Giveaway live — join Discord
Hytale hosting now live
25% OFF — code HYTHOSTNEW
  • العربية
  • Azerbaijani
  • Català
  • 中文
  • Hrvatski
  • Čeština
  • Dansk
  • Nederlands
  • English
  • Estonian
  • Persian
  • Français
  • Deutsch
  • עברית
  • Magyar
  • Italiano
  • Macedonian
  • Norwegian
  • Português
  • Português
  • Română
  • Русский
  • Español
  • Svenska
  • Türkçe
  • Українська
0
HytHost
  • HOME
  • Game Hosting  
    • Minecraft
    • Hytale
    • Counter-Strike 2
    • Counter-Strike 1.6
    • SA:MP
    • FiveM
    • Palworld
    •   View all Games
  • Hosting  
    •   Dedicated Servers
    •   VPS Hosting
    •   Web Hosting
    •   Discord Host
    •   VPN
  • Domains  
    •   Register Domain
    •   Transfer Domain
    •   Domain Checker
  • Company  
    •   Affiliates
    •   Partners
    •   About US
    •   FAQ
    •   Guides
    •   Colocation
    •   Contact Us
Client Area

// LEGAL

Privacy Policy

What personal data we process, why, who receives it, how long we keep it, and the rights you can exercise at any time.

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • SLA
  • DPA

Contents

Contents

Privacy Policy

Last Updated: August 10, 2026 (previous version: April 22, 2026)

The English version of this document is the legally binding version.

This Privacy Policy explains how OKLAKO S.R.L., operating services under the HYTHOST brand, processes personal data in connection with our website, client area, support, billing, hosting services, game server services, VPS services, dedicated services, domain-related services, security operations, and abuse handling.

HYTHOST acts as a data controller for personal data we process for our own account management, billing, support, security, fraud prevention, abuse handling, legal compliance, and service operation purposes. For content, files, databases, and other data uploaded by clients to their own hosting services, the client normally controls the purposes and means of that processing, and HYTHOST acts as a processor under the Data Processing Agreement to the extent applicable.

1. Controller and Contact Details

The controller is OKLAKO S.R.L., identification number (IDNO) 1015600036593, registered office in Chișinău, Republic of Moldova, operating the HYTHOST services. You can contact us for any privacy matter through the HYTHOST client-area support ticket system or by email at [email protected].

2. Personal Data We Process

Depending on how you interact with us, we may process the following categories of personal data:

  • account data, such as name, company name, email address, phone number, address, country, login details, account identifiers, and account status;
  • billing and order data, such as invoices, payment status, payment method references, products ordered, renewals, cancellations, tax-related data, and transaction history;
  • support data, such as ticket messages, replies, attachments, screenshots, diagnostics, service identifiers, chat messages, and communication history;
  • technical and usage data, such as IP addresses, timestamps, browser and device information, referral URLs, access logs, authentication logs, control panel logs, API usage, service activity, traffic metadata, and security events;
  • advertising attribution data where you allow it, such as the ad click identifier (gclid/gbraid/wbraid) from the page you landed on and the landing URL — see Section 6 and the Cookie Policy;
  • service data, such as domain names, hostnames, DNS records, assigned IP addresses, server identifiers, configuration data, resource usage, backups metadata, and operational logs;
  • abuse and security data, such as blacklist or RBL listings, abuse reports, malware reports, phishing reports, spam evidence, DDoS or intrusion indicators, upstream notices, law enforcement notices, investigation notes, and suspension history;
  • verification and fraud-prevention data where reasonably required, such as account verification details, risk signals, and information needed to verify payment or account legitimacy.

3. How We Collect Personal Data

We collect personal data directly from you when you register, order, pay, open a ticket, contact support, configure services, or otherwise use our website or client area. We also collect data automatically through logs, cookies or similar technologies, fraud prevention systems, service monitoring, security tools, abuse monitoring, and infrastructure systems.

We may receive personal data from third parties where necessary to provide or protect services, including payment processors such as Skrill, Paynet, and PayPal; registrars; registries; datacenters; upstream network providers; anti-DDoS providers; blacklist or reputation sources; abuse reporters; law enforcement bodies; and security researchers.

