Ferrix Systems

EEA / GDPR Notice

Last updated: May 27, 2026

This notice supplements our Privacy Policy for individuals in the European Economic Area (EEA), United Kingdom, and Switzerland. Ferrix Systems is the data controller for personal data described here unless we act as a processor on your instructions (for example, data your customers store on servers you rent from us).

1. Data controller and contact

Controller: Ferrix Systems. For privacy requests and questions: legal@ferrix.systems or the contact form or support email address published on our website and in the customer portal. If we appoint an EU or UK representative, we will publish their details on this page.

2. Categories of personal data

Depending on how you use the Services, we may process:

  • Account and identity data (name, email, authentication identifiers, billing contact).
  • Order and provisioning data (products, configuration, IP addresses, hostnames).
  • Billing and payment data (processed largely by Stripe; we receive limited card metadata).
  • Support and communications (tickets, chat, email).
  • Technical and security data (logs, audit events, abuse investigations).
  • Analytics and diagnostics where you have consented (see Privacy Policy).

3. Purposes and legal bases

We process personal data to provide the Services (contract), comply with law (legal obligation), secure our network (legitimate interests), and, where required, with your consent (for example optional analytics). You may withdraw consent for optional processing without affecting core hosting where another basis applies.

4. Recipients and subprocessors

We share data with service providers that help us operate the Services (hosting infrastructure, payment processing, email, chat, authentication providers, and analytics when enabled). A current list of categories of subprocessors is described in our Privacy Policy; we will update it when we add material new subprocessors.

5. International transfers

Personal data may be processed in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms approved under UK and EU law.

6. Retention

We retain personal data for as long as your account is active and as needed for billing, tax, security, and legal claims. Specific retention periods are available on request.

7. Your rights

Subject to exceptions in law, you may have the right to access, rectify, erase, restrict, object, and port your data, and to withdraw consent. You may lodge a complaint with your local supervisory authority. To exercise rights, contact us using the details above; we may need to verify your identity.

8. When you are the controller

If you host personal data about your own users on our Services, you are the controller for that data and we act as a processor. You must provide lawful notices to your users and, where required, a data processing agreement with us before processing special categories of data at scale.

9. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects about individuals without human review, except for fraud prevention and security measures permitted by law.

10. Children

The Services are not directed at children under 16. We do not knowingly collect children's personal data through the portal. Report concerns to legal@ferrix.systems.