Skip to main content

Averonix Host is rolling out new hosting plans and server locations. See what is available

Averonix HostAveronix Host

Privacy Policy

What personal data we collect, why, where it is stored, and what rights you have.

Applies to: Website visitors, customers and their contacts.

Draft, pending professional review

This document is a working draft prepared for review by a qualified legal adviser. It is not legal advice, and it is not the final agreement. Highlighted passages mark positions that must be settled before publication.

1. Who is responsible

Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal, which determines how your personal data is handled. Where another entity issues your invoice, that entity processes the data required for that transaction.

Because we operate servers inside the European Union and the United Kingdom, our processing falls within the GDPR and the UK GDPR in respect of that processing, whatever your own location.

Placeholder, pending verification: DATA PROTECTION CONTACT AND ANY REQUIRED REPRESENTATIVE — TO BE CONFIRMED

2. What we collect

We collect only what the service requires:

  • Account data: name, email, phone, billing address, and for business accounts the company details and tax number required on an invoice.
  • Order and billing data: what you bought, invoices, payment records and payment method tokens. We never receive or store full card numbers.
  • Service data: domains, service records, resource usage and support tickets.
  • Technical data: IP addresses, login history and security logs, used to secure the service and investigate abuse.
  • Domain registrant data, which registries require and may publish subject to WHOIS privacy.

4. Who we share it with

Only where necessary: payment providers, domain registries and registrars, infrastructure and email delivery providers, our live chat provider Tawk.to, and professional advisers or authorities where legally required.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. Where you are a resident of a United States state whose law gives you an opt-out of sale or sharing, there is nothing to opt out of, because we do neither.

5. Where your data is stored

You choose your hosting region when you order. Your site and its contents are stored in that region. Account and billing records are held on our management systems, which are separate from your hosting region.

The law of the country your data sits in governs it. That is why the region you pick is a decision worth making deliberately rather than accepting a default:

Where we operate servers
CountrySitesLaw governing data stored there
NepalKathmanduIndividual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020)
AustraliaSydneyPrivacy Act 1988 (Cth) and the Australian Privacy Principles
IndiaMumbaiDigital Personal Data Protection Act 2023
SingaporeSingaporePersonal Data Protection Act 2012
CanadaBeauharnois, Montréal, Cambridge, TorontoPIPEDA and, because these sites are in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25
United StatesHillsboro, Oregon, Vint Hill, VirginiaUnited States federal law and applicable state law, including the Oregon Consumer Privacy Act
FranceParis, Roubaix, Gravelines, StrasbourgEU GDPR and the French Loi Informatique et Libertés
GermanyLimburg, FrankfurtEU GDPR and the German Bundesdatenschutzgesetz
ItalyMilanEU GDPR and the Italian Codice in materia di protezione dei dati personali
PolandWarsaw, OżarówEU GDPR and the Polish Personal Data Protection Act
United KingdomLondon, ErithUK GDPR and the Data Protection Act 2018

6. Sending data between countries

Choosing a region outside your own country means your data is transferred there. Where a transfer needs a legal mechanism, we apply one; we do not rely on your consent as the mechanism for routine hosting, because consent is a poor and revocable basis for infrastructure.

The mechanism depends on where the data starts and where it goes:

Transfer mechanisms
TransferMechanism
From the EU or EEA to a country without an adequacy decisionStandard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with a transfer impact assessment
From the United KingdomThe UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses
From AustraliaAustralian Privacy Principle 8, under which we remain accountable for the recipient's handling of the data
From New ZealandInformation Privacy Principle 12 of the Privacy Act 2020, which requires comparable safeguards at the destination
From SingaporeThe Transfer Limitation Obligation under the PDPA and the Personal Data Protection Regulations
From Canada, including QuebecPIPEDA accountability, and for Quebec residents a privacy impact assessment before the data leaves the province, as Law 25 requires
From IndiaThe Digital Personal Data Protection Act 2023 and any restrictions notified under it
From NepalThe confidentiality and consent duties under the Individual Privacy Act, 2075. Nepal operates neither an adequacy regime nor a standard-clauses regime, so a transfer out relies on your instruction to us and on the contractual protections in this policy and the Data Processing Addendum.
Between EU or EEA countries, or within one countryNo transfer mechanism is required

7. How long we keep it

Account and service data is retained while your account is active and for a period afterwards. Financial records are retained for the statutory period, which may be longer than the retention you request, and we will tell you when that is the reason we cannot delete something.

