Privacy Policy
The short version
- We are an Irish company. Maxinodes Ltd is the controller of your account, billing and website-visitor data, and a processor of the Content you host with us (that processing is governed by our Data Processing Agreement).
- Your hosted data stays in Europe. Your websites, databases, mailboxes and our backups are held within the EU/EEA, with primary infrastructure in the Netherlands — but our helpdesk provider, the edge network that fronts our own websites and the relay that delivers email sent from our hosting servers are outside the EEA, and our Subprocessors page names every recipient and the safeguard relied on.
- We do not sell your data. We share it only with the providers needed to run the Services, and we name every one of them.
- We never see your payment details. Payments are taken on a hosted page operated by our payment provider.
- If we wrote to you first. We send a small number of business emails, and LinkedIn messages from our founder’s own profile, to people at companies that might want European hosting, only in countries where that is permitted without prior consent. Your work contact came from a professional database or from your public LinkedIn profile, not from you; every such message says who we are, and a reply saying STOP — or an email to privacy@maxinodes.com — stops it for good. Section 2 (“Business-prospect data”) explains it in full.
- You are in control. You can access, correct, export or delete your personal data, object to certain processing, and withdraw consent. Email privacy@maxinodes.com and we respond within one month.
This summary is for convenience only. The numbered clauses below are the binding agreement.
1. Who we are & our role
Maxinodes (“we”, “us”, “our”) is Maxinodes Ltd, a private company limited by shares, registered in Ireland, with its registered office at 1 Ballycoolin Road, Dublin 15, Ireland.
This Privacy Policy explains how we handle personal data relating to our customers, the individuals who use our customers’ accounts, prospective customers, and visitors to our website. It also covers anyone else who writes to us — for example to report abuse — and people who are named in a report or in evidence someone else sends us, whose data therefore reaches us from a third party rather than from them. It also covers people who exchange email with mailboxes hosted on our servers, to the extent that our mail server records that exchange in its logs (section 2). In this policy, Customer (“you”, “your”) means the person or entity that orders the Services we provide.
Your role and ours depend on the data in question:
- We are the controller of the personal data we collect to run our business and our relationship with you — in particular account data, billing data, support and contact-form data, Status-Page subscription data, and the operational logs generated by our systems and by the providers that serve our websites on our behalf. As controller, we decide why and how that data is processed, and this Privacy Policy governs it.
- We are a processor of the Content (also called Customer Data) that you store on, or transmit through, the Services. We process that Content only on your documented instructions, in order to provide the Services. Where you are a Customer, you are the controller of that Content and you remain responsible for the personal data it contains. That processing is governed by our Data Processing Agreement (DPA), not by this policy.
If you have any question about this policy or about how we handle your personal data, contact our privacy team at privacy@maxinodes.com. Support is available in English and Russian every day.
2. The data we collect, by source
We collect the following categories of personal data, grouped by where it comes from. We keep collection to what we genuinely need.
Account data
When you create an account or place an Order through the Client Area at my.maxinodes.com, we collect your name, the name of the organisation you represent (where applicable), your email address, postal address, telephone number, account login credentials (passwords are stored only in hashed form), and your settings and preferences. This data identifies you, secures your account and lets us communicate with you about the Services.
Billing data
To take payment and meet our accounting obligations we collect your billing name and address, the plan you have purchased, your invoices, payment records and transaction history. We never receive or store your card number or its security code. Payments are taken on a hosted page operated by our payment provider, which collects whatever it needs to complete the payment directly from you, under its own privacy policy. We receive confirmation of payment and the reference needed to reconcile it against your invoice. If you turn on automatic card payment, your card is saved by our payment provider, Whop, not by us. We then also keep Whop’s identifiers for your Whop account and for the saved card; the card’s brand, last four digits and expiry date; a record of each automatic charge and its outcome; and a record of your consent, made up of the exact wording you agreed to, the version of our Terms it refers to, when you agreed, which user of your account agreed, and the IP address and browser used.
Domain registration data
If you register, transfer or renew a domain through us, we collect the registrant, administrative, technical and billing contact details for that domain — name, organisation, postal address, email address and telephone number — and pass them to our registrar channel, which submits them to the registry that operates your domain extension, to a data-escrow agent and, for generic extensions, to ICANN. Some of those recipients are outside the EEA. Parts of this data may be published or disclosed through WHOIS and RDAP. Those onward steps happen under ICANN and registry rules that apply to every domain registration whoever you buy it from; they are not within our control, and we cannot apply our own safeguards to them.
Support & helpdesk data
You can reach us through our Help Centre at support.maxinodes.com, through the chat widget on our website and in the Client Area, by email to one of our role inboxes, or through our contact form. Whichever you use, we collect the contents of your message, your contact details, any files you attach, and any account or technical information you share, so that we can investigate and respond. We also keep a record of our correspondence with you. The Client Area no longer has a ticket function — requests that used to be raised there are now raised in the Help Centre. On our website and in the Client Area the chat widget loads only after you opt in to the functional category in our cookie banner; see our Cookie Policy.
All of this correspondence is handled on a helpdesk platform operated by Zendesk, Inc., a Delaware corporation established in the United States, which stores your message, your contact details and our correspondence history on our behalf. The data we hold there currently sits in Zendesk’s Europe (Ireland) region, but Zendesk has given us no commitment to keep it there and may move account data between its regions. Personal data in support correspondence reaches the United States in any event, because Zendesk administers the service from there and uses its own providers there. So support correspondence is processed outside the EEA — that is not a possibility we are hedging against, it is how the service works. The safeguards are those in Zendesk’s published data processing agreement: Binding Corporate Rules approved by the Irish Data Protection Commission, and the European Commission’s Standard Contractual Clauses. Zendesk, Inc. is additionally certified under the EU–US Data Privacy Framework. Our account is on Zendesk’s published online terms; we have not negotiated separate terms with it. Section 6 explains what this means for transfers, and our Subprocessors page gives the detail.
