Last updated: 3 August 2026
This policy explains what personal data SuperBitHost collects, why, how long it is kept, who else sees it, and what rights you have over it. It covers this website, the client area and the services we supply.
SuperBitHost is a trading name of Hostbiss EOOD ("ХОСТБИС" ЕООД), a company registered in Bulgaria.
We are the data controller for the personal data described in this policy. We have not appointed a Data Protection Officer, as we are not required to.
SuperBitHost does not carry out identity verification. We do not ask for, and do not hold, passports, national identity documents, driving licences, proof of address, dates of birth, phone numbers or payment card numbers. You can open an account with an email address alone and pay in cryptocurrency.
This is deliberate. Data that is never collected cannot be leaked, subpoenaed, sold or lost. The list in section 3 is the whole of it.
We do not buy personal data from anyone, and we do not build profiles about you.
We use cookies that are necessary for the site and client area to work, including keeping you logged in and remembering your cookie choice. These cannot be switched off.
We also use Google Analytics to understand how visitors find and move through the site, mainly which sources send us traffic. It is used for aggregate statistics, not to identify you individually, and we do not use it to build advertising profiles. It sets cookies and processes data on Google's infrastructure, which involves a transfer outside the European Economic Area; see section 7.
Google Analytics runs only if you consent through the cookie notice shown on your first visit. You can withdraw consent at any time by clearing your cookies for this site and declining when the notice reappears. Declining has no effect on the service you receive.
We run no advertising on this website. There is no advertising network, no conversion or remarketing tag, no social media pixel and no session recording tool. Google Analytics is the only third party script we load, and it loads only after you accept.
We do not sell personal data, and we never share it for anyone else's marketing. Our customer database is not made available to any third party for that or any similar purpose.
Data reaches others only where a service you have asked for cannot work otherwise:
We operate servers in many countries, including outside the European Economic Area. Where you choose a location outside the EEA, the personal data needed to run that service is processed there.
The Google tags described in section 5 also involve processing outside the EEA. Where we transfer personal data outside the EEA, we rely on the transfer mechanisms available under Chapter V of the GDPR, which for our providers means an adequacy decision where one applies, and otherwise the European Commission's Standard Contractual Clauses.
Choosing a server location is your decision, and it determines where the data on that server is held. Section 9 explains that the contents of your server are yours, not ours.
Your server is yours. We do not inspect, index or mine its contents, and we do not access it except where you ask us to for support, or where we must in order to deal with an abuse or security matter under the Acceptable Use Policy.
Where you store other people's personal data on a service you rent from us, you are the controller of that data and we are the processor. You are responsible for having a lawful basis for it, for answering the requests of the people it concerns, and for securing your own operating system and applications. If you need a written data processing agreement, contact us.
We apply technical and organisational measures appropriate to the risk, including encrypted connections to the website and client area, hashed passwords, restricted staff access on a need to know basis, and physical security at the data centres we use.
No system is perfectly secure. Where a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Bulgarian Commission for Personal Data Protection and, where required, you, in line with our obligations under the GDPR.
Because we hold no verified identity information, access to your account depends on control of your registered email address. Keep it secure and recoverable.
If the GDPR applies to you, you have the right to:
To exercise any of these, open a ticket in the client area or email privacy@superbithost.com. We respond within one month. We do not charge for this, and we will not ask you for identity documents; we will normally verify a request through the registered email address on the account.
You also have the right to complain to a supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria. You may also complain to the authority in your own country of residence.
We may update this policy. The current version is always published at this address with the date it was last updated shown at the top. Where a change materially affects how we handle your data, we will tell you by email or in the client area before it takes effect.