All documents

DOUBLE SERVERS

Legal Information

Privacy Policy

This Policy describes what data DoubleServers collects when you use the https://doubleservers.com website, the control panel and the Telegram bot, why it is needed, how long it is retained, to whom it is disclosed and what rights you have.

1. Who Processes the Data

1.1. The data controller is DoubleServers, a virtual and dedicated server rental service. Contact for personal data matters: support@doubleservers.com (email subject — "Personal data") or a ticket in the control panel.

1.2. This Policy applies to the data of customers and website visitors. It does not extend to data that customers place on their servers: we do not view or process the contents of servers; the customer is responsible for them.

2. What Data We Collect

2.1. Account. Depending on the registration method:

  • when signing in via Telegram — Telegram identifier, first name, last name, username, avatar link; all of this is passed to us by Telegram with your consent at sign-in;
  • when registering by email — email address and password; the password is stored only as an irreversible hash (argon2); we do not see it in plain text and cannot recover it;
  • internal account identifier, registration date, interface language, whether two-factor authentication is enabled.

2.2. Payments: amount, currency, payment method, status, transaction identifier at the payment provider, date. Bank card data and account details do not reach us: they are processed by the payment provider on its side (see section 5). When paying with cryptocurrency, we receive the address and the transaction hash.

2.3. Services: parameters of ordered servers (plan, location, operating system), assigned IP addresses, IP address assignment history, server resource usage statistics (CPU, memory, disk, traffic) — needed for billing and infrastructure protection.

2.4. Technical information about interaction with the website and the control panel: IP address, date and time of the request, requested address, browser and device type; for authenticated requests — together with the account identifier. Account sign-in records (date, IP address, sign-in method, result) are kept for your own security.

2.5. Support requests: message texts, attachments, correspondence history; when contacting us via the Telegram bot — Telegram identifier.

2.6. Records of measures applied to an account or server (warnings, restrictions, blocks) with the reason indicated — we are obliged to keep these as a hosting provider.

2.7. Referral programme. If you signed up through someone else's link, the person who invited you sees the fact and date of your registration and your login in masked form (first two letters, the rest replaced by asterisks). Your full login, email address and any contact details are not disclosed to them. On the leaderboard, participants' names are masked the same way; each person sees their own name in full.

2.8. We do not collect children's data: the services are intended for persons over 18 years of age. We do not request or process special categories of data (health, beliefs, etc.).

3. Why the Data Is Needed and on What Basis

  • conclusion and performance of the agreement: registration, sign-in, provision and payment of services, support, service notifications (expiry, payment credited, restrictions) — basis: performance of the agreement with you;
  • security: protection against unauthorised access, detection and investigation of abuse, handling of complaints — basis: our legitimate interest in protecting the service and other customers;
  • compliance with legal obligations: retention of payment records for accounting purposes, responses to lawful requests from competent authorities, keeping records of moderation measures — basis: legal requirements;
  • service improvement and protection: usage statistics based on request logs (clause 2.4) — basis: legitimate interest; we do not build personal profiles for advertising and do not connect advertising networks.

3.2. We do not send marketing communications. All emails and messages from us are service-related and concern your account and services.

4. How Long the Data Is Retained

4.1. We retain data no longer than necessary for the purposes above, and we set the periods explicitly:

  • account and service data — for as long as the account is active; after deletion of the account at your request — up to 30 days to complete operations and allow backup recovery, then deleted;
  • payment and internal balance records — for the periods established by accounting legislation (as a rule, 5 to 10 years depending on the jurisdiction), since these are financial documents;
  • IP address assignment history and account sign-in records — up to 13 months; this is needed to answer lawful requests of the kind "who held this address at such-and-such time" and to investigate incidents;
  • records of moderation measures (restrictions, blocks and their reasons) — 3 years;
  • panel and API request log (IP address, time, address, account) — 120 days; web server logs — up to 12 months;
  • support correspondence — for as long as the account is active and 12 months after the ticket is closed;
  • anonymised statistics — indefinitely; identity cannot be recovered from them.

