PLATFORM ERP Finance, CRM, HR, inventory, projects TALON Tickets, chat, knowledge base Webmail Email, calendar, contacts
SECURITY & IDENTITY VIGILANTE EDR for Windows endpoints Auris IAM-as-a-Service EU Auris Comply Compliance & audit trail NIS2/DORA
Featured Auris IAM Identity & Access Management One European control plane for adaptive MFA, federated SSO, and immutable audit trails. Explore →
COMPUTE Hosting Shared PHP/MySQL hosting on EU infrastructure VPS Virtual private servers
NETWORK & SECURITY Domains Domain registration & transfer Load Balancer Traffic balancing TLS Managed TLS certificates
STORAGE & DATABASE Object Storage S3-compatible EU storage Block Storage Block storage volumes Managed Databases Managed MySQL, PostgreSQL, MongoDB
MESSAGING & EMAIL Mailboxes Email hosting for business domains Go to console → cloud.altovar.net
DEVELOPMENT Web Development Web applications, SaaS & custom portals — from UI to production deploy. Software Development Custom software, API integrations, automations & scalable architectures for your business. IT & Systems On-site physical infrastructure, Dell PowerEdge servers, maintenance & systems support.
SECURITY & CONSULTING Cybersecurity Penetration testing, vulnerability assessment, incident response & NIS2/DORA/GDPR compliance. IT Consulting Technology roadmap, infrastructure audit & strategic advisory for CTOs and decision makers.
GROWTH & INNOVATION Marketing Digital strategy, SEO, campaigns, brand identity & EU-focused content marketing. Artificial Intelligence AI integration, autonomous agents & intelligent systems for enterprise processes. Machine Learning Custom models, data pipelines & bespoke ML solutions for your industry.
01 NIS2 & DORA

EU compliance for critical infrastructure — audit trail, encryption, incident reporting.

Explore →
02 MSP

Multi-tenant management, PULSE, Vigilante & Citadel in a single console.

Explore →
03 Enterprise

Operational security, IAM, office suite & EU infrastructure for large organisations.

Explore →
04 Research

Threat intelligence, R&D & advanced tools for European security teams.

Explore →
COMPANY CompanyCareersNewsContacts
TRUST Partner ProgramTrust & SecurityRoadmapPress / Media
Log in Request Demo
PLATFORM ERPFinance, CRM, HR, inventory, projectsTALONTickets, chat, knowledge baseWebmailEmail, calendar, contacts
SECURITY & IDENTITY VIGILANTEEDR for Windows endpointsAurisIAM-as-a-Service EUAuris ComplyCompliance & audit trail NIS2/DORA
COMPUTE HostingShared PHP/MySQL hosting on EU infrastructureVPSVirtual private servers
NETWORK & SECURITY DomainsDomain registration & transferLoad BalancerTraffic balancingTLSManaged TLS certificates
STORAGE & DATABASE Object StorageS3-compatible EU storageBlock StorageBlock storage volumesManaged DatabasesManaged MySQL, PostgreSQL, MongoDB
MESSAGING & EMAIL MailboxesEmail hosting for business domains
DEVELOPMENT Web DevelopmentWeb applications, SaaS & custom portals — from UI to production deploy.Software DevelopmentCustom software, API integrations, automations & scalable architectures for your business.IT & SystemsOn-site physical infrastructure, Dell PowerEdge servers, maintenance & systems support.
SECURITY & CONSULTING CybersecurityPenetration testing, vulnerability assessment, incident response & NIS2/DORA/GDPR compliance.IT ConsultingTechnology roadmap, infrastructure audit & strategic advisory for CTOs and decision makers.
GROWTH & INNOVATION MarketingDigital strategy, SEO, campaigns, brand identity & EU-focused content marketing.Artificial IntelligenceAI integration, autonomous agents & intelligent systems for enterprise processes.Machine LearningCustom models, data pipelines & bespoke ML solutions for your industry.
01NIS2 & DORAEU compliance for critical infrastructure — audit trail, encryption, incident reporting.02MSPMulti-tenant management, PULSE, Vigilante & Citadel in a single console.03EnterpriseOperational security, IAM, office suite & EU infrastructure for large organisations.04ResearchThreat intelligence, R&D & advanced tools for European security teams.
COMPANY CompanyCareersNewsContacts
TRUST Partner ProgramTrust & SecurityRoadmapPress / Media
Log in → Request Demo
CONTENTS 01 Purpose of This Page 02 Controller / Processor Role Allocation 03 EU Data Residency & Hosting Position 04 Data Processing Agreement Availability 05 Subprocessor Governance 06 Technical & Organisational Measures 07 Data Subject Rights & Customer Assistance 08 Incident Handling & Breach Notification 09 International Transfers & Safeguards 10 Customer Responsibilities & Shared Responsibility
Privacy Policy →Cookie Policy →Legal Notices →
LEGAL · DATA PROTECTION