This is a different question from where your hosted data lives. Your websites, databases, files and mailboxes are held on our servers in the Netherlands, and your websites are served directly from them. They are not sent to our helpdesk provider and they do not pass through our content-delivery edge. Only what you actually write to us — and anything you choose to paste or attach — goes to the helpdesk.
This applies to privacy and abuse correspondence as well. privacy@maxinodes.com and abuse@maxinodes.com are forwarding addresses rather than mailboxes: mail sent to them is delivered through our Microsoft 365 tenant in the EU and then into the same helpdesk platform. So a request to exercise your data-protection rights, any identity evidence attached to it, and an abuse report together with its logs, message headers and screenshots, are all received and held by Zendesk, Inc. in exactly the same way as an ordinary support message — in the same region, reachable from the United States in the same way — and the sender becomes a contact record there. We would rather tell you that than let you assume otherwise. If you would prefer your correspondence not to pass through a third-party helpdesk, write to us by post at Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland, or email billing@maxinodes.com, which is the one role address that reaches us directly, and ask us to handle your request off the helpdesk.
Please do not send us sensitive information through these channels. Support messages, chat conversations, contact-form enquiries and everything attached to them are stored on a third-party helpdesk platform outside the EEA. Do not send us passwords, API keys, payment-card numbers, copies of identity documents, or special categories of personal data such as health information — whether they are yours or someone else’s. We will never ask you for your Client Area password. If you need to give us something of that kind, tell us first and we will agree a safer route; you can also write to us by post at the address in our company information.
Contact-form data
If you submit our website contact form, we collect the name, email address and message you provide, the topic you select and the language version of the page you are on, so that we can reply to your enquiry. We also record automatically the IP address the submission came from and your browser’s user-agent string, to detect and block automated and abusive submissions. The submission is created as a ticket in our helpdesk (Zendesk, Inc., United States), where your name and email address are stored as a contact record.
Business-prospect data
If we write to you before you have ever written to us, it is because we think the company you work for might want European hosting. We did not collect this data from you. We reach business prospects in two ways, and we do it only in countries whose law permits unsolicited electronic messages to businesses without prior consent, never to consumers or sole traders.
By email. We hold your name, your job title, the name and website of your company, its country, your work email address, the message or messages we sent you and any reply you send. This data comes from Explee, a professional contact database compiled from publicly available business sources (company websites, registers and professional profiles), which also writes and sends our outreach emails from its own mailboxes on our instructions; your address itself stays on its platform and is not shown to us unless you reply. There are at most three emails in total, and every one says who we are, gives our postal address and tells you how to stop.
On LinkedIn. We hold your name, your LinkedIn headline and job title, the name, size and website of your company, your location, the address of your public LinkedIn profile, the public LinkedIn activity that brought you to our attention (for example a post you wrote, or a reaction to a post by a hosting company) and the messages exchanged with you. This data comes from Gojiberry, which finds professionals whose public LinkedIn profile and activity match the kind of business we are looking for, and which sends a connection request and our messages from the LinkedIn account of Maxim, our founder, on our instructions. There is one connection request, with no note, and at most two messages after you accept it; if you do not accept, we do not write. Every message says who we are and how to stop, and links to this page. The messages themselves travel through LinkedIn, which handles them under its own terms and privacy policy, as it does for any member.
Because the data did not come from you, this section together with sections 3, 5, 6, 7 and 8 is the information Article 14 of the GDPR requires us to give you no later than our first message.
Website analytics data
On every visit to our website and the Client Area, our self-hosted Matomo analytics records the pages you view, the page that referred you, your browser and device type, and your IP address in anonymised (shortened) form. It sets no cookies, runs on our own servers, is never shared with advertisers, and is used only to see, in aggregate, which pages are useful and where things break. It does not depend on any choice in our cookie banner.
Advertising-measurement data
On every visit to our website and the Client Area, whatever you choose in our cookie banner, we load the Meta pixel and share with Meta Platforms Ireland Ltd the fact that you visited or converted, your IP address, browser details, the pages you viewed and the _fbp/_fbc identifiers. Where you have given them to us, we also send scrambled (hashed) forms of your details: your email address when you submit the contact form, and your email address, name, telephone number, country and customer number when you create a Client Area account or pay an invoice. We send these events from our own server as well as from your browser, so blocking the pixel in your browser does not stop them. See our Cookie Policy for the full detail, and section 8 for your right to object.
Status-Page subscription data
If you choose to subscribe to incident notifications from our Status Page at status.maxinodes.com, we collect the email address (or other contact endpoint) you provide so that we can send you the updates you asked for. You can unsubscribe at any time. The Status Page is not run on our own servers: it is hosted by our monitoring provider, which is where the subscription itself and the address you give are stored.
Server & operational logs
When you and your end users access the Services and our website, our systems automatically generate operational records such as IP addresses, timestamps, request and error logs, authentication and access logs, and performance and security metrics. We use these to operate, secure, troubleshoot and plan the capacity of the platform.
