Last updated: 3 August 2026

This policy explains what personal data SuperBitHost collects, why, how long it is kept, who else sees it, and what rights you have over it. It covers this website, the client area and the services we supply.

1. Who we are

SuperBitHost is a trading name of Hostbiss EOOD ("ХОСТБИС" ЕООД), a company registered in Bulgaria.

  • Company number (EIK): 208081216
  • Registered address: 49 Tsar Ivan Asen II Street, floor 4, 1124 Sofia, Bulgaria
  • LEI: 6488DWZ3R8L29014XP31
  • Privacy contact: privacy@superbithost.com, or a ticket in the client area

We are the data controller for the personal data described in this policy. We have not appointed a Data Protection Officer, as we are not required to.

2. Our approach: we hold as little as possible

SuperBitHost does not carry out identity verification. We do not ask for, and do not hold, passports, national identity documents, driving licences, proof of address, dates of birth, phone numbers or payment card numbers. You can open an account with an email address alone and pay in cryptocurrency.

This is deliberate. Data that is never collected cannot be leaked, subpoenaed, sold or lost. The list in section 3 is the whole of it.

3. What we collect

  • Account data. The email address you register with, a hashed password, and any name or company name you choose to give. Only the email address is required.
  • Billing data. Invoices, amounts, currency, the services purchased, and the cryptocurrency transaction reference or payment identifier for each payment. We do not receive or store card numbers.
  • Support data. The content of tickets and any correspondence you send us.
  • Service and technical data. The IP addresses assigned to your services, and operational logs from our systems, including client area access logs, which record IP address and time. These exist to run the platform, investigate abuse and diagnose faults.
  • Website analytics. Aggregate statistics about visits to this website, described in section 5.

We do not buy personal data from anyone, and we do not build profiles about you.

4. Why we use it, and our lawful basis

  • To provide the service you ordered - creating your account, provisioning servers, issuing invoices and taking payment, and giving support. Lawful basis: performance of a contract.
  • To keep the platform secure and available - investigating abuse reports, network attacks and faults, and enforcing the Acceptable Use Policy. Lawful basis: our legitimate interest in protecting our network, our customers and third parties.
  • To meet our legal obligations - keeping accounting and tax records, and responding to lawful requests from competent authorities. Lawful basis: legal obligation.
  • To understand how our website is found and used - see section 5. Lawful basis: consent.
  • To send you service messages - invoices, renewal reminders, maintenance and security notices. These are part of the service and are not marketing. Lawful basis: performance of a contract.
  • To send you marketing email, if you have asked to receive it. You can withdraw at any time using the unsubscribe link in any such message. Lawful basis: consent.

5. Cookies and third party tags

We use cookies that are necessary for the site and client area to work, including keeping you logged in and remembering your cookie choice. These cannot be switched off.

We also use Google Analytics to understand how visitors find and move through the site, mainly which sources send us traffic. It is used for aggregate statistics, not to identify you individually, and we do not use it to build advertising profiles. It sets cookies and processes data on Google's infrastructure, which involves a transfer outside the European Economic Area; see section 7.

Google Analytics runs only if you consent through the cookie notice shown on your first visit. You can withdraw consent at any time by clearing your cookies for this site and declining when the notice reappears. Declining has no effect on the service you receive.

We run no advertising on this website. There is no advertising network, no conversion or remarketing tag, no social media pixel and no session recording tool. Google Analytics is the only third party script we load, and it loads only after you accept.

6. Who else sees your data

We do not sell personal data, and we never share it for anyone else's marketing. Our customer database is not made available to any third party for that or any similar purpose.

Data reaches others only where a service you have asked for cannot work otherwise:

  • Data centre and network providers that supply the physical infrastructure your server runs on, in the country you chose.
  • Domain registries and registrars, if you register a domain through us. Registrant details have to be passed to the registry for the domain to exist. What is then published in WHOIS depends on the registry's own rules and on any privacy service applied.
  • Certificate authorities, if you buy an SSL certificate, to the extent needed to validate and issue it.
  • Payment processing, to the extent needed to confirm that a payment has been received.
  • Google, for the analytics described in section 5, and only with your consent.
  • Competent authorities, where we are legally obliged to disclose. We assess every request against the law that actually applies to us and to the server concerned, and we do not disclose voluntarily.

7. International transfers

We operate servers in many countries, including outside the European Economic Area. Where you choose a location outside the EEA, the personal data needed to run that service is processed there.

The Google tags described in section 5 also involve processing outside the EEA. Where we transfer personal data outside the EEA, we rely on the transfer mechanisms available under Chapter V of the GDPR, which for our providers means an adequacy decision where one applies, and otherwise the European Commission's Standard Contractual Clauses.

Choosing a server location is your decision, and it determines where the data on that server is held. Section 9 explains that the contents of your server are yours, not ours.

8. How long we keep it

  • Account data: for as long as you have an account. When you ask us to delete your account profile, we delete it.
  • Invoices and accounting records: retained after account deletion for the period Bulgarian accounting and tax law requires. We cannot delete these on request, because we are legally obliged to keep them.
  • Support tickets: deleted with the account profile, unless a ticket forms part of an unresolved abuse or legal matter.
  • Operational and access logs: kept only as long as they are useful for security and fault diagnosis, and then overwritten in the ordinary course.
  • Server contents: destroyed when the service is terminated. See section 9.

9. Data you store on your own server

Your server is yours. We do not inspect, index or mine its contents, and we do not access it except where you ask us to for support, or where we must in order to deal with an abuse or security matter under the Acceptable Use Policy.

Where you store other people's personal data on a service you rent from us, you are the controller of that data and we are the processor. You are responsible for having a lawful basis for it, for answering the requests of the people it concerns, and for securing your own operating system and applications. If you need a written data processing agreement, contact us.

10. Security

We apply technical and organisational measures appropriate to the risk, including encrypted connections to the website and client area, hashed passwords, restricted staff access on a need to know basis, and physical security at the data centres we use.

No system is perfectly secure. Where a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Bulgarian Commission for Personal Data Protection and, where required, you, in line with our obligations under the GDPR.

Because we hold no verified identity information, access to your account depends on control of your registered email address. Keep it secure and recoverable.

11. Your rights

If the GDPR applies to you, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Rectification of data that is inaccurate or incomplete.
  • Erasure of your data, subject to records we are legally required to keep.
  • Restriction of processing in certain circumstances.
  • Object to processing carried out on the basis of legitimate interests, and to direct marketing at any time.
  • Data portability for data you provided to us, in a structured, commonly used, machine readable format.
  • Withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before it.

To exercise any of these, open a ticket in the client area or email privacy@superbithost.com. We respond within one month. We do not charge for this, and we will not ask you for identity documents; we will normally verify a request through the registered email address on the account.

You also have the right to complain to a supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria. You may also complain to the authority in your own country of residence.

12. Changes to this policy

We may update this policy. The current version is always published at this address with the date it was last updated shown at the top. Where a change materially affects how we handle your data, we will tell you by email or in the client area before it takes effect.

Do You Have Any Questions? Contact Us Today!

Open Support Ticket