GPU Server Hub Privacy Policy
Version 1.1 dated 9 September 2026
English translation revision EN-1
This document is an English translation provided for convenience. The Polish version 1.1 is binding. In the event of any discrepancy, the Polish version prevails, subject to the priority of an individually agreed Order and any mandatory provisions of law.
Public path on the Provider's website: /privacy-policy/
This Policy applies to the gpuserverhub.com, gpuserverhub.pl and gpuserverhub.eu websites, their www variants, the temporary gpu.bestconnect.pl website, sales and technical contact, and the data of individuals representing B2B customers. Data stored by the Customer on the rented Server is governed by the separate data processing terms in the Terms available at /terms/.
1. Controller
The controller is Janusz Ciuruś, conducting business under the business name BESTCONNECT CIURUŚ JANUSZ, Królówka 261, 32-722 Królówka, Poland, Polish Tax Identification Number (NIP) 8681799622, National Business Registry Number (REGON) 120967456, operating under the GPU Server Hub brand.
Contact for all data-related matters: contact@gpuserverhub.com.
2. Data we process
Depending on the contact and use of the website, we may process:
- first name, surname, position, business name, address, Polish Tax Identification Number (NIP) or EU VAT number and registration details;
- email address, telephone number and the content of correspondence and reports;
- Order, invoice, payment and Agreement history data;
- IP address, date and time of connection, requested resource, session identifier, browser type and security information;
- technical Service data, addressing, and failure, abuse, administrative access and intervention logs;
- data necessary to comply with a legal obligation or defend against a claim.
We do not request passwords, private keys or unnecessary special-category data to be sent by email.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| enquiry and offer for an individual conducting business in their own name | steps taken before entering into an Agreement — Article 6(1)(b) GDPR |
| contact with a representative, employee or User of a business | legitimate interest in communication and performance of the B2B relationship — Article 6(1)(f) GDPR |
| conclusion and performance of an Agreement with an individual conducting business in their own name | Article 6(1)(b) GDPR |
| invoices, VAT, KSeF, taxes and accounting | legal obligations — Article 6(1)(c) GDPR |
| security of the website, Servers and network, evidence of acceptance, fraud prevention, and establishment and enforcement of claims | legitimate interest — Article 6(1)(f) GDPR |
| handling a person reporting abuse and a person identified in the report | obligations under the DSA or other legislation — Article 6(1)(c); otherwise, legitimate interest in protecting the network and rights — Article 6(1)(f) |
| compliance with an order, the obligations of an electronic communications undertaking or a response to a competent authority | Article 6(1)(c) GDPR |
| contact concerning our own similar services | legitimate interest under Article 6(1)(f), with the right to object; communications requiring consent under separate legislation are sent only after consent has been obtained |
Our legitimate interests are the secure provision of B2B services, communication with persons representing the Customer, prevention of fraud, establishment of facts, and protection and enforcement of rights.
4. Sources of data
We obtain data directly from the contacting person or the Customer, from the operation of the website and infrastructure, from authorised Users, network operators, the bank, a credible person reporting abuse, and public registers of businesses and taxpayers.
If we did not obtain data directly from the relevant person, we provide that person with a link to this Policy no later than at first contact or within the period required by Article 14 GDPR. Information may be withheld only under a documented exception provided for by law.
5. Recipients
Data may be received, only to the extent necessary, by:
- authorised persons acting for Bestconnect;
- the bank, accounting provider, Polish National e-Invoice System (KSeF), legal advisers and authorities empowered by law;
- providers maintaining our own infrastructure and email, if engaged;
- Quicktel Sp. z o.o., operator of 4DataCenter, with respect to colocation, physical security and commissioned remote-hands interventions;
- telecommunications operators cooperating in traffic transmission and incident handling.
The current version of the website does not provide for third-party analytics, advertising, social networks, card payments or profiling. Before they are enabled, this Policy will be updated and any consent required for cookies will be obtained.
6. Transfers outside the EEA
Under the initial architecture, the website, Orders, email, control plane and security logs are maintained in Poland, and the Servers are located in Katowice. We do not plan to transfer data outside the EEA. Adding a provider or location in another country requires the information to be updated in advance; for a transfer outside the EEA, we will use a legal basis under Chapter V GDPR and make information about the safeguards available.
7. Retention periods
- enquiries that do not result in an Agreement — normally up to 12 months after the contact is closed;
- Agreement data, evidence of acceptance and service records — for the term of the Agreement and the limitation period for related claims; we limit the evidential register to the identifier, time, representation details, versions and SHA-256 hashes of documents, IP address, and normalised browser information needed to demonstrate the process;
- accounting and tax documents — for the period required by law, normally 5 years calculated under the applicable tax legislation;
- website, security and administrative-access logs — normally up to 12 months, and longer where they concern an incident, claim or legal obligation;
- abuse and incident reports — until the matter is closed and for the period necessary to defend rights or required by law;
- data based solely on consent — until consent is withdrawn, without affecting the lawfulness of earlier processing.
Retention of Customer Data on the Server is described in the Terms, including the export and provider-switching procedure.
8. Rights
Within the limits of the GDPR, a person has the right to:
- access their data and receive a copy;
- rectification;
- erasure or restriction of processing;
- data portability where applicable;
- object to processing based on legitimate interests, including direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting prior lawful processing;
- lodge a complaint with the President of the Polish Personal Data Protection Office: uodo.gov.pl.
A request may be sent to the contact address. We may request information necessary to verify identity securely.
9. Requirement to provide data
Providing data in an ordinary contact form is voluntary, but we cannot respond without return contact details. Identification, representation, contact and billing data required in an Order is necessary to conclude and perform the Agreement and comply with legal obligations.
10. Automated decisions
We do not make decisions about individuals that produce legal effects based solely on automated processing, and we do not profile them. Automated security signals may cause brief technical isolation, but a longer restriction of the Service is subject to human review in accordance with the Terms.
11. Cookies and browser storage
- The website uses only cookies or storage necessary for transmission, security, remembering the language selection and operation of the form.
- Necessary mechanisms cannot be disabled on the service side, but they may be removed in the browser; some functions may then not work.
- Analytics or marketing cookies will not be enabled before voluntary consent is obtained. Refusing them may not block an Order.
12. Security and roles in relation to the Server
We protect data using measures appropriate to the risk, including access restrictions, intervention logging, infrastructure safeguards and an incident procedure.
With respect to data that the Customer places on the Server, the Customer normally determines the purposes and means of processing, while Bestconnect acts as a processor solely with respect to the infrastructure layer. Details and the shared responsibility model are set out in the Data Processing Agreement forming part of the Terms.
13. Amendments to the Policy
We publish the current version at /privacy-policy/ on the Provider's website. We will notify the Customer by email of a material change affecting an ongoing Agreement. The version history remains available for download.