Legal & Compliance

GDPR & Privacy Compliance

How PowerDown Hosting protects your personal data and complies with GDPR, India's DPDPA, and applicable Nepalese privacy laws.

Last updated: August 2026 · PowerDown Hosting

GDPR CompliantDPDPA 2023 (India)Nepal Privacy ActPCI DSS PaymentsTLS 1.2+ Encrypted

Right to Access

View your data

Data Portability

Export your data

Right to Erasure

Delete your data

Contact Us

support@powerdown.in

1. Introduction

This GDPR & Privacy Compliance document explains how PowerDown Hosting ("we", "our", "us") handles personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679, applicable Indian data protection legislation including the Digital Personal Data Protection Act, 2023 (DPDPA), and relevant privacy laws applicable in Nepal. We are committed to protecting the privacy and rights of all individuals whose personal data we process, regardless of their location. Data Controller: PowerDown Hosting Contact: support@powerdown.in Website: https://powerdown.in Location: Indore, Madhya Pradesh, India

2. Lawful Basis for Processing

We only process your personal data when we have a lawful basis to do so. The legal bases we rely on are: Contractual Necessity (GDPR Article 6(1)(b)) We process your data to fulfil our contract with you — i.e., to provide the hosting services you have purchased. This includes order processing, account management, invoicing, and technical support. Legitimate Interests (GDPR Article 6(1)(f)) We process certain data based on our legitimate business interests, including: • Fraud detection and prevention • Network security monitoring • Improving our services • Abuse prevention Legal Obligation (GDPR Article 6(1)(c)) We may process data to comply with applicable laws, including responding to lawful requests from government authorities, tax obligations, and regulatory requirements under Indian and Nepalese law. Consent (GDPR Article 6(1)(a)) Where we rely on consent (e.g., marketing communications), you have the right to withdraw consent at any time without affecting the lawfulness of prior processing.

3. Personal Data We Collect

We collect only the minimum personal data necessary for our services: Identity & Contact Data • Full name, email address, mobile number • Company name (if applicable) • Billing address, country, state Financial & Transaction Data • Transaction ID, payment status, payment method, amount paid • GST/VAT number (where applicable) • Note: We do NOT store card numbers, CVV, OTP, or banking credentials Technical & Usage Data • IP address, browser type, operating system • Pages visited, session duration, referral URL • Server usage statistics Support Data • Support ticket content and communication history • Server access logs (for troubleshooting purposes) We do NOT collect: • Sensitive personal data (health, biometric, religious, political data) • Data from children under 18 years of age

4. Your Rights Under GDPR & DPDPA

Your Rights
Under the GDPR and India's Digital Personal Data Protection Act, 2023, you have the following rights: Right to Access (Article 15 GDPR / Section 11 DPDPA) You can request a copy of all personal data we hold about you. Right to Rectification (Article 16 GDPR) You can request correction of inaccurate or incomplete personal data. Right to Erasure / "Right to be Forgotten" (Article 17 GDPR / Section 12 DPDPA) You can request deletion of your personal data where: • The data is no longer necessary for its original purpose • You withdraw consent and no other legal basis exists • The data has been unlawfully processed Note: We may retain certain data to fulfil legal obligations. Right to Restrict Processing (Article 18 GDPR) You can request that we limit how we use your data in certain circumstances. Right to Data Portability (Article 20 GDPR) You can request a copy of your data in a structured, commonly used, machine-readable format. Right to Object (Article 21 GDPR) You can object to processing based on legitimate interests, including direct marketing. Right to Withdraw Consent You can withdraw consent for marketing communications at any time. Rights Under DPDPA (India) The Digital Personal Data Protection Act, 2023 grants Indian residents the right to access, correct, and erase personal data held by data fiduciaries. To exercise any of these rights, contact us at: support@powerdown.in

5. Cookies & Tracking

We use cookies and similar tracking technologies on our website. Essential Cookies (Always Active) Required for the website to function properly. These cannot be disabled. • Session management and login persistence • Security tokens and CSRF protection • Load balancing Functional Cookies • Remember language and regional preferences • Save user settings and preferences Analytics Cookies (with consent) • Understanding how visitors use our website • Improving user experience • Tracking page performance We do NOT use: • Advertising or behavioural targeting cookies • Third-party tracking for ad networks • Persistent fingerprinting techniques Managing Cookies You can control cookies through your browser settings. Disabling non-essential cookies will not affect your ability to use our services, but may affect website functionality.

