Privacy Policy
Revision dated July 14th, 2026
1. General Provisions#
This Privacy Policy governs the processing of personal data that Senko Digital LLC (hereinafter referred to as the Company) collects from users when they use the website and hosting services. The Company is registered in Georgia, but no customer data is stored in Georgia. Account, billing, and support data is stored on our infrastructure in Germany and Finland, and Client Content is stored in the location the Client selects, being Germany, Finland, or the Netherlands.
- The Company offers its services primarily to customers in the European Union and the European Economic Area, and processes personal data on infrastructure located in Germany, Finland, and the Netherlands. Regulation (EU) 2016/679 (the “GDPR”) therefore applies to our processing of your personal data, both because we offer services to data subjects in the EEA (Article 3(2) GDPR) and because the processing is carried out on infrastructure within the European Union. In addition, the Law of Georgia on Personal Data Protection applies to the processing that our personnel carry out from Georgia, where the Company is registered — principally the administration of the Services and the provision of support. No customer data is stored in Georgia.
- This Privacy Policy applies to all personal data processed by the Company, regardless of the means of collection (website, client area, email, support tickets, or other communication channels).
- By using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data processing practices, please do not use our services.
- For personal data contained in the content that the Client stores on or transmits through our servers (such as the data of the Client’s own customers or end users), the Client acts as the data controller and the Company acts as a data processor, processing such content only as necessary to provide the hosting services and in accordance with the Client’s instructions. The terms governing that processing are set out in Schedule 1 (Data Processing) to our Terms of Service, which is in force for every such Client without any separate request or signature (see Section 15).
2. Data We Collect#
Data You Provide Directly
- Full name (for identification, account creation, and service provision)
- Email address (for account management, notifications, support, and essential communications)
- Country of residence (for service provision, tax compliance, and jurisdictional requirements)
- Phone number, if provided (for account verification and support)
- Billing address (for billing, invoicing, and tax purposes)
- Payment information and payment method (for processing payments, refunds, and recurring billing)
- Payment card data: Senko Digital LLC does not store full credit card numbers or sensitive authentication data (CVV/CVC). We store only the minimum data necessary to identify the transaction: card provider (e.g., Visa), last 4 digits, holder name, bank name, and bank country. All recurring billing is processed by our PCI-DSS compliant payment processors, who retain the necessary payment tokens on our behalf. This minimal data is stored for fraud prevention and recurring billing purposes.
- Support ticket contents and communications, including the full chat history of support conversations conducted through our Telegram and Discord channels (for providing customer support and maintaining service records)
- Email correspondence between you and the Company, including its content and attachments (for providing support, managing your account, and maintaining service records). This correspondence is stored in our Google Workspace email accounts — see Section 7.
- Domain registrant data, where you register or transfer a domain through us: the registrant name, organisation, postal address, email address, and telephone number required by the registry and by ICANN policy. This data is passed to our registrar and to the relevant domain registry, and may be held by a registry data-escrow agent. Depending on the top-level domain, some registrant data may be published in public WHOIS/RDAP directories, although personal data of individual registrants is generally redacted; where the registry offers it, we apply the available privacy or redaction option.
- Account credentials and security data, including the password (stored only in hashed form), two-factor authentication (2FA) settings, and any SSH keys or API tokens added by the Client (for account access, authentication, and security)
- Content the Client stores on or transmits through our servers, including files, databases, websites, emails, and application data, which may contain personal data of the Client's own end users (processed on the Client's behalf to provide the hosting services — see Section 1)
- Identity verification data: collected only where verification is required (for example, under the sanctions and eligibility checks in our Terms of Service): government-issued identity documents (such as a passport or national ID) and, where the verification is carried out for sanctions purposes, proof-of-address documentation to establish your location. Proof of address is not requested for any other type of check. This data is collected and processed on our behalf by our identity-verification provider, Sumsub (see Section 7). We do not collect facial images or biometric data as part of this process.
