Retslav B.V. ("Retslav", "we", "us", "our") is committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR/AVG) and applicable Dutch privacy laws. This Privacy Policy explains how we collect, use, store, and protect your personal data in connection with our three-pillar service model:
- DDoS-bescherming (vaste prijzen): Always-on DDoS-mitigatie met transparante, vaste maandprijzen.
- Game Server Hosting: High-performance game server hosting met DDoS-bescherming, SSD-opslag, en dedicated CPU-resources.
- Website Hosting: Snelle en veilige website hosting met automatische DDoS-bescherming, SSL-certificaten, en dagelijkse backups.
This policy applies to all users of our platform, including visitors, account holders, and customers. By using our services, you acknowledge the practices described in this policy.
1. Data Controller & Contact Information
Retslav B.V. is the data controller for the personal data collected through our services. If you have any questions about this policy or wish to exercise your rights, please contact us:
We have appointed a privacy contact who can be reached at [email protected] for all data protection matters, including data subject access requests.
2. Information We Collect
We collect data necessary to provide, maintain, and improve our three-pillar services. The specific data we collect depends on which services you use:
2.1 Data Collected Across All Services
- Account Information: Email address, username, password (hashed), account preferences, and billing address.
- Communication Data: Correspondence with our support team, including tickets, chat messages, and email exchanges.
- Usage & Log Data: IP addresses, browser type and version, device identifiers, operating system, referral source, page views, and session duration. This data is collected via server logs and analytics tools (including Google Analytics).
- Cookie Data: We use functional cookies (essential for platform operation), analytical cookies (to understand usage patterns), and preference cookies (to remember your settings). You can manage cookie preferences in your browser settings.
2.2 Per-Pillar Data Collection
- DDoS-bescherming (vaste prijzen): Network traffic metadata (source IP, protocol, packet size), mitigation logs, attack forensic data, and customer IP ranges to be protected. We do not inspect packet payloads unless required for attack analysis.
- Game Server Hosting: Game server configurations, plugin/data files you upload, player connection logs (IP, timestamps), and resource usage metrics (CPU, RAM, disk).
- Website Hosting: Website files and databases you upload, web traffic logs, SSL certificate metadata, and backup archives.
2.3 Payment Data
Payment transactions are processed exclusively by our third-party payment processor (Stripe). We do not store full credit card numbers, CVV codes, or bank account details. Stripe may share limited billing information with us (e.g., last four digits, expiry date, billing name and address) for invoicing and dispute resolution purposes.
3. Legal Bases for Processing
We process your personal data on the following legal bases under the GDPR:
- Contractual Necessity (Art. 6(1)(b)): To deliver the services you have requested, process payments, and provide customer support.
- Legitimate Interests (Art. 6(1)(f)): To maintain platform security, prevent fraud and abuse, analyse usage patterns to improve services, and send service-related communications. We balance these interests against your privacy rights and ensure minimal data use.
- Consent (Art. 6(1)(a)): For marketing communications and non-essential cookies. You may withdraw consent at any time.
- Legal Obligation (Art. 6(1)(c)): To comply with applicable laws, including the Dutch Cyberbeveiligingswet (NIS2-implementatie), tax regulations, and data breach notification requirements.
4. How We Use Your Information
- Service Delivery: Creating and managing accounts, provisioning servers (DDoS mitigation, game servers, web hosting), processing payments, and providing technical support.
- Security & Abuse Prevention: Monitoring network traffic for attack patterns (DDoS detection), detecting unauthorized access, enforcing our Acceptable Use Policy, and maintaining platform integrity.
- Service Improvement: Analyzing usage trends, monitoring performance metrics, debugging technical issues, and developing new features.
- Communication: Sending transactional emails (invoices, service notices, security alerts), responding to support requests, and (with consent) sending marketing communications about relevant services or offers.
- Compliance: Fulfilling legal obligations under NIS2, tax law, and data breach notification requirements, including reporting significant incidents to the NCSC (Nationaal Cyber Security Centrum) where required.
5. Data Sharing & Processors
We do not sell your personal data to third parties. We may share your data with the following categories of recipients, all of whom are contractually bound to process data only on our instructions and in compliance with the GDPR:
- Payment Processors (Stripe): Payment processing, fraud detection. Stripe Privacy Policy
- Infrastructure Providers: Datacenter partners and cloud infrastructure providers who host our servers. These providers have no access to your personal data beyond what is necessary for hardware/network maintenance.
