Privacy Notice

Last revised 18 February 2026

This privacy notice ("Privacy Notice") for SPACELAMA KFT ("the Company", "we", "us", or "our") explains how and why we collect, use, disclose, and otherwise process ("process") personal data when you interact with us.

This Privacy Notice applies when you:

  • Visit www.spacelama.com (the "Website");
  • Purchase or use our shared hosting services;
  • Register or manage a domain name through us;
  • Purchase SSL certificates or related security services;
  • Contact our customer support or communicate with us;
  • Receive invoices, billing communications, or make payments;
  • Participate in sales discussions, marketing communications, promotions, or events;
  • Otherwise interact with us in connection with our services (collectively, the "Services").

For the purposes of Regulation (EU) 2016/679 ("GDPR"), this Privacy Notice describes the categories of personal data we process; the purposes and legal bases for processing; the recipients of personal data; applicable retention periods; international data transfers; and your rights as a data subject.

The Company's details

Name: SPACELAMA KFT
Registration Number: 13-09-234900
Registered Office: 15, Ráckeve, Március, Apt.: 3/B, 2300, Hungary
Contact: support@spacelama.com

Where required under Regulation (EU) 2016/679 ("GDPR"), we act as either:

  • Data Controller – for customer registration, billing, domain registration, support, and payment data.
  • Data Processor – for personal data stored by customers on their hosted websites.

Questions or concerns?

Reading this Privacy Notice will assist you in understanding your privacy rights and options. Should you have further questions or concerns, please reach out to us at support@spacelama.com

1. DEFINITIONS

Personal Data – Any information relating to an identified or identifiable natural person (GDPR Art. 4(1)).

Customer – Any individual or legal entity purchasing Services.

Account Data – Data required to create and maintain a SpaceLama account.

Hosted Data – Content, files, databases, emails, and other information stored in a hosting account.

2. CONTROLLER AND PROCESSOR ROLES

2.1 When We Act as Data Controller

We act as Data Controller when we determine the purposes and means of processing personal data. This applies to personal data collected for the following purposes:

  • Account registration and identification
  • Billing, invoicing, and payment processing (including payments processed via Stripe or other payment providers)
  • Customer communication
  • Support tickets
  • Domain registration data collected as part of our services (subject to registrar obligations, see Section 3.4)
  • Fraud prevention
  • Legal and regulatory compliance (GDPR Art. 24)

Processing in this context is carried out to provide, manage, and improve our Services, and to comply with applicable legal obligations.

2.2 When We Act as Data Processor

For Hosted Data stored in a Customer's hosting account:

  • The Customer is the Data Controller (GDPR Art. 4(7)) and determines the purposes and means of processing.
  • SpaceLama acts as Data Processor (GDPR Art. 28), processing data only on the documented instructions of the Customer.
  • Processing includes website visitor data, customer databases, email accounts, logs, and backups, solely to provide hosting services.
  • Customers remain fully responsible for ensuring GDPR compliance of their website; establishing a lawful basis for any data collection; obtaining cookie consent where required; configuring website and application security

2.3 Processing on Behalf of Third-Party Providers

In some cases, SpaceLama may process personal data on behalf of third-party service providers, including:

  • Payment processors
  • Backup or infrastructure providers
  • Other software or services used to operate or maintain the Services

In these situations:

  • The third-party provider may act as a Data Controller or Data Processor, depending on the context.
  • When processing personal data on our instructions for the provision of Services, they act as Data Processor (GDPR Art. 28).
  • SpaceLama acts strictly as Data Processor, processing data only as necessary to provide the contracted service and in accordance with the documented instructions of the third-party provider.
  • We implement technical and organizational measures to maintain security, confidentiality, and GDPR compliance, including sub-processor management.

2.4 Domain Registration Obligations (ICANN / Registrar Roles)

When you register a domain through SpaceLama, we act as a reseller of an ICANN-accredited registrar or other registry-accredited reseller. Under our agreements with the registrars (ConnectReseller, NameSilo, CentralNic Reseller, ResellerClub) and applicable ICANN or registry rules:

  • Certain registrant, administrative, and technical contact data must be collected and transmitted to the registry or registrar.
  • Some of this data may be published via WHOIS/RDAP or shared with third parties for lawful purposes.
  • Depending on the registrar agreement, the registrar may be the Data Controller, or SpaceLama may act as joint controller for specific aspects of domain registration data (GDPR Art. 26).
  • SpaceLama processes this data only as necessary to fulfill registrar obligations and in accordance with GDPR requirements for security and confidentiality.
  • Customers are responsible for providing accurate contact information and ensuring any necessary consents are obtained for transferring personal data to the registrar or registry.

