Hosted in the Netherlands · GDPR-aligned · Free migration from your current host
Legal

Privacy Policy

1. Who we are & our role

Maxinodes (“we”, “us”, “our”) is Maxinodes Ltd, a private company limited by shares, registered in Ireland, with its registered office at 1 Ballycoolin Road, Dublin 15, Ireland.

This Privacy Policy explains how we handle personal data relating to our customers, the individuals who use our customers’ accounts, prospective customers, and visitors to our website. It also covers anyone else who writes to us — for example to report abuse — and people who are named in a report or in evidence someone else sends us, whose data therefore reaches us from a third party rather than from them. In this policy, Customer (“you”, “your”) means the person or entity that orders the Services we provide.

Your role and ours depend on the data in question:

  • We are the controller of the personal data we collect to run our business and our relationship with you — in particular account data, billing data, support and contact-form data, Status-Page subscription data, and the operational logs generated by our systems and by the providers that serve our websites on our behalf. As controller, we decide why and how that data is processed, and this Privacy Policy governs it.
  • We are a processor of the Content (also called Customer Data) that you store on, or transmit through, the Services. We process that Content only on your documented instructions, in order to provide the Services. Where you are a Customer, you are the controller of that Content and you remain responsible for the personal data it contains. That processing is governed by our Data Processing Agreement (DPA), not by this policy.

If you have any question about this policy or about how we handle your personal data, contact our privacy team at privacy@maxinodes.com. Support is available in English and Russian every day.

2. The data we collect, by source

We collect the following categories of personal data, grouped by where it comes from. We keep collection to what we genuinely need.

Account data

When you create an account or place an Order through the Client Area at my.maxinodes.com, we collect your name, the name of the organisation you represent (where applicable), your email address, postal address, telephone number, account login credentials (passwords are stored only in hashed form), and your settings and preferences. This data identifies you, secures your account and lets us communicate with you about the Services.

Billing data

To take payment and meet our accounting obligations we collect your billing name and address, the plan you have purchased, your invoices, payment records and transaction history. We do not receive or store payment-instrument data. Payments are taken on a hosted page operated by our payment provider, which collects whatever it needs to complete the payment directly from you, under its own privacy policy. We receive confirmation of payment and the reference needed to reconcile it against your invoice.

Domain registration data

If you register, transfer or renew a domain through us, we collect the registrant, administrative, technical and billing contact details for that domain — name, organisation, postal address, email address and telephone number — and pass them to our registrar channel, which submits them to the registry that operates your domain extension, to a data-escrow agent and, for generic extensions, to ICANN. Some of those recipients are outside the EEA. Parts of this data may be published or disclosed through WHOIS and RDAP. Those onward steps happen under ICANN and registry rules that apply to every domain registration whoever you buy it from; they are not within our control, and we cannot apply our own safeguards to them.

Support & helpdesk data

You can reach us through our Help Centre at support.maxinodes.com, through the chat widget on our website and in the Client Area, by email to one of our role inboxes, or through our contact form. Whichever you use, we collect the contents of your message, your contact details, any files you attach, and any account or technical information you share, so that we can investigate and respond. We also keep a record of our correspondence with you. The Client Area no longer has a ticket function — requests that used to be raised there are now raised in the Help Centre. On our website and in the Client Area the chat widget loads only after you opt in to the functional category in our cookie banner; see our Cookie Policy.

All of this correspondence is handled on a helpdesk platform operated by Zendesk, Inc., a Delaware corporation established in the United States, which stores your message, your contact details and our correspondence history on our behalf. The data we hold there currently sits in Zendesk’s Europe (Ireland) region, but Zendesk has given us no commitment to keep it there and may move account data between its regions. Personal data in support correspondence reaches the United States in any event, because Zendesk administers the service from there and uses its own providers there. So support correspondence is processed outside the EEA — that is not a possibility we are hedging against, it is how the service works. The safeguards are those in Zendesk’s published data processing agreement: Binding Corporate Rules approved by the Irish Data Protection Commission, and the European Commission’s Standard Contractual Clauses. Zendesk, Inc. is additionally certified under the EU–US Data Privacy Framework. Our account is on Zendesk’s published online terms; we have not negotiated separate terms with it. Section 6 explains what this means for transfers, and our Subprocessors page gives the detail.