4. Purposes and Legal Bases

We process personal data for the following purposes and legal bases:

  • to create and administer accounts, process orders, provide services, manage renewals, and handle support, based on contract performance or steps taken before entering into a contract;
  • to issue invoices, keep accounting records, process payments, handle tax obligations, and respond to lawful requests, based on legal obligations;
  • to secure accounts, prevent fraud, detect abuse, monitor IP reputation, investigate incidents, enforce Terms of Service, protect infrastructure, and protect third parties, based on legitimate interests and, where applicable, legal obligations;
  • to communicate service notices, maintenance notices, abuse tickets, suspension notices, billing notices, and operational updates, based on contract performance and legitimate interests;
  • to improve our website, services, support, security controls, and internal administration, based on legitimate interests;
  • to measure website usage and advertising performance with Google Analytics and Google Ads, based on your consent given through the cookie banner (see Section 6), which you can withdraw at any time;
  • to send optional marketing communications where you have consented or where applicable law allows, with the option to withdraw consent or opt out where required.

5. Abuse Monitoring, Blacklists, and Automated Decisions

HYTHOST may use automated and manual tools to detect fraud, compromised services, spam, SMTP abuse, malware, phishing, botnets, DDoS participation, intrusion attempts, public blacklist or RBL listings, reputation incidents, and other violations of our Terms of Service.

If an individual IP address assigned to your service is confirmed as listed on a public blacklist or if an abuse report is credible, we may open a support ticket that includes the affected IP address, listing or report source, lookup link, related service, evidence available to us, and the response deadline. For ordinary blacklist listings, the Terms of Service normally provide 12 hours to respond and remediate. If no client reply is detected after the deadline and the IP address remains listed, automated systems may suspend the related service through our billing or service management system. Severe, repeated, ongoing, legal-risk, upstream-requested, or infrastructure-risk cases may lead to immediate suspension, quarantine, filtering, or restriction.

Where a suspension or restriction is triggered by automated monitoring without human involvement, you have the right not to be subject to a decision based solely on automated processing where applicable law grants that right: you can always obtain human intervention, express your point of view, and contest the decision by replying to the support ticket or contacting support with context, evidence, or a remediation plan. Abuse tickets are reviewed by staff.

6. Cookies, Analytics, and Advertising Measurement

Our website and client area use cookies, session identifiers, security tokens, and similar technologies. They fall into two groups, described in detail in the Cookie Policy:

  • strictly necessary technologies, used to keep users logged in, protect forms and checkout, remember preferences, detect abuse, and operate the client area — including technologies used by WHMCS, Cloudflare (including Turnstile bot protection), and the live chat where enabled. These do not require consent;
  • measurement technologies, used only with your consent: Google Analytics 4 (website usage statistics), Google Ads conversion measurement (which purchases resulted from an ad, including a first-party cookie storing the ad click identifier), and Microsoft Clarity session analytics where enabled.

When you first visit, a cookie banner asks whether you allow measurement technologies. Nothing in the measurement group is activated before you choose, and Google tags operate in consent-denied mode (no cookies, no persistent identifiers) unless you accept. You can change or withdraw your choice at any time using the "Cookie preferences" link in the website footer. If you decline, Google may still receive short-lived, cookieless technical pings that carry no persistent identifier, which Google uses for aggregate statistical modeling.

Server logs may record IP address, browser information, requested URL, referrer, date and time, and security-related events. We also keep a first-party record of page interactions (such as button clicks) on our own infrastructure, tied to a random session identifier (the hh_sid cookie, 365 days). Alongside each interaction that record stores your IP address, browser user agent, referring page and, where present, the advertising click identifier — we use it to tell real visitors from bots, to understand where orders come from, and to debug the order process. It is never shared with advertising platforms and is kept for 90 days (Section 9).

