Privacy Policy
Effective date
Your privacy is important to us
At Aquila, we attach great importance to your privacy and the protection of your personal data.
We therefore process your personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR), and the Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
When you call on us, you share personal data with us. You must therefore be able to trust that we handle this data carefully and confidentially. This privacy statement explains how we do this.
The privacy statement applies to all services of Van Nieuwenhuyzen Arno, with registered office at Richard Neyberghlaan 162/1, 1020 Brussels and company number 1029.332.029, as well as to the website www.aquilahosting.com (hereinafter "Aquila" or "we"), which acts as the data controller.
By using our services and website, you acknowledge that you have read this privacy statement. We may change the privacy policy at any time. It is therefore advisable to consult this privacy statement regularly.
Which personal data do we process?
Depending on the relationship we have with you, we process different data.
If you are a customer, we process the following personal data of the person who manages the account:
- Identification and contact data: name, email address, billing address;
- Account data: username, password and login, user ID, profile data;
- Technical identifiers: IP address, browser and device information, session IDs, login history;
- Payment and billing data: payment method and metadata, payment history, subscription data, invoices and receipts, fraud and risk data; where applicable: VAT number (for professional customers operating as a sole proprietorship);
- Usage and interaction data: telemetry, usage activity and interaction and transaction data on our platform;
- Communication data: content and metadata of emails we send you (confirmations, invoices, security notifications), as well as support communication.
If you purchase a game server from us, the following data is also processed in the context of the operation of that server:
- Player IDs of persons who connect to your game server (such as Steam IDs or Minecraft usernames), insofar as these can be regarded as personal data;
- Console and chat logs of the game server, insofar as these contain personal data;
- Server and session data that is automatically generated during the operation of the server.
In this regard, it is important that game servers and in-game communication are not intended for the storage or exchange of sensitive personal data. Users who purchase a game server are themselves responsible for the use of that server and for compliance with the applicable privacy legislation with respect to the players who connect to their server.
If you are a supplier, we process your VAT number and billing and bank details (if a sole proprietorship) and furthermore the name, contact details and function of your staff members, employees or appointees. In addition, we also process the notes of our discussions, data regarding complaints, accidents and incidents or judicial data.
All data provided to us is used for the performance of our task, in compliance with the principle of minimal data processing.
You can visit our website without disclosing personal data. In that case, it is however possible that certain data is collected via cookies; read more about this in our cookie statement.
You are solely responsible for the accuracy of the data you disclose to us and/or enter.
How do we collect personal data?
We collect personal data directly, when you disclose your data to us in person, by email, by telephone, by video conference, or as it is registered via our website.
Certain technical data (such as IP address, browser and device information) is collected automatically when you use our website or services, via cookies and similar technologies. You will find more information about this in our cookie statement.
When you provide us with information about third parties, your employees or appointees, we assume that these third parties have given you permission to pass on that information to us for processing and transfer in the same way as your own.
For what purposes do we use your personal data?
If you are a customer, we collect your data:
- for the conclusion and performance of the agreement concluded between us;
- for the invoicing of our services;
- to ensure the follow-up of our commercial relationship;
- to answer your questions and communicate with you;
- to send you transactional emails (such as payment confirmations, invoices and security notifications);
- to handle complaints and comments;
- to monitor and improve the operation and security of our services;
- to ensure the technical operation, availability and stability of our game server services and underlying infrastructure;
- to comply with legal obligations or respond to any reasonable requests from competent authorities;
- to safeguard our rights and to defend our interests.
If you are a supplier, we collect the personal data of your employees and appointees:
- For the conclusion and performance of the agreement existing between us;
- To ask your questions and communicate with you;
- To safeguard our own rights and to defend our interests;
- For the fulfilment of our legal obligations (e.g. accounting).
On what legal basis do we process your data?
If you are a customer, Aquila processes your personal data primarily because this processing is necessary for the conclusion and performance of the agreement concluded between us. This concerns in particular data relating to your identity, account, communication and the use of our services, insofar as these are necessary to give you access to the services, manage your account and provide support.
The processing of data relating to invoicing, payments and accounting takes place on the basis of legal obligations to which Aquila is subject. The same applies to processing that is necessary to comply with reasonable and lawful requests from competent government authorities.
In addition, Aquila processes certain personal data of customers on the basis of its legitimate interest. This mainly concerns technical, usage and log data that is generated when using our website and services. Aquila's legitimate interest here consists specifically of:
- ensuring the security, integrity and availability of its IT systems and infrastructure;
- monitoring and improving the operation, performance and reliability of its services;
- preventing, detecting and limiting abuse, malfunctions or other technical incidents.
If you are a supplier, Aquila processes personal data of your appointees and contact persons because this processing is necessary for the conclusion and performance of the contractual relationship. This concerns data necessary for communication, administrative management and follow-up of the cooperation.
The processing of data relating to invoicing, payments and accounting obligations takes place on the basis of legal obligations.
In clearly defined situations, Aquila may process personal data of customers, suppliers or third parties on the basis of its legitimate interest, when this is necessary for the exercise, substantiation or defence of its rights. This may relate, among other things, to relevant identification, communication, transaction or log data in the context of disputes, complaints, contestations or legal proceedings.
Who has access to your personal data?
We only share your personal data with your consent or if it is necessary to provide you with our services, or to comply with our legal obligations. (E.g.: to external organisations responsible for delivery, government authorities, etc.)
We may share your personal data with affiliated companies or with third parties who carry out (part of) the assignment on our behalf. In that case, we do not allow them to use or disclose this data in a manner that does not comply with the cases described in this privacy statement.
If these third parties process your personal data at our request and must be regarded as a processor, we conclude a processing agreement in which the necessary arrangements are included to guarantee the correct processing and security of your personal data. This is done, among other things, via standard contractual clauses as agreed within the EU.
For our services, we rely on the following processors, with whom we have concluded a processing agreement or have relied on their GDPR-compliant data processing addendum:
| Processor | Role | Personal data concerned |
|---|---|---|
| Stripe Incorporated (US) | Billing | Name, email address, billing address, payment details and payment metadata, payment history, subscription data, invoices and receipts, fraud and risk data |
| Clerk Incorporated (US) | User authentication | Name, email address, username and profile data, OAuth provider data, user IDs and session IDs, login history, IP address, browser and device information, authentication and security logs, MFA data |
| Resend Incorporated (US) | Transactional email sending | Email address of sender and recipient, email content (subject and message content), email metadata (timestamp, delivery status, bounces) |
| Cloudflare Incorporated (US) | CDN, proxy and security | IP addresses, browser and device information, request metadata (timestamp, headers), security and bot detection data |
| Hetzner Online GmbH (EU) | Hosting infrastructure and database storage | All personal data processed and stored in the context of the operation of our servers and self-hosted database (user account data, transaction data, application data); access logs |
Insofar as Stripe Incorporated processes personal data in the context of its core activities as a payment service provider, such as payment processing, fraud and risk management and compliance with financial obligations, it acts as a separate data controller within the meaning of the GDPR. Stripe's privacy policy applies to these processing activities.
Stripe, Clerk, Resend and Cloudflare are established in the United States. The transfer of your personal data to these parties takes place on the basis of standard contractual clauses (Standard Contractual Clauses, SCCs) as approved by the European Commission.
We may also disclose your personal data:
- When certain legislation or a legal procedure obliges us to do so;
- In the context of an investigation into suspected or actual fraudulent and illegal activities;
- When this is necessary for the defence of our own interests, e.g. in the context of legal proceedings.
We do not sell the personal data we have collected to third parties, nor do we release it to them, except in the cases described in this privacy statement or as was communicated to you at the time of collection.
We reserve the right to transfer personal data in the event that we sell part or all of our business or our assets. If such a sale occurs, we will take all reasonable measures to encourage the acquirer to process the personal data provided to us correctly, and in a manner consistent with this privacy statement.
Links to other websites
Our website contains links to other websites. This privacy statement applies only to our website. We therefore advise you to consult the privacy statement of the other websites. We are not liable for the privacy policy of other websites, even if you visit that website via one of the links on our website. This also applies to the secure websites of the bank to which you are redirected upon payment.
How long is your data retained?
We retain personal data for as long as necessary to provide you with our services or for other essential purposes, such as complying with our legal obligations.
Personal data of customers is deleted 10 years after the end of the cooperation, after the last contact or after the end of the service provision, except in the event of an ongoing dispute.
Personal data of suppliers is deleted 10 years after the end of the cooperation or the last contact, unless in the event of an ongoing dispute.
Is your data safe with us?
We have taken the necessary physical, technical and organisational security measures to effectively protect your personal data against unauthorised access and use and disclosures.
- When processing your personal data, we strictly apply the principle of minimal data processing and minimal retention period.
- Our employees and subcontractors have been extensively informed about our privacy and security policy and have the obligation to act in accordance with this privacy statement.
What are your rights?
In accordance with the GDPR, you can ask us at any time to view, adjust, correct, restrict or wholly or partially erase your personal data. You can also always ask us for a copy of the personal data we have received from you.
Furthermore, you can also object to the processing of your personal data.
Following such a request, we will only continue to process this personal data insofar as and to the extent that we have a valid reason to continue processing it, or if this would be necessary to comply with a legal obligation.
When the processing is based on your consent, you can always withdraw this consent, in whole or in part. This may however have the consequence that we can no longer provide our services.
When you have a request, a question or a complaint about the processing of your personal data, you can address it to [email protected]. We undertake to respond to these requests and complaints in a timely manner.
If at any time you feel that one of your rights has not been respected, you can also file a complaint with the Belgian Data Protection Authority via the complaint form provided for this purpose on their website (www.gegevensbeschermingsautoriteit.be).
Contact
If you have any questions about the privacy statement or about the way we process your personal data, you can always contact us:
Van Nieuwenhuyzen Arno / Aquila
Richard Neyberghlaan 162/1, 1020 Brussels
[email protected]
+32 472 390 465