This is a different question from where your hosted data lives. Your websites, databases and files are served directly from our own servers in the Netherlands. They are not sent to our helpdesk provider and they do not pass through our content-delivery edge. Only what you actually write to us — and anything you choose to paste or attach — goes to the helpdesk.

This applies to privacy and abuse correspondence as well. privacy@maxinodes.com and abuse@maxinodes.com are forwarding addresses rather than mailboxes: mail sent to them is delivered through our Microsoft 365 tenant in the EU and then into the same helpdesk platform. So a request to exercise your data-protection rights, any identity evidence attached to it, and an abuse report together with its logs, message headers and screenshots, are all received and held by Zendesk, Inc. in exactly the same way as an ordinary support message — in the same region, reachable from the United States in the same way — and the sender becomes a contact record there. We would rather tell you that than let you assume otherwise. If you would prefer your correspondence not to pass through a third-party helpdesk, write to us by post at Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland, or email billing@maxinodes.com, which is the one role address that reaches us directly, and ask us to handle your request off the helpdesk.

Please do not send us sensitive information through these channels. Support messages, chat conversations, contact-form enquiries and everything attached to them are stored on a third-party helpdesk platform outside the EEA. Do not send us passwords, API keys, payment-card numbers, copies of identity documents, or special categories of personal data such as health information — whether they are yours or someone else’s. We will never ask you for your Client Area password. If you need to give us something of that kind, tell us first and we will agree a safer route; you can also write to us by post at the address in our company information.

Contact-form data

If you submit our website contact form, we collect the name, email address and message you provide, the topic you select and the language version of the page you are on, so that we can reply to your enquiry. We also record automatically the IP address the submission came from and your browser’s user-agent string, to detect and block automated and abusive submissions. The submission is created as a ticket in our helpdesk (Zendesk, Inc., United States), where your name and email address are stored as a contact record.

Advertising-measurement data (only with your consent)

If — and only if — you opt in to the Marketing category in our cookie banner, we load the Meta pixel and share with Meta Platforms Ireland Ltd the fact that you visited or converted, your IP address, browser details, the pages you viewed, the _fbp/_fbc identifiers, and — where you have given it to us, for example by submitting the contact form — a hashed (scrambled) form of your email address. We send the same events from our own server as well as from your browser; the information is the same either way. If you do not opt in, none of this is collected or sent. See our Cookie Policy for the full detail.

Status-Page subscription data

If you choose to subscribe to incident notifications from our Status Page at status.maxinodes.com, we collect the email address (or other contact endpoint) you provide so that we can send you the updates you asked for. You can unsubscribe at any time. The Status Page is not run on our own servers: it is hosted by our monitoring provider, which is where the subscription itself and the address you give are stored.

Server & operational logs

When you and your end users access the Services and our website, our systems automatically generate operational records such as IP addresses, timestamps, request and error logs, authentication and access logs, and performance and security metrics. We use these to operate, secure, troubleshoot and plan the capacity of the platform.

Edge / content-delivery request logs

Requests to our website and Client Area pass through a global content-delivery and security network operated by Microsoft. For each request it records the client IP address and port, the country derived from it, the requested URL, the referring page, the browser user-agent string, the TLS version and a TLS/device fingerprint. Collection happens at whichever Microsoft edge location serves the request, which may be outside the EEA; the records are written to a Microsoft log workspace in the EU (West Europe) and retained for 30 days. This applies to our own websites and the Client Area. The websites we host for you are not behind that network at all — they are served straight from our servers in the Netherlands, and requests to them generate no edge log.