7. Recipients and Processors

We may share personal data only where necessary for the purposes described in this Policy, including with:

  • payment processors, banks, fraud prevention providers, and accounting providers, including Skrill, Paynet, and PayPal where you choose or use those payment methods;
  • datacenters, upstream network providers, anti-DDoS providers, IP reputation providers, and infrastructure providers;
  • domain registrars, registries, SSL certificate authorities, software vendors, license providers, and control panel providers;
  • email delivery providers, including Amazon Web Services (Amazon SES) for transactional email such as invoices, notifications, and support replies;
  • live chat and support tooling — our live chat runs on Chatwoot software operated on our own infrastructure; Discord, Inc. where you contact us through Discord; and Cloudflare, Inc. for content delivery, security, and Turnstile bot protection;
  • measurement providers, only with your consent: Google Ireland Ltd / Google LLC (Google Analytics 4, Google Ads) and Microsoft Corporation (Clarity) where enabled;
  • professional advisers, auditors, insurers, and legal representatives;
  • public authorities, courts, regulators, law enforcement, or other parties where required by law or where necessary to protect rights, safety, security, infrastructure, or third parties.

We require service providers that process personal data on our behalf to use appropriate security and confidentiality measures, to act under a data processing agreement where required, and to process data only for authorized purposes. Game servers and their control panel run on infrastructure operated by HYTHOST itself.

8. International Transfers

Services may involve providers, infrastructure, registries, software vendors, payment processors, support tools, community platforms, anti-abuse tools, or clients located in the Republic of Moldova, the European Economic Area, the United States, or other countries.

Where personal data is transferred to a country that does not provide an adequate level of data protection, we rely on appropriate safeguards required by applicable law, in particular the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) or equivalent contractual safeguards. For providers in the United States that are certified under the EU-U.S. Data Privacy Framework (including Google, Microsoft, Amazon Web Services, and Cloudflare), transfers that originate in the European Economic Area may also rely on that framework; transfers originating in the Republic of Moldova rely on the safeguards required by Law No. 195/2024. You can request more information about the safeguard applied to a specific transfer through the contact channels in Section 1.

Domain registrations, SSL certificates, abuse handling, payments, security investigations, and infrastructure operations may require data to be shared with providers or authorities outside your country, depending on the service and the incident.

9. Retention

We keep personal data only for as long as necessary for the purposes described in this Policy. The following periods normally apply:

  • client service content (server files, databases, game world data): deleted at the moment the service is terminated, immediately and irreversibly, as described in the Terms of Service Section 8.4;
  • cookie consent choice: 180 days, after which the banner asks again;
  • provisioning and module logs of our billing system: 30 days;
  • the first-party interaction record described in Section 6 (session identifier, IP address, user agent, referring page, advertising click identifier): 90 days, then deleted automatically;
  • invoices, billing, contract, and accounting records: kept for the retention period required by the accounting and tax law of the Republic of Moldova; we cannot delete these earlier, including on request;
  • account and contact data: kept while the client account exists, and afterwards only as long as needed to handle disputes, chargebacks, tax obligations and legal claims;
  • support tickets and chat transcripts: a ticket is closed automatically after 5 days without activity (you can always reply to reopen it), and the correspondence is kept while it may still be needed to support the service relationship or to defend a claim;
  • abuse reports, security incidents, and suspension history: kept as long as needed to prevent repeated abuse, document our decisions, and defend legal claims;
  • technical and access logs: kept for as short a time as our infrastructure requires, and longer only for a specific ongoing security, fraud, billing, or legal matter.

Where no legal obligation requires us to keep a record, you can ask us to delete it and we will do so — see Section 11. For the categories above where we state a criterion rather than a fixed number of months, the criterion is the applicable limitation period for claims and the duration of the purpose described.

Where an investigation, dispute, or legal obligation requires it, specific records may be kept longer, limited to what is necessary for that purpose.

10. Security and Data Breach Notification

We use technical and organizational measures intended to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, and other unlawful processing. These measures may include access controls, authentication controls, logging, monitoring, network protection, staff confidentiality, backups, and security review processes.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will inform affected individuals without undue delay where the breach is likely to result in a high risk to them, as required by applicable law.

No online service can be guaranteed completely secure. You are responsible for securing your own services, applications, accounts, passwords, keys, scripts, plugins, servers, and backups.