- Analytics Providers (Google Analytics): Pseudonymized usage analytics. Google Privacy Policy
- Communication Tools: Email delivery services and ticketing platforms used for support correspondence.
- Legal Authorities: If required by Dutch or EU law, or to protect our legal rights, we may disclose data to law enforcement or regulatory bodies.
Where we engage data processors, we have Data Processing Agreements (DPAs) in place that ensure compliance with Art. 28 GDPR. A list of our current sub-processors is available upon request.
6. International Data Transfers
Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA). When we transfer data to third countries, we ensure adequate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission.
- Transfer to countries with an adequacy decision from the European Commission.
- Binding Corporate Rules where applicable.
Our primary infrastructure is located within the Netherlands and the European Union. Contact us for a copy of the applicable safeguards.
7. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy, or as required by law:
- Account Data: Retained for the duration of your account's active status, plus 30 days after termination (grace period), after which it is permanently deleted unless legal retention obligations apply.
- Billing Records: Retained for 7 years after the end of the financial year, as required by Dutch tax law (bewaarplicht).
- Usage & Log Data: Server logs retained for a maximum of 6 months. Aggregated/anonymized analytics may be retained indefinitely.
- Support Tickets: Retained for 2 years after the last interaction, unless the ticket contains billing records (see above).
- Traffic Metadata (DDoS-bescherming): Mitigation logs and attack forensic data retained for up to 12 months for security analysis and legal compliance.
- Backup Copies: Personal data in backups is retained for the backup retention period (typically 30 days) and securely overwritten thereafter.
8. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR. You can exercise these rights by contacting [email protected]:
- Right of Access (Art. 15): Request confirmation of whether we process your data and request a copy of the personal data we hold.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to Restriction of Processing (Art. 18): Request that we limit processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): Request a structured, machine-readable copy of your data, or have it transferred to another controller.
- Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling and direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: If you believe we have not processed your data lawfully, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
We will respond to your request within one month (Art. 12 GDPR). Requests may be extended by two months for complex or high-volume requests, with notification.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption in transit (TLS 1.2+/HTTPS) for all web traffic.
- Encryption at rest for sensitive data where feasible.
- Access controls and authentication requirements for administrative access.
- Regular security audits and penetration testing.
- Incident response procedures aligned with NIS2 requirements.
- Employee training on data protection and privacy.
While we strive to protect your data, no method of transmission or storage is 100% secure. We encourage you to use strong passwords and enable two-factor authentication where available.
10. NIS2 Compliance & Incident Notification
As a provider of digital infrastructure, Retslav complies with the Dutch Cyberbeveiligingswet (implementing the EU NIS2 Directive). In the event of a significant security incident involving your personal data:
- We will notify the NCSC (Nationaal Cyber Security Centrum) within 24 hours, as required by law.
- If the incident poses a risk to your rights and freedoms, we will notify you without undue delay.
- We maintain an incident response plan and conduct regular drills to ensure timely and effective response.
11. Cookies & Tracking Technologies
We use the following categories of cookies on our website:
- Functional (essential): Required for platform operation, including session management and authentication. No consent required.
- Analytical: Google Analytics helps us understand how visitors interact with our site. Data is pseudonymized (IP anonymization enabled).
- Preference: Remember your settings and preferences (e.g., language, theme).
You can control cookies through your browser settings. Blocking functional cookies may impact platform functionality. For more information about how Google Analytics handles data, see Google's Privacy Policy.
12. Children's Privacy
Our services are not directed to children under the age of 16. We do not knowingly collect personal data from minors. If you become aware that a child has provided us with personal data without parental consent, please contact [email protected] so we can take appropriate action.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. Significant changes will be notified via:
- A notice on our website or dashboard.
- Email notification for material changes (if we have your email address).
The "Last updated" date at the top of this policy indicates when it was last revised. Continued use of our services after changes take effect constitutes acceptance of the updated policy.
14. Contact & Complaints
If you have any questions, concerns, or complaints about this Privacy Policy or our data handling practices, please contact us:
You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch DPA):
autoriteitpersoonsgegevens.nl