Privacy Policy.
How LemonHosting handles personal data under the Dutch AVG and the EU General Data Protection Regulation.
Last updated: August 20, 2026. Replace the bracketed controller details and confirm the actual processors, retention periods and cookie tools before publishing.
1. Controller
The controller is [LEGAL COMPANY NAME], trading as LemonHosting, KvK number [KVK NUMBER], registered at [REGISTERED ADDRESS]. Contact: [PRIVACY EMAIL ADDRESS]. LemonHosting determines why and how account, billing, support and website personal data is processed.
2. Data we process
Depending on how you use the service, we may process your name, email address, account identifiers, invoices, payment references, support messages, IP addresses, device and security logs, server identifiers, console or diagnostic logs, and information you provide for migration or abuse reports.
Server content such as worlds, files, databases and backups is processed to provide hosting. Where we process that content only on your instructions, you may be the controller and LemonHosting may act as processor. A separate data processing agreement should be used for business customers where required by Article 28 AVG/GDPR.
3. Purposes and legal bases
We process account and service data to perform the hosting contract under Article 6(1)(b) AVG/GDPR. We process billing records to comply with legal obligations under Article 6(1)(c). We process security, abuse-prevention and operational logs based on our legitimate interests under Article 6(1)(f), balanced against your rights. We send optional marketing only with consent where consent is required.
4. Processors and sharing
We may use processors for infrastructure, payments, email, customer support, monitoring, backups and security. They may process data only under our instructions and appropriate contractual safeguards. We do not sell personal data. Discord is a separate platform; when you use it, Discord processes data under its own privacy policy.
5. International transfers
If a provider processes personal data outside the European Economic Area, we use a lawful transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or another mechanism allowed by Chapter V AVG/GDPR. The final provider list and transfer safeguards should be documented in the internal processing register.
6. Retention
We retain account and contract records for the duration of the customer relationship and for legally required accounting, tax, fraud-prevention or dispute periods. Support messages and technical logs are retained only as long as needed for support, security and service administration. Exact periods should be set in the final retention schedule.
7. Cookies
Necessary session and security cookies may be used to operate authenticated areas. Analytics, marketing and other non-essential cookies require prior consent where required under Dutch Telecommunications Act rules and the AVG/GDPR. You can withdraw consent through the cookie settings mechanism used on the live website.
8. Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, data portability, or object to processing based on legitimate interest. You may withdraw consent at any time; withdrawal does not affect processing that took place before withdrawal. Contact us through [PRIVACY EMAIL ADDRESS]. We may verify your identity and normally respond within one month, with an extension permitted for complex requests.
9. Complaints
You may complain to us first. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in your EU country of residence or work.
10. Security and breaches
We use reasonable technical and organizational measures such as access controls, security monitoring and limited staff permissions. If a personal-data breach creates a risk to individuals, we will assess it and notify the Autoriteit Persoonsgegevens within the applicable 72-hour period where required, and notify affected people where the AVG/GDPR requires it.
11. Children
Our services are not directed at children. We do not knowingly collect children’s personal data for marketing. If you believe a child has provided personal data, contact us so we can assess and remove it where appropriate.
12. Changes
We may update this policy when our services, processors or legal obligations change. The latest version will be published on this page.
LEMONHOSTING