Privacy Notice
Version: 1.2
Effective date: 24 July 2026
Last updated: 24 July 2026
1. Who we are
hionet is the trading name of Ionut-Laurentiu Hurmuz, a UK sole trader at Flat 1, The Granaries, Bepton Road, Midhurst, GU29 9LU, United Kingdom. Email [email protected] or phone 07448927304 about privacy. The telephone number is not a support channel.
This notice covers customers, prospective customers, website visitors, authorised users, support requesters, abuse reporters and users of hionet-controlled community features.
2. Our data-protection roles
We are normally a controller for account registration, orders, billing, customer communications, fraud prevention, security, website operation, analytics and advertising, complaints, online-safety moderation, legal compliance and our own business records.
For personal data contained in a business customer's game server, Discord bot, databases, configuration, files or logs, we normally act as that customer's processor. The customer decides the purposes and essential means. We process that content to provide, secure and support the Service on documented instructions under the Data Processing Addendum.
We may act as a controller for limited customer-content data where independently necessary to protect security, investigate abuse, moderate hionet-controlled features, establish legal claims or comply with law.
3. Data we collect
Depending on the interaction, we collect:
name, organisation, postal address, email and phone;
account credentials, roles, preferences, authentication records and Discord sign-in identifiers where Discord login is used;
order, Service, selected data-centre location, invoice, transaction status and payment-reference data;
IP addresses, device/browser information, access, firewall, authentication, usage, performance and diagnostic logs;
tickets, emails, complaint and abuse reports, attachments and call notes you choose to provide;
public profiles, listings, reviews, comments, messages and moderation records on hionet-controlled features;
website usage, consent choices, advertising and cookie identifiers described in the Cookie Policy; and
customer content, which may include game files, mods, plugins, worlds, databases, player information, game chat or console logs, Discord user and server identifiers, bot interactions, messages, moderation records, configuration and bot code.
We do not routinely inspect customer game chat, console output, databases, bot messages or files. Authorised administrators may access them where the customer requests support or where reasonably necessary for a security, abuse or legal investigation. Discord bot tokens are stored in customer-controlled files or configuration. hionet administrators can technically view them but may access them only for authorised support or a security or abuse investigation.
Payment-card and wallet details are generally collected by Stripe or PayPal rather than stored in full by hionet.
4. Purposes and lawful bases
Purpose | Typical data | UK GDPR lawful basis |
|---|---|---|
Create accounts, accept orders, manually provision and support Services, administer renewal and cancellation | Identity, contact, account, order, service and communications | Contract; steps requested before contract |
Invoice, collect and reconcile payments | Identity, contact, invoice, transaction and payment references | Contract; legal obligation; legitimate interests in accounting and debt management |
Secure accounts and infrastructure, monitor reliability, prevent fraud and investigate abuse | Account, IP, logs, service, fraud and communications | Legitimate interests in security, fraud prevention and protecting users; legal obligation where applicable |
Operate public profiles, listings, reviews, comments, messaging, Discord communities and game servers | Account, identifiers, user content, moderation and reports | Contract where applicable; legitimate interests in operating and protecting community features; legal obligation |
Respond to complaints, rights requests, legal claims and government demands | Identity, communications, logs and compliance records | Legal obligation; legitimate interests in resolving disputes and establishing or defending claims |
Measure and improve the website | Usage, device, diagnostics and analytics identifiers | Consent where required; limited exempt statistical storage only where the legal conditions are met |
Advertising measurement and audience tools | Device, cookie, event and campaign identifiers | Consent |
Send essential service, billing, security and policy messages | Contact, account and order | Contract; legal obligation; legitimate interests in service administration |
Send optional marketing | Contact and marketing preferences | Consent where required; otherwise legitimate interests where direct-marketing law permits |
Meet tax, accounting, sanctions and regulatory duties | Identity, transaction and compliance | Legal obligation; legitimate interests where applicable |
Where we rely on legitimate interests, we consider necessity, proportionality and the impact on individuals. Consent can be withdrawn without affecting earlier lawful processing.
5. Sharing and providers
We share personal data only as reasonably necessary with infrastructure and data-centre providers, Cloudflare, payment providers, the self-hosted Paymenter billing and ticket platform, the self-hosted Pterodactyl server panel, Grafana Cloud and custom monitoring, email hosting, analytics and advertising providers, authorised Romanian support contractors, professional advisers, affected customers or reporters where lawful, and courts or authorities where required.