Data Collected Automatically
- IP address (for security, fraud prevention, abuse detection, and service delivery)
- Browser type and version, operating system, and device information (for website optimization and security)
- Pages visited, time spent on pages, referral sources, and clickstream data (for analytics and service improvement)
- Cookies and similar technologies (for website functionality and user experience — see Section 8)
- Server access logs and error logs (for security monitoring, troubleshooting, and abuse prevention)
Data Received from Third Parties
- Payment confirmation and transaction data from payment processors (for order fulfillment and fraud prevention)
- Fraud screening results from payment processors (for fraud prevention and risk assessment)
- Profile data from social login providers (Google, GitHub) when the Client chooses to register or sign in using them — such as name, email address, and provider account identifier (for account creation and authentication)
3. Purpose of Data Processing#
- To provide, manage, and maintain our hosting services and user accounts (legal basis: contract performance)
- To process payments, refunds, and manage billing (legal basis: contract performance)
- To communicate with users and provide customer support (legal basis: contract performance, legitimate interests)
- To ensure network security and prevent fraud, abuse, and unauthorized access (legal basis: legitimate interests)
- To monitor and enforce compliance with our Terms of Service and Acceptable Use Policy (legal basis: legitimate interests, contract performance)
- To improve our services based on user feedback and analytics (legal basis: legitimate interests, consent where required)
- To send essential service notifications such as maintenance alerts, security updates, and billing reminders (legal basis: contract performance)
- To comply with applicable legal obligations, respond to legal processes, and cooperate with regulatory authorities (legal basis: legal obligation)
- To verify your identity, location, and eligibility, and to carry out sanctions and fraud screening where required (legal basis: legal obligation and legitimate interests)
4. Legal Basis for Processing#
We process your personal data only when we have a valid legal basis to do so. The specific legal basis depends on the type of data and the purpose of processing:
- Contract performance — processing necessary for providing our hosting services, managing your account, processing payments, and delivering customer support (applies to: account data, billing data, support communications).
- Consent — where we seek your explicit permission, such as for marketing communications, non-essential cookies, and optional analytics. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
- Legitimate interests — where processing is necessary for our business purposes, such as fraud prevention, network security, service improvement, and abuse detection, provided these interests do not override your fundamental rights and freedoms.
- Legal obligation — where we need to process data to comply with applicable laws, including Georgian tax law, applicable sanctions measures, and law enforcement requests.
5. Your Data Protection Rights#
Depending on your location and applicable laws, you may have the following data protection rights:
Under Georgian Data Protection Law
- Right to be informed about how your personal data is processed
- Right to access your personal data and receive a copy
- Right to request the correction, update, or completion of inaccurate or incomplete data
- Right to request the blocking of your personal data
- Right to request the deletion or destruction of your data, including where it has been processed unlawfully or is no longer necessary
- Right to data portability — to receive your personal data in a structured, commonly used format
- Right to withdraw your consent at any time where processing is based on consent
- Right not to be subject to a decision based solely on automated processing, including profiling
- Right to lodge a complaint with the State Audit Office of Georgia — which, since 2 March 2026, is the supervisory authority for personal data protection in Georgia and the legal successor of the former Personal Data Protection Service — or to seek a judicial remedy
Under EU GDPR (for EEA residents)
- Right to be informed about how your personal data is used
- Right to access your personal data and receive a copy
- Right to have inaccurate data rectified
- Right to erasure ('right to be forgotten') in certain circumstances
- Right to restrict processing of your data
- Right to data portability
- Right to object to processing based on legitimate interests or direct marketing
- Right not to be subject to automated decision-making, including profiling
- Right to lodge a complaint with your local data protection authority
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
6. Data Retention#
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or to meet our legal obligations. The following retention periods apply:
- Account information (name, email, country): Retained for the duration of the account and for up to 6 years after account closure, in line with the retention period mandated by the accounting legislation of Georgia and applicable tax and regulatory obligations.