Our mail server also logs the email it handles for the mailboxes and websites on our hosting servers: for each message, the sender and recipient addresses, the subject line, the time, the message identifier, the IP addresses of the servers and devices involved, and whether the message was accepted or refused; and for each mailbox sign-in, the mailbox, the IP address and whether it succeeded. These records concern our customers’ own users and the people who write to them or receive mail from them. We use them to deliver mail, to investigate delivery problems and abuse, and to protect mailboxes from break-ins. They are rotated weekly and kept for about five weeks (section 7).
Edge / content-delivery request logs
Requests to our website and Client Area pass through a global content-delivery and security network operated by Microsoft. For each request it records the client IP address and port, the country derived from it, the requested URL, the referring page, the browser user-agent string, the TLS version and a TLS/device fingerprint. Collection happens at whichever Microsoft edge location serves the request, which may be outside the EEA; the records are written to a Microsoft log workspace in the EU (West Europe) and retained for 30 days. This applies to our own websites and the Client Area. The websites we host for you are not behind that network at all — they are served straight from our servers in the Netherlands, and requests to them generate no edge log.
3. Why we use your data & our legal bases
We process personal data only where we have a lawful basis to do so under Article 6 of the General Data Protection Regulation (GDPR). The table below sets out, for each purpose, an example and the legal basis we rely on. Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms.
| Purpose | Example | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Services & managing your account | Provisioning your Self-Managed or Managed plan, authenticating logins, applying your settings, and giving you access to the Client Area. | Performance of a contract (Art. 6(1)(b)) — processing necessary to deliver the Services you ordered. |
| Billing, payments & renewals | Issuing invoices, taking payment through our payment provider, processing renewals, credits and refunds, and charging your saved card for renewal invoices when you have turned on automatic payment. | Performance of a contract (Art. 6(1)(b)). |
| Keeping tax & accounting records | Retaining invoices and financial records for the period required by Irish law. | Legal obligation (Art. 6(1)(c)). |
| Providing support & responding to enquiries | Handling support tickets, answering contact-form messages, and keeping a record of our correspondence. | Performance of a contract (Art. 6(1)(b)) for account-related support; legitimate interests (Art. 6(1)(f)) for general or pre-sales enquiries — our interest in responding to and assisting the people who contact us. |
| Detecting & blocking automated and abusive form submissions | Recording the IP address and browser user-agent string a contact-form submission came from, and applying a rate limit, so that automated submissions can be identified and refused. | Legitimate interests (Art. 6(1)(f)) — our interest in keeping our contact channels usable and free of automated abuse. We began doing this after a flood of automated submissions in August 2026. |
| Securing the platform & preventing fraud and abuse | Monitoring for intrusions and abuse, investigating reports to abuse@maxinodes.com, maintaining access and security logs, and detecting fraudulent payments. Filtering the email our servers receive and send: checking the IP address of each connecting mail server against blocklists, scoring incoming mail for spam on our own server, and limiting how much mail each domain can send per hour. Every order placed in the Client Area is scored for fraud risk by MaxMind, Inc. before it is accepted; what is sent, and the safeguard for sending it, are in section 6. | Legitimate interests (Art. 6(1)(f)) — our interest in keeping the Services, our customers and our infrastructure secure and free from fraud and abuse. Where applicable we also rely on legal obligation (Art. 6(1)(c)). |
| Capacity planning & improving the Services | Analysing aggregate performance and usage metrics to plan capacity and improve reliability. | Legitimate interests (Art. 6(1)(f)) — our interest in operating a reliable, well-sized platform. |
| Website analytics | Measuring, with our self-hosted Matomo, which pages of our website and the Client Area are visited and how, in aggregate. | Legitimate interests (Art. 6(1)(f)) — our interest in knowing which parts of our website are useful so that we can improve them. |
| Advertising measurement | Telling Meta, through the Meta pixel and from our server, about visits, enquiries, new accounts and payments, so that we can see which of our Facebook and Instagram ads work. | Legitimate interests (Art. 6(1)(f)) — our interest in measuring whether our advertising works and in not paying to advertise to people who have already found us. You can object at any time (section 8). |
| Service communications | Sending essential notices about your account, security, billing, maintenance and Status-Page incidents you subscribed to. | Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — our interest in keeping you informed about the Services you use. |
| Marketing | Sending optional newsletters or product news where you have asked to receive them. | Consent (Art. 6(1)(a)). You can withdraw your consent at any time, with no effect on the Services. |
| Business-to-business prospecting | Sending a short business offer by email or LinkedIn message to the people who look after a company’s website, and answering their replies (“Business-prospect data” in section 2). | Legitimate interests (Art. 6(1)(f)) — our interest in telling businesses that might want European hosting that we exist. We limit it to work contacts at companies, to countries whose law allows such messages without prior consent, to a first email and at most two follow-ups or a LinkedIn connection request and at most two messages, and we stop the moment you object (section 8). |
| Establishing, exercising or defending legal claims | Retaining limited records where needed to resolve a dispute or enforce our terms. This includes the record of your consent to automatic payment, which we need if a charge is disputed. | Legitimate interests (Art. 6(1)(f)) — our interest in protecting our legal rights. |
We do not carry out automated decision-making that produces legal or similarly significant effects on you, and we do not engage in profiling for those purposes.
Our website and the Client Area sit behind a content-delivery and security edge. It absorbs distributed denial-of-service traffic, applies an IP blocklist and a per-IP rate limit, and blocks matching requests automatically. It is not an application firewall with a managed rule set, and we will not describe it as one — the substantive request filtering is done by our own servers behind it. If you believe a request of yours has been blocked in error, contact support and we will look at it.