3. WHAT INFORMATION DO WE COLLECT AND CATEGORIES OF PERSONAL DATA

We collect and process personal data to provide, operate, and improve our Services. The type of data we collect depends on your interactions with us, the Services you use, and the choices you make. This includes both data you provide and data we collect automatically.

3.1 Personal Information You Provide to Us

We gather personal data that you willingly share when you:

  • Sign up for a customer account
  • Purchase or use our Services, including hosting, domain registration, and SSL certificates
  • Express interest in our products or Services
  • Participate in activities, promotions, or events
  • Contact our customer support team or otherwise communicate with us

The personal information you provide may include the following categories:

Account Registration & Identification Data include:

  • Full name
  • Company name (if B2B)
  • Billing address
  • Email address
  • Phone number
  • VAT number (if applicable)

In some cases, we may request additional verification information if legally required, for fraud prevention, or if unusual activity is detected.

When registering a customer account, certain personal information is required as "mandatory fields," generally including:

  • Personal Details: First Name, Last Name, Company/Organization Name, Address, Street/City/State, Province/Country/Zip Code, Country, Phone Number, Email Address
  • Company Details (for business registrations): First Name, Last Name, Email, Username, Phone Number, Company Name, Company Address, Street, City, State/Province, Country, ZIP/Postal Code, VAT ID, Preferred Currency, Referral Channel

This information is used for customer identification, account management, and service provision. The legal basis for processing this data is the necessity to fulfill contractual or pre-contractual obligations.

You may also voluntarily provide additional information for our legitimate interest in verification, fraud prevention, and more efficient communication.

To access your account, you will create a User-ID and password. It is essential to ensure that your login credentials remain confidential and are not accessible to unauthorized individuals.

3.2 Billing & Payment Data

We collect and process payment-related personal data necessary to manage subscriptions, billing, and secure transactions for our Services.

This may include:

  • Payment method details (e.g., cardholder name, partial card number, expiry date — processed via secure payment service providers such as Stripe or other authorized providers);
  • Transaction history;
  • Subscription period (monthly/yearly);
  • Billing and invoicing details;
  • Payment status and renewal information.

We do not store full card numbers or sensitive authentication data on our servers.

3.3 Domain Registration Data

  • Registrant, administrative, and technical contact data
  • Email, phone, address
  • DNS records
  • Domain transfer codes (EPP)

3.4 Support Data

  • Support ticket contents and attachments
  • Communication logs
  • IP address used when contacting support

3.5 Other Voluntary Data

  • Any additional information provided for verification or improved communication
  • User-ID and password for account access

The legal basis for processing these data is generally the performance of a contract with you (Art. 6(1)(b) GDPR) or compliance with legal obligations (Art. 6(1)(c) GDPR). Certain voluntary data may be processed based on our legitimate interests (Art. 6(1)(f) GDPR) or your consent (Art. 6(1)(a) GDPR).

3.6 Information Collected Automatically

When you visit, use, or interact with our Services, we automatically collect certain information to maintain the security, functionality, and performance of the Services, as well as for internal analytics and reporting. This information does not specifically identify you but may include the following categories:

(a) Log and Usage Data

  • Pages visited, referring URLs, and subsequent websites accessed
  • Data volume transmitted, access status, operating system, browser type, settings, and version
  • Details about your activity within the Services, including timestamps, pages or files viewed, searches, and other actions
  • Service-related, diagnostic, usage, and performance details gathered by our servers

(b) Device Data

  • Device and application identification numbers
  • Browser type, operating system, hardware model, IP address, internet service provider
  • Device name, country, device location (if available), mobile carrier, and system configuration details
  • Language preferences

(c) Location Data

  • IP-Based Location Data: We may derive approximate geographic location (such as country or region) from your IP address for purposes of security monitoring, fraud prevention, service optimization, analytics, and regional compliance requirements. IP-based or system-level location processing is based on our legitimate interests in maintaining service security, preventing fraud, ensuring network integrity, and optimizing service delivery (Art. 6(1)(f) GDPR or local equivalent).
  • Device-Based or Precise Geolocation (Where Applicable): We do not independently request or actively collect precise geolocation data. Where mobile applications, browser features, analytics providers, advertising technologies, or operating system-level permissions enable the collection of more precise location data, such processing is carried out by the relevant third-party provider in accordance with their own privacy policies and consent mechanisms. You may modify or withdraw location permissions at any time through your device or browser settings. Restricting location access may limit certain functionalities of third-party features integrated into the Services.