3. Why we use your data & our legal bases

We process personal data only where we have a lawful basis to do so under Article 6 of the General Data Protection Regulation (GDPR). The table below sets out, for each purpose, an example and the legal basis we rely on. Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms.

Purpose Example Legal basis (GDPR Art. 6)
Providing the Services & managing your account Provisioning your Self-Managed or Managed plan, authenticating logins, applying your settings, and giving you access to the Client Area. Performance of a contract (Art. 6(1)(b)) — processing necessary to deliver the Services you ordered.
Billing, payments & renewals Issuing invoices, taking payment through our payment provider, processing renewals, credits and refunds. Performance of a contract (Art. 6(1)(b)).
Keeping tax & accounting records Retaining invoices and financial records for the period required by Irish law. Legal obligation (Art. 6(1)(c)).
Providing support & responding to enquiries Handling support tickets, answering contact-form messages, and keeping a record of our correspondence. Performance of a contract (Art. 6(1)(b)) for account-related support; legitimate interests (Art. 6(1)(f)) for general or pre-sales enquiries — our interest in responding to and assisting the people who contact us.
Detecting & blocking automated and abusive form submissions Recording the IP address and browser user-agent string a contact-form submission came from, and applying a rate limit, so that automated submissions can be identified and refused. Legitimate interests (Art. 6(1)(f)) — our interest in keeping our contact channels usable and free of automated abuse. We began doing this after a flood of automated submissions in August 2026.
Securing the platform & preventing fraud and abuse Monitoring for intrusions and abuse, investigating reports to abuse@maxinodes.com, maintaining access and security logs, and detecting fraudulent payments. Legitimate interests (Art. 6(1)(f)) — our interest in keeping the Services, our customers and our infrastructure secure and free from fraud and abuse. Where applicable we also rely on legal obligation (Art. 6(1)(c)).
Capacity planning & improving the Services Analysing aggregate performance and usage metrics to plan capacity and improve reliability. Legitimate interests (Art. 6(1)(f)) — our interest in operating a reliable, well-sized platform.
Service communications Sending essential notices about your account, security, billing, maintenance and Status-Page incidents you subscribed to. Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — our interest in keeping you informed about the Services you use.
Marketing Sending optional newsletters or product news where you have asked to receive them. Consent (Art. 6(1)(a)). You can withdraw your consent at any time, with no effect on the Services.
Establishing, exercising or defending legal claims Retaining limited records where needed to resolve a dispute or enforce our terms. Legitimate interests (Art. 6(1)(f)) — our interest in protecting our legal rights.

We do not carry out automated decision-making that produces legal or similarly significant effects on you, and we do not engage in profiling for those purposes.

Our website and the Client Area sit behind a content-delivery and security edge. It absorbs distributed denial-of-service traffic, applies an IP blocklist and a per-IP rate limit, and blocks matching requests automatically. It is not an application firewall with a managed rule set, and we will not describe it as one — the substantive request filtering is done by our own servers behind it. If you believe a request of yours has been blocked in error, contact support and we will look at it.

4. Resold Email

Where you purchase Resold Email through us — Microsoft 365 or Google Workspace mailboxes — those mailboxes and their contents live in your own tenant with Microsoft or Google. We act only as a reseller: we set up and bill the subscription. We are not the processor of your email content, that content does not sit on Maxinodes infrastructure, and it is not covered by our SLA or by our EU-only backup commitment.

The handling of your mailbox data is governed by the privacy notice, data processing agreement and service terms of the provider you choose (Microsoft or Google), and you contract with that provider for the email service through us. We process only the account and billing data needed to provision and invoice the subscription, as described in sections 2 and 3 above.

