Static Data Hosting Server Management Privacy Policy
Effective date: 29 August 2026
Version: 2.0
This Privacy Policy explains how Static Data Hosting (“SDH,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal data in connection with our websites, ClientBox, support channels, billing activities, and Server Management Services.
This Policy is a privacy notice, not a request for blanket consent and not a waiver of privacy rights. We rely on the lawful basis appropriate to each processing activity. When the law requires consent—such as for optional direct marketing—we will request it separately, and you may withdraw it without affecting earlier lawful processing.
1. Scope
This Policy applies to personal data relating to customers, prospective customers, customer representatives, authorized users, website visitors, support contacts, and individuals whose data SDH may encounter while providing Server Management Services.
It does not govern a third party’s independent processing practices. Third-party websites, data centers, payment providers, control panels, software vendors, and communication services may publish their own privacy notices.
2. Who Is Responsible for Personal Data
For account registration, billing, sales, website operation, security, and SDH’s own business records, SDH acts as the personal information controller.
When SDH accesses or handles personal data stored on a customer-controlled server solely to provide requested administration, troubleshooting, monitoring, migration, backup, security, or related work, the customer normally acts as the personal information controller and SDH acts as its personal information processor. In that role, SDH processes personal data only for the Services, on the customer’s documented instructions, as permitted by the Server Management Terms, or as required by law.
Controller identity and registered business name: Static Data Hosting
Business address: South Poblacion, San Fernando, Cebu, Philippines
Privacy contact: legal@staticdatahosting.com
Telephone: +63 925 890 2923 / +63 969 300 1000
3. Personal Data We Collect
Depending on how you interact with SDH, we may collect the following:
- Identity and contact data: name, company or organization, job title, billing address, country, email address, telephone number, and authorized-user details.
- Account and authentication data: ClientBox account identifier, username, password hash, multi-factor authentication status, security and login records, and account permissions.
- Order, billing, and transaction data: services ordered, invoices, payment status, currency, tax-related information, transaction identifiers, payment method type, and limited payment details supplied by a payment provider. Full payment-card details are ordinarily processed by the applicable payment provider, not stored directly by SDH.
- Technical and usage data: IP address, browser and device information, operating system, time zone, referring page, pages or products viewed, cookie or similar identifiers, session data, and interaction logs.
- Communications and support data: tickets, emails, chat records, call notes, attachments, diagnostic output, instructions, feedback, and the history of work requested or performed.
- Server and access data: server hostname, IP address, operating system, installed services, configuration details, control-panel details, authorized data-center contacts, administrative credentials or access keys, logs, alerts, and other information necessary to perform the Services.
- Customer-hosted data: limited personal data or content encountered on a managed server while diagnosing or completing authorized work. SDH does not intentionally inspect customer-hosted content beyond what is reasonably necessary for the requested task, security, or legal compliance.
- Fraud, abuse, and compliance data: risk signals, payment disputes, suspected misuse, sanctions or identity-verification results where applicable, legal requests, and records needed to establish, exercise, or defend legal claims.
Please do not send personal data, passwords, private keys, database exports, or production content that is not necessary for the requested work. Use the secure submission method specified by SDH for privileged access information.
4. How We Collect Personal Data
We collect personal data:
- directly from you or an authorized representative when you register, order, pay, contact us, submit a support request, or provide server access;
- automatically through our websites, ClientBox, security tools, cookies, logs, and monitoring systems;
- from payment providers, fraud-prevention services, communications providers, data centers, software vendors, domain or hosting partners, and other suppliers used to provide the Services; and
- from public records, competent authorities, or other lawful sources where reasonably necessary for security, fraud prevention, dispute handling, or compliance.
5. Purposes and Lawful Bases
We process personal data only for a specified and legitimate purpose and only to the extent reasonably necessary. Depending on the activity, the lawful basis may be performance of a contract, steps requested before entering a contract, compliance with a legal obligation, consent, protection of vital interests, or a legitimate interest that is not overridden by the rights and freedoms of the data subject.
- Provide and administer the Services: create and secure accounts, verify authority, provision plans, access managed systems, perform requested tasks, monitor covered systems, respond to incidents, and communicate service information. The usual basis is contract necessity or steps requested before contracting.