(d) Cookies and Other Tracking Technologies

We also use cookies and similar technologies from third-party service providers to improve analytics, functionality, and security. These technologies may include session or persistent cookies, web beacons, and local storage objects. For more details, please see our Cookie Policy.

(e) Temporary Data Storage

  • Log files and other automatically collected data are temporarily stored to facilitate website delivery and to maintain IT system security (e.g., protection against DDoS attacks)
  • Unless otherwise specified, IP addresses are anonymized as soon as possible to prevent identification
  • The legal basis for temporary storage is the necessity to provide our website and fulfill a contract or pre-contractual measures (Art. 6(1)(b) GDPR); further storage with anonymized IP addresses is based on our legitimate interest in protecting IT systems (Art. 6(1)(f) GDPR).
  • Personal evaluation of the data, especially for marketing purposes, does not occur without prior consent

3.7 Special Categories of Personal Data

We do not intentionally collect or process special categories of personal data within the meaning of Article 9 of the General Data Protection Regulation ("GDPR"), or personal data relating to criminal convictions and offences under Article 10 GDPR, when acting as a Data Controller.

However, in the context of providing hosting and related infrastructure services, we may process personal data — including special categories of personal data — solely in our capacity as a Data Processor, where such data is included in content hosted or transmitted by our customers.

In such cases:

  • We act exclusively on the documented instructions of the customer;
  • The customer acts as the Data Controller and is responsible for determining the lawful basis for processing;
  • We do not access, review, or monitor hosted content except where necessary for security, technical support, or as required by law.

Customers are responsible for ensuring that their use of our Services complies with applicable data protection laws.

4. HOW DO WE PROCESS YOUR INFORMATION?

We utilize your data to provide, improve, and manage our Services, communicate with you, ensure security, prevent fraud, and comply with legal obligations. Additionally, we may use your information for other purposes with your consent. This includes:

4.1 Account Creation and Management

We use your information to create, maintain, and manage your Spacelama account, including facilitating access to hosting, domain registration, and SSL certificate services.

4.2 Service Delivery

We use your information to provide, manage, and maintain the services you request. This includes:

(a) Hosting Services:

We use your data to provide the hosting services you have requested, including account provisioning, cPanel access, email accounts, backups, and third-party software integrations.

(b) Domain Registration and SSL Certificates:

For domain name and SSL certificate registration, we process your information to submit required data to registries or Certificate Authorities, ensure compliance with registry rules, and facilitate management of your domains and SSL certificates. These services are separate products with their own terms and obligations. For SSL certificates, we submit information to Certificate Authorities to issue and manage certificates in accordance with their rules and industry standards.

(c) Public Registry / WHOIS Compliance:

In certain jurisdictions and pursuant to ICANN or registry rules, domain registration information may be made publicly available through WHOIS searches. We store this information and may provide it to registries, escrow providers, or authorities as required.

4.3 Customer Support & Communications

(a) Customer support:

We use your information to provide support, respond to inquiries, and resolve any issues related to the services you have requested.

(b) Mandatory communication:

We also send essential account, service, and billing notifications that cannot be opted out of while your account is active. These include updates about your account status, service availability, billing, and compliance matters.

(c) Optional communication:

In addition, we may send optional administrative, marketing, and promotional communications according to your preferences. You can manage or opt out of these communications at any time.

4.4 Order Fulfillment

To process and manage orders, payments, refunds, exchanges, and domain/SSL renewals or transfers.

4.5 Feedback Requests

We use your data to request feedback and to contact you about your experience with our Services.

4.6 User-to-User Communications (if applicable)

We may use your information to facilitate communication between users of our Services, such as interactions between sub-accounts, where the functionality is supported by the Service.

4.7 Service Protection

To ensure the security and integrity of our Services, we monitor and analyze activity to detect and prevent fraud, abuse, spam, security incidents, unauthorized access, and other threats. This includes protection against DDoS attacks, server or network incidents, and compliance with registry and Certificate Authority requirements (e.g., handling abuse reports).