5. Sharing & subprocessors

We do not sell your personal data. Apart from the advertising measurement described below — which runs only if you opt in, and which you can switch off at any time — we do not share your personal data for anyone else’s marketing. We share personal data only where it is necessary to provide the Services, comply with the law, or protect our rights:

  • Subprocessors. We use a small number of providers to help us deliver the Services, and we name every one of them. As at the date of this policy they are Worldstream (Netherlands) for our servers, network and data centre; Microsoft for the content-delivery and security edge in front of our own websites and the Client Area, for the DNS of our own domains, and for our own mail platform; BunnyWay d.o.o. (Slovenia) for the authoritative DNS of customer domains; Zendesk, Inc. (United States) for our helpdesk, chat, Help Centre and role-inbox mail; Backblaze, Inc. for encrypted off-site backup storage in Amsterdam; Postmark (United States) for transactional email from the Client Area; Key-Systems GmbH (Germany) for domain registration; and UptimeRobot s. r. o. (Slovakia) for monitoring and the Status Page. Each is engaged under written terms — in most cases the provider’s own published data-processing terms — requiring appropriate security and confidentiality. Our Subprocessors page sets out, for each of them, what it does, where it processes data, which Services it applies to and, where it is outside the EEA, the transfer safeguard relied on; our DPA governs subprocessing of Content.
  • Our payment provider — not acting on our instructions. Where you pay an invoice in cryptocurrency, the payment is taken on a page hosted by NOWPayments. We send it only the amount, the currency and the invoice number; everything else — your IP address, device and browser details, and your wallet and transaction data — it collects from you directly, on its own page and under its own privacy policy. It does that for its own purposes rather than on our instructions, so it is not our subprocessor. Its country of establishment is not covered by an EU adequacy decision and it offers no Standard Contractual Clauses; our Subprocessors page says so plainly so that you know before you start a payment.
  • Meta (advertising measurement) — only with your consent. Where you opt in to the Marketing category, we and Meta Platforms Ireland Ltd act as joint controllers for the collection and transmission of the measurement data described in section 2. That means Meta does not merely act on our instructions: it also uses that data for its own purposes under its own Data Policy, over which we have no control. Meta is therefore not a subprocessor and does not appear on our Subprocessors page. You can withdraw consent at any time using the Cookie settings button at the top of our Cookie Policy, which stops any further data being sent. The joint arrangement covers only the collection of that data on our site and its transmission to Meta; what Meta does with it afterwards is Meta’s own processing, which we neither control nor describe here. Because we are joint controllers, Article 26(3) lets you exercise your rights against either of us: write to privacy@maxinodes.com and we will deal with what is ours and pass on what is not, or go to Meta directly.
  • Professional advisers and authorities. We may disclose data to our accountants, auditors or legal advisers, or to a public authority, court or regulator, where we are legally required to do so or where it is necessary to establish, exercise or defend legal claims.
  • Business transfers. If our business is reorganised, merged or sold, personal data may be transferred as part of that transaction, subject to the protections of this policy and applicable law. We will inform you of any such change that materially affects how your personal data is handled.

6. Where your data is stored & international transfers

What stays in the EU/EEA

The hosting platform itself is in Europe and has not moved. The websites, databases, files and mailboxes you host with us are stored and served from enterprise data centres in the Netherlands. Requests to a site you host with us go straight to those servers — they do not pass through the edge network described below, and no third party terminates the connection on the way. The authoritative DNS for customer domains is operated by a provider established in the EU, behind our own ns1/ns2.maxinodes.com nameservers; because DNS is answered from a worldwide anycast network, a lookup arriving from a resolver outside the EEA is answered outside the EEA, and those lookups come from recursive resolvers rather than from identifiable visitors.

Our backups are stored in Amsterdam, in the EU. They are encrypted on our own hardware before they are uploaded and the key never leaves it, so the storage provider holds data it has no means to read. It can see the backup metadata — object names, sizes and timestamps — and it is a US-incorporated company, so we treat that metadata as transferred and rely on the safeguards in the table below. It cannot read the contents.

What is transferred outside the EU/EEA

Three things we need in order to run the Services do involve a transfer, and we would rather set them out plainly than bury them.