- Payment and billing data: Retained for up to 6 years after the last transaction, as mandated by the accounting legislation of Georgia and applicable tax obligations.
- Server and access logs: Retained for up to 12 months for security and abuse prevention purposes.
- Support ticket records: Retained for up to 3 years after resolution for quality assurance and dispute resolution.
- Analytics data: Aggregated and anonymized analytics data may be retained indefinitely. Identifiable analytics data is retained for up to 26 months.
- Identity verification data (an identity document and — for sanctions checks only — proof-of-address documentation): where the verification is completed and no concerns arise, this data is deleted from the systems of our identity-verification provider within 60 days of the verification being completed, and we keep only a minimal record that the verification took place — its date, reference, and outcome — without the documents themselves. Where the verification identifies a sanctions match, fraud, or another breach of our Terms of Service, the data and the record of the decision are retained for up to 5 years from that decision, in order to evidence our compliance, to prevent re-registration, and to establish, exercise, or defend legal claims.
- Email correspondence: retained for up to 3 years after the last message in the thread, in line with the retention period for support records.
- Domain registrant data: retained for as long as the domain is registered through us and for up to 2 years after it expires or is transferred away, and for any longer period that the relevant registry or ICANN policy requires us or the registry to retain it.
- Client Content (the content you store on or transmit through our servers): retained for as long as the service is active. On termination or expiry, it is held for seven (7) days so that you may retrieve it, and is then permanently deleted, as provided in Section 7 of our Terms of Service and in Schedule 1 to that agreement. You are responsible for maintaining your own backups.
- The Company may retain certain data for longer periods as required by law or for legitimate business purposes, including dispute resolution and enforcement of agreements.
7. Data Sharing with Third Parties#
Your data will not be shared with third parties without your consent, except when necessary for service provision, legal compliance, or protection of our legitimate interests. Not every recipient is our processor: some, such as payment providers, decide for themselves how they use your data and act as independent controllers. We identify below which is which, because the safeguards differ.
Processors acting on our instructions
The following service providers process personal data on our behalf and on our documented instructions. Each is bound by a written data processing agreement — in each case incorporated into that provider’s terms of service, which we have accepted — requiring it to implement appropriate security measures, process the data only as instructed, keep it confidential, and assist us in meeting our obligations to you.
- Infrastructure and security for our own websites: Cloudflare (Cloudflare, Inc.) — for CDN services, DDoS protection, and website security; and Sucuri (GoDaddy Media Temple, Inc., d/b/a Sucuri) — for website security monitoring, malware detection and removal, and web application firewall services. Both are established in the United States. These providers serve only our own public websites and the Client Area. No customer service is proxied through them: traffic to and from the servers, game servers, and websites we host for you does not pass through Cloudflare or Sucuri, and neither provider receives, inspects, or stores the content you host with us. What they process is limited to data about visitors to our own sites, such as IP address, request metadata, and security telemetry.
- Communications: Mailgun (Mailgun Technologies, Inc., established in the United States) — for transactional email delivery (order confirmations, support responses, account notifications); and Google Workspace (Google Ireland Limited, established in Ireland) — for the email accounts we use to correspond with Clients, meaning that the content of email correspondence between you and the Company is stored on Google Workspace.
- Analytics: Google Analytics (Google Ireland Limited) — for website usage analysis and service improvement, deployed only where you have consented to non-essential cookies. We also use Umami, which we host ourselves on our own infrastructure; Umami analytics data is not shared with any third party and does not leave our infrastructure.
- Domain registration and transfers: Hosting Concepts B.V. — our domain registrar, established in the Netherlands. Where you register or transfer a domain through us, the registrant details required by the registry and by ICANN policy (including name, postal address, email address, and telephone number) are shared with the registrar and, as required, with the relevant domain registry.