4.8 Usage Analysis

We use your information to monitor and analyze interactions with our Services to optimize performance, improve system functionality, and enforce fair use. This may include combining data in aggregated or anonymized form to identify usage trends, assess service performance, and enhance the overall user experience.

4.9 Marketing Communications

We utilize your personal information to send you marketing and promotional messages according to your marketing preferences. You can opt out of our marketing emails at any time. For more information, see below.

4.10 Targeted Advertising

We use your information to create and display personalized content and advertisements tailored to your interests and location. For more information, see our Cookie Policy.

4.11 Marketing Effectiveness

We utilize your information to assess the success of our marketing and promotional efforts and make them more relevant to you.

4.12 Vital Interests

To protect individuals from imminent harm or to address security threats.

4.13 Data Retention

We retain personal and account information only for as long as necessary to provide our Services, as well as to comply with legal obligations, registry, ICANN, and Certificate Authority requirements, enforce agreements, maintain backups, and resolve disputes.

5. LEGAL BASES FOR PROCESSING PERSONAL INFORMATION

We process your personal data in accordance with applicable data protection laws, including the GDPR, and only when we have a valid legal basis to do so. The legal basis for processing your data may vary depending on your location, the Services you use, and the purpose of the processing.

The primary legal bases we rely on include:

5.1 Consent (Art. 6(1)(a) GDPR or local equivalent)

We may process your data if you have explicitly given permission to use your personal information for a specific purpose, such as:

  • Receiving marketing communications (4.9 Marketing Communications, 4.10 Targeted Advertising, 4.11 Marketing Effectiveness)
  • Enabling optional features or services, including feedback requests (4.5 Feedback Requests)

You can withdraw your consent at any time.

5.2 Performance of a Contract (Art. 6(1)(b) GDPR or local equivalent)

We may process your data when necessary to fulfill our contractual obligations to you. This includes:

  • Providing our services, including hosting and software integrations (4.2 Hosting Services)
  • Account creation, maintenance, and management (4.1 Account Creation and Management)
  • Domain registration and SSL certificate issuance (4.2 Domain Registration & SSL Certificates)
  • Providing any other paid services;
  • Facilitating user-to-user communications where supported by the Service (4.6 User-to-User Communications)
  • Responding to support inquiries and sending mandatory service notifications (4.3 Customer Support & Communications – mandatory notifications)
  • Processing orders, payments, refunds, and domain/SSL renewals or transfers (4.4 Order Fulfillment)
  • Processing information produced during employment, business, or professional activity consistent with its original purpose.

5.3 Legal Obligations (Art. 6(1)(c) GDPR or local equivalent)

We may process your data to comply with legal requirements, such as:

  • Tax and accounting obligations, financial and regulatory reporting, or law enforcement requests;
  • Processing information necessary for legal proceedings, witness statements, or insurance claims (4.13 Data Retention)
  • Exercising and defending legal rights;
  • Compliance with Registry, ICANN, and Certificate Authority rules: We access publicly available records, such as WHOIS domain data, submit required information to registries, ICANN, or Certificate Authorities, and handle abuse reports as necessary to monitor registry compliance, prevent abuse, and meet legal or contractual obligations related to domain registration and SSL certificate management (4.2 Domain Registration & SSL Certificates, 4.2 Public Registry / WHOIS Compliance, 4.7 Service Protection).

5.4 Legitimate Interests (Art. 6(1)(f) GDPR or local equivalent)

We may process your data when reasonably necessary for our legitimate business interests, provided these interests do not override your rights and freedoms. Examples include:

  • Fraud prevention and security monitoring (4.7 Service Protection)
  • Ensuring network and service stability (4.2 Hosting Services, 4.8 Usage Analysis)
  • Improving and enhancing our services (4.2 Service Delivery, 4.8 Usage Analysis)
  • Analyzing usage patterns for product development and internal reporting (4.8 Usage Analysis);
  • Supporting marketing activities in ways that do not involve sending promotional communications to users who have opted out; for example, measuring campaign performance, analyzing engagement metrics, and assessing overall marketing effectiveness (4.11 Marketing Effectiveness), provided that the 90-day window under legitimate interest is a temporary exception to the general consent rule.
  • Diagnosing problems and preventing unauthorized access or abuse (4.7 Service Protection);
  • Investigating or preventing fraud, abuse, or other unlawful activity (4.7 Service Protection)
  • Detecting or preventing financial abuse (4.7 Service Protection)
  • Ensuring secure payment processing, preventing fraud, managing disputes, and protecting our business operations.

5.5 Vital Interests

In certain situations or jurisdictions, we may process personal data without explicit consent where permitted by local laws, including but not limited to:

  • Protecting an individual's best interests when consent cannot be obtained in a timely manner (4.12 Vital Interests);
  • Identifying injured, ill, or deceased persons and contacting next of kin (4.12 Vital Interests).

5.6 Special Circumstances and Other Jurisdictional Considerations

In certain situations or jurisdictions, we may process personal data without explicit consent where permitted by local laws, including but not limited to processing information produced during employment, business, or professional activity consistent with its original purpose.

6. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We may share the personal information we collect with your consent and in the following situations:

6.1 Within Our Company

We may share personal data with authorized personnel, departments, or any member of our corporate group, including subsidiaries or holding companies as defined by Hungarian law. This sharing is limited to purposes necessary to provide, manage, and improve our Services, including hosting, domain registration, SSL certificate management, customer support, and Service Protection (Section 4.1–4.7).

6.2 With Business Partners, Suppliers, and Sub-contractors

We may share personal data with business partners, suppliers, or sub-contractors to fulfill contracts with them or with you in connection with the Services we provide. This includes partners who assist with hosting, domain registration, SSL certificates, payment processing, or other Service-related operations (Section 4.2–4.4).

6.3 With Service Providers

We may share personal data with service providers who perform data-related services on our behalf, or who help us maintain, enhance, and optimize our website, Services, or customer experience. Examples include analytics, backup, infrastructure, or technical support providers (Section 4.7–4.8).

6.4 Business Transactions

We may share personal data with third parties in the event of a business or asset sale, equity transaction, merger, acquisition, or in preparation for such transactions, while ensuring continued protection of your information (Section 4.4 Order Fulfillment, 4.5 Feedback Requests).

6.5 Legal Obligations

We may disclose personal data to comply with applicable laws, court orders, or regulatory requirements, or to enforce our legal rights or obligations. This includes domain registration compliance, ICANN/registry requirements, Certificate Authority obligations, and data retention as required by law (Section 4.2 Domain Registration & SSL Certificates, 4.2 Public Registry / WHOIS Compliance, 4.13 Data Retention).

6.6 Protection of Rights and Safety

We may share personal data when necessary to protect our rights, property, or safety, as well as the rights, property, or safety of our customers or others. This includes handling abuse reports, fraud prevention, service security, and emergency situations (Section 4.7 Service Protection, 4.12 Vital Interests).

7. WHAT IS OUR POSITION ON THIRD-PARTY WEBSITES?

7.1 Third-Party Websites and Services

Our Services may include links to third-party websites, online services, mobile applications, or advertisements from entities not affiliated with SpaceLama. These links or advertisements may direct you to other websites, services, or applications.

  • We do not guarantee the security, privacy practices, or content of any third-party websites or services.
  • Inclusion of a link or advertisement does not imply endorsement by SpaceLama.
  • Any information you provide to third parties is not covered by this Privacy Notice, and SpaceLama is not responsible for their practices.
  • You should review the privacy policies of such third parties and contact them directly with any questions or concerns.

7.2 Visitors of Users' Websites or Services

SpaceLama may process certain information related to visitors and users of websites, applications, or services operated by our customers ("Users of Users") solely on behalf of those customers.

(a) Roles and Responsibilities

  • The customer operating the site or service is the Data Controller under applicable data protection laws, including GDPR, determining the purposes and means of processing personal data.
  • SpaceLama acts as a Data Processor, processing personal data only on documented instructions from the customer. This includes visitor logs, form submissions, sub-account interactions, and backups necessary to provide hosting, domain, or related services.

(b) Customer Responsibilities

Customers are responsible for:

  • Ensuring GDPR and other applicable privacy compliance.
  • Establishing a lawful basis for data collection, including obtaining consent where required.
  • Providing accurate privacy notices and managing user rights (access, correction, deletion).
  • Ensuring security and authorized use of information collected from their visitors or users.

(c) SpaceLama Responsibilities

When acting as a Data Processor, SpaceLama:

  • Processes data only according to the customer's instructions.
  • Implements technical and organizational measures to protect security, confidentiality, and GDPR compliance.
  • Manages any sub-processors in line with GDPR obligations.

(d) Visitor Guidance

If you are a visitor or end-user of a website or service hosted by SpaceLama for customer, please contact that website owner directly to exercise your privacy rights or ask questions about data processing. SpaceLama does not have a direct relationship with visitors and cannot act on requests except as instructed by the customer.

8. DIRECT MARKETING AND SERVICE NOTIFICATIONS

8.1 Managing Your Communication Preferences

When creating an Account on the SpaceLama Platform, you can manage your preferences regarding the receipt of communications, including marketing offers, service expiration reminders, and renewal notifications, through your email, phone (SMS or WhatsApp), or your Account settings.

8.2 Marketing Communications via Email

We may send marketing communications (e.g., newsletters, special offers, or other Service-related updates) to your email only if you have explicitly consented at registration or thereafter (Art. 6(1)(a) GDPR). This allows us to provide you with information about products, services, and updates relevant to you.

We may also contact you via email with surveys or feedback requests, only if you have provided consent (Art. 6(1)(a) GDPR). This helps us understand customer needs and improve the quality of our Services.

For active users, SpaceLama may send marketing communications based on legitimate interest (Art. 6(1)(f) GDPR) for up to 90 days after last interaction (e.g., subscription expiration or termination), after which explicit consent is required.

8.3 Marketing Related to Unfinished Purchases

Transactional messages necessary to complete an unfinished purchase (e.g., payment reminders, order confirmations) are not considered marketing and may be sent under our legitimate interest (Art. 6(1)(f) GDPR), even if you have not provided explicit marketing consent. Basic reminders to complete an unfinished purchase may also be sent under legitimate interest. Any additional marketing content, such as upsell or promotional offers included in these communications, requires your explicit consent (Art. 6(1)(a) GDPR).

8.4 Marketing Communications via Phone (SMS or WhatsApp)

We only send marketing messages via SMS or WhatsApp if you have explicitly consented (Art. 6(1)(a) GDPR). You may withdraw your consent at any time. Consent for phone communications is valid for up to 36 months after your last interaction (e.g., subscription expiration or termination), unless withdrawn earlier. After this period, we will request renewed consent before sending further messages.

8.5 Transactional and Service Notifications via Phone (SMS or WhatsApp)

We may send important transactional messages regarding:

  • (a) Subscriptions and payments (e.g., service expiration reminders, failed payments)
  • (b) Account and security updates (e.g., login alerts, password changes)
  • (c) Service status or changes (e.g., outages, significant updates affecting Service use)

These messages are not marketing communications and are sent based on our legitimate interest (Art. 6(1)(f) GDPR) to ensure proper Service provision, account security, and prevent service disruptions. Some transactional messages may be mandatory under applicable laws or regulations (e.g., ICANN rules for domain registration) and cannot be opted out of.

8.6 Personalization of Communications

Depending on your preferences, communications may be personalized using information you have provided (e.g., location, purchase history) or data collected through your use of the Service.

8.7 Right to Object / Revoke Consent

You may withdraw consent or object to direct marketing at any time by:

  • (a) Following the unsubscribe instructions in the received communication (e.g., email link or SMS instructions)
  • (b) Contacting us directly at support@spacelama.com

9. PAYMENT PROCESSING AND FINANCIAL TRANSACTIONS

We use third-party payment service providers to facilitate payments for our Services.

9.1 Payment Service Providers

When you choose to pay by card or other electronic method (including balance top-ups and automatic renewals), the transaction is processed by an external payment service provider.

Depending on the specific processing activity, such providers may act:

  • As Data Processors, processing payment-related personal data on our behalf and in accordance with a data processing agreement; and/or
  • As Independent Data Controllers, where required under applicable financial services regulations, payment network rules, anti-money laundering (AML) obligations, fraud prevention frameworks, or regulatory reporting requirements.

In their capacity as independent controllers, payment service providers determine the purposes and means of processing in accordance with their own privacy policies.

Financial institutions involved in the transaction (including acquiring and issuing banks), payment networks, and supervisory authorities may also process payment-related personal data under their own legal and regulatory responsibilities.

9.2 Invoice and Bank Transfer Payments

Where payment is made via invoice and bank transfer:

  • We remain the Data Controller for billing and invoicing activities;
  • Banking institutions process transaction data independently under applicable financial regulations.

9.3 Recurring Payments and Subscription Renewals

For subscription-based Services, recurring payments may be processed by payment service providers.

Such providers may process payment data on our behalf for technical execution of recurring charges, while also acting independently where required for fraud monitoring, compliance, dispute handling, or financial risk management.