- Bill and collect payment: issue invoices and receipts, process payments, maintain transaction records, manage renewals, credits, refunds, overdue balances, and payment disputes. The usual basis is contract necessity, legal obligation, or legitimate interests.
- Provide support and maintain service quality: investigate requests, retain work history, prevent repeated issues, train authorized personnel, and improve procedures. The usual basis is contract necessity or legitimate interests.
- Protect systems, customers, and the public: authenticate users, log administrative activity, detect fraud and abuse, investigate security events, prevent unauthorized access, and enforce applicable terms. The usual basis is contract necessity, legal obligation, or legitimate interests.
- Comply with law and protect legal rights: maintain legally required records, respond to valid legal process, cooperate with competent authorities, and establish, exercise, or defend claims. The usual basis is legal obligation or legitimate interests.
- Operate and improve our website and business: measure performance, understand service demand, troubleshoot errors, and improve usability. The usual basis is legitimate interests or consent where required.
- Send marketing communications: send optional news, promotions, or product information. The usual basis is consent or another lawful basis permitted by applicable law. You may opt out of marketing at any time; service, security, billing, and legal notices are not marketing.
6. Server Credentials and Privileged Access
Administrative credentials and access keys are used only by personnel or contractors who need them to perform authorized work. SDH applies reasonable access controls and uses encryption in transit and, where stored, appropriate protection at rest. No security method is infallible, and SDH does not promise that any transmission, storage system, or managed server is completely secure.
Where practicable, customers should create a unique, temporary, least-privilege account for SDH, enable multi-factor authentication, and revoke or rotate access promptly when work or the service relationship ends. Customers should not reuse personal or production passwords.
7. Customer-Hosted Personal Data
The customer determines what data is placed on its server and why that data is processed. The customer is responsible for providing required privacy notices, establishing a lawful basis, responding to data-subject requests, maintaining appropriate backups, and issuing lawful and documented instructions to SDH.
SDH will not sell customer-hosted data or use it for advertising. SDH may access, copy, alter, transmit, restore, or delete limited customer-hosted data only as reasonably necessary to perform an authorized task, protect the managed environment, comply with law, or address an emergency within the scope of the Services.
If an instruction appears unlawful or materially inconsistent with applicable data-protection requirements, SDH may pause the affected work and request clarification. Additional processor obligations are stated in the Server Management Terms.
8. Cookies and Similar Technologies
Our websites and ClientBox may use cookies or similar technologies that are:
- strictly necessary for authentication, security, shopping-cart, session, and account functions;
- functional to remember preferences;
- analytics-related to understand site performance and use; or
- marketing-related where enabled and legally permitted.
Where required, non-essential cookies will be subject to your choices. Blocking necessary cookies may prevent account or checkout features from working correctly.
9. When We Disclose Personal Data
SDH does not sell personal data. We may disclose only the data reasonably necessary to the following categories of recipients:
- authorized SDH staff, contractors, and professional advisers subject to confidentiality obligations;
- ClientBox, hosting, infrastructure, backup, monitoring, security, communications, support, analytics, and other technology providers;
- banks, payment processors, fraud-prevention services, and accounting providers;
- data centers, software licensors, control-panel vendors, and other suppliers involved in an ordered service;
- a successor or prospective successor in a merger, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and legal safeguards;
- competent courts, regulators, law-enforcement bodies, government agencies, or other persons when disclosure is required by law, valid legal process, or reasonably necessary to protect legal rights, safety, or service integrity; and
- other persons when you direct or validly authorize the disclosure.
Service providers processing personal data for SDH are required, as applicable, to process it only for authorized purposes, maintain confidentiality, apply appropriate safeguards, assist with relevant compliance obligations, and delete or return data when their work ends unless retention is legally permitted.
10. International Processing and Transfers
SDH and its service providers may process personal data in the Philippines or in other countries where personnel, infrastructure, payment, communications, or support providers operate. Those countries may have different privacy laws.
When personal data is transferred or processed outside the Philippines, SDH remains accountable as required by applicable law and uses contractual, technical, organizational, or other reasonable safeguards appropriate to the data and risk.
