Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal.
Version and effective date are applied when the document is approved and published through the admin content module.
Averonix Host is rolling out new hosting plans and server locations. See what is available
What personal data we collect, why, where it is stored, and what rights you have.
Applies to: Website visitors, customers and their contacts.
Draft, pending professional review
This document is a working draft prepared for review by a qualified legal adviser. It is not legal advice, and it is not the final agreement. Highlighted passages mark positions that must be settled before publication.
Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal, which determines how your personal data is handled. Where another entity issues your invoice, that entity processes the data required for that transaction.
Because we operate servers inside the European Union and the United Kingdom, our processing falls within the GDPR and the UK GDPR in respect of that processing, whatever your own location.
Placeholder, pending verification: DATA PROTECTION CONTACT AND ANY REQUIRED REPRESENTATIVE — TO BE CONFIRMED
We collect only what the service requires:
Every use below has a purpose and, where the GDPR or UK GDPR applies, a legal basis under Article 6. We do not process personal data for a purpose you would not expect from the list here.
| What we do | Why | Basis where the GDPR applies |
|---|---|---|
| Provide, configure and support the service | You asked us to host something | Performance of a contract |
| Invoice you and collect payment | You bought a service | Performance of a contract |
| Keep financial and tax records | Statutory record-keeping | Legal obligation |
| Meet registry and ICANN requirements for domains | A registry requires it | Legal obligation, and performance of a contract |
| Detect and prevent fraud and abuse | Protecting our network and other customers | Legitimate interests |
| Secure the platform and investigate incidents | Protecting you and us | Legitimate interests |
| Send marketing | Only where you asked for it | Consent, withdrawable at any time |
You choose your hosting region when you order. Your site and its contents are stored in that region. Account and billing records are held on our management systems, which are separate from your hosting region.
The law of the country your data sits in governs it. That is why the region you pick is a decision worth making deliberately rather than accepting a default:
| Country | Sites | Law governing data stored there |
|---|---|---|
| Nepal | Kathmandu | Individual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020) |
| Australia | Sydney | Privacy Act 1988 (Cth) and the Australian Privacy Principles |
| India | Mumbai | Digital Personal Data Protection Act 2023 |
| Singapore | Singapore | Personal Data Protection Act 2012 |
| Canada | Beauharnois, Montréal, Cambridge, Toronto | PIPEDA and, because these sites are in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25 |
| United States | Hillsboro, Oregon, Vint Hill, Virginia | United States federal law and applicable state law, including the Oregon Consumer Privacy Act |
| France | Paris, Roubaix, Gravelines, Strasbourg | EU GDPR and the French Loi Informatique et Libertés |
| Germany | Limburg, Frankfurt | EU GDPR and the German Bundesdatenschutzgesetz |
| Italy | Milan | EU GDPR and the Italian Codice in materia di protezione dei dati personali |
| Poland | Warsaw, Ożarów | EU GDPR and the Polish Personal Data Protection Act |
| United Kingdom | London, Erith | UK GDPR and the Data Protection Act 2018 |
Choosing a region outside your own country means your data is transferred there. Where a transfer needs a legal mechanism, we apply one; we do not rely on your consent as the mechanism for routine hosting, because consent is a poor and revocable basis for infrastructure.
The mechanism depends on where the data starts and where it goes:
| Transfer | Mechanism |
|---|---|
| From the EU or EEA to a country without an adequacy decision | Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with a transfer impact assessment |
| From the United Kingdom | The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses |
| From Australia | Australian Privacy Principle 8, under which we remain accountable for the recipient's handling of the data |
| From New Zealand | Information Privacy Principle 12 of the Privacy Act 2020, which requires comparable safeguards at the destination |
| From Singapore | The Transfer Limitation Obligation under the PDPA and the Personal Data Protection Regulations |
| From Canada, including Quebec | PIPEDA accountability, and for Quebec residents a privacy impact assessment before the data leaves the province, as Law 25 requires |
| From India | The Digital Personal Data Protection Act 2023 and any restrictions notified under it |
| From Nepal | The confidentiality and consent duties under the Individual Privacy Act, 2075. Nepal operates neither an adequacy regime nor a standard-clauses regime, so a transfer out relies on your instruction to us and on the contractual protections in this policy and the Data Processing Addendum. |
| Between EU or EEA countries, or within one country | No transfer mechanism is required |
Account and service data is retained while your account is active and for a period afterwards. Financial records are retained for the statutory period, which may be longer than the retention you request, and we will tell you when that is the reason we cannot delete something.
Placeholder, pending verification: RETENTION PERIODS PER DATA CLASS — TO BE CONFIRMED AGAINST NEPALESE AND AUSTRALIAN REQUIREMENTS
Everyone who deals with us can ask for a copy of their personal data, ask us to correct it, and ask us to delete it. Deletion is honoured except where we are legally required to retain records, in which case we tell you what is retained and why. Requests can be raised from the client area and we do not charge for them.
Beyond that baseline, your rights depend on where you live and which regulator hears a complaint:
| Where you live | Law that applies | Complaints go to |
|---|---|---|
| Nepal | Individual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020) | Nepal has no dedicated data-protection authority. Claims under the Individual Privacy Act are brought through the courts. |
| Australia | Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Notifiable Data Breaches scheme in Part IIIC | Office of the Australian Information Commissioner (OAIC) |
| New Zealand | Privacy Act 2020, the Information Privacy Principles, IPP 12 on cross-border disclosure, and the notifiable privacy breach regime in Part 6 | Office of the Privacy Commissioner |
| Singapore | Personal Data Protection Act 2012, including the Data Breach Notification obligation and the Do Not Call provisions | Personal Data Protection Commission (PDPC) |
| Canada | Personal Information Protection and Electronic Documents Act (PIPEDA), and for Quebec residents the Act respecting the protection of personal information in the private sector as amended by Law 25 | Office of the Privacy Commissioner of Canada, and the Commission d'accès à l'information du Québec for Quebec residents |
| France | General Data Protection Regulation (EU) 2016/679 and Loi n° 78-17 du 6 janvier 1978 (Informatique et Libertés) | Commission Nationale de l'Informatique et des Libertés (CNIL) |
| United States | no single federal privacy statute. State privacy laws apply by residence, including the California Consumer Privacy Act as amended by the CPRA, and the consumer data protection acts of Virginia, Colorado, Connecticut, Utah, Oregon and Texas | the Federal Trade Commission under section 5 of the FTC Act, state Attorneys General, and the California Privacy Protection Agency |
If you are in the EU, the EEA or the UK, or your data is processed in one of our European regions, you also have the right to restrict processing, to object to processing carried out on the basis of our legitimate interests, and to receive your data in a portable, machine-readable format.
Where we process on the basis of consent, you can withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew, and it does not affect your service, because we never rely on consent to run the service itself.
You may lodge a complaint with your own supervisory authority. For France that is the CNIL; for the UK, the Information Commissioner's Office.
Orders may be screened automatically for fraud. A screening result can delay provisioning, but it never terminates an account on its own: a person reviews anything that would refuse or cancel your order, and you can ask us to explain the outcome and to reconsider it.
If a breach affects your personal data we will tell you, and we will notify the relevant regulator where the law requires it. The deadlines differ by regime and we work to the shortest one that applies:
We use encryption in transit, encryption of sensitive stored data, access controls, audit logging and multi-factor authentication on administrative accounts. No system is perfectly secure, and we will not claim otherwise.
Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal.
Version and effective date are applied when the document is approved and published through the admin content module.