4. Email
4.1 Mailboxes on our hosting plans
Every hosting plan includes Hosted Mailboxes: email accounts on your own domain, stored on our servers. The mail in them — messages, attachments, headers, folders and the addresses of the people you correspond with — is Content. We process it as your processor, on your instructions and under our DPA, and you are its controller.
- Where it is stored. Mailboxes are stored on our hosting server in the Netherlands. Copies are kept in our off-site backups on Backblaze B2 in its EU region (Amsterdam), encrypted at rest (AES-256) by the storage provider, for the backup retention period of your plan.
- Incoming mail. Filtering runs on our own server. Before a message is accepted, the IP address of the server delivering it is checked against DNS blocklists; that lookup sends the blocklist operator the IP address only, never the message, and known spam sources are refused. Accepted mail is scored for spam on our own server, and spam is filed into the Junk folder.
- Outgoing mail. Mail sent from your mailboxes, and mail your websites send (contact forms, shop receipts and the like), is handed to MailChannels Corporation, which relays it to the recipient’s mail server and filters it for spam and abuse on the way. MailChannels is established in Canada and its relay infrastructure is in the United States, so every message sent from our servers leaves the EEA (section 6). It receives the whole message, its headers and the sender and recipient addresses. MailChannels states that it deletes the content once the message is delivered; it keeps delivery logs (sender, recipients, subject, sending account and IP address) for up to 35 days, and its terms allow it to examine messages to deal with spam and abuse.
- Mail logs. Our mail server logs each message it handles and each mailbox sign-in, as described under “Server & operational logs” in section 2. We are the controller of those logs, and we keep them for about five weeks.
Once a message has left our servers, the recipient’s provider handles it under its own terms. When a hosting service ends, its mailboxes go with it: a cancelled service is suspended on its cancellation date and deleted 14 days later, as set out in clause 15 of our Terms of Service, so move or export any mail you need before the cancellation date.
4.2 Managed Email
Where you purchase Managed Email through us — Microsoft 365 or Google Workspace mailboxes — those mailboxes and their contents live in your own tenant with Microsoft or Google. Our role is that of agent and administrator: the subscription is taken out in your name, we arrange it, pay for it and recover from you what we paid, and we hold an ordinary administrator account on your tenant so that we can administer it for you. You can remove that access. For Managed Email we are not the controller or the processor of your email content: that content does not sit on Maxinodes infrastructure, and it is not covered by our SLA or by our commitment to keep backups within the EU/EEA.
The handling of your mailbox data is governed by the privacy notice, data processing agreement and service terms of the provider you choose (Microsoft or Google), and you contract with that provider for the email service through us. We process only the account and billing data needed to provision and invoice the subscription, as described in sections 2 and 3 above.
5. Sharing & subprocessors
We do not sell your personal data. Apart from the advertising measurement described below, we do not share your personal data for anyone else’s marketing. We share personal data only where it is necessary to provide the Services, comply with the law, or protect our rights:
- Subprocessors. We use a small number of providers to help us deliver the Services, and we name every one of them. As at the date of this policy they are Worldstream (Netherlands) for our servers, network and data centre; Microsoft for the content-delivery and security edge in front of our own websites and the Client Area, for the DNS of our own domains, and for our own mail platform; BunnyWay d.o.o. (Slovenia) for the authoritative DNS of customer domains; Zendesk, Inc. (United States) for our helpdesk, chat, Help Centre and role-inbox mail; Backblaze, Inc. for off-site backup storage in Amsterdam, including the contents of mailboxes on our hosting plans; Postmark (United States) for transactional email from the Client Area and the notices our hosting server sends to our own staff; MailChannels Corporation (Canada, with relay infrastructure in the United States) for relaying the email sent from mailboxes and websites on our hosting servers; Key-Systems GmbH (Germany) for domain registration; UptimeRobot s. r. o. (Slovakia) for monitoring and the Status Page; and MaxMind, Inc. (United States) for screening orders for fraud. Each is engaged under written terms — in most cases the provider’s own published data-processing terms — requiring appropriate security and confidentiality. Our Subprocessors page sets out, for each of them, what it does, where it processes data, which Services it applies to and, where it is outside the EEA, the transfer safeguard relied on; our DPA governs subprocessing of Content.
- Our payment providers — not acting on our instructions. An invoice is paid on a page hosted by whichever provider you choose: Whop for card, Apple Pay, Google Pay, PayPal, iDEAL, Bancontact and SEPA Direct Debit, or NOWPayments for cryptocurrency. To either of them we send only the amount, the currency and the invoice number, and your card details never reach us. Everything else you give them directly, on their own pages and under their own privacy policies, and each also collects your IP address and your device and browser details. Each does that for its own purposes rather than on our instructions, which is why neither is our subprocessor. Whop differs from NOWPayments in one way worth knowing: it creates a Whop account for you and sends back to us — and we keep in our billing records — your name, email address, billing address, telephone number where you gave one, the brand and last four digits of your card, and the fraud-risk score it assigned. If you turn on automatic card payment, Whop also saves your card to your Whop account and charges it for your renewal invoices when we ask it to; the card itself stays with Whop. Neither provider’s country of establishment is covered by an EU adequacy decision, and neither offers us Standard Contractual Clauses; our Subprocessors page sets out for each of them what is and is not on offer, so that you know before you start a payment.
