Privacy Notice

Version: 1.2

Effective date: 24 July 2026

Last updated: 24 July 2026

1. Who we are

hionet is the trading name of Ionut-Laurentiu Hurmuz, a UK sole trader at Flat 1, The Granaries, Bepton Road, Midhurst, GU29 9LU, United Kingdom. Email [email protected] or phone 07448927304 about privacy. The telephone number is not a support channel.

This notice covers customers, prospective customers, website visitors, authorised users, support requesters, abuse reporters and users of hionet-controlled community features.

2. Our data-protection roles

We are normally a controller for account registration, orders, billing, customer communications, fraud prevention, security, website operation, analytics and advertising, complaints, online-safety moderation, legal compliance and our own business records.

For personal data contained in a business customer's game server, Discord bot, databases, configuration, files or logs, we normally act as that customer's processor. The customer decides the purposes and essential means. We process that content to provide, secure and support the Service on documented instructions under the Data Processing Addendum.

We may act as a controller for limited customer-content data where independently necessary to protect security, investigate abuse, moderate hionet-controlled features, establish legal claims or comply with law.

3. Data we collect

Depending on the interaction, we collect:

  • name, organisation, postal address, email and phone;

  • account credentials, roles, preferences, authentication records and Discord sign-in identifiers where Discord login is used;

  • order, Service, selected data-centre location, invoice, transaction status and payment-reference data;

  • IP addresses, device/browser information, access, firewall, authentication, usage, performance and diagnostic logs;

  • tickets, emails, complaint and abuse reports, attachments and call notes you choose to provide;

  • public profiles, listings, reviews, comments, messages and moderation records on hionet-controlled features;

  • website usage, consent choices, advertising and cookie identifiers described in the Cookie Policy; and

  • customer content, which may include game files, mods, plugins, worlds, databases, player information, game chat or console logs, Discord user and server identifiers, bot interactions, messages, moderation records, configuration and bot code.

We do not routinely inspect customer game chat, console output, databases, bot messages or files. Authorised administrators may access them where the customer requests support or where reasonably necessary for a security, abuse or legal investigation. Discord bot tokens are stored in customer-controlled files or configuration. hionet administrators can technically view them but may access them only for authorised support or a security or abuse investigation.

Payment-card and wallet details are generally collected by Stripe or PayPal rather than stored in full by hionet.

4. Purposes and lawful bases

Purpose

Typical data

UK GDPR lawful basis

Create accounts, accept orders, manually provision and support Services, administer renewal and cancellation

Identity, contact, account, order, service and communications

Contract; steps requested before contract

Invoice, collect and reconcile payments

Identity, contact, invoice, transaction and payment references

Contract; legal obligation; legitimate interests in accounting and debt management

Secure accounts and infrastructure, monitor reliability, prevent fraud and investigate abuse

Account, IP, logs, service, fraud and communications

Legitimate interests in security, fraud prevention and protecting users; legal obligation where applicable

Operate public profiles, listings, reviews, comments, messaging, Discord communities and game servers

Account, identifiers, user content, moderation and reports

Contract where applicable; legitimate interests in operating and protecting community features; legal obligation

Respond to complaints, rights requests, legal claims and government demands

Identity, communications, logs and compliance records

Legal obligation; legitimate interests in resolving disputes and establishing or defending claims

Measure and improve the website

Usage, device, diagnostics and analytics identifiers

Consent where required; limited exempt statistical storage only where the legal conditions are met

Advertising measurement and audience tools

Device, cookie, event and campaign identifiers

Consent

Send essential service, billing, security and policy messages

Contact, account and order

Contract; legal obligation; legitimate interests in service administration

Send optional marketing

Contact and marketing preferences

Consent where required; otherwise legitimate interests where direct-marketing law permits

Meet tax, accounting, sanctions and regulatory duties

Identity, transaction and compliance

Legal obligation; legitimate interests where applicable

Where we rely on legitimate interests, we consider necessity, proportionality and the impact on individuals. Consent can be withdrawn without affecting earlier lawful processing.

