Privacy Policy
About the company
H2NEXUS CLOUD SERVICES FZCO
- License No. (company)
- 86508
- Registered address
- IFZA Business Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
- Registered
- 26.03.2026
Published and came into effect21.07.2026
This Privacy Policy explains how H2NEXUS CLOUD SERVICES - FZCO the “Company”, “H2NEXUS”, “we”, “us”, “our” collects, uses, stores, discloses and protects personal data when the Client uses our website, Client Area, control panel, hosting services, support services and related services. In this Policy, the “Client” means any person or entity visiting our website or using our Services.
This Policy is intended to comply with applicable UAE data protection requirements, including the UAE Personal Data Protection Law where applicable, and may also apply together with GDPR or other data protection rules where such laws apply to a particular Client or processing activity.
Contents
- 1. Our Commitment
- 2. Data We Collect
- 3. How We Collect Data
- 4. Purposes of Processing
- 5. Legal Basis
- 6. Disclosure of Data
- 7. International Transfers
- 8. Retention
- 9. Security
- 10. Data Breach and Security Incidents
- 11. Client Rights
- 12. Marketing Communications
- 13. Cookies and Similar Technologies
- 14. Third-Party Links and Services
- 15. Client-Hosted Personal Data
- 16. Children’s Data
- 17. GDPR and Other International Laws
- 18. Changes to this Privacy Policy
- 19. Contact
1. Our Commitment#
1.1. We respect the Client's privacy and process personal data only where necessary for account management, service delivery, billing, support, security, abuse handling, fraud prevention, legal compliance and improvement of our Services.
1.2. We do not sell the Client's personal data.
1.3. We do not actively inspect Client-hosted content except where necessary for abuse handling, security, legal compliance, infrastructure protection or technical support requested by the Client.
2. Data We Collect#
We may collect and process the following categories of data:
2.1. Account data: name, company name, email address, Telegram username, phone number, billing address, country, account ID, login data and account settings.
2.2. Verification data: identity documents, business registration documents, beneficial ownership information, payment verification data, KYC/KYB information and sanctions screening information where required.
2.3. Payment data: payment method, transaction ID, payment status, invoices, balance records, refund details, chargeback data, payment processor metadata, cryptocurrency transaction hashes and related financial records. We normally do not store full card numbers.
2.4. Service data: ordered services, tariff, IP addresses assigned to the Client, server identifiers, operating system templates, configuration metadata, usage records, bandwidth usage, resource consumption, renewal dates and service status.
2.5. Technical data: IP addresses, browser type, device information, operating system, user agent, cookies, session identifiers, login timestamps, API logs, control panel actions, security events and diagnostic data.
2.6. Support data: tickets, emails, Telegram messages, attachments, screenshots, logs, abuse responses and communications with our support team.
2.7. Abuse and security data: abuse reports, firewall events, traffic metadata, packet samples, spam reports, blacklists, malware indicators, complaint evidence and investigation notes.
2.8. Website analytics data: pages visited, referrer, approximate location, browser language, screen data, performance metrics and other website usage data.
2.9. Client-hosted data: content, files, databases, logs or server data hosted by the Client. We process this primarily as infrastructure provider and normally only access it where necessary for service delivery, support, abuse investigation, security or legal compliance.
3. How We Collect Data#
3.1. Directly from the Client when the Client registers, orders Services, contacts support, submits documents, makes payments or configures Services.
3.2. Automatically when the Client uses our website, Client Area, control panel, API or Services.
3.3. From payment processors, banks, crypto payment providers, fraud prevention providers, KYC/KYB providers and sanctions screening providers.
3.4. From abuse reporters, security researchers, upstream providers, data centres, law enforcement, regulators and third-party service providers.
