{"id":21551,"date":"2018-05-24T13:25:20","date_gmt":"2018-05-24T11:25:20","guid":{"rendered":"https:\/\/hetzner.co.za\/help-centre\/?p=21551"},"modified":"2025-12-12T12:53:29","modified_gmt":"2025-12-12T10:53:29","slug":"data-protection-managed-hosting","status":"publish","type":"post","link":"https:\/\/xneelo.co.za\/help-centre\/products-and-services\/data-protection-managed-hosting\/","title":{"rendered":"Our role in protecting your data on our managed hosting products"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">A component of our <a href=\"https:\/\/xneelo.co.za\/web-hosting\/\" target=\"_blank\" rel=\"noopener\">Shared<\/a> and <a href=\"https:\/\/xneelo.co.za\/managed-servers\/\" target=\"_blank\" rel=\"noopener\">Dedicated Managed<\/a> hosting products is the storage of customers\u2019 website and email data. As we store the data, under data protection law we are viewed as a processor (or operator) of the data for our customers who are called controllers (or responsible parties).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We have no knowledge of the actual data that our customers store on our hosting platform, which may include personal data. As we have no involvement with the data other than storing it, our obligations relating to data protection law in this context are limited.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Contrast this to the personal data identifying our customers that we store in our customer database; here we are fully obligated under the data protection law as a data controller.<\/span><\/p>\n<p><span style=\"text-decoration: underline;\"><span style=\"font-weight: 400;\">An example:<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">When a customer signs up with us, they voluntarily provide us with their personal data as part of the signup process. We have full knowledge and control of this data. If a customer requests that we make visible to them what data of theirs we have, we are able to do so. Customers are able to independently access contact and banking details associated with their hosting accounts and update or remove this data via the control panel.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When a customer uploads their Web application and associated data to our managed hosting platform, we don\u2019t know the type nor the content of the data uploaded. Should our customer, in turn, store their end customer\u2019s personal data, only our customer can make visible to the end customer what data about them is stored. Here the end customer is the controller, our customer the processor and we are the sub-processor of any personal data.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Our security obligations and how we fulfill them<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">We are obliged to implement appropriate technical and organisational measures to prevent a breach into our managed hosting servers which may allow access to personal data stored on the servers.\u00a0 We have always viewed this as an obligation on us, and therefore at a technology level, data protection law does not change anything for us in the context of these products.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our servers are managed in accordance with security best practices for servers on the internet, providing a mass-market managed hosting service.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">We do not run any services on our servers that are not required to deliver the hosting service. Having extraneous services active on a server increase the attack risk unnecessarily.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">We apply software package security updates provided by our Linux distribution (Debian) as follows:<\/span>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Non-critical updates are applied within a week of release.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Critical updates are aimed to be applied within 24 hours of release.<\/span><\/li>\n<\/ol>\n<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">We do not store customers\u2019 mailbox, FTP or MySQL database passwords in cleartext.<\/span>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Passwords are stored using a salted, one-way hashing algorithm.<\/span><\/li>\n<\/ol>\n<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Vulnerability scans and penetration tests are performed against our managed hosting servers and any critical issues exposed are resolved as a priority.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Firewalls are employed to restrict access to any services on the servers that are not purposed for public consumption.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Various intrusion detection mitigation systems are employed at the server level.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">A basic Web Application Firewall is employed to mitigate a certain degree of relevant attacks.<\/span>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">An advanced Web Application Firewall (<a href=\"https:\/\/xneelo.co.za\/cloudbric\/\" target=\"_blank\" rel=\"noopener\">Cloudbric WAF<\/a>) is available as an optional extra for customers who store particularly sensitive data.<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h2><span style=\"font-weight: 400;\">Encryption of data stored by customers on our Managed Servers<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">We do not encrypt any data stored by customers on our managed servers. The reasons for this are:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The controller of the data (ie. our customer) is the only one positioned to know whether or not data should be encrypted.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Our view is that the most effective place to encrypt personal data is at the point where the controller is able to affect the encryption (and decryption).<\/span>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Sensitive emails should be encrypted at the source and decrypted only by the recipient (i.e. utilising asymmetric key pair encryption)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Web application files and database tables should be encrypted and decrypted by the Web application itself<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n","protected":false,"plain":"<span >A component of our <a href=\"https:\/\/xneelo.co.za\/web-hosting\/\" target=\"_blank\" rel=\"noopener\">Shared<\/a> and <a href=\"https:\/\/xneelo.co.za\/managed-servers\/\" target=\"_blank\" rel=\"noopener\">Dedicated Managed<\/a> hosting products is the storage of customers\u2019 website and email data. As we store the data, under data protection law we are viewed as a processor (or operator) of the data for our customers who are called controllers (or responsible parties).<\/span>\r\n\r\n<span >We have no knowledge of the actual data that our customers store on our hosting platform, which may include personal data. As we have no involvement with the data other than storing it, our obligations relating to data protection law in this context are limited.<\/span>\r\n\r\n<span >Contrast this to the personal data identifying our customers that we store in our customer database; here we are fully obligated under the data protection law as a data controller.<\/span>\r\n\r\n<span ><span >An example:<\/span><\/span>\r\n\r\n<span >When a customer signs up with us, they voluntarily provide us with their personal data as part of the signup process. We have full knowledge and control of this data. If a customer requests that we make visible to them what data of theirs we have, we are able to do so. Customers are able to independently access contact and banking details associated with their hosting accounts and update or remove this data via the control panel.<\/span>\r\n\r\n<span >When a customer uploads their Web application and associated data to our managed hosting platform, we don\u2019t know the type nor the content of the data uploaded. Should our customer, in turn, store their end customer\u2019s personal data, only our customer can make visible to the end customer what data about them is stored. Here the end customer is the controller, our customer the processor and we are the sub-processor of any personal data.<\/span>\r\n<h2><span >Our security obligations and how we fulfill them<\/span><\/h2>\r\n<span >We are obliged to implement appropriate technical and organisational measures to prevent a breach into our managed hosting servers which may allow access to personal data stored on the servers.\u00a0 We have always viewed this as an obligation on us, and therefore at a technology level, data protection law does not change anything for us in the context of these products.<\/span>\r\n\r\n<span >Our servers are managed in accordance with security best practices for servers on the internet, providing a mass-market managed hosting service.<\/span>\r\n<ol>\r\n \t<li ><span >We do not run any services on our servers that are not required to deliver the hosting service. Having extraneous services active on a server increase the attack risk unnecessarily.<\/span><\/li>\r\n \t<li ><span >We apply software package security updates provided by our Linux distribution (Debian) as follows:<\/span>\r\n<ol>\r\n \t<li ><span >Non-critical updates are applied within a week of release.<\/span><\/li>\r\n \t<li ><span >Critical updates are aimed to be applied within 24 hours of release.<\/span><\/li>\r\n<\/ol>\r\n<\/li>\r\n \t<li ><span >We do not store customers\u2019 mailbox, FTP or MySQL database passwords in cleartext.<\/span>\r\n<ol>\r\n \t<li ><span >Passwords are stored using a salted, one-way hashing algorithm.<\/span><\/li>\r\n<\/ol>\r\n<\/li>\r\n \t<li ><span >Vulnerability scans and penetration tests are performed against our managed hosting servers and any critical issues exposed are resolved as a priority.<\/span><\/li>\r\n \t<li ><span >Firewalls are employed to restrict access to any services on the servers that are not purposed for public consumption.<\/span><\/li>\r\n \t<li ><span >Various intrusion detection mitigation systems are employed at the server level.<\/span><\/li>\r\n \t<li ><span >A basic Web Application Firewall is employed to mitigate a certain degree of relevant attacks.<\/span>\r\n<ol>\r\n \t<li ><span >An advanced Web Application Firewall (<a href=\"https:\/\/xneelo.co.za\/cloudbric\/\" target=\"_blank\" rel=\"noopener\">Cloudbric WAF<\/a>) is available as an optional extra for customers who store particularly sensitive data.<\/span><\/li>\r\n<\/ol>\r\n<\/li>\r\n<\/ol>\r\n<h2><span >Encryption of data stored by customers on our Managed Servers<\/span><\/h2>\r\n<span >We do not encrypt any data stored by customers on our managed servers. The reasons for this are:<\/span>\r\n<ol>\r\n \t<li ><span >The controller of the data (ie. our customer) is the only one positioned to know whether or not data should be encrypted.<\/span><\/li>\r\n \t<li ><span >Our view is that the most effective place to encrypt personal data is at the point where the controller is able to affect the encryption (and decryption).<\/span>\r\n<ol>\r\n \t<li ><span >Sensitive emails should be encrypted at the source and decrypted only by the recipient (i.e. utilising asymmetric key pair encryption)<\/span><\/li>\r\n \t<li ><span >Web application files and database tables should be encrypted and decrypted by the Web application itself<\/span><\/li>\r\n<\/ol>\r\n<\/li>\r\n<\/ol>"},"excerpt":{"rendered":"<p>A component of our Shared and Dedicated Managed hosting products is the storage of customers\u2019 Website and Email data.<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"lsx_disable_title":"0","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","footnotes":""},"categories":[205],"tags":[24075,24072,23072,20944,20510,17868,479],"topics":[10413,10377],"class_list":["post-21551","post","type-post","status-publish","format-standard","hentry","category-products-and-services","tag-processor","tag-protect-data","tag-data-security","tag-our-role-in-protecting-your-data-on-our-managed-hosting-products","tag-personal-data","tag-gdpr","tag-security","topics-mail-security","topics-website-security"],"acf":[],"additional_meta":{"category_title":[{"term_id":205,"name":"Products and Services","slug":"products-and-services","term_group":0,"term_taxonomy_id":205,"taxonomy":"category","description":"Products and Services provided by xneelo","parent":0,"count":93,"filter":"raw","term_order":"98","cat_ID":205,"category_count":93,"category_description":"Products and Services provided by xneelo","cat_name":"Products and Services","category_nicename":"products-and-services","category_parent":0}],"tag_title":[{"term_id":24075,"name":"processor","slug":"processor","term_group":0,"term_taxonomy_id":24075,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw","term_order":"134"},{"term_id":24072,"name":"protect data","slug":"protect-data","term_group":0,"term_taxonomy_id":24072,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw","term_order":"135"},{"term_id":23072,"name":"data security","slug":"data-security","term_group":0,"term_taxonomy_id":23072,"taxonomy":"post_tag","description":"","parent":0,"count":2,"filter":"raw","term_order":"467"},{"term_id":20944,"name":"Our role in protecting your data on our managed hosting products","slug":"our-role-in-protecting-your-data-on-our-managed-hosting-products","term_group":0,"term_taxonomy_id":20944,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw","term_order":"1162"},{"term_id":20510,"name":"personal data","slug":"personal-data","term_group":0,"term_taxonomy_id":20510,"taxonomy":"post_tag","description":"","parent":0,"count":2,"filter":"raw","term_order":"1305"},{"term_id":17868,"name":"gdpr","slug":"gdpr","term_group":0,"term_taxonomy_id":17868,"taxonomy":"post_tag","description":"","parent":0,"count":3,"filter":"raw","term_order":"2168"},{"term_id":479,"name":"security","slug":"security","term_group":0,"term_taxonomy_id":479,"taxonomy":"post_tag","description":"","parent":0,"count":5,"filter":"raw","term_order":"2670"}]},"featured_image_src":null,"author_info":{"display_name":"marketing","author_link":"https:\/\/xneelo.co.za\/help-centre\/author\/marketing\/","author_avatar":"https:\/\/secure.gravatar.com\/avatar\/a6ea315e112423b2b955cb020fbce2b0835956c6ad85ff0f13f1db298977eaaa?s=96&d=mm&r=g"},"_links":{"self":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/posts\/21551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/comments?post=21551"}],"version-history":[{"count":0,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/posts\/21551\/revisions"}],"wp:attachment":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/media?parent=21551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/categories?post=21551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/tags?post=21551"},{"taxonomy":"topics","embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/topics?post=21551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}