Placeholder, pending verification: RETENTION PERIODS PER DATA CLASS — TO BE CONFIRMED AGAINST NEPALESE AND AUSTRALIAN REQUIREMENTS

8. Your rights, by where you live

Everyone who deals with us can ask for a copy of their personal data, ask us to correct it, and ask us to delete it. Deletion is honoured except where we are legally required to retain records, in which case we tell you what is retained and why. Requests can be raised from the client area and we do not charge for them.

Beyond that baseline, your rights depend on where you live and which regulator hears a complaint:

Statutory rights and regulators
Where you liveLaw that appliesComplaints go to
NepalIndividual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020)Nepal has no dedicated data-protection authority. Claims under the Individual Privacy Act are brought through the courts.
AustraliaPrivacy Act 1988 (Cth), the Australian Privacy Principles, and the Notifiable Data Breaches scheme in Part IIICOffice of the Australian Information Commissioner (OAIC)
New ZealandPrivacy Act 2020, the Information Privacy Principles, IPP 12 on cross-border disclosure, and the notifiable privacy breach regime in Part 6Office of the Privacy Commissioner
SingaporePersonal Data Protection Act 2012, including the Data Breach Notification obligation and the Do Not Call provisionsPersonal Data Protection Commission (PDPC)
CanadaPersonal Information Protection and Electronic Documents Act (PIPEDA), and for Quebec residents the Act respecting the protection of personal information in the private sector as amended by Law 25Office of the Privacy Commissioner of Canada, and the Commission d'accès à l'information du Québec for Quebec residents
FranceGeneral Data Protection Regulation (EU) 2016/679 and Loi n° 78-17 du 6 janvier 1978 (Informatique et Libertés)Commission Nationale de l'Informatique et des Libertés (CNIL)
United Statesno single federal privacy statute. State privacy laws apply by residence, including the California Consumer Privacy Act as amended by the CPRA, and the consumer data protection acts of Virginia, Colorado, Connecticut, Utah, Oregon and Texasthe Federal Trade Commission under section 5 of the FTC Act, state Attorneys General, and the California Privacy Protection Agency

9. Additional rights under the GDPR and UK GDPR

If you are in the EU, the EEA or the UK, or your data is processed in one of our European regions, you also have the right to restrict processing, to object to processing carried out on the basis of our legitimate interests, and to receive your data in a portable, machine-readable format.

Where we process on the basis of consent, you can withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew, and it does not affect your service, because we never rely on consent to run the service itself.

You may lodge a complaint with your own supervisory authority. For France that is the CNIL; for the UK, the Information Commissioner's Office.

10. Automated decisions

Orders may be screened automatically for fraud. A screening result can delay provisioning, but it never terminates an account on its own: a person reviews anything that would refuse or cancel your order, and you can ask us to explain the outcome and to reconsider it.

11. If something goes wrong

If a breach affects your personal data we will tell you, and we will notify the relevant regulator where the law requires it. The deadlines differ by regime and we work to the shortest one that applies:

  • GDPR and UK GDPR: notification to the supervisory authority within 72 hours of becoming aware, where the breach is likely to result in a risk to individuals.
  • Australia: the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), for eligible data breaches likely to cause serious harm.
  • New Zealand: notifiable privacy breaches under Part 6 of the Privacy Act 2020.
  • Singapore: the mandatory Data Breach Notification obligation under the PDPA.
  • Canada: breaches of security safeguards presenting a real risk of significant harm, reportable under PIPEDA, and to the Commission d'accès à l'information under Law 25.
  • United States: state breach notification statutes, which vary by the residence of the affected individual.

12. Security

We use encryption in transit, encryption of sensitive stored data, access controls, audit logging and multi-factor authentication on administrative accounts. No system is perfectly secure, and we will not claim otherwise.

Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal.

Version and effective date are applied when the document is approved and published through the admin content module.