4.2. Backups of our systems are overwritten on a rolling basis; deleted data disappears from them within 30 days.

5. To Whom the Data Is Disclosed

5.1. We do not sell personal data and do not pass it on for third-party advertising. Data is received only by those without whom the service cannot be provided:

  • payment providers — for processing payments and refunds: Platega (SBP, bank cards), WATA (SBP) and Shkeeper (cryptocurrency). They receive what is needed for the payment: amount, order identifier; you enter card details on the provider's side and they do not reach us;
  • infrastructure providers on whose facilities the servers run: Hetzner Online GmbH (Germany, Finland), OVH SAS (France, Poland and others), Contabo GmbH (Germany), Hostup AB (Sweden), as well as our own infrastructure in European data centres. They receive only the technical data necessary to create and operate the server; your name, email and Telegram identifiers are not passed to them;
  • Telegram — when signing in via Telegram and when sending notifications to the Telegram bot;
  • email services — for delivering emails to the address you have specified;
  • competent authorities — only on the basis of a lawful, properly executed request, to the extent it requires (see the Acceptable Use Policy, section 5).

5.2. Data is stored on servers in the European Union. Part of the technical processing (protecting the website against attacks) is performed via network filters that see the IP address and the requested page address; account contents do not pass through them.

5.3. If the data controller is a person outside your country, your data may be processed in the jurisdiction of the controller. We ensure its protection to the extent described in section 6, regardless of the place of processing.

6. How the Data Is Protected

  • connections to the website, the control panel and the API — over HTTPS only;
  • account passwords are stored as an argon2 hash; the passwords of your servers that we display in the control panel are stored encrypted and decrypted only when shown to you;
  • access to data is limited to staff who need it for their work; administrator actions are logged;
  • two-factor authentication is available for accounts; it is mandatory for staff sign-in;
  • the service and infrastructure are protected by network filters; password-guessing attempts and suspicious sign-ins are automatically rate-limited.

6.2. There is no such thing as absolute protection. If a breach affecting your data occurs, we will notify you and, where required by law, the supervisory authority within the prescribed time limits.

7. Cookies and Local Storage

7.1. Only technically necessary means are used for the website to operate: a session cookie (a signed sign-in token inaccessible to page scripts), a record of the selected interface language and service data for protection against request forgery. Signing in to the control panel is impossible without them, so no separate consent is required for them.

7.2. We do not use third-party advertising or tracking cookies and do not connect external analytics counters. Visit statistics are built from the logs of our own server (clause 2.4).

7.3. When signing in via Telegram and when protecting forms, scripts of Telegram and, if enabled, the reCAPTCHA service may be loaded; their operation is governed by the policies of the respective services.

8. Your Rights

8.1. You have the right to:

  • obtain a copy of the data we hold about you;
  • rectify inaccurate data — email, name and linked Telegram can be changed by you in your profile;
  • delete your account and data — active services are then terminated, while records we are legally obliged to retain (payments, moderation measures) are kept until the established periods expire, in anonymised form where possible;
  • restrict processing or object to it where it is carried out on the basis of our legitimate interest;
  • receive your data in a machine-readable format (portability);
  • lodge a complaint with the data protection supervisory authority in your place of residence.

8.2. Send requests to support@doubleservers.com from the address linked to your account, or via a ticket in the control panel — this is how we verify that the request comes from the account owner. We respond within 30 days; if the request is complex, the period may be extended by a further 30 days with notice to you.

8.3. We do not make decisions producing legal effects concerning you solely on the basis of automated processing. Automatic restrictions (for example, upon detection of an attack from a server) can always be contested via support and are reviewed by a human.

9. Changes to This Policy

9.1. We may update this Policy. The current version and its effective date are always available at https://doubleservers.com/legal/privacy.

9.2. We notify you of material changes via the control panel, by email or in Telegram at least 7 days before they take effect. Continued use of the services after that date constitutes acceptance of the new version.

Last updated: 6 September 2026

DoubleServers · support@doubleservers.com · abuse@doubleservers.com