Privacy Policy

1. Introduction

Cloudnovi BV, trading under the KGB Hosting brand, is responsible for the account, support, security, billing, website and mobile-device data described in this policy. Cloudnovi BV is registered in Belgium under number 0727732404 (VAT BE0727732404).

This policy applies when you use the KGB Hosting website, customer panel, hosting services, support channels and mobile app.

2. Information We Collect

Account and billing data may include your name, username, email address, physical address, phone number, company and tax details, service and invoice records, and payment-related information. Payment providers may collect full payment credentials directly under their own privacy terms.

Service and support data may include server identifiers and status, resource usage, configurations, files, backups, schedules, console or activity records, security events, subusers, support tickets, replies and attachments.

The mobile app also handles a random device identifier, device name or model, operating system, app version, access times and notification preferences. If you enable Android support notifications, it registers a Firebase Cloud Messaging token and language preference. Authentication and security records can include IP address, user-agent, sign-in history and authentication-provider information.

3. How We Use Your Information

We use personal data for the following purposes:

  • To provide and maintain our service
  • To notify you about changes to our service
  • To allow you to participate in interactive features of our service
  • To provide support
  • To authenticate users, secure accounts and services, and prevent abuse
  • To deliver support-reply notifications that mobile-app users enable
  • To comply with legal obligations and protect our legal rights

4. Data Storage and Security

We use technical and organizational safeguards intended to protect personal data, including encrypted network connections and access controls. The mobile app uses the operating system's secure storage for its refresh token, temporary sign-in transaction and random device identifier. It receives only the result of a biometric check and does not receive or store a fingerprint or face template.

No system can guarantee absolute security. You are responsible for protecting access to your devices, account credentials and hosted services and for reporting suspected misuse promptly.

5. Third-party Disclosure

We do not sell or rent personal data or use the mobile app for third-party advertising. We share relevant data with infrastructure, security, communications, payment and professional service providers only where needed to operate KGB Hosting, meet legal obligations or protect users and the service.

Google Firebase Cloud Messaging processes a mobile-device token to deliver optional Android notifications. Other providers may act on our instructions or as independent controllers for their own services. If processing involves an international transfer, we use safeguards required by applicable data-protection law.

6. Cookies

We use strictly necessary cookies and browser storage to operate the website, remember your language choice, protect forms from abuse, and remember your cookie preferences. Optional analytics storage is used only if you choose to allow analytics.

You can accept, reject, or customize optional analytics storage in the cookie banner. You can reopen Cookie Settings from the footer at any time to change or withdraw your choice.

The mobile app does not use browser cookies. It stores language, theme, biometric-lock and notification preferences locally. A downloaded file may be placed temporarily in the app cache or passed to another app you choose when you use a share action.

NameProviderPurposeTypeDurationCategory
kgb_cookie_consent_v1KGB HostingStores your cookie preference.localStorageUntil cleared or changedNecessary
kgb_preferred_localeKGB HostingRemembers your language preference.Cookie and localStorageUp to 1 yearNecessary
kgb_latency_resultsKGB HostingCaches latency test results during your visit.sessionStorageCurrent browser sessionNecessary
_ga / _ga_*Google AnalyticsMeasures page views and website interactions when analytics is accepted.CookieSet by Google AnalyticsAnalytics
PostHog storagePostHogMeasures anonymous product and funnel events when analytics is accepted.Cookie/localStorageSet by PostHogAnalytics
Plausible analyticsPlausible / Cloudnovi analytics endpointMeasures anonymous website events when analytics is accepted.Script requestNo first-party tracking cookie expectedAnalytics
Cloudflare Turnstile signalsCloudflareProtects contact and waitlist forms from spam and automated abuse.Security processingManaged by CloudflareNecessary

7. Retention

When self-service account deletion succeeds, the operational account and authentication or access data are deleted or revoked. This includes sessions, API keys, mobile authorizations and push tokens, OAuth tokens and codes, passkeys, recovery tokens, SSH keys, linked sign-in accounts, saved payment methods and cart data.

Invoices, orders, services, payments, refunds, subscriptions, payment requests, tax and credit records, and the minimum billing identity snapshot required to interpret those records are retained for statutory VAT and accounting obligations. They are detached from the active account and kept until 31 December of the tenth year after deletion. Deletion can be temporarily blocked by owned resources, active services or subscriptions, unresolved financial items, disputes, legal holds, or unavailable mandatory retention storage; the deletion flow identifies the required next action.

Other data is kept only as long as needed for service delivery, account security, dispute handling and applicable legal duties. Retention varies by record type and requirement.

In the mobile app, the local refresh token is removed when the device authorization is revoked or you sign out, subject to operating-system behavior. The random device identifier and preferences may remain until you clear the app's data or uninstall it.

8. Your Rights

Depending on applicable law, you may request access, correction, deletion, restriction or portability of your personal data, object to certain processing, withdraw consent where processing relies on it, and complain to a competent data-protection authority.

Mobile-app users can disable support notifications, revoke authorized devices and sign out in Settings. Account owners can initiate and complete self-service deletion in the app or at https://panel.kgb-hosting.com/account-deletion without reinstalling the app. Submit other privacy requests through a verified KGB Hosting support ticket or email support@kgb-hosting.com.

9. Customer-hosted Content

For personal data a customer or its authorized users place on a hosted server, the customer's and Cloudnovi BV's responsibilities depend on the context and applicable law. Customers remain responsible for having a lawful basis and appropriate notices for personal data they choose to collect or host.

10. Changes to this Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the last modified date.

Last Modified: 10 September 2026
If you have questions about our privacy practices, send a verified support ticket or email support@kgb-hosting.com.