3.5. From public sources where necessary for fraud prevention, sanctions screening, abuse handling or compliance.
4. Purposes of Processing#
We process personal data for the following purposes:
4.1. To create and manage the Client's account.
4.2. To provide, activate, maintain and support Services.
4.3. To process payments, invoices, renewals, refunds, taxes and accounting records.
4.4. To verify identity, business details, payment ownership and eligibility to use Services.
4.5. To prevent fraud, abuse, spam, cyberattacks, unauthorised access and misuse of Services.
4.6. To investigate abuse reports, security incidents, complaints, blacklisting and network issues.
4.7. To communicate with the Client about Services, maintenance, outages, invoices, abuse reports, legal notices and support requests.
4.8. To improve our website, Client Area, products, infrastructure, security and support.
4.9. To comply with legal, regulatory, tax, accounting, AML, sanctions and law enforcement obligations.
4.10. To enforce our Terms, Acceptable Use Policy, Anti-Spam Policy and other agreements.
4.11. To send service-related notices and, where permitted, product updates or marketing communications.
5. Legal Basis#
Where a legal basis is required, we rely on one or more of the following:
5.1. Performance of a contract with the Client.
5.2. Compliance with legal obligations.
5.3. Legitimate interests, including service operation, network security, fraud prevention, abuse handling, business administration and improvement of Services.
5.4. Consent, where required for specific processing such as certain marketing communications or optional cookies.
5.5. Protection of rights, safety and security of the Company, Clients, third parties and the public.
6. Disclosure of Data#
We may disclose personal data to:
6.1. Payment processors, banks, card processors, digital wallet providers and cryptocurrency payment processors.
6.2. Data centres, upstream providers, IP transit providers, DDoS mitigation providers, cloud providers, software vendors and infrastructure suppliers.
6.3. KYC/KYB providers, fraud prevention providers, sanctions screening providers and compliance vendors.
6.4. Professional advisers, accountants, auditors, lawyers and insurers.
6.5. Law enforcement, courts, regulators, tax authorities, competent UAE authorities or other authorities where required or legally permitted.
6.6. Abuse reporters, affected third parties, security organisations, anti-abuse organisations or network operators where necessary to investigate, prevent or mitigate abuse.
6.7. A buyer, successor or assignee in connection with merger, acquisition, restructuring, sale of assets or business transfer.
6.8. Third-party software or licence providers where contractually required to verify licensing or compliance.
6.9. Other parties with the Client's consent or instruction.
6.10. Affiliated group companies, including H2NEXUS LTD, a company incorporated in England and Wales under company number 15222392, where they accept, collect or process payments or perform related billing, accounting, support or compliance functions on our behalf.
7. International Transfers#
7.1. The Company may process and store data in the UAE, European Union, United Kingdom, United States or other countries where our infrastructure, suppliers, payment providers, support systems or data centres operate.
7.2. The server location selected by the Client may determine where Client-hosted data is stored.
7.3. By using the Services, the Client acknowledges that data may be transferred internationally where necessary to provide the Services, process payments, deliver support, prevent abuse or comply with law.
7.4. Where required, the Company will use appropriate contractual, organisational and technical safeguards for international transfers.
8. Retention#
8.1. We retain personal data only for as long as reasonably necessary for the purposes described in this Policy.
8.2. Account, billing, tax and transaction records may be retained for the period required by applicable tax, accounting, AML, fraud prevention or legal obligations.
8.3. Support tickets and communications may be retained for service history, dispute resolution, security and quality purposes.
8.4. Technical logs, security logs and abuse records may be retained for security, fraud prevention, abuse prevention and legal defence.
8.5. Client-hosted server data may be deleted after Service expiry, cancellation or termination according to the applicable Terms and product rules.
8.6. Expired Services may have data retained for up to 3 days, and PROMO, trial or short-term Services may have data retained for up to 1 day or deleted earlier.
8.7. Backups, snapshots and residual copies may persist temporarily after deletion due to technical backup cycles.
9. Security#
9.1. We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure.
9.2. Measures may include access controls, authentication controls, encryption in transit, logging, network security controls, staff confidentiality obligations, restricted access and monitoring.
9.3. No internet-based service is completely secure. We cannot guarantee absolute security.
9.4. The Client is responsible for securing the Client's own account, passwords, SSH keys, API keys, operating systems, applications, firewalls, backups and hosted data.
