SAFENIX
Privacy Policy
Last updated: September 2026 — v1.6
Version: This Privacy Policy supersedes v1.1, which described a second product — a plugin for websites on shared hosting, for which we generated and held the encryption key. That product is not offered, so Section 3 is unconditional again rather than split in two. v1.6 conditions the continuous-backup statement in Section 1 on the server supporting it, the same change made to the Terms of Service in v1.3; its note is in CHANGES-v1.6.md. v1.5 gives one label to one document: two different texts were accepted as v1.4, and its note is in CHANGES-v1.5.md. v1.4 records what the customer dashboard's page counter collects; its changes are in CHANGES-v1.4.md. v1.3 records the decisions counsel settled on 2026-08-26 — a representative in the Union, no Data Protection Officer, and the complaint route — and its changes are in CHANGES-v1.3.md. Every removal in v1.2 and its reason is in CHANGES-v1.2.md. v1.1 in turn superseded v1.0, which described data handling that did not match the software; those corrections are in CHANGES-v1.1.md.
Scope: This policy governs how Safenix processes personal data of its customers — the businesses and individuals who subscribe. It does not govern how customers process the personal data of their own end users, which is covered by the Data Processing Agreement between Safenix and each customer.
1. Who we are
Safenix is a backup service for business servers. We protect infrastructure with scheduled backups, and with continuous database capture where the server supports it, stored in German datacentres.
| Legal entity | Eurhosting SHPK |
| NIPT | M52305043P |
| Registered in | Albania |
| Registered address | Sallmone, Shijak — Durrës, Albania |
| Brand | Safenix is a commercial brand of Eurhosting SHPK and not a separate company. The contracting party, the merchant on your card statement, and the data controller are all Eurhosting SHPK. |
| Website | https://safenix.eu — the dashboard is at app.safenix.eu |
| privacy@safenix.eu | |
| Data protection contact | dpo@safenix.eu |
| Representative in the Union (Article 27) | Padovani s.r.o., Czech Republic — a company under the same ownership as Eurhosting SHPK, appointed in writing as our representative in the Union. You may address our representative on any matter relating to the processing described here, in place of or in addition to us. |
We have no Data Protection Officer, and that is a conclusion rather
than an omission. Counsel has assessed Article 37 and found that none
of its three cases applies to us: we are not a public authority; our core
activity is storing data our customers encrypt, not monitoring people
systematically; and the processing does not reach large scale — the assessment
holds even if every customer of Eurhosting were to use Safenix. We carry out no
profiling. dpo@safenix.eu is a working address for data protection
questions and is read by the person responsible for them; it does not imply an
appointment under Article 37.
Our role. For data about you as our customer, we are the data controller. For data inside the backups you create, we are a processor acting on your instructions — and we cannot read it. Section 3 sets that out; it is the most important section in this policy.
2. What data we collect and why
2.1 Account data
Legal basis: contract performance, Art. 6(1)(b).
2.2 Your acceptance of our terms
When you register, we record which version of these documents you accepted, a cryptographic hash of the exact text you were shown, the date, and your email address. This is how we can show what was agreed and when. The record of your acceptance is kept in our compliance record; see Section 4.
Legal basis: contract performance, Art. 6(1)(b), and our legitimate interest in being able to evidence the agreement, Art. 6(1)(f).
2.3 Billing data
Legal basis: contract performance, Art. 6(1)(b), and legal obligation for accounting records, Art. 6(1)(c).
2.3a Your VAT registration
We sell to businesses, so when you register we ask for your member state and
your VAT number. We check it against the European Commission's VIES register and
keep the result and the date we checked. Where the register
returns your business name and address — most member states do not — we keep
those too, because they are the strongest evidence that the number belongs to
you.
What we send to VIES is your member state code and your VAT
number, and nothing else. Not your name, your email address, your plan,
or anything about what you back up. VIES is run by the European Commission and
is inside the EU, so this adds no transfer outside the EEA. It is a recipient of
that data and not a processor acting for us.
We keep the checks because if a VAT number turns out not to belong to
the person who used it, the tax consequence is theirs and we have to be able to
show what we asked and what we were told.
Legal basis: legal obligation, Art. 6(1)(c), and contract performance, Art. 6(1)(b).
2.4 Metadata about your systems
When you install our agent, we receive operational metadata — never the content of your backups:
What we do not receive: the content of your backups, your file names, or the paths of your files. Where our compliance record refers to what was backed up, it holds a one-way hash and never a readable path.
Legal basis: contract performance, Art. 6(1)(b).
2.5 Log data and IP addresses
Retention: 90 days. Legal basis: legitimate interest in security and service reliability, Art. 6(1)(f).
2.6 Support communications
Retained while your account is active and for 90 days after closure. Legal basis: legitimate interest, Art. 6(1)(f), and contract performance, Art. 6(1)(b).
