's Standard Contractual Clauses. Each provider's own privacy notice has the details, and you can request a copy of the relevant safeguards from us.
In addition, our accountant receives the billing records needed for bookkeeping and tax filings, and invoice data is transmitted to the Greek tax authority (ΑΑΔΕ) through the myDATA system, as Greek law requires. Beyond that, we disclose personal data only if the law requires it.
5. How long we keep it
- Account data — for as long as your account exists; after account closure we delete or anonymise it within 3 months, except data we must keep longer (below).
- Invoices and tax records — as long as Greek tax legislation requires (at least five years).
- Tax-location evidence — kept with invoices and tax records for the statutory tax-record period.
- Server files, databases and backups — deleted when the service is terminated (see the Terms, section 10).
- Public web access logs — rotated daily; the active log and 10 rotations are normally retained (about 11 days). Other operational and security logs use schedules appropriate to their purpose and are kept no longer than 12 months, most much shorter.
- Support tickets — kept while your account exists and up to 24 months after it closes, for follow-ups and the defence of legal claims.
- Aggregate site reports — Prometheus retains the fixed-category counts for 30 days. The reports contain no IP address, user agent, full URL, query string, referrer URL, customer field or record identifier. Payment and tax records remain subject to their separate legal retention periods above.
6. Players on your server
If you run a server, your players' data (usernames, UUIDs, IP addresses, chat) ends up in your server's files and logs, which we host for you. What runs on the server and what data it collects is your decision — for that content we act on your behalf. Where you are the controller of your community's data, section 15 of the Terms of Service serves as our data-processing agreement with you under Article 28 GDPR.
7. Your rights
You have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to receive it in a portable format (Arts. 15–21 GDPR). Exercise them via a support ticket or email to support@yiorashost.com — we respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In Greece that is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), dpa.gr — though we would appreciate the chance to resolve any concern directly first.
8. Security
All connections to the store, panel and customer databases are encrypted with TLS. Access to infrastructure is restricted, key-based and logged; customer servers run isolated from one another; passwords are stored only as hashes. No internet service can promise perfect security, but if a breach ever affects your data we will notify you and the authority as the GDPR requires.
9. Minors
The Service is not directed at children under 15, matching Greece's age of digital consent (Law 4624/2019). Customers between 15 and 18 need a parent or guardian per our Terms.
10. Cookies and analytics
We run advertising campaigns on Google, and we measure which of them lead to a sale. That measurement uses Google's tag on our store pages, and it only starts once you accept it in the cookie banner. Until you accept, the tag is loaded with every advertising and analytics storage permission switched off: it writes no advertising cookie, reads nothing from your device and Google receives no advertising identifier from us. If you reject, it stays that way permanently, and nothing about the site changes.
If you do accept, Google sets advertising and analytics cookies, we send Google a page view for the pages you open on the store, and when an invoice is paid we send a purchase event containing the invoice number, the amount excluding VAT and the currency. That lets us see which advert produced which sale. We never send Google your name, email address, postal address, server details or payment details. Google does see your IP address, as any website you load something from does; that is a property of the request itself, not something we report. The Cookie Policy lists the individual cookies and is where you withdraw consent.
Separately from all of the above — and regardless of what you choose in the banner — every normal web request creates a short-lived Nginx access-log entry. On our own infrastructure we turn those entries into rolling aggregate counts for fixed page groups (home, plans, content, documentation, legal, cart and checkout), coarse referrer groups and HTTP status classes. Known automated clients are filtered from human counts. An approximate 24-hour visit total is deduplicated temporarily in process memory using IP address and user agent; that set is discarded as soon as each calculation finishes and is never stored or exported.
Only the aggregate counts enter our private monitoring system. Paymenter separately contributes aggregate order totals, successful-payment counts and amounts by currency; no customer, order, invoice or transaction identifier enters analytics. These reports help us decide whether to improve discovery, landing pages, plans or checkout and to detect service errors. See the Cookie Policy for browser-storage details.
11. Changes
We will update this policy when our processing changes — for example new providers or features — and note the date at the top. For significant changes we notify you by email.