9.5. The Client must notify us promptly upon suspecting unauthorised access to the Client's account or Services.
10. Data Breach and Security Incidents#
10.1. If we become aware of a security incident affecting personal data, we will take reasonable steps to investigate, contain and mitigate the incident.
10.2. Where legally required, we will notify affected users, regulators or authorities.
10.3. Notification may be sent by email, Client Area notice or other appropriate communication channel.
10.4. The Client is responsible for ensuring that the Client's registered email address is valid and monitored.
11. Client Rights#
Depending on applicable law, the Client may have rights to:
11.1. Access personal data we hold about the Client.
11.2. Correct inaccurate or incomplete data.
11.3. Request deletion of personal data.
11.4. Restrict or object to certain processing.
11.5. Request portability of certain data.
11.6. Withdraw consent where processing is based on consent.
11.7. Object to marketing communications.
11.8. Lodge a complaint with a competent data protection authority where applicable.
To exercise rights, contact support@h2.nexus. We may need to verify the Client's identity before responding.
12. Marketing Communications#
12.1. We may send service-related messages, invoices, abuse notices, security notices, maintenance notices and legal notices. These are not marketing and cannot always be disabled while the Client uses the Services.
12.2. We may send product updates, offers or promotional communications where permitted by law.
12.3. The Client may unsubscribe from marketing communications using the unsubscribe link or by contacting support.
13. Cookies and Similar Technologies#
13.1. We may use cookies, session identifiers, local storage and similar technologies.
13.2. Cookies may be used for authentication, session security, fraud prevention, account functionality, preferences, analytics and performance measurement.
13.3. The Client may disable cookies in the browser, but parts of the website, Client Area or control panel may not function correctly.
13.4. Third-party services, such as payment providers, analytics providers or security providers, may use their own cookies subject to their own privacy policies.
14. Third-Party Links and Services#
14.1. Our website or Client Area may contain links to third-party websites, payment pages, software, panels or services.
14.2. We are not responsible for third-party privacy practices, content, security or terms.
14.3. The Client should review third-party privacy policies before submitting data to them.
15. Client-Hosted Personal Data#
15.1. If the Client uploads, stores or processes personal data using our infrastructure, the Client is responsible for ensuring a lawful basis to do so.
15.2. The Client is responsible for privacy notices, consents, contracts, security controls, data subject requests and compliance obligations relating to data hosted by the Client.
15.3. The Company acts primarily as an infrastructure provider for Client-hosted data, unless otherwise agreed in writing.
15.4. The Client must not use the Services to process personal data unlawfully or in violation of UAE law, applicable data protection law or third-party rights.
16. Children’s Data#
16.1. Our Services are not intended for persons under 18.
16.2. We do not knowingly collect personal data from children for account registration.
16.3. Any content involving exploitation or abuse of minors is strictly prohibited and may be reported to competent authorities.
17. GDPR and Other International Laws#
17.1. Where GDPR, UK GDPR or another data protection law applies to a specific processing activity, the Company will process personal data in accordance with applicable mandatory requirements.
17.2. For EU/EEA/UK Clients, rights may include access, rectification, erasure, restriction, objection, data portability and the right to lodge a complaint with a supervisory authority.
17.3. Where Client-hosted data requires a Data Processing Agreement, the Client may request one through support.
17.4. International transfers may rely on contractual safeguards or other lawful transfer mechanisms where required.
18. Changes to this Privacy Policy#
18.1. We may update this Privacy Policy from time to time.
18.2. Material changes may be notified by email, Client Area notice or website notice.
18.3. Continued use of the Services after the updated Policy becomes effective means the Client accepts the updated Policy.
19. Contact#
For privacy questions, data requests or complaints:
H2NEXUS CLOUD SERVICES - FZCO
Email: support@h2.nexus
Abuse/security: abuse@h2.nexus root@h2.nexus
Client Area: my.h2.nexus