2.7 Marketing consent
If you tick the box when you register, we record your email address, that you consented, when, and where. It is a separate record on a separate legal basis from your account, so closing your account does not withdraw it — see Section 6. You can withdraw at any time from the link in any message we send.
Legal basis: consent, Art. 6(1)(a).
2.8 Referral codes
If you arrive by a partner's link, the code from that link is kept in your own browser's local storage until you register, and is then recorded on your account so we know who introduced you. Nothing is sent to us before you register, and we do not create any record about a visitor who does not.
Legal basis: legitimate interest in administering partner arrangements, Art. 6(1)(f).
3. Whether we can read your backups — we cannot
This is the section to read. It is short because the answer has no conditions in it.
This has no exception. We offer one product, and there is no subscription, plan or arrangement under which we hold your encryption key. We hold no customer encryption key of any kind.
We are saying this plainly because v1.1 of this policy said the opposite for one product, and said it prominently. It described a plugin for websites on shared hosting, where we generated and held the key because a shared host has nowhere to put one that an attacker who reaches the site could not also reach. That was true when it was written. That product is not offered, and the sentence above is unconditional again — not because the reasoning changed, but because the product it applied to is not sold. If we offer it in future, this section gets its exception back, in the same words, before the first site is protected.
4. What we deliberately do not do
5. How long we keep your data
| Category | Retention | Why |
|---|---|---|
| Backup data (encrypted) | Your plan's retention window — 30, 60 or 90 days, six months where you have bought extended retention, or a figure agreed with you on the Critical plan. Deleted within 30 days of account closure. | Contract delivery |
| Account and contact data | Duration of subscription, then deleted with the account | Contract performance |
| Billing records | Duration of subscription + 7 years | Accounting obligations |
| Card registration reference | Duration of subscription; deleted with the account | Taking the payment you agreed to |
| Compliance record entries | Retained indefinitely — see below | Evidence of what was done with your data, including its deletion |
| Acceptance of terms | The identifying record is deleted with your account. The fact that a version was accepted, and when, remains in the compliance record | Evidence that an agreement existed |
| IP address and access logs | 90 days | Security |
| Support communications | Duration of subscription + 90 days | Support and dispute resolution |
| Marketing consent | Until you withdraw it — see Section 6 | It is yours, not your employer's |
Our compliance record cannot be deleted, and here is why. It is a single append-only chain covering every customer, where each entry commits cryptographically to the one before it. Removing your entries would break the evidence for everyone else in it — and those entries are the proof that your data was deleted when you asked. The chain holds identifiers, sizes, timestamps and hashes. It holds no email addresses, no file names, no file contents, no database contents and no system names.
The previous version of this policy said these records were deleted 90 days after termination. That was never possible and the statement has been removed.
Where your data is, and who can reach it. Your encrypted
backups are stored in Germany with Hetzner, and our control plane is hosted in
Germany with KeyWeb. We are an Albanian company, and the people who
operate that control plane do so from Albania — so although your data
stays on servers in the EU, it is reachable from outside it, and that counts as
a transfer. We say so because "our infrastructure is in Germany" is true and does
not answer the question.
The transfer is covered by the European Commission's standard contractual
clauses, and we have prepared an assessment of what it means. The short version:
your backups are encrypted with a key we have never had, so anyone who
compelled us to hand them over would get files nobody can read. That
protection does not extend to the other things we hold — your email address, your
billing records, and the names of your protected systems — which we can read and
which such a request would reach.
6. Closing your account
When your account is erased we revoke every credential first, then delete your stored backups, then your records. You receive a certificate stating what was deleted, what was not, and why.
Three things are deliberately kept, and we say so rather than leaving you to find out:
Where an object in storage is still inside its retention lock and cannot be deleted immediately, the certificate says so and gives the date it becomes deletable, and we retry until it is gone.
7. Who we share your data with
| Sub-processor | Role | Location | Data shared | Safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Object storage | Germany (EU) | Encrypted backup objects; object keys and sizes | EU; intra-EU transfer; data processing agreement |
| KeyWeb AG | Hosting for our control plane, and for the mail server that sends your alerts | Germany (EU) | Everything our service holds, as its hosting provider — and with it the addresses we send alerts to and the text of those alerts, which includes the name of the protected system concerned | EU; intra-EU transfer; data processing agreement |
| Pago | Payment processing | Albania — outside the EU and the EEA | Amount, currency, a ten-character payment reference, and a short description of what is being bought. Not your name, address, telephone number or email address | Transfer to a third country — mechanism to be confirmed and recorded before publication. See below. |
| There is no third-party email provider. Alerts and service email are sent from our own infrastructure, which KeyWeb hosts — so the row above covers them, and no separate recipient exists. | ||||
Sub-processor changes: we will notify you at least 30 days before adding or replacing one, and you may object.
We may also disclose data where required by law, court order or a regulatory authority. Where legally permitted, we will tell you first.