- Meta (advertising measurement). We and Meta Platforms Ireland Ltd act as joint controllers for the collection and transmission of the measurement data described in section 2. That means Meta does not merely act on our instructions: it also uses that data for its own purposes under its own Data Policy, over which we have no control. Meta is therefore not a subprocessor and does not appear on our Subprocessors page. This runs on every visit to our website and the Client Area and is not switched off by our cookie banner; section 8 explains your right to object to it. The joint arrangement covers only the collection of that data on our site and its transmission to Meta; what Meta does with it afterwards is Meta’s own processing, which we neither control nor describe here. Because we are joint controllers, Article 26(3) lets you exercise your rights against either of us: write to privacy@maxinodes.com and we will deal with what is ours and pass on what is not, or go to Meta directly.
- Business prospecting. Explee (operated, according to its published terms, by Explee Ltd, a company registered in England and Wales) finds the business contacts described in section 2 and sends and receives our outreach emails on our behalf, as our processor. It holds the prospect’s name, job title, company and work email address, the messages we send and any reply. It is involved with business prospects only — never with customers, the Client Area or the Content we host.
- Business prospecting on LinkedIn. Gojiberry (operated, according to its published terms, by SUPERFRUITS SAS, a company registered in France) finds the business contacts on LinkedIn described in section 2 and sends our connection requests and messages from our founder’s LinkedIn account on our behalf, as our processor. It holds the prospect’s name, job title, company, location, public LinkedIn profile and the activity that brought them to our attention, and the messages exchanged. LinkedIn carries those messages as it does for any member, under its own terms and privacy policy, and is not our processor. Gojiberry is involved with business prospects only — never with customers, the Client Area or the Content we host.
- Professional advisers and authorities. We may disclose data to our accountants, auditors or legal advisers, or to a public authority, court or regulator, where we are legally required to do so or where it is necessary to establish, exercise or defend legal claims.
- Business transfers. If our business is reorganised, merged or sold, personal data may be transferred as part of that transaction, subject to the protections of this policy and applicable law. We will inform you of any such change that materially affects how your personal data is handled.
6. Where your data is stored & international transfers
What stays in the EU/EEA
The hosting platform itself is in Europe and has not moved. The websites, databases, files and mailboxes you host with us are stored in enterprise data centres in the Netherlands, and your websites are served from there. Requests to a site you host with us go straight to those servers — they do not pass through the edge network described below, and no third party terminates the connection on the way. The authoritative DNS for customer domains is operated by a provider established in the EU, behind our own ns1/ns2.maxinodes.com nameservers; because DNS is answered from a worldwide anycast network, a lookup arriving from a resolver outside the EEA is answered outside the EEA, and those lookups come from recursive resolvers rather than from identifiable visitors.
Our backups are stored in Amsterdam, in the EU. They include the contents of mailboxes on our hosting plans. They are encrypted at rest (AES-256) by the storage provider, which holds the encryption keys; they are not encrypted on our servers before upload. Because the provider is a US-incorporated company and holds the keys, we treat the backups themselves, and not only their metadata, as transferred, and rely on the safeguards in the table below.
What is transferred outside the EU/EEA
Four things we need in order to run the Services do involve a transfer, and we would rather set them out plainly than bury them.
Support. Our helpdesk is Zendesk, Inc., a Delaware corporation in the United States. Everything you send us through a support ticket, through live chat, through the contact form, or by email to support@, privacy@ or abuse@maxinodes.com is held on its platform, together with our replies and the record of the correspondence. Email to those addresses reaches our own Microsoft 365 mailboxes in the EU first and is then forwarded on to Zendesk, so there are two steps rather than one. Zendesk currently holds that data in its Europe (Ireland) region, but we have not bought the option that would turn that placement into a contractual commitment, and Zendesk reserves the right to move account data between regions. Personal data also reaches the United States through Zendesk’s own operations and through the US providers it uses to run its platform. We therefore treat everything sent to our support channels as transferred to the United States, and we rely on the safeguards below rather than on where the data happens to sit today.
The edge in front of our own websites. Our marketing site, our Client Area at my.maxinodes.com and our statistics dashboard are served through Microsoft Azure Front Door. It terminates the TLS connection, caches our public marketing pages, and screens incoming requests. In doing so it processes the visitor’s IP address, browser user-agent, the URL requested and the technical details of the request. Front Door is a global network: your request is handled at whichever Microsoft point of presence is nearest to you, which for a visitor outside Europe means outside the EEA, and Microsoft excludes this service from its EU Data Boundary commitment. Our own copy of the resulting logs is kept in Microsoft’s West Europe region for 30 days. Two limits are worth stating: sites you host with us are not behind Front Door at all, and Client Area pages are not cached at the edge. Front Door sets no cookies — see our Cookie Policy.
Transactional email. The automated messages our billing system sends you — invoices, order confirmations and password resets — are delivered through Postmark, a transactional email service established in the United States that offers no EU data-residency option. It receives your name, your email address, the invoice or order reference and the contents of the message. It also carries the notices our hosting server sends to our own staff. This is transactional mail only: not support correspondence, not marketing, and not the mail sent from mailboxes or websites on our hosting servers, which goes through the relay described next.
Outgoing email. Every message sent from a mailbox on our hosting plans, and every message a website on our servers sends, is relayed to its recipient through MailChannels Corporation, a company established in British Columbia, Canada, whose relay infrastructure is in the United States. It receives the whole message, its headers, the sender and recipient addresses and the account and IP address it was sent from, and it filters the message for spam and abuse before passing it on. MailChannels states that it deletes the content once the message is delivered, and it keeps delivery logs (sender, recipients, subject, sending account and IP address) for up to 35 days. Mail you receive does not pass through it.