The current provider and location schedule is at Subprocessors and Data Locations. Stripe, PayPal, Google, Meta and TikTok may act as independent or joint controllers for parts of their payment, advertising, fraud or platform processing under their own notices.
We do not sell personal data. We use Meta, Google Ads and TikTok advertising tools only after the required consent. Those tools may involve sharing or targeted advertising as defined by some non-UK privacy laws; use “Cookie settings” or Global Privacy Control to opt out where supported.
6. Locations and international transfers
The customer chooses the advertised hosting location before ordering. Current locations include Amsterdam, Frankfurt, London, Montreal, Singapore, Sydney, Los Angeles, New York, Miami, Dallas and Dublin. hionet administrative access is from the United Kingdom, and authorised support-contractor access may occur from Romania.
Other account, payment, monitoring, analytics and advertising data may be processed internationally. Where a UK restricted transfer occurs, we use an applicable UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework where available, a UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful mechanism. We do not enable a location or provider for restricted personal-data processing unless an applicable transfer mechanism and required assessment are in place.
7. Retention and deletion
Record | Retention |
|---|---|
Account and contract records | 6 years after account closure or the last Service ends |
Invoices, payments and tax records | 6 years after the end of the relevant accounting period |
Closed support tickets and ordinary communications | 24 months |
Ordinary infrastructure and application logs | 14 days |
Resource and performance metrics | 30 days |
Authentication, firewall and abuse-detection logs | 90 days |
Closed complaints, fraud and abuse matters | 12 months, or longer while a dispute, investigation, legal hold or lawful request continues |
Marketing preference and suppression records | As long as necessary to honour the choice or objection |
Cookie-consent records | 6 months, unless a material change requires a new choice sooner |
Customer files, databases, configurations, logs and bot code after termination | Permanently deleted within 24 hours after termination |
Infrastructure recovery copies of customer content | None are maintained |
Customers must export content before expiry or termination. We may preserve specific material for a legal hold or investigation and delete it when that need ends.
8. Your rights
Depending on applicable law, you may ask to access, correct, erase, restrict or receive a portable copy of your personal data, object to legitimate-interests processing or direct marketing, and withdraw consent. Email [email protected]. We may verify identity and authority proportionately.
In the UK, you may complain to the Information Commissioner's Office. People elsewhere may also have a right to complain to their local authority. For data controlled by a hionet customer in customer-hosted content, contact that customer first.
9. Cookies, advertising choices and Global Privacy Control
Use “Cookie settings” to accept or reject non-essential categories and change a previous choice. hionet recognises Global Privacy Control as an opt-out signal for non-essential advertising and sale/share processing where technically supported. Essential account, security and payment technologies remain active where legally exempt.
10. Automated indicators and restrictions
Monitoring thresholds may flag suspected fraud, attacks, compromise or resource abuse and may trigger temporary rate limits, port blocks or isolation where necessary to protect systems. Material suspension or termination normally receives human review, except where immediate emergency action is required; emergency action is reviewed promptly afterwards.
11. Security and personnel
We use access controls, strong authentication, logging, monitoring, supplier controls and incident procedures proportionate to risk. Administrative access is limited to hionet and authorised support contractors bound by confidentiality. The website, account panel and supported file-transfer methods use encryption in transit. hionet does not promise application-level encryption of customer files, databases or bot tokens stored inside customer configuration.
No internet service is completely secure. Customers must secure credentials, software and bot tokens and maintain independent backups.
12. Children
Customers must be at least 18. Public community features may be visible to non-customers. Customers operating game communities or Discord bots that involve younger users are responsible for lawful bases, notices, safeguards and parental authorisation where required. Contact us if you believe personal data relating to a child has been handled inappropriately.
13. Contact and changes
Privacy questions and requests: [email protected]
Postal address: hionet, Flat 1, The Granaries, Bepton Road, Midhurst, GU29 9LU, United Kingdom
Telephone: 07448927304
hionet has not appointed a Data Protection Officer. We may update this notice when processing, suppliers, features or law change. The version and dates above identify the applicable notice.