6. Data Retention

We retain personal data only for as long as necessary: Active Accounts • Account and billing data: retained for the duration of the service relationship • Support communications: 2 years from the last interaction • Transaction records: 7 years (required by Indian tax laws — Income Tax Act, 1961) After Account Closure • Account data anonymized or deleted within 30 days of account closure • Billing records retained for 7 years (legal obligation) • Server data deleted within 5 days of service expiry (see Fair Usage Policy) Legal Hold • Data may be retained longer if required by law, regulation, or ongoing legal proceedings Data subjects in India and Nepal may request earlier deletion of non-legally-required data by contacting us at support@powerdown.in.

7. Data Sharing & Third Parties

We share personal data only where strictly necessary: Service Providers (Data Processors) • Payment gateways (Razorpay) — for processing transactions • Datacenter operators — for physical server infrastructure • Domain registrars — for domain management services • Email service providers — for transactional emails All service providers are bound by Data Processing Agreements (DPAs) and are required to implement appropriate security measures. Legal Disclosure We may disclose personal data when required by: • Court orders or subpoenas • Government or regulatory authority requests • Compliance with the IT Act, 2000 (India) or applicable Nepalese law • Prevention or detection of fraud or criminal activity We NEVER: • Sell personal data to third parties • Share data for advertising purposes • Transfer data to countries without adequate protection without appropriate safeguards

8. Data Security Measures

Secured
We implement comprehensive technical and organisational security measures: Technical Measures • SSL/TLS encryption for all data in transit (TLS 1.2+) • AES-256 encryption for sensitive data at rest • Password hashing using bcrypt (industry standard) • Firewalls and intrusion detection systems • Regular security patches and updates • Access controls with principle of least privilege • Secure HTTPS-only communications Organisational Measures • Staff access to personal data on a need-to-know basis • Confidentiality agreements for all team members • Incident response procedures Payment Security • PCI DSS-compliant payment processing via Razorpay • Card details never stored on our systems • Tokenised payment processing In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33/34.

9. International Data Transfers

PowerDown Hosting is based in India. If personal data is transferred internationally, we ensure appropriate safeguards are in place. For EU/EEA residents Data transfers are protected by: • Standard Contractual Clauses (SCCs) approved by the European Commission • Adequacy decisions where applicable • Explicit consent where required For Indian residents Data processing complies with the Digital Personal Data Protection Act, 2023 (DPDPA). Cross-border transfers follow prescribed rules under the Act. For Nepalese residents Data handling follows applicable Nepalese privacy regulations including the Privacy Act, 2075 and Electronic Transactions Act, 2063.

10. Children's Privacy

Our services are strictly intended for individuals aged 18 years and above. We do not knowingly collect, store, or process personal data of children under 18. If we become aware that we have inadvertently collected data from a minor, we will delete it immediately upon discovery. Parents or guardians who believe their child has provided us with personal data should contact us at support@powerdown.in immediately.

11. Data Protection Contact

PowerDown Hosting has designated a point of contact for all data protection and privacy matters. For GDPR requests, privacy complaints, or data subject rights requests: Email: support@powerdown.in Website: https://powerdown.in Address: PowerDown Hosting, Indore, Madhya Pradesh, India Response Time: We aim to respond to all data subject requests within 30 days. For complex requests, we may extend this period by a further 60 days, in which case we will notify you. EU Residents: EU residents may also lodge a complaint with their local data protection supervisory authority if they believe we have not handled their data correctly. Indian Residents: Complaints may be submitted to the Data Protection Board of India once established under the DPDPA, 2023.

12. Data Breach Response

Critical
In the event of a personal data breach, PowerDown Hosting will: Immediate Response (0–24 hours) • Identify and contain the breach • Assess the nature and scope of the breach • Engage our incident response team Notification (within 72 hours) • Notify relevant supervisory authorities (as required by GDPR Article 33) • Document all details of the breach • Assess risk to affected individuals Customer Notification • If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay • Notification will include: nature of the breach, categories of data involved, likely consequences, measures taken Post-Breach • Root cause analysis and remediation • Update security measures to prevent recurrence • File post-incident report To report a suspected data breach or security vulnerability: support@powerdown.in

13. Updates to This Policy

We may update this GDPR & Privacy Compliance document from time to time to reflect changes in: • Our data processing practices • Applicable laws and regulations • Our services and operations When we make material changes, we will: • Update the "Last Updated" date at the top of this page • Post a notice on our website for significant changes • Where required, notify you via email Continued use of our services after such changes constitutes acceptance of the updated policy. This document was last updated: August 2026

Privacy or GDPR request?

Contact us to exercise your data rights or for any privacy questions.

support@powerdown.in

Join Our Discord

Connect with our community of gamers and developers

Get instant support, share experiences, and stay updated with the latest news

Join Us On Discord
2026 VPS SaleLIMITED TIME
View Sale Plans