Data protection

Privacy Policy

A French hosting provider since 2011, OnetSolutions processes personal data to open your account, run your services and meet its obligations as an operator. This policy sets out exactly which data, why, for how long and with whom it is shared.

Last updated : September 2026

European hosting

Your data stays within the European Union, in ISO 27001 certified data centres.

Never sold

We do not sell or rent your data, to anyone, under any circumstances.

A direct contact

A question, or a request about your rights? Write to dpo@onetsolutions.net.

Two roles not to be confused

The GDPR distinguishes the controller, who decides the purposes, from the processor, who acts on instructions. Depending on the data involved, OnetSolutions takes one role or the other — and your remedies differ accordingly.

Your customer data: we are the controller

Account, orders, invoices, support tickets, console login records, commercial communications: we alone determine the purposes and retention periods. This is the scope covered by this policy, and this is where you exercise your rights with us.

Data hosted on your services: we are the processor

Whatever you store or process on your VPS, GPU instances and shared hosting remains entirely under your responsibility. We do not access it, except on your instruction, during a security incident or under legal compulsion. That scope is governed by our terms of service, not by this document.

Who is responsible for your data?

The controller for the data described below is the company that publishes the onetsolutions.net website and the associated services.

Legal name
ONETSOLUTIONS — Société par actions simplifiée
Registration
Bordeaux Trade Register — SIREN 533 905 659
VAT number
FR27 533905659
CNIL declaration
1524760v0
Data protection contact
dpo@onetsolutions.net
Supervisory authority
CNIL — 3 place de Fontenoy, 75007 Paris, France (cnil.fr)

The data we collect

We collect only what is necessary to open an account, operate your services and comply with our obligations as a hosting provider and domain registrar. We collect no special category data within the meaning of Article 9 GDPR.

Identity data

First and last name, company name, EU VAT number, postal address, email address, phone number, customer ID. During an anti-fraud check, proof of identity or proof of address may occasionally be requested.

Billing data

Order history, invoices, credit notes, account balance, payment method used and card fingerprint. Full card numbers never pass through our servers: they are entered directly with our PCI-DSS certified payment providers.

Service usage data

Subscribed services, provisioned instances and hosting plans, managed domain names, resource consumption, backups and snapshots, administration tasks, monitoring alerts.

Communication data

Support tickets and their attachments, emails exchanged with our teams, complaints, abuse reports, satisfaction survey responses, communication preferences and consent status.

Technical and connection data

IP address, timestamps, session identifier, user agent, pages viewed, authentication and action logs in the console, identifiers of trackers set on our websites.

How we use your data

Every processing activity is tied to a defined purpose, a legal basis and a retention period. Once those periods expire, data is deleted or anonymised, except for archives the law requires us to keep.

The processing without which we can neither open your account nor deliver the services you order.

PurposeData involvedLegal basisRetention periodRecipients
Creating and managing the customer account: signup, authentication, two-factor, management of organisations, projects and roles
  • Identity
  • Connection
  • Performance of the contract
  • Duration of the contractual relationship, then 5 years of archiving (commercial limitation period)
  • OnetSolutions teams
  • Email service provider
Providing and administering services: provisioning VPS, GPU instances and hosting plans, monitoring, backups, administration console
  • Identity
  • Service usage
  • Connection
  • Performance of the contract
  • Duration of the contractual relationship
  • Backups purged within 30 days of termination
  • OnetSolutions technical teams
  • Network protection provider
Registering and managing domain names, including publication of the information required by registries
  • Identity
  • Billing
  • Technical
  • Performance of the contract
  • Legal and contractual obligation imposed by ICANN and the registries
  • Lifetime of the domain name, plus any period imposed by the relevant registry
  • Partner registrars
  • Registries (AFNIC, Verisign, etc.)
  • Public WHOIS and RDAP databases
Billing, collection, account balance management and refunds
  • Identity
  • Billing
  • Performance of the contract
  • Accounting legal obligation
  • 10 years from the close of the financial year (Article L123-22 of the French Commercial Code)
  • Payment providers
  • Chartered accountant
  • Banking institution
  • Tax authorities
Customer support: ticket handling, technical assistance, incident follow-up and commercial enquiries
  • Identity
  • Communication
  • Service usage
  • Connection
  • Performance of the contract
  • Legitimate interest (service quality)
  • Duration of the contractual relationship, then 3 years
  • OnetSolutions support and technical teams

The periods shown refer to retention in the active database, followed where required by law or limitation periods by intermediate archiving with restricted access.