11. Retention
We retain personal data only for as long as reasonably necessary for the stated purpose, an active service relationship, legitimate business needs, security and audit requirements, legal or tax obligations, or the establishment, exercise, or defense of claims.
- Account, order, invoice, transaction, and support records are retained for the applicable legal, accounting, dispute, and operational period.
- Security and access logs are retained for the period reasonably necessary to detect, investigate, and document security events.
- Server credentials should be removed from active systems or rendered inaccessible when no longer required for the Services, subject to lawful retention, security, dispute, and backup-cycle limitations.
- Customer-hosted data temporarily copied for a support task is deleted or returned after the task or service ends when reasonably practicable, unless continued storage is authorized by the customer or law.
- Backup copies may remain until they are overwritten through the applicable backup cycle and will remain protected while retained.
We may retain de-identified or aggregated information that can no longer reasonably identify an individual.
12. Security
SDH uses reasonable and appropriate organizational, physical, and technical measures designed to protect personal data against accidental or unlawful destruction, alteration, loss, disclosure, access, or other unauthorized processing. Measures may include HTTPS, encryption where appropriate, authentication controls, role-based access, logging, vulnerability management, backups, confidentiality duties, incident procedures, and personnel training.
Security is a shared responsibility. Customers must protect their account, use strong and unique credentials, enable available multi-factor authentication, restrict authorized users, maintain backups, update contact information, and report suspected compromise promptly.
13. Personal Data Breaches
SDH maintains procedures to identify, assess, document, contain, and mitigate security incidents and personal data breaches. Where notification is legally required, SDH will notify the National Privacy Commission and affected data subjects within the period required by applicable law. When SDH acts as a processor, it will notify the responsible customer without undue delay after confirming a relevant breach and will reasonably assist with the customer’s response obligations.
14. Your Privacy Rights
Subject to the Data Privacy Act of 2012, its implementing rules, and applicable exceptions, a data subject may have the right to:
- be informed about the processing of personal data;
- object to certain processing, including direct marketing;
- access personal data and specified information about its processing;
- correct inaccurate or incomplete personal data;
- request erasure, blocking, or suspension where the legal requirements are met;
- withdraw consent where processing depends on consent;
- obtain data portability where applicable;
- seek indemnification for damages as provided by law; and
- lodge a complaint with the National Privacy Commission.
To exercise a right, email legal@staticdatahosting.com. Describe the request and the account or data involved. We may take proportionate steps to verify identity and authority before disclosing, correcting, exporting, or deleting data. A request may be limited or denied where permitted or required by law, including where data is needed to provide an active service, protect another person, comply with a legal obligation, investigate a violation, or establish or defend a claim.
If SDH holds the data only as a processor for a customer, we may refer the request to that customer and reasonably assist it in responding.
15. Marketing Choices
You may unsubscribe through the link in a marketing email or by contacting us. Opting out of marketing does not stop transactional messages such as invoices, renewal notices, service notices, security alerts, policy notices, or responses to support requests.
16. Children
The Server Management Services are intended for businesses and persons legally capable of entering a contract. They are not directed to children. Do not submit a child’s personal data to SDH unless you have lawful authority and the processing is necessary for an authorized service task.
17. Changes to This Policy
We may update this Policy to reflect changes in law, technology, providers, or business practices. We will post the revised version and effective date. Where a change materially affects how we process personal data, we will provide additional notice or obtain consent when required by law. Changes do not retroactively authorize materially different processing of data already collected when a new lawful basis or consent is required.
18. Contact and Complaints
For privacy questions, requests, or complaints, contact:
Privacy Officer / Legal Contact
Static Data Hosting
Email: legal@staticdatahosting.com
Address: South Poblacion, San Fernando, Cebu, Philippines
Telephone: +63 925 890 2923 / +63 969 300 1000
We will review privacy complaints in good faith. You may also contact or lodge a complaint with the National Privacy Commission of the Philippines.
19. Legal Framework
This Policy is intended to operate consistently with the Philippine Data Privacy Act of 2012, its Implementing Rules and Regulations, and other applicable privacy and electronic-commerce requirements. If applicable law provides greater protection, that law controls.