Budgethost compliance
Last updated: 9 August 2026
This page explains how Budgethost AB approaches data protection and information security when providing services through budgethost.io, my.budgethost.io and our hosting infrastructure.
It describes when Budgethost AB acts as a data controller or data processor, how Data Processing Agreements are handled, the measures used to protect information, and the infrastructure providers and subprocessors involved in delivering our services.
What is personal data?
Personal data is any information relating to an identified or identifiable natural person. This includes information such as names, addresses, email addresses, telephone numbers, online identifiers and IP addresses.
Certain information is classified as special-category personal data and receives additional protection under the GDPR. This includes information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric identification, health, sex life or sexual orientation.
Personal data relating to criminal convictions and offences is governed separately under Article 10 of the GDPR.
Customers must ensure that they have a valid legal basis and appropriate safeguards before collecting or processing personal data through services hosted by Budgethost AB.
Our roles under the GDPR
Whether an organization acts as a data controller or data processor depends on who determines why and how personal data is processed. Budgethost AB may act as a controller for some processing activities and as a processor for others.
Budgethost AB as data controller
Budgethost AB acts as the data controller when we determine why and how personal data is processed.
This includes personal data used for:
- Creating and administering customer and portal accounts.
- Managing customer relationships and billing.
- Providing customer support.
- Preventing fraud, misuse and unauthorized access.
- Maintaining the security and operation of our services.
- Sending essential service and account communications.
- Meeting legal, accounting and regulatory obligations.
Our Privacy Policy explains the categories of information we collect, the legal grounds we rely upon, how long information is retained and the rights available to individuals.
Budgethost AB as data processor
Budgethost AB normally acts as a data processor when we store, transmit, back up or otherwise process personal data contained in a customer’s hosted services solely to provide those services according to the customer’s documented instructions.
In this situation, the customer normally acts as the data controller and is responsible for:
- Establishing a valid legal basis for the processing.
- Providing required information to affected individuals.
- Responding to requests from data subjects.
- Configuring and using the service appropriately.
- Giving lawful and documented instructions to Budgethost AB.
- Ensuring that the hosted service complies with applicable data protection laws.
The exact roles of each party depend on the relevant processing activity and contractual relationship.
Resellers and delegated access
Some customers receive or manage services through an authorized reseller.
The data protection roles of the customer, reseller and Budgethost AB depend on their respective responsibilities and contractual arrangements. Each party remains responsible for its own obligations as a controller or processor.
Customers may authorize team members or resellers to access selected organizations and workspaces through my.budgethost.io. Budgethost AB applies the configured role-based permissions, but customers and resellers are responsible for deciding who should receive access and for reviewing that access when responsibilities change.
Technical and organizational security measures
Budgethost AB applies technical and organizational measures appropriate to the nature of the services provided and the risks associated with processing personal data.
These measures include, where applicable:
- Role-based access controls and limited administrative permissions.
- Multi-factor authentication for supported portal accounts.
- Secure password hashing.
- Encryption of network communications using TLS.
- Logging of security-relevant and administrative activity.
- Service-health and operational monitoring.
- Backup and recovery procedures.
- Controlled software maintenance and security updates.
- Procedures for identifying, assessing and responding to security incidents.
Access to customer systems and personal data is limited to authorized persons who require access for service delivery, support, maintenance or security purposes.
Our security measures are reviewed and adjusted as our services, systems and identified risks change.
Only retain measures that are actually implemented across the services covered by the page.
Data location and international transfers
Data location and international transfers
Budgethost AB’s primary infrastructure for hosting customer services is located in Sweden.
The processing location of each subprocessor is identified in the subprocessor list below.
If personal data must be transferred outside the European Economic Area, Budgethost AB ensures that an appropriate transfer mechanism is in place. This may include an adequacy decision adopted by the European Commission or approved Standard Contractual Clauses together with any additional safeguards required by law.
Providers used by Budgethost AB for its own account administration, website analytics or payment processing are described in our Privacy Policy and Cookie Policy. Such providers are not necessarily subprocessors of customer-hosted data.
Processors and service providers
A processors or service providers is a third party engaged by Budgethost AB to process personal data on behalf of a customer when Budgethost AB is itself acting as a data processor.
Before appointing a subprocessor, Budgethost AB evaluates whether the provider offers sufficient data-protection and security guarantees. Subprocessors are contractually required to comply with data-protection obligations equivalent to those applying to Budgethost AB for the relevant processing.
At the time of the latest update, Budgethost AB does not engage any third-party subprocessors to process customer-hosted content.
| Provider | Country | Purpose | Data processed | Role |
|---|---|---|---|---|
| Realtime Register B.V. | Netherlands | Domain registration, renewal, transfer and communication with domain registries | Domain-holder and contact details, domain information and order metadata | Processor or subprocessor, depending on Budgethost’s role in the relevant customer relationship |
Infrastructure providers
The following provider supplies physical infrastructure used to operate Budgethost AB’s own systems. It is listed separately because it does not routinely access or process customer-hosted data on behalf of Budgethost AB.
| Provider | Country | Service | Data access |
|---|---|---|---|
| Ansluten Hosting i Sverige AB | Sweden | Physical colocation facilities, including equipment space, power, cooling and network connectivity. | No routine access to customer data or Budgethost AB systems. |
Changes to subprocessors
Where the applicable Data Processing Agreement provides general authorization to use subprocessors, Budgethost AB will inform affected customers before adding or replacing a subprocessor.
The notification will identify the provider, processing purpose and processing location. Customers may raise reasonable data-protection objections within the period stated in their Data Processing Agreement.
Personal-data breaches
Budgethost AB maintains procedures for identifying, investigating and responding to suspected personal-data breaches.
When Budgethost AB acts as a data processor, we notify the affected data controller without undue delay after becoming aware of a personal-data breach involving data processed on that controller’s behalf.
When Budgethost AB acts as a data controller, we assess whether the incident must be reported to the relevant supervisory authority. Where required by the GDPR, notification will be made without undue delay and, where feasible, within 72 hours after we become aware of the breach.
Affected individuals will be informed where required by applicable law.
Contact and related policies
Budgethost AB
Hulta 6525
SE-242 95 Hörby
Sweden
VAT number: SE559255575801
Email: info@budgethost.io
Privacy Policy: https://budgethost.io/privacy-policy/
Cookie Policy: https://budgethost.io/cookie-policy/
Swedish Authority for Privacy Protection: https://www.imy.se/