Our processors

We neither sell nor rent your data. We use providers for specific operations, bound by a processing agreement compliant with Article 28 GDPR that prohibits any use on their own behalf.

  • processing payments, handling refunds and combating fraud
  • registering and managing domain names with registrars and registries
  • network protection, DDoS filtering and DNS resolution
  • delivering our operational emails and information campaigns
  • audience measurement and usage analysis of our websites and customer console
  • application monitoring and error tracking
  • collecting customer reviews and running satisfaction surveys
  • keeping our accounts, banking operations and debt recovery
  • legal advice, auditing and certification of our infrastructure
  • identity verification and review of high-risk orders

Every processor is assessed for its security and compliance guarantees before being retained. The contract concluded with it restricts its involvement to the sole purposes for which it was chosen, prohibits any processing on its own behalf and requires it to maintain technical and organisational measures appropriate to the risk. The current list of named processors can be obtained on request at dpo@onetsolutions.net.

We also share data outside any processing arrangement in three cases only: on request from an authorised authority, to establish or defend legal claims, and in the event of a sale, merger or partial transfer of assets — in which case you would be informed beforehand.

Transfers outside the European Union

Our infrastructure and our customers' data are hosted within the European Union, in ISO 27001 certified data centres. Running and storing your services involves no transfer outside the European Economic Area.

Some providers we use for payment, audience measurement or application monitoring may host or access data from a third country. Such transfers are limited to the data strictly necessary for the purpose concerned.

They rely either on an adequacy decision of the European Commission or on the standard contractual clauses set out in Implementing Decision (EU) 2021/914 of 4 June 2021, supplemented where appropriate by additional technical measures such as encryption and pseudonymisation. A copy of these safeguards can be requested at dpo@onetsolutions.net.

Security of your data

We implement technical and organisational measures proportionate to the risk, regularly reassessed and aligned with the state of the art.

Encryption of data in transit (TLS) and of sensitive data at rest
Strong authentication of the customer console with TOTP or email two-factor
Strict isolation between virtualised customer environments
Centralised logging and monitoring of access and administration actions
Internal permissions on a least-privilege basis, reviewed periodically
Documented incident and personal data breach management procedure
Physical access control and video surveillance of data centres
Encrypted and tested backups, redundancy of critical components
Continuous vulnerability scanning of our own exposed assets
Security and data protection awareness training across all teams

In accordance with our terms of service, you remain solely responsible for the security of the content, systems and applications you deploy on the resources made available to you, and for their backups. If you identify a vulnerability in our services, report it to abuse@onetsolutions.net.

See our Security page

Specific cases

Your rights

The GDPR grants you rights over your data. Their scope depends on the legal basis of the processing concerned: a right to erasure cannot, for instance, override a legal retention obligation.

Right of access

Obtain confirmation that we process data about you and receive a copy of it, together with information about the processing.

Right to rectification

Have inaccurate or incomplete data corrected. Most of your information can be edited directly from your account settings.

Right to erasure

Request deletion of data that is no longer necessary, subject to our legal retention obligations as an accounting entity and hosting provider.

Right to restriction

Request the temporary freezing of a processing activity, notably while a contested accuracy or an objection is being examined.

Right to object

Object to processing based on our legitimate interest on grounds relating to your particular situation, and without having to give reasons for commercial prospecting.

Right to portability

Receive the data you provided to us in a structured, machine-readable format, where the processing is based on the contract or on your consent.

Withdrawal of consent

Withdraw consent at any time, without affecting the lawfulness of processing already carried out.

Post-mortem directives

Set directives on what happens to your data after your death, and designate the person responsible for carrying them out.

Exercising your rights

Send your request to dpo@onetsolutions.net, or open a ticket from your customer area, stating the right you are invoking. Some of your data can also be viewed and edited directly from your account settings.

We respond within one month of receipt, extendable by two months for complex or numerous requests, in which case you would be informed. Proof of identity may be requested where there is reasonable doubt as to the requester's identity, and it is deleted as soon as the request is closed.

If you consider that your rights are not being respected, you may lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online at cnil.fr.

Data protection

dpo@onetsolutions.net

Support ticket

Open a ticket

Changes to this policy

This policy evolves with our services, our providers and the applicable regulations. Any new version takes effect on the date it is published on this page.

Where a change materially affects your rights or introduces a new purpose, we inform you by email or through your customer account before it takes effect, and we obtain your consent where consent is required.

Last updated : September 2026