- Backup and image storage: Backblaze (Backblaze, Inc.) — S3-compatible object storage in a European Union region, used only to hold game-server backups that you initiate and virtual-machine image extracts that we create at your request. Nothing is uploaded automatically or on a continuous basis, and Backblaze has no access to your account, billing, or support data. Because such a backup or image forms part of your own content, it may contain personal data of your end users. Backblaze, Inc. is established in the United States; see Section 10.
- Identity verification and compliance screening: Sumsub (Sum and Substance Ltd, United Kingdom) — where identity verification is required (for example, under the sanctions and eligibility checks described in our Terms of Service), Sumsub verifies your identity on our behalf and screens you against sanctions, watchlist, and politically-exposed-person databases. This involves a government-issued identity document, and proof-of-address information additionally where the check is carried out for sanctions purposes. No facial image or biometric data is collected or processed. Sumsub also acts as an independent controller to the extent it maintains its own screening databases and meets its own regulatory obligations.
Independent controllers with whom we share data
The following recipients do not act on our instructions. They determine the purposes and means of their own processing — principally to meet their own anti-money-laundering, fraud-prevention, tax, and regulatory obligations — and are therefore independent controllers, each responsible for its own processing under its own privacy policy, which we encourage you to read.
- Payment providers: Keepz, Payssion, PayPal, Cryptomus, NOWpayments, and Paddle.com Market Ltd — for processing payments, refunds, and fraud prevention. Where the Client chooses to pay through Paddle, Paddle.com Market Ltd acts as the merchant of record for that transaction and processes the Client’s billing, tax, and fraud-screening data in that capacity. Our PayPal payments are handled by PayPal Pte. Ltd., established in Singapore and licensed by the Monetary Authority of Singapore as a Major Payment Institution under the Payment Services Act 2019; see Section 10 for how that transfer is handled.
We remain responsible for our own processing and for our choice of processors, and we assess each of them before engagement. We are not responsible for the independent processing carried out by the controllers identified above, which is governed by their own terms and privacy policies.
We may also disclose your data when required by law, court order, or governmental authority, or when necessary to protect our rights, property, or safety, or that of our users or the public.
8. Use of Cookies#
We use cookies and similar technologies on our website. Cookies are small text files stored on your device that help us provide and improve our services.
Strictly Necessary Cookies
These cookies are essential for the website to function properly. They include session cookies, authentication cookies, and security cookies. These cannot be disabled.
Analytical Cookies
We use Google Analytics (provided by Google Ireland Limited) to understand how visitors interact with our website. It collects information such as pages visited, time spent on pages, and referral sources, and it is loaded only where you have consented to analytical cookies. We also use Umami, a privacy-focused analytics platform that we host ourselves on our own infrastructure; it does not use cookies, does not collect personal data, and does not share data with any third party.
Functional Cookies
These cookies enable enhanced functionality such as language preferences and region selection. They may be set by us or by third-party providers whose services we have added to our pages.
Where required by applicable law, we will obtain your consent before placing non-essential cookies on your device. You can manage your cookie preferences through your browser settings or through our cookie consent mechanism on the website.
9. Data Protection Measures#
The Company implements appropriate technical and organizational measures to protect Client data against unauthorized access, alteration, disclosure, or destruction.
- Technical measures include: encryption of data in transit (TLS/SSL), encrypted storage where applicable, firewall protection, intrusion detection systems, regular security updates and patching, and access logging.
- Organizational measures include: role-based access controls limiting data access to authorized personnel only, employee confidentiality obligations, regular security assessments, and incident response procedures.
- No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
10. International Data Transfers#
No customer data is stored in Georgia. The account, billing, and support data of which the Company is the controller is stored on our infrastructure in Germany and Finland. Client Content is stored in the location selected by the Client, being Germany, Finland, or the Netherlands. Personal data may nevertheless be transferred outside your country of residence, as described below.
- Access from Georgia. We store no customer data in Georgia. Our personnel in Georgia do, however, access data held on our EEA infrastructure in order to administer the Services and provide support. The data is not shared with any other organisation as a result: it remains ours, held on our EEA infrastructure, and subject to the GDPR. We limit that access to authorised personnel under role-based access controls, bind those personnel to confidentiality, and log the access, as described in Section 12. Georgian data protection law also applies to the processing our personnel carry out in Georgia.