Business prospecting. A fifth transfer sits outside the Services themselves and concerns business prospects only. Explee, which finds the business contacts described in section 2 and sends our outreach emails, is established in the United Kingdom. Transfers to the United Kingdom are covered by the European Commission’s adequacy decision for the United Kingdom under the GDPR, so no further safeguard is required. The provider does not publish where it processes data or a list of its own sub-processors; we would rather say that than imply a commitment it has not made. It is never involved with customers or the Content we host.
Business prospecting on LinkedIn. Gojiberry, which finds business contacts on LinkedIn and sends our LinkedIn messages, is established in France, inside the EEA, so using it is not itself a transfer out of the EEA. Its own privacy policy names Stripe, Supabase and OpenAI as examples of the providers it uses, says that data may be transferred to processors in the United States under Standard Contractual Clauses, and makes its full list of subprocessors available only on request; we would rather tell you that than imply more. It is never involved with customers or the Content we host.
The safeguards we rely on
| Recipient | What it receives | Transfer mechanism |
|---|---|---|
| Zendesk, Inc. (United States) | Support tickets, live chat, Help Centre activity, contact-form enquiries, and mail sent to our support@, privacy@ and abuse@ addresses. | The safeguards are those in Zendesk’s published data processing agreement: Binding Corporate Rules approved by the Irish Data Protection Commission, and the European Commission’s Standard Contractual Clauses. Zendesk, Inc. is additionally certified under the EU–US Data Privacy Framework. Our account is on Zendesk’s published online terms; we have not negotiated separate terms with it. |
| Microsoft (global edge network) | IP address, user-agent, requested URL and request metadata for visits to our own websites and the Client Area, in edge access and filtering logs. | Microsoft’s Products and Services Data Protection Addendum, which applies the European Commission’s 2021 Standard Contractual Clauses to transfers of customer data out of the EEA within the Microsoft group, including to Microsoft Corporation in the United States. Microsoft Corporation is also certified under the EU–US Data Privacy Framework. |
| Postmark (United States) | Your name, your email address, the invoice or order reference and the contents of the automated account emails our billing system sends you; also the notices our hosting server sends to our own staff. | Postmark’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses. ActiveCampaign, the group it belongs to, is additionally certified under the EU–US Data Privacy Framework. |
| MailChannels Corporation (Canada; relay infrastructure in the United States) | Every message sent from mailboxes and websites on our hosting servers: its content, headers, sender and recipient addresses, and the sending account and IP address. | The European Commission’s adequacy decision for Canada. MailChannels has not signed a separate data processing agreement with us; its own terms govern its processing. It does not publish a list of its own sub-processors or where it processes data. |
| Backblaze, Inc. (United States; storage in Amsterdam) | Our off-site backups, including the contents of mailboxes on our hosting plans, encrypted at rest (AES-256) with keys it holds, and the metadata about them. | Backblaze’s data processing agreement for EEA residents, which incorporates the European Commission’s Standard Contractual Clauses. |
| MaxMind, Inc. (United States) | When you place an order: your IP address, your email address, the billing name, address and country you entered, your telephone number where you gave one, and the amount and currency of the order. No card details — those never reach us. | MaxMind’s data processing addendum, which incorporates the European Commission’s Standard Contractual Clauses. MaxMind, Inc. is additionally self-certified under the EU–US Data Privacy Framework, but the contract we rely on is the Clauses. |
| Explee (United Kingdom) | The name, job title, company and work email address of business prospects, the outreach messages we send them and any reply. | The European Commission’s adequacy decision for the United Kingdom under the GDPR. Explee acts under its published Terms of Use, which describe it as a processor of the data our account holds; we have not negotiated separate terms with it. |
The Subprocessors page lists every provider we use, where each one processes data, and the mechanism relied on for each. Each mechanism above is published by the provider at the link given; if you would like us to walk you through what applies to your own data, email privacy@maxinodes.com.
Two further flows sit outside that table. Domain registration (section 2): our registrar channel is established in the EEA, but registrant data is passed onward to the registry that runs your domain extension, to a data-escrow agent and, for generic extensions, to ICANN — some of them outside the EEA, under ICANN and registry rules rather than under our contract. We cannot apply our own safeguards to those steps, and we say so rather than implying otherwise. Cryptocurrency payments (section 5): our payment provider is established outside the EEA, is not covered by an adequacy decision, and offers no Standard Contractual Clauses; it collects your data directly on its own hosted page, as its own controller.
The advertising measurement in section 2 is different again: Meta may transfer the resulting data to the United States and other countries outside the EU/EEA under its own transfer mechanisms, including the EU–US Data Privacy Framework and Standard Contractual Clauses. The adequacy of that framework has been challenged and remains the subject of litigation before the EU courts. Edge delivery, our helpdesk and the outgoing-mail relay also involve processing outside the EEA, because they are necessary to serve this site, to answer support requests and to deliver the email you send; the recipients and safeguards are set out above and in section 5.
There is one nuance to be aware of in relation to Managed Email (section 4.2). Because those mailboxes live in your own Microsoft 365 or Google Workspace tenant rather than on our infrastructure, the storage location and any international transfer of that mailbox data are determined by your chosen provider under its own arrangements (for example its Standard Contractual Clauses or adequacy mechanisms). For that email content, the provider — not Maxinodes — is the relevant party for transfers, and that data sits outside our commitment to keep backups within the EU/EEA. Mailboxes on our hosting plans (section 4.1) are the opposite case: they are stored in the Netherlands and backed up in the EU, and only the mail you send from them leaves the EEA, through the relay described above.