Support. Our helpdesk is Zendesk, Inc., a Delaware corporation in the United States. Everything you send us through a support ticket, through live chat, through the contact form, or by email to support@, privacy@ or abuse@maxinodes.com is held on its platform, together with our replies and the record of the correspondence. Email to those addresses reaches our own Microsoft 365 mailboxes in the EU first and is then forwarded on to Zendesk, so there are two steps rather than one. Zendesk currently holds that data in its Europe (Ireland) region, but we have not bought the option that would turn that placement into a contractual commitment, and Zendesk reserves the right to move account data between regions. Personal data also reaches the United States through Zendesk’s own operations and through the US providers it uses to run its platform. We therefore treat everything sent to our support channels as transferred to the United States, and we rely on the safeguards below rather than on where the data happens to sit today.

The edge in front of our own websites. Our marketing site, our Client Area at my.maxinodes.com and our statistics dashboard are served through Microsoft Azure Front Door. It terminates the TLS connection, caches our public marketing pages, and screens incoming requests. In doing so it processes the visitor’s IP address, browser user-agent, the URL requested and the technical details of the request. Front Door is a global network: your request is handled at whichever Microsoft point of presence is nearest to you, which for a visitor outside Europe means outside the EEA, and Microsoft excludes this service from its EU Data Boundary commitment. Our own copy of the resulting logs is kept in Microsoft’s West Europe region for 30 days. Two limits are worth stating: sites you host with us are not behind Front Door at all, and Client Area pages are not cached at the edge. Front Door sets no cookies — see our Cookie Policy.

Transactional email. The automated messages our billing system sends you — invoices, order confirmations and password resets — are delivered through Postmark, a transactional email service established in the United States that offers no EU data-residency option. It receives your name, your email address, the invoice or order reference and the contents of the message. This is transactional mail only: not support correspondence, not marketing, and not the mailboxes we resell.

The safeguards we rely on

Recipient What it receives Transfer mechanism
Zendesk, Inc. (United States) Support tickets, live chat, Help Centre activity, contact-form enquiries, and mail sent to our support@, privacy@ and abuse@ addresses. The safeguards are those in Zendesk’s published data processing agreement: Binding Corporate Rules approved by the Irish Data Protection Commission, and the European Commission’s Standard Contractual Clauses. Zendesk, Inc. is additionally certified under the EU–US Data Privacy Framework. Our account is on Zendesk’s published online terms; we have not negotiated separate terms with it.
Microsoft (global edge network) IP address, user-agent, requested URL and request metadata for visits to our own websites and the Client Area, in edge access and filtering logs. Microsoft’s Products and Services Data Protection Addendum, which applies the European Commission’s 2021 Standard Contractual Clauses to transfers of customer data out of the EEA within the Microsoft group, including to Microsoft Corporation in the United States. Microsoft Corporation is also certified under the EU–US Data Privacy Framework.
Postmark (United States) Your name, your email address, the invoice or order reference and the contents of the automated account emails our billing system sends you. Postmark’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses. ActiveCampaign, the group it belongs to, is additionally certified under the EU–US Data Privacy Framework.
Backblaze, Inc. (United States; storage in Amsterdam) Backup objects we have already encrypted, and the metadata about them. It has no means to read the contents. Backblaze’s data processing agreement for EEA residents, which incorporates the European Commission’s Standard Contractual Clauses.

The Subprocessors page lists every provider we use, where each one processes data, and the mechanism relied on for each. Each mechanism above is published by the provider at the link given; if you would like us to walk you through what applies to your own data, email privacy@maxinodes.com.

Two further flows sit outside that table. Domain registration (section 2): our registrar channel is established in the EEA, but registrant data is passed onward to the registry that runs your domain extension, to a data-escrow agent and, for generic extensions, to ICANN — some of them outside the EEA, under ICANN and registry rules rather than under our contract. We cannot apply our own safeguards to those steps, and we say so rather than implying otherwise. Cryptocurrency payments (section 5): our payment provider is established outside the EEA, is not covered by an adequacy decision, and offers no Standard Contractual Clauses; it collects your data directly on its own hosted page, as its own controller.