- Storage within the EEA. Germany, Finland, and the Netherlands are all within the EEA, so no additional transfer mechanism is required for storing data in, or moving data between, those locations.
- By using our services, you acknowledge that your data may be processed in Georgia, in the EEA countries where our servers are located, and by the providers identified in Section 7 in the countries stated there.
- Providers within the EEA or covered by an adequacy decision. Google Ireland Limited (Ireland), which provides our Google Workspace email and Google Analytics, and Hosting Concepts B.V. (Netherlands), our domain registrar, are both established within the EEA, so no transfer mechanism is required for them. Sum and Substance Ltd (United Kingdom), our identity-verification provider, is covered by the European Commission’s adequacy decision for the United Kingdom, which was renewed in December 2025; the United Kingdom also appears on the list of states offering adequate safeguards maintained under Georgian law.
- Transfers from our EU infrastructure to providers in the United States. Cloudflare (Cloudflare, Inc.) and Sucuri (GoDaddy Media Temple, Inc., d/b/a Sucuri), which provide security and content-delivery services, and Mailgun (Mailgun Technologies, Inc.), which delivers our transactional email, are established in the United States. These transfers are made from our infrastructure in the European Union and are therefore governed by Chapter V of the GDPR. Each of these providers incorporates a data processing agreement into its terms of service, including the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), which apply to our use of their services; each is also currently certified under the EU–US Data Privacy Framework. We supplement these safeguards with encryption in transit and at rest and by disclosing to each provider only the data it needs.
- Backblaze. The object storage we use for game-server backups and virtual-machine image extracts is located in a European Union region, so that data is stored within the EEA, and nothing is uploaded to it automatically. Backblaze, Inc. is established in the United States; to the extent it can access that data from the United States, the transfer is governed by Chapter V of the GDPR, and Backblaze incorporates the Standard Contractual Clauses into its terms of service. Backblaze is also currently certified under the EU–US Data Privacy Framework.
- PayPal. Where you choose to pay by PayPal, your payment is handled by PayPal Pte. Ltd., established in Singapore, which acts as an independent controller and not on our instructions. Singapore is not covered by an EU adequacy decision. We transfer to PayPal only the limited data needed to create and reconcile the payment you have asked us to take — such as your email address, the order reference, and the amount — while the payment details themselves are given by you to PayPal directly through its own checkout. Because we offer PayPal as a standing payment method rather than on an occasional basis, we do not rely on the contractual derogation in Article 49(1)(b) of the GDPR for these transfers. They are instead governed by Chapter V of the GDPR and made under the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), which are incorporated into PayPal's data protection terms and apply to our use of PayPal. We supplement those clauses by disclosing to PayPal only the data described above. If you prefer not to have your data transferred to Singapore, you can choose any of our other payment methods, and we will not transfer your data to PayPal.
- Countries outside the EEA. Where your data is transferred to a provider outside the European Economic Area, the legal protections in that country may differ from those available to you in the EEA. In particular, public authorities there may in certain circumstances be able to access data held by providers subject to their jurisdiction, and the remedies available to you may be narrower than those you have under EU law. We take this into account when choosing providers: we disclose to each provider only the data it needs, we encrypt data in transit and at rest, and we put in place the safeguards described above.
11. Changes to the Privacy Policy#
The Company may update this Privacy Policy from time to time. Updates — including any change to the recipients of your data or to the countries to which it is transferred — are made in accordance with the procedure in Section 2.2 of our Terms of Service: when the Privacy Policy is updated, you are asked to review the updated version and to accept it expressly, by activating a confirmation checkbox in your Client Area, before continuing to use the Services. Your acceptance is recorded at that point, and mere continued use of the Services is never treated as acceptance of a change. Separately, where we add or replace a sub-processor with access to Client Content, you additionally receive at least thirty (30) days' prior written notice and may object on reasonable data protection grounds, as provided in Schedule 1 (Data Processing) to our Terms of Service.