7. How long we keep it
We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it. Our standard retention periods are:
| Category | Retention period |
|---|---|
| Server & operational logs (on our own servers) | Approximately 90 days, after which they are deleted or aggregated, unless a specific log is retained longer to investigate a security incident or to establish, exercise or defend a legal claim. |
| Mail-server logs (sender, recipients, subject, IP addresses and mailbox sign-ins) | Rotated weekly and kept for about five weeks, unless a specific log is retained longer to investigate abuse or a security incident. Outgoing messages held back by our spam filter are kept for 14 days. The relay that delivers outgoing mail keeps its own delivery logs for up to 35 days, under its own terms. |
| Edge / content-delivery request logs | 30 days, in a log workspace located in the EU (West Europe), after which they are deleted automatically. |
| Tax & accounting records (including invoices) | Approximately 6 years, as required by Irish tax and company law. |
| Automatic-payment records (your consent and each automatic charge) | For as long as automatic payment is on, and then for the tax-retention period above, so that we can answer a disputed charge. |
| Account data | For the life of your account, plus the tax-retention period above for any records that also form part of our accounting and tax records. Other account data is deleted or anonymised once it is no longer needed after closure. |
| Support, helpdesk & contact-form data (customers) | For the duration of your relationship with us and a reasonable period afterwards to handle follow-up queries and disputes, after which it is deleted. This correspondence is held on our third-party helpdesk platform. |
| Enquiries from people who are not customers | Deleted within 12 months of the last message, unless a dispute or investigation is live. This correspondence is also held on our third-party helpdesk platform. |
| Status-Page subscription data | Until you unsubscribe or the subscription is no longer active. The subscription record is held by our monitoring provider. |
| Domain registration contact data | For as long as the domain is registered through us, and afterwards for the period the registry, the data-escrow arrangement or ICANN rules require. Those periods are set by the registry, not by us. |
| Business-prospect data | If you do not reply: deleted within 6 months of our last message; Gojiberry itself deletes the LinkedIn lead data it holds 60 days after last refreshing it. If you reply and become a customer: it becomes account data. If you tell us to stop: your email address or LinkedIn profile address — and, if you ask, your company’s domain — is kept on a suppression list for as long as we do any outreach at all, which is the only way we can make sure we never write to you again. A LinkedIn conversation also stays in both members’ LinkedIn inboxes until either of you deletes it there. |
The Content you host with us, including the mail in your mailboxes, is retained and deleted in accordance with your instructions and our DPA and Terms of Service, not under the periods above.
8. Your rights
Under the GDPR and Irish data-protection law you have the following rights in relation to your personal data:
- Access — to obtain confirmation that we process your personal data and a copy of it.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to have your personal data deleted where there is no overriding reason for us to keep it (for example our legal retention obligations).
- Restriction — to ask us to limit how we use your personal data in certain circumstances.
- Portability — to receive the personal data you provided to us, where processing is based on consent or contract and carried out by automated means, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection — to object to processing carried out on the basis of our legitimate interests (see the table in section 3), including our website analytics and our advertising measurement with Meta. Where you object, we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You can object to direct marketing — including a business email or LinkedIn message we sent you before you had ever written to us — at any time and without giving a reason, and we will stop: reply STOP to the message, or email privacy@maxinodes.com.
- Withdrawing consent — where we rely on your consent (for example marketing emails, or live chat in our cookie banner), you can withdraw it at any time. This does not affect the lawfulness of processing carried out before you withdrew it.
To exercise any of these rights, email privacy@maxinodes.com. We may need to verify your identity before acting on a request. We will respond within one month of receiving your request; where a request is complex or you have made several, we may extend this by up to two further months and will tell you if we do. Exercising these rights is normally free of charge.
If you are not satisfied with how we have handled your personal data or a request, you have the right to lodge a complaint with the supervisory authority — in Ireland, the Data Protection Commission. Full details are in the Contact section below.
9. How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and disclosure. We make no certification claims of any kind. These measures include:
- Encryption of data in transit using current TLS, on our website, in the Client Area and on the hosting platform; mail apps must connect to our mail server over TLS (plain-text sign-ins are refused), and mail exchanged with other mail servers is encrypted whenever the other server supports it;
- Customer Data for the hosting Services, including mailboxes, stored on servers we administer in the Netherlands, and our backups stored within the EU/EEA and encrypted at rest (AES-256) by the storage provider;
- An honest statement of the limit of that: the disks in our servers are not themselves encrypted, so live data at rest is protected by logical isolation, filesystem permissions and access control rather than by full-disk encryption;
- Account passwords stored as salted one-way hashes and never in plain text;
- Access controls and the principle of least privilege, so staff can access only the data they need for their role, with administrative access to our servers by SSH key only and password authentication disabled for administrator logins;
- Two-factor authentication on the administrative interfaces of our virtualisation host and our hosting platform, and available to you on your Client Area account;
- Firewalling on the virtualisation host and on each individual virtual machine, brute-force protection (including temporary lock-outs after repeated failed mailbox sign-ins), and automated screening of requests to our website and the Client Area at our content-delivery edge, which may block a request on the basis of its source IP address or rate;
- Monitoring and logging of access and of platform activity to detect and respond to suspicious events.