The optional advertising measurement in section 2 is different again: if you opt in to the Marketing category, Meta may transfer the resulting data to the United States and other countries outside the EU/EEA under its own transfer mechanisms, including the EU–US Data Privacy Framework and Standard Contractual Clauses. The adequacy of that framework has been challenged and remains the subject of litigation before the EU courts. Advertising measurement is the only processing on this site that depends on your consent, and declining the Marketing category stops it completely. Edge delivery and our helpdesk also involve processing outside the EEA, but they are not consent-dependent, because they are necessary to serve this site and to answer support requests; the recipients and safeguards are set out above and in section 5.

There is one nuance to be aware of in relation to Resold Email (section 4). Because those mailboxes live in your own Microsoft 365 or Google Workspace tenant rather than on our infrastructure, the storage location and any international transfer of that mailbox data are determined by your chosen provider under its own arrangements (for example its Standard Contractual Clauses or adequacy mechanisms). For that email content, the provider — not Maxinodes — is the relevant party for transfers, and that data sits outside our EU-only backup commitment.

7. How long we keep it

We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it. Our standard retention periods are:

Category Retention period
Server & operational logs (on our own servers) Approximately 90 days, after which they are deleted or aggregated, unless a specific log is retained longer to investigate a security incident or to establish, exercise or defend a legal claim.
Edge / content-delivery request logs 30 days, in a log workspace located in the EU (West Europe), after which they are deleted automatically.
Tax & accounting records (including invoices) Approximately 6 years, as required by Irish tax and company law.
Account data For the life of your account, plus the tax-retention period above for any records that also form part of our accounting and tax records. Other account data is deleted or anonymised once it is no longer needed after closure.
Support, helpdesk & contact-form data (customers) For the duration of your relationship with us and a reasonable period afterwards to handle follow-up queries and disputes, after which it is deleted. This correspondence is held on our third-party helpdesk platform.
Enquiries from people who are not customers Deleted within 12 months of the last message, unless a dispute or investigation is live. This correspondence is also held on our third-party helpdesk platform.
Status-Page subscription data Until you unsubscribe or the subscription is no longer active. The subscription record is held by our monitoring provider.
Domain registration contact data For as long as the domain is registered through us, and afterwards for the period the registry, the data-escrow arrangement or ICANN rules require. Those periods are set by the registry, not by us.

The Content you host with us is retained and deleted in accordance with your instructions and our DPA and Terms of Service, not under the periods above.

8. Your rights

Under the GDPR and Irish data-protection law you have the following rights in relation to your personal data:

  • Access — to obtain confirmation that we process your personal data and a copy of it.
  • Rectification — to have inaccurate personal data corrected and incomplete data completed.
  • Erasure — to have your personal data deleted where there is no overriding reason for us to keep it (for example our legal retention obligations).
  • Restriction — to ask us to limit how we use your personal data in certain circumstances.
  • Portability — to receive the personal data you provided to us, where processing is based on consent or contract and carried out by automated means, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection — to object to processing carried out on the basis of our legitimate interests (see the table in section 3). Where you object, we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You can object to direct marketing at any time, and we will stop.
  • Withdrawing consent — where we rely on your consent (for example marketing), you can withdraw it at any time. This does not affect the lawfulness of processing carried out before you withdrew it.

To exercise any of these rights, email privacy@maxinodes.com. We may need to verify your identity before acting on a request. We will respond within one month of receiving your request; where a request is complex or you have made several, we may extend this by up to two further months and will tell you if we do. Exercising these rights is normally free of charge.

If you are not satisfied with how we have handled your personal data or a request, you have the right to lodge a complaint with the supervisory authority — in Ireland, the Data Protection Commission. Full details are in the Contact section below.