12. Contact Information#
If you have any questions regarding the processing of your data or wish to exercise your data protection rights, please contact us:
- Email: [email protected]
- Registered address: Senko Digital LLC, Terenti Graneli Street N10-12, Entrance 2, Floor 1, Tbilisi, Georgia
- Supervisory authority: for complaints regarding our processing of personal data under Georgian law, you may contact the State Audit Office of Georgia (sao.ge), which has been the supervisory authority for personal data protection since 2 March 2026, succeeding the former Personal Data Protection Service.
- EU/EEA Data Protection Authorities: If you are located in the EU/EEA and believe your data has been processed unlawfully, you have the right to lodge a complaint with your local data protection authority.
13. Children's Data#
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without verified parental consent, we will take steps to delete that information promptly.
If you believe that we have inadvertently collected data from a minor, please contact us immediately at [email protected].
14. Automated Decision-Making#
The Company does not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Where we screen account sign-ups and account activity against sanctions lists and fraud-risk indicators — including through a third-party identity-verification and screening provider — a potential match is reviewed by a member of our staff before any decision to refuse, suspend, or terminate an account is made. You have the right to obtain human intervention, to express your point of view, and to contest such a decision by contacting [email protected]. If our practices change in the future, we will update this Privacy Policy and provide appropriate information and safeguards.
15. Data Processing Agreement#
Where the Company processes personal data on a Client’s behalf — that is, personal data contained in the content the Client stores on or transmits through our servers — the terms required by Article 28 of the GDPR and Article 36 of the Law of Georgia on Personal Data Protection are already in force between us. They are set out in Schedule 1 (Data Processing) to our Terms of Service, which forms part of the Agreement and is accepted when the Client accepts the Terms of Service. No separate request or signature is needed, and this applies to every Client for whom we act as a processor.
Clients who additionally require a separately executed Data Processing Agreement — for example on their own paper, or to satisfy their own customers’ procurement requirements — may request one at [email protected]. Where such an agreement is executed, it prevails over Schedule 1.
16. Data Breach Notification#
In the event of a personal data incident, the Company will notify the competent supervisory authority without undue delay and, where the applicable notification threshold is met, no later than 72 hours after identifying the incident. Under Georgian law that threshold is reached where the incident is, with medium or high probability, likely to cause significant damage to, or pose a significant threat to, fundamental rights and freedoms; under the GDPR, notification is required unless the incident is unlikely to result in a risk to your rights and freedoms.
Where the incident is likely to result in a high risk to your rights and freedoms — under Georgian law, a high probability of significant damage or a significant threat to them — we will also inform you directly, without undue delay. We may be relieved of that duty where we had taken appropriate protective measures that prevented the risk from materialising, for example where the data was encrypted or otherwise rendered unintelligible to unauthorised persons.
Where we act as a processor on behalf of a Client, we will notify that Client of an incident affecting their data without undue delay, and provide the information they need in order to meet their own notification obligations.
17. Marketing Communications#
- We offer an optional newsletter containing company news, such as new product lineups, service announcements, and updates. We send it only where you have consented to receive it, and never as a condition of using the Services.
- You may unsubscribe at any time by clicking the unsubscribe link in the footer of any such email. Unsubscribing from the newsletter does not affect essential service communications (such as billing, security, and maintenance notifications), which are necessary to provide the Services.
18. Final Provisions#
- This Privacy Policy should be read together with our Terms of Service and Acceptable Use Policy, which together govern your use of the Services.
- If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect.
- This Privacy Policy is governed by the laws of Georgia, without prejudice to any mandatory data protection rights you may have under the GDPR or other applicable laws of your country of residence.
- This Privacy Policy is provided in multiple languages for convenience. In the event of any discrepancy between versions, the English version prevails.