Last Updated: January 21, 2026
At PenguHost, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our game server hosting services. This policy complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
The data controller responsible for your personal information is:
PenguHost
Email: contact@penguhost.com
Website: https://penguhost.com
We collect different types of information depending on how you use our Services:
When you create an account, we collect:
Legal Basis: Contract performance (GDPR Art. 6(1)(b)) - necessary to provide hosting services.
For billing purposes, we collect:
Legal Basis: Contract performance and legal obligation (tax records retention).
Important: We do NOT store credit card numbers. All payment processing is handled by certified third-party payment processors.
For game server and Discord bot hosting, we collect:
Legal Basis: Contract performance - necessary to provide the hosting service you requested.
We automatically collect certain technical information:
Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) - to ensure security, prevent fraud, and improve our services.
We use cookies and similar technologies for:
You can control cookie preferences through your browser settings. Disabling essential cookies may affect website functionality.
We use your personal information for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Contract performance |
| Providing hosting services (game servers, Discord bots) | Contract performance |
| Processing payments and maintaining billing records | Contract performance, Legal obligation |
| Customer support and communication | Contract performance, Legitimate interest |
| Service improvements and analytics | Legitimate interest |
| Security monitoring and fraud prevention | Legitimate interest, Legal obligation |
| Compliance with legal obligations | Legal obligation |
| Marketing communications (with consent) | Consent (GDPR Art. 6(1)(a)) |
We do not sell or rent your personal information to third parties. We may share your information with:
All service providers are contractually bound to protect your data and process it only as instructed by us.
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, law enforcement).
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred. We will notify you of any such change and provide options regarding your information.
Your data is primarily stored and processed within the European Union. If data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, such as:
We implement comprehensive security measures to protect your personal information:
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account information | While account is active + 30 days after closure |
| Server files and source code | While service is active + 7 days after cancellation |
| Billing records | 7 years (legal requirement for tax purposes) |
| Support tickets | 3 years after resolution |
| Analytics data | 26 months (anonymized) |
| Security logs | 90 days |
After these periods, data is securely deleted or anonymized.
If you are located in the European Union, you have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you.
You can request correction of inaccurate or incomplete personal data.
You can request deletion of your personal data, subject to legal retention requirements.
You can request that we limit how we use your data in certain circumstances.
You can request your data in a structured, machine-readable format for transfer to another provider.
You can object to processing based on legitimate interests or for direct marketing purposes.
Where we process data based on consent, you can withdraw consent at any time.
You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
Our Services are not intended for individuals under the age of 16 without parental consent. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information without consent, please contact us immediately.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Material changes will be communicated via:
Changes will be effective 30 days after notification, unless a shorter period is required by law. Your continued use of our Services after changes take effect constitutes acceptance of the updated Privacy Policy.
For data protection inquiries, you can contact our Data Protection Officer at:
Email: dpo@penguhost.com
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: contact@penguhost.com
Data Protection Officer: dpo@penguhost.com
Support: Available 24/7 via Discord and ticket system
We aim to respond to all privacy-related inquiries within 30 days as required by GDPR.