9. How we protect your data

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and disclosure. We make no certification claims of any kind. These measures include:

  • Encryption of data in transit using current TLS, on our website, in the Client Area and on the hosting platform;
  • Customer Data for the hosting Services stored on our own servers in the Netherlands, and our backups stored within the EU/EEA, encrypted on our own infrastructure before they leave it with the key held only on our own hardware;
  • An honest statement of the limit of that: the disks in our servers are not themselves encrypted, so live data at rest is protected by logical isolation, filesystem permissions and access control rather than by full-disk encryption;
  • Account passwords stored as salted one-way hashes and never in plain text;
  • Access controls and the principle of least privilege, so staff can access only the data they need for their role, with administrative access to our servers by SSH key only and password authentication disabled for administrator logins;
  • Two-factor authentication on the administrative interfaces of our virtualisation host and our hosting platform, and available to you on your Client Area account;
  • Firewalling on the virtualisation host and on each individual virtual machine, brute-force protection, and automated screening of requests to our website and the Client Area at our content-delivery edge, which may block a request on the basis of its source IP address or rate;
  • Monitoring and logging of access and of platform activity to detect and respond to suspicious events.

No method of transmission or storage is completely secure, but we work to keep our measures appropriate to the risks involved. You are responsible for keeping your account credentials confidential and for the security choices you make within your own services.

10. Cookies

Our website and the Client Area use a limited set of cookies and similar technologies. How we use them, and the choices available to you, are described in our Cookie Policy. The cookie banner is where you accept or decline the functional and marketing categories, and the choice you make on any of our sites applies to all of them.

Our Help Centre at support.maxinodes.com is a different case, and we would rather be straight about it. Although it is on our own domain, the site is operated for us by our helpdesk provider, Zendesk, Inc., and pages there set cookies and store data on your device under that provider’s own arrangements — including by Cloudflare, Inc., which Zendesk uses to serve and protect the site. That site now carries a consent banner of its own, and it records the same choice as the banner on our website and in the Client Area, so one decision covers all three. What it can act on there is narrower, and it says so itself. It holds the chat widget back until you allow live chat — until then the widget is told to store nothing on your device and is kept hidden — and it deletes Meta’s _fbp and _fbc identifiers if you decline marketing. It cannot reach what the platform sets for itself: Zendesk’s Help Centre session cookie, Zendesk’s own measurement of that site, and Cloudflare’s bot-protection cookies all load with the page, before any of our code runs. For those, your browser settings are the control — and you do not need to visit the Help Centre to reach us at all: the addresses in the Contact section below work just as well.

11. Children

The Services are intended for businesses and for adults, and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@maxinodes.com and we will take appropriate steps to delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our Services or the law. When we do, we will revise the version and date at the top of the page. The version in force is always the one published at this URL. Where a change is material, we will take reasonable steps to notify you — for example by email or a notice in the Client Area — before it takes effect. For a map of our other legal documents, see the legal hub.

What changed in this version. This version was published on August 7, 2026 to record four infrastructure changes and the transfers that follow from them: authoritative DNS for customer domains moved to an EU provider on July 26, 2026; our own websites and the Client Area were placed behind Microsoft’s global edge network and our corporate DNS moved to Azure DNS on August 4, 2026; and support moved from our own self-hosted helpdesk to Zendesk, Inc. in the United States on August 6, 2026. Customer websites were not affected by any of them and are still served directly from our servers in the Netherlands. The full record is in the change history on our Subprocessors page.

Contact

Privacy and data-protection enquiries: privacy@maxinodes.com.

By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.

Mail sent to that address reaches our own Microsoft 365 tenant in the EU and is then forwarded into our helpdesk platform, operated by Zendesk, Inc., a Delaware corporation established in the United States. Your message, anything attached to it and our correspondence about it are stored there. Our account data is currently held in its Europe (Ireland) region, but we have no contractual commitment to that region, and the provider and its named United States sub-processors can reach that data from the United States — so it is processed outside the EEA. If you would rather your message did not pass through a third-party helpdesk — for example because it includes identity documents, or because it names someone else — write to us by post at the address above, or email billing@maxinodes.com, which reaches us directly.

If you have a concern about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the supervisory authority in Ireland:

Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie

You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence.