Privacy Policy
This policy explains what personal data Kairo Hosting collects, why we collect it, how long we keep it, and the rights you have over it under the GDPR.
Last updated:
1. Controller
The controller responsible for your personal data is Kai Klein, 3 Um Beil, 7653 Heffingen, Luxembourg. You can contact us about anything on this page at support@kairohosting.com. Full operator details are on the Imprint page.
2. Data we collect
When you sign in with Discord. We use Discord OAuth with the identify, email and guilds.join scopes. From that we store your Discord user ID, username, display name, avatar reference, and email address, plus the OAuth access and refresh tokens needed to keep your session working and, with your agreement, to add you to our Discord server.
When you use a server. We store the servers on your account and their details — name, plan, status, assigned IP address, and the relevant timestamps — along with the world and configuration data you upload to the server itself.
Automatically. Our servers and network protection process technical data such as IP addresses, timestamps and request details in log files. This is necessary to operate the service, detect abuse and defend against attacks.
We do not use advertising trackers, and we do not sell your personal data.
3. Why we use it and on what legal basis
- To provide the service you ordered — account creation, running and managing your server, support and billing. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To keep the platform secure and stable — abuse detection, DDoS mitigation, logging and troubleshooting. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
- To meet legal obligations — for example retaining invoices and accounting records. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Optional extras such as joining our Discord. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
4. Cookies
We only set one cookie: an essential, httpOnly session cookie that keeps you signed in for up to seven days. It is strictly necessary to operate the login, so it does not require consent. We do not use analytics, advertising or profiling cookies.
Our fonts are self-hosted and served from our own domain, so loading a page does not send your IP address to a third-party font provider.
5. Who we share data with
We share personal data only with providers that help us run the service, and only as far as necessary:
- Discord — for login and, if you agree, adding you to our Discord server. Your avatar is loaded directly from Discord's CDN when you view the dashboard.
- Our data centre and network providers in the Netherlands, who host the infrastructure your server runs on.
- Payment providers, who process your payment data under their own privacy policies.
- Authorities, where we are legally required to disclose data.
Where a provider processes data on our behalf, we have a data processing agreement in place. If data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
6. How long we keep it
- Account data: for as long as your account exists, and deleted within a reasonable period after you close it.
- Server and world data: until the service is terminated, plus a short grace period, after which it is deleted.
- Server and security logs: kept only as long as needed for security and troubleshooting, then deleted.
- Invoices and accounting records: kept for the retention period required by tax law.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected and, in certain cases, erased;
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing that already happened;
- lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, email support@kairohosting.com. We will respond within the time limits set by law, normally one month.
8. Security
We use appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), httpOnly session cookies, access controls, and DDoS protection. No system is perfectly secure, but we work to keep the risk as low as we reasonably can.
9. Children
Our services are not directed at children below the age at which they can consent to online services in their country. If you believe a child has given us personal data without the required consent, contact us and we will delete it.
10. Changes to this policy
We may update this policy as our service changes. The current version is always available here, with the last-updated date shown at the top of the page.