Privacy Policy
A French hosting provider since 2011, OnetSolutions processes personal data to open your account, run your services and meet its obligations as an operator. This policy sets out exactly which data, why, for how long and with whom it is shared.
Last updated : September 2026European hosting
Your data stays within the European Union, in ISO 27001 certified data centres.
Never sold
We do not sell or rent your data, to anyone, under any circumstances.
A direct contact
A question, or a request about your rights? Write to dpo@onetsolutions.net.
Two roles not to be confused
The GDPR distinguishes the controller, who decides the purposes, from the processor, who acts on instructions. Depending on the data involved, OnetSolutions takes one role or the other — and your remedies differ accordingly.
Your customer data: we are the controller
Account, orders, invoices, support tickets, console login records, commercial communications: we alone determine the purposes and retention periods. This is the scope covered by this policy, and this is where you exercise your rights with us.
Data hosted on your services: we are the processor
Whatever you store or process on your VPS, GPU instances and shared hosting remains entirely under your responsibility. We do not access it, except on your instruction, during a security incident or under legal compulsion. That scope is governed by our terms of service, not by this document.
Who is responsible for your data?
The controller for the data described below is the company that publishes the onetsolutions.net website and the associated services.
- Legal name
- ONETSOLUTIONS — Société par actions simplifiée
- Registration
- Bordeaux Trade Register — SIREN 533 905 659
- VAT number
- FR27 533905659
- CNIL declaration
- 1524760v0
- Data protection contact
- dpo@onetsolutions.net
- Supervisory authority
- CNIL — 3 place de Fontenoy, 75007 Paris, France (cnil.fr)
The data we collect
We collect only what is necessary to open an account, operate your services and comply with our obligations as a hosting provider and domain registrar. We collect no special category data within the meaning of Article 9 GDPR.
Identity data
First and last name, company name, EU VAT number, postal address, email address, phone number, customer ID. During an anti-fraud check, proof of identity or proof of address may occasionally be requested.
Billing data
Order history, invoices, credit notes, account balance, payment method used and card fingerprint. Full card numbers never pass through our servers: they are entered directly with our PCI-DSS certified payment providers.
Service usage data
Subscribed services, provisioned instances and hosting plans, managed domain names, resource consumption, backups and snapshots, administration tasks, monitoring alerts.
Communication data
Support tickets and their attachments, emails exchanged with our teams, complaints, abuse reports, satisfaction survey responses, communication preferences and consent status.
Technical and connection data
IP address, timestamps, session identifier, user agent, pages viewed, authentication and action logs in the console, identifiers of trackers set on our websites.
How we use your data
Every processing activity is tied to a defined purpose, a legal basis and a retention period. Once those periods expire, data is deleted or anonymised, except for archives the law requires us to keep.
The processing without which we can neither open your account nor deliver the services you order.
| Purpose | Data involved | Legal basis | Retention period | Recipients |
|---|---|---|---|---|
| Creating and managing the customer account: signup, authentication, two-factor, management of organisations, projects and roles |
|
|
|
|
| Providing and administering services: provisioning VPS, GPU instances and hosting plans, monitoring, backups, administration console |
|
|
|
|
| Registering and managing domain names, including publication of the information required by registries |
|
|
|
|
| Billing, collection, account balance management and refunds |
|
|
|
|
| Customer support: ticket handling, technical assistance, incident follow-up and commercial enquiries |
|
|
|
|
The periods shown refer to retention in the active database, followed where required by law or limitation periods by intermediate archiving with restricted access.
Our processors
We neither sell nor rent your data. We use providers for specific operations, bound by a processing agreement compliant with Article 28 GDPR that prohibits any use on their own behalf.
- processing payments, handling refunds and combating fraud
- registering and managing domain names with registrars and registries
- network protection, DDoS filtering and DNS resolution
- delivering our operational emails and information campaigns
- audience measurement and usage analysis of our websites and customer console
- application monitoring and error tracking
- collecting customer reviews and running satisfaction surveys
- keeping our accounts, banking operations and debt recovery
- legal advice, auditing and certification of our infrastructure
- identity verification and review of high-risk orders
Every processor is assessed for its security and compliance guarantees before being retained. The contract concluded with it restricts its involvement to the sole purposes for which it was chosen, prohibits any processing on its own behalf and requires it to maintain technical and organisational measures appropriate to the risk. The current list of named processors can be obtained on request at dpo@onetsolutions.net.
We also share data outside any processing arrangement in three cases only: on request from an authorised authority, to establish or defend legal claims, and in the event of a sale, merger or partial transfer of assets — in which case you would be informed beforehand.
Transfers outside the European Union
Our infrastructure and our customers' data are hosted within the European Union, in ISO 27001 certified data centres. Running and storing your services involves no transfer outside the European Economic Area.
Some providers we use for payment, audience measurement or application monitoring may host or access data from a third country. Such transfers are limited to the data strictly necessary for the purpose concerned.
They rely either on an adequacy decision of the European Commission or on the standard contractual clauses set out in Implementing Decision (EU) 2021/914 of 4 June 2021, supplemented where appropriate by additional technical measures such as encryption and pseudonymisation. A copy of these safeguards can be requested at dpo@onetsolutions.net.
Security of your data
We implement technical and organisational measures proportionate to the risk, regularly reassessed and aligned with the state of the art.
In accordance with our terms of service, you remain solely responsible for the security of the content, systems and applications you deploy on the resources made available to you, and for their backups. If you identify a vulnerability in our services, report it to abuse@onetsolutions.net.
See our Security pageSpecific cases
Your rights
The GDPR grants you rights over your data. Their scope depends on the legal basis of the processing concerned: a right to erasure cannot, for instance, override a legal retention obligation.
Right of access
Obtain confirmation that we process data about you and receive a copy of it, together with information about the processing.
Right to rectification
Have inaccurate or incomplete data corrected. Most of your information can be edited directly from your account settings.
Right to erasure
Request deletion of data that is no longer necessary, subject to our legal retention obligations as an accounting entity and hosting provider.
Right to restriction
Request the temporary freezing of a processing activity, notably while a contested accuracy or an objection is being examined.
Right to object
Object to processing based on our legitimate interest on grounds relating to your particular situation, and without having to give reasons for commercial prospecting.
Right to portability
Receive the data you provided to us in a structured, machine-readable format, where the processing is based on the contract or on your consent.
Withdrawal of consent
Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
Post-mortem directives
Set directives on what happens to your data after your death, and designate the person responsible for carrying them out.
Exercising your rights
Send your request to dpo@onetsolutions.net, or open a ticket from your customer area, stating the right you are invoking. Some of your data can also be viewed and edited directly from your account settings.
We respond within one month of receipt, extendable by two months for complex or numerous requests, in which case you would be informed. Proof of identity may be requested where there is reasonable doubt as to the requester's identity, and it is deleted as soon as the request is closed.
If you consider that your rights are not being respected, you may lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online at cnil.fr.
Changes to this policy
This policy evolves with our services, our providers and the applicable regulations. Any new version takes effect on the date it is published on this page.
Where a change materially affects your rights or introduces a new purpose, we inform you by email or through your customer account before it takes effect, and we obtain your consent where consent is required.
Last updated : September 2026