9.4 Tax and Financial Compliance

We may share limited transaction-related information with external tax or accounting service providers for the purpose of VAT calculation, reporting, and statutory financial compliance. These providers act on our behalf under appropriate contractual safeguards.

10. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

We may employ cookies and other tracking technologies to collect and store your information.

Our use of cookies and similar tracking technologies (such as web beacons and pixels) helps us access and store information. For comprehensive details about how we utilize these technologies and how you can manage your cookie preferences, please refer to our Cookie Policy.

11. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

We conduct business globally and may transfer your personal information to our trusted partners and service providers with servers located outside the European Economic Area (EEA). The privacy and data protection laws in these countries may differ from, and potentially be less stringent than, those in your own country. As a result, your personal data may be subject to access requests by government authorities, courts, or law enforcement under local applicable laws.

For transfers of personal data from the EEA, Switzerland, or the United Kingdom, we implement appropriate safeguards to ensure the lawful processing and protection of your personal data. These safeguards may include Standard Contractual Clauses (SCCs) approved by the European Commission.

We are committed to taking all necessary measures to protect your personal information in compliance with this Privacy Notice and applicable laws.

12. HOW LONG DO WE RETAIN YOUR INFORMATION?

12.1 General Retention

We retain your personal information only for as long as it is necessary to provide and manage our Services, including hosting, domain registration, SSL certificate issuance, and related functionalities, or to comply with applicable legal obligations. Once your data is no longer required for these purposes, we will ensure it is securely deleted or anonymized in accordance with our retention policies.

For hosting services, customer-uploaded content and hosted data are retained for the duration of the active service and for up to 30 days following suspension or termination due to non-payment or account closure, after which such content is deleted from active systems. Certain account-related metadata, including transactional records, billing information, and security logs, may be retained for longer periods where required by law or for legitimate business purposes as described below.

12.2 Account Deactivation and Erasure Requests

You may request that we erase your personal information and close your SpaceLama Account at any time. Upon such request, we will remove or anonymize your personal identifiers while retaining necessary data for legal compliance or legitimate business interests as described below.

12.3 Legal and Regulatory Retention

Certain personal data may be retained after account closure to comply with statutory or contractual obligations, including but not limited to:

  • Tax, accounting, or financial reporting requirements (for example, billing records retained in accordance with Hungarian accounting law, typically 8 years);
  • Anti-money laundering (AML) obligations;
  • Legal reporting or auditing obligations;
  • Domain registration compliance with ICANN or other registry rules, including dispute resolution requirements;
  • SSL certificate management and Certificate Authority requirements.

12.4 Retention for Legitimate Business Interests

We may retain limited personal data after account closure for legitimate business purposes, including:

  • Fraud detection and prevention;
  • Security monitoring and protection of the SpaceLama Platform;
  • Dispute resolution and enforcement of agreements;
  • Investigation or prevention of abuse, unlawful activity, or financial misconduct.

Such retention is time-limited and proportionate to the purpose (for example, up to 1 year for security- or fraud-related purposes), after which the data will be anonymized or deleted. This may include limited account metadata, authentication logs, IP records, and transactional information necessary to maintain system integrity and protect against abuse.

12.5 Support and Communications Data

Customer support communications and support tickets are retained for up to 3 years after resolution for operational, quality assurance, dispute resolution, and legal compliance purposes, unless a longer retention period is required by law.

12.6 De-Personalization

Where possible, personal identifiers such as name, email address, and contact details will be removed or replaced (e.g., user@deleted.com) while preserving necessary operational or transactional information, including:

  • Purchased or subscribed services;
  • Login activity and account metadata;
  • Payment and transaction history.

This allows us to maintain compliance, resolve disputes, and protect our systems without retaining identifiable personal data longer than necessary.

12.7 Public and Third-Party Data

Certain information may remain publicly visible or with third parties even after account closure:

  • Domain registration information (e.g., WHOIS) may continue to be publicly available as required by registry or ICANN rules.
  • Forum posts, reviews, or other public contributions may remain online; however, personal identifiers will be removed.

12.8 Technical Backups

Residual copies of personal information may persist temporarily in backups for operational resilience, disaster recovery, or technical reasons. These backups are maintained in accordance with our data protection and security measures and are not used for active processing.

13. HOW DO WE KEEP YOUR INFORMATION SECURE?

We implement appropriate technical and organizational measures to protect personal data in accordance with GDPR Art. 32. These measures include firewalls, server isolation (e.g., CloudLinux), account-level resource limits, access controls with restricted administrative support, regular backups (e.g., JetBackup), and DNS/email security (SPF, DKIM, DMARC).

While we take all reasonable steps to secure your data, no system is completely secure. Transmission or storage of personal data is at your own risk, and we recommend using secure environments and strong passwords.

Sub-Processors

SpaceLama may engage sub-processors for hosting infrastructure, domain registration, backups, and support software. Customers authorize sub-processor use under the Hosting Agreement (GDPR Art. 28(2)). We maintain a current list of sub-processors and make it available to customers upon request.

Automated Decision-Making (GDPR Art. 22)

We do not perform automated decision-making that produces legal or similarly significant effects.

Data Breach Notification (GDPR Arts. 33–34)

SpaceLama will notify affected users without undue delay where required by law. Supervisory authorities will be informed as mandated. For Hosted Data breaches caused by customer applications, the Customer is responsible for managing notifications.

14. DO WE COLLECT INFORMATION FROM MINORS?

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. We do not knowingly seek out or engage in marketing activities targeted at children under 18 years old. By using our Services, you confirm that you are at least 18 years old. Should we learn that we have unintentionally collected personal information from users under the age of 18, we will deactivate the account and promptly remove the data from our records. If you become aware that we have collected information from a child under 18, please notify us at support@spacelama.com.

15. WHAT ARE YOUR PRIVACY RIGHTS?

You are entitled to certain rights regarding your personal information and how it is processed.

Your Rights

  • Access Your Data: You have the right to know if we are processing your data and to request access to the information outlined in this Privacy Notice. You can also request a copy of your data. Submit requests at support@spacelama.com. We may need to verify your identity and ask for additional details to locate your data.
  • Restrict Processing: You can request that we limit the processing of your data in certain situations, such as if you dispute its accuracy, if the processing is unlawful but you oppose deletion, if we no longer need the data but you require it for legal claims, or if you object to the processing pending verification of our legitimate grounds.
  • Correct Your Data: You have the right to request corrections to any inaccurate data and to complete any incomplete data.
  • Delete Your Data: You can request deletion of your data if it is no longer necessary for the purposes it was collected, if we lack a legal basis for its use, if we are required by law to delete it, if you withdraw consent, or if you object to processing based on our legitimate interests without overriding reasons for processing. Note that this right is not absolute, and we may need to retain some information for legal obligations or administrative purposes, such as record-keeping or detecting fraud. Data retention is outlined in the "How Long We Keep Your Personal Data" section above.
  • Object to Processing: You can object to the processing of your data when it is based on our legitimate interests. You may also object at any time to the processing of your personal data for direct marketing purposes, and we will cease such processing without undue delay.
  • Data Portability: You can request a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format and ask us to transfer it to another data controller where technically feasible. This right applies where processing is based on your consent or for performing a contract with you and is carried out by automated means.
  • Posthumous Data Management: You have the right to specify the handling of your data after your passing, including whether it should be deleted, retained, or transferred to a designated individual, where permitted by applicable law.

You have the right to withdraw your consent to data processing at any time when consent is the legal basis for processing. To exercise any of these rights, please contact us as described in the "How Can You Contact Us" section below.

Filing a Complaint

If you have concerns about how we process your personal data, please contact us, and we will try to resolve your issues. If you feel your concerns are not addressed, you may file a complaint with your local supervisory authority:

  • EU Data Protection Authorities (DPAs): Contact details are available here: EDPB Members.
  • Hungarian National Authority for Data Protection and Freedom of Information: Details can be found here: NAIH.
  • Swiss Federal Data Protection and Information Commissioner (FDPIC): Contact details are here: FDPIC.
  • Information Commissioner's Office (United Kingdom): Contact details are here: ICO.

16. DO WE MAKE UPDATES TO THIS POLICY?

We may update this Privacy Notice periodically. Each new version will be marked with a "Revised" date and will take effect once posted. For significant changes, we will notify you by prominently posting a Policy of the changes or by sending you a direct notification. We encourage you to review this Privacy Notice regularly to stay informed about how we are protecting your information. The updates will be effective from the date posted, and that users should check the Policy before using Services.

17. HOW CAN YOU CONTACT US?

For questions, comments about this Privacy Notice, or to file a complaint or request, you may contact us by email at support@spacelama.com, or by mail at:

SPACELAMA KFT
15, Ráckeve, Március, Apt.: 3/B, 2300, Hungary