5. Sharing and providers

We share personal data only as reasonably necessary with infrastructure and data-centre providers, Cloudflare, payment providers, the self-hosted Paymenter billing and ticket platform, the self-hosted Pterodactyl server panel, Grafana Cloud and custom monitoring, email hosting, analytics and advertising providers, authorised Romanian support contractors, professional advisers, affected customers or reporters where lawful, and courts or authorities where required.

The current provider and location schedule is at Subprocessors and Data Locations. Stripe, PayPal, Google, Meta and TikTok may act as independent or joint controllers for parts of their payment, advertising, fraud or platform processing under their own notices.

We do not sell personal data. We use Meta, Google Ads and TikTok advertising tools only after the required consent. Those tools may involve sharing or targeted advertising as defined by some non-UK privacy laws; use “Cookie settings” or Global Privacy Control to opt out where supported.

6. Locations and international transfers

The customer chooses the advertised hosting location before ordering. Current locations include Amsterdam, Frankfurt, London, Montreal, Singapore, Sydney, Los Angeles, New York, Miami, Dallas and Dublin. hionet administrative access is from the United Kingdom, and authorised support-contractor access may occur from Romania.

Other account, payment, monitoring, analytics and advertising data may be processed internationally. Where a UK restricted transfer occurs, we use an applicable UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework where available, a UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful mechanism. We do not enable a location or provider for restricted personal-data processing unless an applicable transfer mechanism and required assessment are in place.

7. Retention and deletion

Record

Retention

Account and contract records

6 years after account closure or the last Service ends

Invoices, payments and tax records

6 years after the end of the relevant accounting period

Closed support tickets and ordinary communications

24 months

Ordinary infrastructure and application logs

14 days

Resource and performance metrics

30 days

Authentication, firewall and abuse-detection logs

90 days

Closed complaints, fraud and abuse matters

12 months, or longer while a dispute, investigation, legal hold or lawful request continues

Marketing preference and suppression records

As long as necessary to honour the choice or objection

Cookie-consent records

6 months, unless a material change requires a new choice sooner

Customer files, databases, configurations, logs and bot code after termination

Permanently deleted within 24 hours after termination

Infrastructure recovery copies of customer content

None are maintained

Customers must export content before expiry or termination. We may preserve specific material for a legal hold or investigation and delete it when that need ends.

8. Your rights

Depending on applicable law, you may ask to access, correct, erase, restrict or receive a portable copy of your personal data, object to legitimate-interests processing or direct marketing, and withdraw consent. Email [email protected]. We may verify identity and authority proportionately.

In the UK, you may complain to the Information Commissioner's Office. People elsewhere may also have a right to complain to their local authority. For data controlled by a hionet customer in customer-hosted content, contact that customer first.

9. Cookies, advertising choices and Global Privacy Control

Use “Cookie settings” to accept or reject non-essential categories and change a previous choice. hionet recognises Global Privacy Control as an opt-out signal for non-essential advertising and sale/share processing where technically supported. Essential account, security and payment technologies remain active where legally exempt.

10. Automated indicators and restrictions

Monitoring thresholds may flag suspected fraud, attacks, compromise or resource abuse and may trigger temporary rate limits, port blocks or isolation where necessary to protect systems. Material suspension or termination normally receives human review, except where immediate emergency action is required; emergency action is reviewed promptly afterwards.

11. Security and personnel

We use access controls, strong authentication, logging, monitoring, supplier controls and incident procedures proportionate to risk. Administrative access is limited to hionet and authorised support contractors bound by confidentiality. The website, account panel and supported file-transfer methods use encryption in transit. hionet does not promise application-level encryption of customer files, databases or bot tokens stored inside customer configuration.

No internet service is completely secure. Customers must secure credentials, software and bot tokens and maintain independent backups.

12. Children

Customers must be at least 18. Public community features may be visible to non-customers. Customers operating game communities or Discord bots that involve younger users are responsible for lawful bases, notices, safeguards and parental authorisation where required. Contact us if you believe personal data relating to a child has been handled inappropriately.

13. Contact and changes

Privacy questions and requests: [email protected]
Postal address: hionet, Flat 1, The Granaries, Bepton Road, Midhurst, GU29 9LU, United Kingdom
Telephone: 07448927304

hionet has not appointed a Data Protection Officer. We may update this notice when processing, suppliers, features or law change. The version and dates above identify the applicable notice.