The transfer to Pago in Albania for payment processing rests on a data processing agreement between Eurhosting SHPK and Pago, which has been requested and is awaiting signature.
8. Where your data is stored
Backup data and our control plane are in Germany: object storage with Hetzner Online GmbH, hosting with KeyWeb AG. Backup data does not leave the EU.
Payment processing is the exception, and it is the only one. It is carried out by Pago in Albania, outside the EU and the EEA. What goes there is set out in Section 7: an amount, a currency, a reference and a description. No backup data and no name or address of yours is involved.
Eurhosting SHPK is registered in Albania, which is not an EU member state. Administrative access to metadata by our staff therefore constitutes a transfer from the EU to a third country, governed by the Standard Contractual Clauses, Module Two (controller to processor) adopted by Commission Implementing Decision (EU) 2021/914 and included in our Data Processing Agreement. Your backup data stays in Germany. Albania's own data protection law — 124/2024 — is aligned with the European rules, and our assessment of that transfer is available on request.
9. Your rights under GDPR
| Right | What it means | How to exercise it |
|---|---|---|
| Access (Art. 15) | A copy of the personal data we hold about you. | Email privacy@safenix.eu — we respond within 30 days. |
| Rectification (Art. 16) | Correction of inaccurate data. | Update it in the dashboard, or email privacy@safenix.eu. |
| Erasure (Art. 17) | Deletion of your data and closure of your account. | Email privacy@safenix.eu. We act on the request and issue a deletion certificate. Self-service deletion from the dashboard is not currently available. |
| Restriction (Art. 18) | Pausing processing while a dispute is resolved. | Email privacy@safenix.eu with details. |
| Portability (Art. 20) | Your data in a usable form. | Perform a restore, from the dashboard or with the agent, which returns your files and databases. This needs your own encryption key, because we do not have it. The dashboard's compliance export contains records about your backups, not the backups themselves. |
| Object (Art. 21) | Objection to processing based on legitimate interest. | Email privacy@safenix.eu. |
| Withdraw consent | Where we rely on consent, such as marketing. | The unsubscribe link in any marketing email, or email privacy@safenix.eu. |
You may lodge a complaint with the supervisory authority of the country where you live, where you work, or where you believe the problem happened. That is your right under Article 77 and it is the route we would point you to first: every EU member state has one, and they answer in your own language.
You may also address our representative in the Union, Padovani s.r.o. in the Czech Republic, whose supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů). And because Eurhosting SHPK is an Albanian company, the Commissioner for the Right to Information and Protection of Personal Data in Albania supervises us under Albanian law — law 124/2024, which is aligned with the European rules.
10. How we protect your data
In the event of a security incident affecting your personal data we will notify you without undue delay and in any case within 72 hours of becoming aware.
11. Cookies and tracking
| What | Purpose | Duration | Type |
|---|---|---|---|
| Session cookie | Keeps you signed in to the dashboard | Session | Strictly necessary |
| Referral code, in your browser's local storage | Remembers which partner introduced you, until you register | Until you register or clear it | Functional |
We set no advertising cookies and no third-party tracking pixels.
The customer dashboard counts page views. The counter is our own software, running on our own infrastructure in the European Union. It sets no cookie and does not profile you: what it records is not linked to your account, to you, or to your activity on any other website. The operator console has no counter.
12. Children's data
Safenix is a business service. We do not knowingly collect data from or about children under 16. If you believe a child has provided us with personal data, contact privacy@safenix.eu and we will delete it.
13. Changes to this policy
When our practices change, we will post the updated policy with a new date and email you at least 14 days before it takes effect. For significant changes we will ask you to accept the new version, and we will record which version you accepted and when.
14. Contact
| Privacy | privacy@safenix.eu |
| Data protection | dpo@safenix.eu |
| Postal | Eurhosting SHPK, Sallmone, Shijak — Durrës, Albania |
| Response time | We aim to respond within 5 business days and always within the 30-day statutory limit. |
Appendix — legal basis summary
| Processing activity | Personal data | Legal basis | Art. |
|---|---|---|---|
| Account creation and management | Email, password hash, company name, authenticator enrolment | Contract | 6(1)(b) |
| Recording acceptance of terms | Email, document version and hash, timestamp | Contract; legitimate interest in evidence | 6(1)(b), 6(1)(f) |
| Service delivery | System metadata, system names, operational logs | Contract | 6(1)(b) |
| Alerting | Email address, system name | Contract | 6(1)(b) |
| Billing and invoicing | Billing history, card registration reference | Contract | 6(1)(b) |
| Accounting records | Billing history | Legal obligation | 6(1)(c) |
| Security monitoring | IP address, access logs | Legitimate interest | 6(1)(f) |
| Support communications | Message content, account history | Legitimate interest | 6(1)(f) |
| Partner attribution | Referral code on the account | Legitimate interest | 6(1)(f) |
| Marketing communications | Email address | Consent | 6(1)(a) |
End of document — Safenix Privacy Policy v1.4