No method of transmission or storage is completely secure, but we work to keep our measures appropriate to the risks involved. You are responsible for keeping your account credentials confidential and for the security choices you make within your own services.
10. Cookies
Our website and the Client Area use a limited set of cookies and similar technologies. How we use them, and the choices available to you, are described in our Cookie Policy. The cookie banner is where you allow or decline live chat, and the choice you make on any of our sites applies to all of them. Our analytics and advertising measurement (section 2) run whatever you choose there.
Our Help Centre at support.maxinodes.com is a different case, and we would rather be straight about it. Although it is on our own domain, the site is operated for us by our helpdesk provider, Zendesk, Inc., and pages there set cookies and store data on your device under that provider’s own arrangements — including by Cloudflare, Inc., which Zendesk uses to serve and protect the site. That site now carries a consent banner of its own, and it records the same choice as the banner on our website and in the Client Area, so one decision covers all three. What it can act on there is narrower, and it says so itself. It holds the chat widget back until you allow live chat — until then the widget is told to store nothing on your device and is kept hidden. It cannot reach what the platform sets for itself: Zendesk’s Help Centre session cookie, Zendesk’s own measurement of that site, and Cloudflare’s bot-protection cookies all load with the page, before any of our code runs. For those, your browser settings are the control — and you do not need to visit the Help Centre to reach us at all: the addresses in the Contact section below work just as well.
11. Children
The Services are intended for businesses and for adults, and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@maxinodes.com and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our Services or the law. When we do, we will revise the version and date at the top of the page. The version in force is always the one published at this URL. Where a change is material, we will take reasonable steps to notify you — for example by email or a notice in the Client Area — before it takes effect. For a map of our other legal documents, see the legal hub.
What changed in this version. Version 2.8, published on September 19, 2026, covers the mailboxes included with our hosting plans. Section 4 now has two parts: mailboxes on our hosting plans, whose content we process as your processor, and Managed Email, as before. Sections 1, 2, 3 and 7 describe our mail-server logs and mail filtering, the people they concern and how long we keep the logs; sections 5 and 6 add MailChannels (Canada, with relay infrastructure in the United States), which relays the email sent from our hosting servers and has done so since September 17, 2026, before this notice, and extend Postmark to the notices our hosting server sends to our own staff; and sections 6 and 9 record that our backups, which include mailbox contents, are encrypted at rest by the storage provider rather than on our own servers before upload. Nothing else changed. Version 2.7, published on September 16, 2026, adds automatic card payment, which you can turn on in the Client Area. Section 2 describes the card reference and the consent record we keep when you do, section 3 gives the legal basis, section 5 says that Whop then saves your card, and section 7 sets how long those records are kept. It also corrects section 5, which said that Whop emails you its own order confirmation; it no longer does. Nothing else changed. Version 2.6, published on September 14, 2026, adds business-to-business prospecting on LinkedIn, and was published before the first such message was sent: section 2 describes the LinkedIn data we hold and where it comes from, section 3 extends the legal basis to LinkedIn messages, sections 5 and 6 name Gojiberry (France) as the provider that finds the contacts and sends the messages and explain why using it is not a transfer out of the EEA, section 7 adds its retention period and the LinkedIn suppression record, and section 8 restates the right to object. Nothing else changed. Version 2.5, published on September 13, 2026, adds business-to-business prospecting, and was published before the first such email was sent: section 2 describes the data we hold about business prospects and where it comes from, section 3 gives the legal basis, sections 5 and 6 name Explee (United Kingdom) as the provider that finds the contacts and sends the messages and state the transfer basis relied on, section 7 sets the retention period, and section 8 restates the right to object. Nothing else changed. Version 2.4, published on September 10, 2026, records that our website analytics and our advertising measurement with Meta no longer depend on the choice you make in our cookie banner: from that date they run on every visit to our website and the Client Area, on the basis of our legitimate interests. Section 2 now describes the analytics data and lists every detail we send to Meta in hashed form, and section 3 gives the legal basis for each. Version 2.3, published on August 31, 2026, renamed Resold Email to Managed Email and restated section 4. The subscription is taken out in your own name; we arrange it, pay for it on your behalf and recover what we paid, and our access to your tenant is an ordinary administrator account you can remove at any time, not delegated administrative access. Your Managed Email mailbox content was always outside our processing and still is. The previous version was published on August 7, 2026 to record four infrastructure changes and the transfers that follow from them: authoritative DNS for customer domains moved to an EU provider on July 26, 2026; our own websites and the Client Area were placed behind Microsoft’s global edge network and our corporate DNS moved to Azure DNS on August 4, 2026; and support moved from our own self-hosted helpdesk to Zendesk, Inc. in the United States on August 6, 2026. Customer websites were not affected by any of them and are still served directly from our servers in the Netherlands. The full record is in the change history on our Subprocessors page.
Contact
Privacy and data-protection enquiries: privacy@maxinodes.com.
By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.
Mail sent to that address reaches our own Microsoft 365 tenant in the EU and is then forwarded into our helpdesk platform, operated by Zendesk, Inc., a Delaware corporation established in the United States. Your message, anything attached to it and our correspondence about it are stored there. Our account data is currently held in its Europe (Ireland) region, but we have no contractual commitment to that region, and the provider and its named United States sub-processors can reach that data from the United States — so it is processed outside the EEA. If you would rather your message did not pass through a third-party helpdesk — for example because it includes identity documents, or because it names someone else — write to us by post at the address above, or email billing@maxinodes.com, which reaches us directly.
If you have a concern about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the supervisory authority in Ireland:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence.