Hostlim
  • Home
  • Domains
    • Register a Domain
    • Renew Domains
    • Transfer Domain
  • Services
    • Managed WordPressFully managed for your website
    • Managed WooCommerceManaged care for your online store
    • Email Hosting
    • WHMCS Modules
    • WordPress Plugins
  • Support
    • Tickets
    • Open Ticket
    • Knowledgebase
    • Announcements
  • Contact Us
View plansLog in
Log inView plans
Shopping Cart
  • Login
  • Register
  • Forgot Password?
  1. Portal Home
  2. Privacy Policy
HOSTLIM

Privacy Policy

How we use personal data for your account, support and services.

Last updated: 2026-10-11
Terms of Service Privacy Policy Acceptable Use Copyright

On this page

1. Controller and contactClarification of this notice2. Data and sources3. Purposes and lawful bases4. Hosted customer data5. Recipients and international transfers6. Retention and security7. Cookies, analytics and chat8. Rights and complaints9. Automated decisions and updates

1. Controller and contact

Hostlim is a trading name of OMER RETZEPOGLOU MPARIS TOU RAMADAN (Sole proprietorship), registered at Σέλερο, Ξάνθη, Ελλάδα, postal code 67150, tax/VAT number 130102610, G.E.MI. registration 170544846000. Contact: info@hostlim.com, telephone +30 6934641482. The business record is available in the G.E.MI. registry.

For personal-data enquiries contact info@hostlim.com. This policy concerns processing by Hostlim as controller, particularly for accounts, billing and support enquiries.

Clarification of this notice

This notice presents known facts and current practices. Precise category-specific retention limits or criteria, Analytics/chat settings, processing contracts and international-transfer safeguards require further verification and completion. Publication does not confirm that these matters have already been resolved. Contact info@hostlim.com for specific information or to exercise your rights.

2. Data and sources

We receive information you provide in forms, your account and support communications, together with service-use data. Payment and social sign-in providers supply information needed to confirm the transaction or sign-in.

  • Identity and contact information: name, business name, address, email and telephone.
  • Billing information: tax details, orders, invoices and payment status.
  • Service and support information: domains, technical settings, requests and files you provide to resolve problems.
  • Technical information: IP address, device/browser details, access and security logs, login times and events.
  • Cookie, analytics and chat data to the extent those functions are used with an appropriate lawful basis.

3. Purposes and lawful bases

Each use has a specific purpose. Data required for a contract or legal obligation are necessary to supply or invoice the service; not providing them may prevent an order. Optional choices are not a condition of purchase.

  • Contract (GDPR Article 6(1)(b)): account creation, hosting, orders, payments and technical support. For corporate contacts who are not themselves contracting parties, legitimate interests in managing the business relationship may apply.
  • Legal obligation (Article 6(1)(c)): tax/accounting records, lawful authority requests and required disclosures.
  • Legitimate interests (Article 6(1)(f)): securing accounts and services, preventing fraud and abuse, investigating incidents and establishing legal claims, subject to balancing your rights.
  • Consent (Article 6(1)(a)): optional marketing and non-essential tracking where required. Withdrawal of consent does not affect prior lawful processing.

4. Hosted customer data

For personal data stored in your websites and shops, you normally determine the purposes and Hostlim acts as processor. This public policy does not replace the written Article 28 GDPR data processing agreement.

Article 28 requires the agreement to specify instructions, confidentiality, security, sub-processing, assistance with rights and breaches, audits, return and deletion. The required contract with each partner must be verified separately. Do not send special-category data through ordinary support requests without prior arrangement.

5. Recipients and international transfers

Access is limited to authorised personnel who need it for their work and service partners for infrastructure, security/CDN, payments, support, communications, accounting and legal advice. Authority disclosures require a legal obligation or another lawful basis. Confirmed recipients and roles are: Cloudflare for security and CDN; the infrastructure provider for hosting and technical operation; Google Drive (a personal account) for backup storage in addition to backups on our own server; Stripe and the relevant payment providers/banks for card payments, bank transfers or IRIS; AADE through TIMOLOGIO for invoicing and tax obligations; easy.gr and apiname.com for domain registration and management; Google Analytics for optional statistics after consent; Tawk.to for optional chat after consent. WhatsApp or Viber may be used when you choose to contact us through them. Email runs on our own server. Payment services, authorities and other recipients may act as independent controllers for their own lawful purposes.

Transfers outside the EEA require an appropriate legal mechanism, such as an applicable adequacy decision or standard contractual clauses with necessary supplementary safeguards. The current position is: providers such as Cloudflare, Google, Stripe, Tawk.to, WhatsApp and Viber may process data outside the EEA, depending on the service and applicable settings. The applicable transfer arrangements and safeguards for the actual accounts used still require verification. In particular, Google Drive backups currently use a personal account; this notice does not assert that a Google Workspace/Cloud processor agreement applies to it. Ask info@hostlim.com for clarification.

6. Retention and security

GDPR requires personal data not to be retained longer than necessary for their purpose. Accounting records are subject to statutory tax retention periods and lawful extensions. The known current practice is described below; describing multi-year retention does not assert that every period has been reviewed or is lawful.

Appropriate technical and organisational safeguards are applied according to risk. No system is absolutely secure. Statutory breach-notification duties apply when their conditions are met.

  • Accounts and orders: may currently be retained for several years. A category-specific maximum period or precise deletion criteria have not yet been established in this notice; see the clarification below.
  • Support and chats: may currently be retained for several years, including messages concerning technical work or disputes. Their precise deletion criteria and the retention settings of external chat services still require clarification.
  • Access and security logs: may currently be retained for several years. Their category-specific retention limits still require clarification; the 30-day website-deletion rule is not a confirmed retention limit for these separate records.
  • Backups and post-termination data: copies are stored on our server and in a personal Google Drive account. During active service they may remain for long periods, including several years; a fixed maximum age of active-service copies has not yet been specified; website data and all backups under our control, both on the server and in Google Drive, are deleted no later than 30 days after the service actually ends. Request export before termination; access during the deletion period is not guaranteed. This deadline does not apply to accounting records or separate records subject to a different lawful retention obligation.
  • Cookies and analytics: the hl_consent_v1 preference cookie lasts 180 days. The exact cookie lifetimes and data-retention settings for Analytics and external chat services have not yet been verified; withdrawal blocks future loading of the optional tools but is not automatic deletion of data already held by their providers.

7. Cookies, analytics and chat

Necessary cookies support functions such as sign-in, sessions, security and shopping carts. Non-essential cookies or similar device access require prior consent where Greek Law 3471/2006 requires it. Continued browsing alone is not consent.

Tools used on this website and preference controls are: Google Analytics and Tawk.to remain blocked until you choose the corresponding category. The first screen gives equally prominent options to reject, accept all or set preferences. You can change or withdraw your choice through the Cookie settings button. Withdrawal reloads the page to stop optional tools. The necessary hl_consent_v1 cookie stores your preferences for 180 days. Acceptance of optional technologies must be freely given, with rejection and preference changes available. Deleting browser cookies does not automatically delete other data already collected.

8. Rights and complaints

Subject to the relevant legal conditions, you can request access, correction, erasure, restriction, portability and object to processing. You can object to direct marketing at any time. For data hosted on behalf of a website operator, contact that controller; our duties to assist as processor remain.

Send requests to info@hostlim.com. We may ask only for reasonable identity evidence needed to protect you. We normally respond within one month. Where a further two-month extension is permitted, we explain the reason within the first month. Exercising rights is normally free.

You may complain to the Hellenic Data Protection Authority or the competent authority in your habitual residence, workplace or place of the alleged infringement.

9. Automated decisions and updates

Our actual use of automated decisions with legal or similarly significant effects is described here: whether any actual processing constitutes a solely automated decision with legal or similarly significant effects under Article 22 GDPR has not yet been verified for this notice. Where Article 22 applies, its conditions and safeguards must be met, including information about the logic and effects and the applicable rights to human intervention and challenge. Contact the privacy address for clarification concerning your case. Where such processing applies, the legally required information about logic, significance, consequences and safeguards is provided.

The update date appears above. Material changes are communicated appropriately and fresh consent is requested where required.

Questions about these policies? Contact us →
Withdraw from contract here
HOSTLIM

Ready to get started?

Choose fully managed hosting for your WordPress website or WooCommerce store.

View hosting plans Contact Us
Hostlim

Fully managed WordPress & WooCommerce hosting. Updates, security and performance handled by our team.

About Us Contact Us
  • Help Center
  • Knowledgebase
  • Network Status
  • Support Tickets
  • Contact Support
  • Services
  • Domain Search
  • Managed WordPress
  • Managed WooCommerce
  • WordPress Plugins
  • Account
  • Client Area
  • Shopping Cart
  • Register
  • Login
  • Password Reset

© 2026 Hostlim. All rights reserved.

  • Terms of Use
  • Privacy Policy
  • Acceptable Use
  • Copyright

Developed by Grafiman

Use of this Site is subject to express terms of use. By using this site, you signify that you agree to be bound by these Universal Terms of Service.


.
Loading...
Loading...

Choose language

English English
Ελληνικά Ελληνικά
Choose language
English
Ελληνικά

Generate Password

Please enter a number between 8 and 64 for the password length

Your cookie choices

We use necessary cookies to run this website. Google Analytics and Tawk.to chat only load with your permission. You can change your choices at any time.

Privacy policy

Cookie preferences

Optional categories stay off until you select them. Your choice is stored for 6 months in this browser.

Necessary

Sign-in, security, shopping cart and saving cookie preferences.

Always active
Contact us