Privacy Policy
1. Controller
MackNet Sàrl, 65, rue des Bruyères, L-1274 Howald, Luxembourg, telephone +352 2021 2025, e-mail privacy@macknet.eu, is the controller for the processing described in this Privacy Policy unless MackNet acts only as a processor for a customer. MackNet has not designated a Data Protection Officer; privacy enquiries and requests may be sent to privacy@macknet.eu.
2. Data we process
- Name, first name, company, language, e-mail, postal address and telephone number.
- Account, order, contract, domain, KYC and billing information. Stripe processes payment-method data.
- IP addresses, browser/device, authentication, security, usage and system logs.
- E-mail correspondence, support tickets and remote-support records.
- Customer-selected data stored in hosting, cloud, S3, backup and managed systems.
3. How we obtain personal data
Most personal data is obtained directly from you or from the customer or organisation you represent. Depending on the service and context, MackNet may also obtain personal data from your employer or organisation, MackNet customers and their authorised contacts, domain registries or registrars, service providers, and public business or company registers. Where personal data is obtained indirectly, the categories of data generally correspond to those described in section 2, and MackNet provides the information required by applicable data protection law within the applicable timeframe.
4. Purposes and legal bases
| Purpose | Legal basis |
| Provide and administer services | Performance of contract and pre-contract steps |
| Billing, accounting, tax and legal records | Legal obligations and performance of contract |
| KYC, domain registration and abuse handling | Contract, legal/registry obligations and legitimate interests in fraud/abuse prevention and accurate service administration |
| Security, fraud prevention, monitoring and incident response | Legal obligations and legitimate interests in protecting MackNet systems, services, customers and third parties |
| Support and customer communication | Contract and legitimate interests in effective support, service administration and customer relationship management |
| Website contact form and reCAPTCHA | Legitimate interests in responding to enquiries and preventing automated abuse; consent where legally required |
| Plausible analytics | Legitimate interests in privacy-friendly aggregate website analysis; self-hosted without analytics cookies |
5. Website technologies
MackNet uses a self-hosted Plausible instance for aggregate analytics without analytics cookies. Google reCAPTCHA is active on the contact form to prevent automated fraud and abuse and may process device, application and other technical information for that purpose and for service security. Google currently processes reCAPTCHA customer data as a processor. Necessary platform authentication and session technologies may also be used. A separate cookie notice shall describe any non-essential cookies or similar technologies if introduced.
6. Recipients and processors
Depending on the service, recipients or processors may include Gcore, EuroDNS, Restena/DNS-LU, Stripe, Auth0, Microsoft, ModernX, GitLab, Odoo, Datadog, Twingate, 1Password, TeamViewer, WebPros/Monitoring360, PagerDuty, Synology, OVH and Google for reCAPTCHA, as well as professional advisers and competent authorities where required. A current subprocessor list is available on request or through the customer documentation.
7. International transfers
MackNet configures its listed service environments for EU processing where available. Some providers or support operations may involve access or transfers outside the EEA. In such cases MackNet uses an applicable adequacy decision, Standard Contractual Clauses or another lawful transfer safeguard. Information about the applicable safeguard and, where available, a copy of the relevant safeguard may be requested at privacy@macknet.eu.
8. Retention
| Data | Typical retention |
| Invoices/accounting | 10 years |
| Contracts/orders | 10 years after termination |
| Inactive platform account | Disabled at termination; deleted/anonymised after 5 years |
| Support tickets | 5 years |
| Normal logs | 15 days |
| Security logs | 90 days where feasible |
| Incident evidence | 10 years |
| Operational backups | 30 days |
| Server-room video | 30 days; incident extracts may be retained longer |
| Prospect data | Up to 3 years after last contact |
| Domain data | According to registry and legal requirements |
9. Customer service content
Where a customer places personal data in hosting, cloud, S3, backups, e-mail or managed systems, the customer generally determines the purposes and is controller. MackNet processes the data under the Customer DPA. MackNet may have technical or root-level access but uses it only to provide, secure and support the service or comply with law.
10. Data provision and consequences of not providing data
Certain identification, contact, billing, payment and service-configuration data is necessary to enter into or perform a contract with MackNet. KYC, domain-registration or similar information may also be required by law, registry rules or contractual obligations. If required information is not provided, MackNet may be unable to create or maintain an account, register or renew a domain, provide or support a service, process payment, issue an invoice, or comply with applicable legal or registry requirements.
11. Automated decision-making and profiling
MackNet does not use solely automated decision-making, including profiling, that produces legal effects concerning an individual or similarly significantly affects an individual.
12. Rights
Subject to the GDPR, you may request access, rectification, erasure, restriction and data portability, and you may object to processing, in particular where processing is based on legitimate interests. Where processing is based on consent, you may withdraw that consent at any time with future effect without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with the Luxembourg National Commission for Data Protection (CNPD). Requests may be sent to privacy@macknet.eu.
13. Security and breaches
MackNet uses access controls, MFA, encryption, network segmentation, monitoring, backups and incident procedures. No system can be guaranteed completely secure. Suspected privacy or security incidents may be reported to security@macknet.eu or privacy@macknet.eu.
14. Changes
MackNet may update this policy to reflect changes to services, suppliers, processing activities or legal requirements. The “Last updated” date will be changed when this policy is revised, and material changes will be communicated where required by law.
Updated on 01.08.2026