11. Your Rights

Subject to applicable law and any legal limitations, you have the right to request access to your personal data, correction of inaccurate data, deletion of data, restriction of processing, objection to processing, data portability, withdrawal of consent where processing is based on consent, and information about processing activities.

You can exercise account access and correction rights through the client area where available. For other requests, contact us through the client-area support ticket system or by email at [email protected]. We may need to verify your identity before responding. We respond to requests without undue delay and at the latest within one month; this period may be extended by up to two further months for complex or numerous requests, in which case we will tell you why.

Some requests may be limited or refused where we must retain data for billing, tax, accounting, legal, security, abuse prevention, dispute resolution, service operation, or legitimate-interest reasons; where that happens, we will explain the reason unless the law prevents it.

12. Complaints

If you believe your personal data has been processed unlawfully, you can contact us first so we can review the issue. You also have the right to lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova (CNPDCP, datepersonale.md) or, if you are in the European Union or European Economic Area, with the supervisory authority of your country of residence, place of work, or the place of the alleged infringement.

13. Children's Data

HYTHOST services are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact support so we can review and take appropriate action.

14. Third-Party Websites and Services

Our website or services may link to third-party websites, control panels, payment pages, community platforms, registrars, software providers, or other external services. Their privacy practices are governed by their own privacy policies, not this Privacy Policy.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect service changes, legal changes, security practices, or operational changes. The latest version will be published on this page. For material changes we will give reasonable advance notice by email, client-area notification, or a clear notice on this page. Continued use of our website or services after an update means the updated Policy applies from the date shown above.

16. Legal Framework Note

This Policy is designed to meet the requirements of the data protection laws applicable to HYTHOST: Law No. 195/2024 of the Republic of Moldova on personal data protection, in force as of August 23, 2026, which transposes the principles of the EU General Data Protection Regulation (GDPR), and the GDPR itself to the extent it applies to our processing of data of individuals in the European Union or European Economic Area.

Something unclear in this document? Open a ticket from your client area or write to [email protected] and a person will answer — we would rather explain a clause than have you guess at it.

Products

  • Game Hosting
  • VPS Hosting
  • Web Hosting
  • Dedicated
  • Colocation
  • View All

Support

  • Guides
  • Open Ticket
  • Live Chat
  • Discord
  • Knowledge Base

Company

  • About Us
  • Partners
  • Affiliates
  • Contact Us

Account

  • Client Area
  • Login
  • Register

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • SLA
  • DPA
  • Cookie preferences
HytHost

Reliable hosting from Chișinău, Moldova — game servers, VPS, dedicated servers and domains, backed by real infrastructure and human support.

Operated by OKLAKO S.R.L. Chișinău, Republic of Moldova Email: [email protected]
Voxility DDoS protection
Built for game hosting
99.9% Uptime SLA
Datacenter in Chișinău
Payment methods
  • Visa / Mastercard
  • PayPal
  • Google Pay
  • Apple Pay
  • Skrill
  • paysafecard
  • Neteller
© 2026 HytHost. All rights reserved.
Network & Infrastructure Monitored
  • العربية
  • Azerbaijani
  • Català
  • 中文
  • Hrvatski
  • Čeština
  • Dansk
  • Nederlands
  • English
  • Estonian
  • Persian
  • Français
  • Deutsch
  • עברית
  • Magyar
  • Italiano
  • Macedonian
  • Norwegian
  • Português
  • Português
  • Română
  • Русский
  • Español
  • Svenska
  • Türkçe
  • Українська

Loading...
Loading...
Choose language
العربية
Azerbaijani
Català
中文
Hrvatski
Čeština
Dansk
Nederlands
English
Estonian
Persian
Français
Deutsch
עברית
Magyar
Italiano
Macedonian
Norwegian
Português
Português
Română
Русский
Español
Svenska
Türkçe
Українська

Generate Password

Please enter a number between 8 and 64 for the password length

We use strictly necessary cookies to run the site, and analytics and advertising measurement only if you allow it. Read the Cookie Policy