Data Processing& GDPR

Last updated: 2026-05-04 · Version 1.0

Jurisdiction: GDPR 2016/679 · European Union

TABLE OF CONTENTS
01 Purpose of This Page 02 Controller / Processor Role Allocation 03 EU Data Residency & Hosting Position 04 Data Processing Agreement Availability 05 Subprocessor Governance 06 Technical & Organisational Measures 07 Data Subject Rights & Customer Assistance 08 Incident Handling & Breach Notification 09 International Transfers & Safeguards 10 Customer Responsibilities & Shared Responsibility
Privacy Policy →Cookie Policy →Legal Notices →
Procurement-facing GDPR summary

This page is the operational overview we expect privacy, security, procurement, and legal teams to read first. It complements the Privacy Policy and any executed DPA; it does not replace either of them.

01 Compliance summary

Purpose of This Page

This page summarises Altovar's public GDPR and data-processing posture for procurement, legal, security, and privacy review. It is designed to answer the recurring questions raised during vendor onboarding, due diligence, and security assessments.

It complements — and does not replace — the Privacy Policy, Cookie Policy, Terms of Service, and any executed Data Processing Agreement (DPA).
02 Art. 4 & 28 GDPR

Controller / Processor Role Allocation

Altovar as controller: For personal data collected through our website, sales motions, account administration, invoicing, support correspondence, and marketing preferences, Altovar acts as an independent data controller.

Altovar as processor: Where a customer uses Altovar services to store, analyse, transmit, or otherwise process personal data on that customer's behalf, Altovar acts as processor and the customer remains controller unless a different allocation is defined in the contract or service architecture.

Role allocation is further specified in the applicable Order Form, service documentation, and DPA.
03 Art. 5 & 44 GDPR

EU Data Residency & Hosting Position

Altovar is established in Europe and designs its infrastructure strategy to preserve EU jurisdictional control, low transfer risk, and operational transparency.

Our standard service posture is EU-hosted. Primary application workloads, databases, backups, and operational systems are selected to keep production data inside the EEA wherever the product architecture allows. Where edge-delivery or support tooling introduces a third-country touchpoint, Altovar applies documented safeguards and limits access to the minimum necessary scope.
04 Art. 28 GDPR

Data Processing Agreement Availability

Altovar provides a Data Processing Agreement for processor scenarios. For Business and Enterprise arrangements, DPA language may be embedded in the Order Form or master services agreement. For other customers, a standard DPA is available on request.

The DPA covers processing instructions, confidentiality, subprocessors, security measures, breach notification, assistance with data-subject rights, deletion / return of data, and audit cooperation within commercially reasonable boundaries.

Requests for a DPA or contract addendum can be sent to [email protected].
05 Vendor oversight

Subprocessor Governance

Altovar uses a controlled vendor review process for infrastructure, payments, communications, and supporting security services. Each processor or subprocessor is evaluated for technical fit, jurisdictional implications, security controls, contractual coverage, and incident-response maturity before production use.

Subprocessors are bound by written contracts that reflect GDPR Article 28 requirements where applicable. Altovar maintains an internal register of subprocessors and provides notice of material changes through the contractual mechanisms defined in the DPA or customer agreement.
06 Art. 32 GDPR

Technical & Organisational Measures

Altovar applies layered technical and organisational measures appropriate to the sensitivity of the workload and the service tier involved. These measures typically include access control, least-privilege administration, MFA on internal systems, encrypted transport, encrypted storage where relevant, audit logging, vulnerability management, backup controls, and environment segregation.

Our measures are reviewed as products evolve. Where a customer requires a TOMs summary for procurement or audit purposes, Altovar can provide a current overview under NDA or as part of the DPA / security review workflow.
07 Art. 12–23 GDPR

Data Subject Rights & Customer Assistance

When Altovar acts as controller, we respond directly to access, rectification, deletion, objection, portability, and restriction requests in line with our Privacy Policy.

When Altovar acts as processor, we assist the customer — within the capabilities of the service and the contractual framework — so the customer can meet its own obligations toward data subjects. This may include export support, deletion workflows, access logging, or operational coordination through support and privacy channels.
08 Art. 33–34 GDPR

Incident Handling & Breach Notification

Altovar operates incident-management procedures for security, availability, confidentiality, and integrity events affecting customer or corporate data.

Where Altovar acts as processor and becomes aware of a personal-data breach affecting customer data, we notify the customer without undue delay so the customer can assess any supervisory-authority or data-subject notification obligations. Where Altovar acts as controller, we assess and handle notification duties directly in accordance with GDPR and applicable national law.
09 Chapter V GDPR

International Transfers & Safeguards

Altovar does not position third-country transfers as a default operating model. If a specific service dependency, support flow, or edge-delivery function creates a transfer scenario, Altovar relies on an identified legal transfer mechanism and proportionate supplementary measures before production use.

Depending on the vendor and processing context, these safeguards may include adequacy decisions, Standard Contractual Clauses, access minimisation, encryption, and transfer-impact assessment work.
10 Shared accountability

Customer Responsibilities & Shared Responsibility

GDPR compliance is not achieved by vendor posture alone. Customers remain responsible for choosing an appropriate legal basis, configuring their environments lawfully, setting retention rules consistent with their obligations, and giving valid instructions for processor scenarios.

Altovar provides the contractual and technical scaffolding required for compliant use, but each customer remains accountable for the way it uses the service in its own context, including employee access, uploaded content, retention choices, and third-party integrations.
DATA PROTECTION

NEED A DPA?WE HAVE IT READY.

If your procurement flow needs a DPA, TOMs summary, subprocessor confirmation, or security questionnaire routing, contact our privacy channel directly.

REQUEST DPA →
DPA Available on request
EU HOSTING Europe
DSAR SLA 30 calendar days
BREACH NOTICE Without undue delay

EU-sovereign stack for MSPs and enterprises. Security, cloud, productivity, and AI. A single European platform.

All products →
Cloud ↳VPS ↳Hosting ↳Object Storage ↳Managed Databases ↳Domains
Services ↳Cybersecurity ↳Web & Software Dev ↳IT & Systems ↳Marketing ↳AI & ML
Company ↳About Us ↳Careers ↳News ↳Contacts
Trust ↳Partner Program ↳Trust & Security ↳Roadmap ↳Press / Media
FORGED IN EUROPE. FOR EUROPE.
© 2026 Altovar · VAT IT03086750993 · ALL RIGHTS RESERVED
Privacy Policy · Cookie Policy · Terms of Service · Legal Notices · Data Processing & GDPR ·
TRUST & TRANSPARENCY
This website runs on green hosting - verified by thegreenwebfoundation.org GDPR COMPLIANT WCAG 2.2 AA — W3C Web Content Accessibility Guidelines, level AA
ALTOVAR
Cookies & tracking

We use technical cookies to keep the site running. With your consent we also use analytics and marketing cookies to improve the product. You can change your mind at any time.

Read the privacy policy →
Cookies & tracking

We use technical cookies to keep the site running. With your consent we also use analytics and marketing cookies to improve the product. You can change your mind at any time.

01
Necessary Always on

Required for the site to work (login, preferences, security). Always on.

02

Help us understand how the site is used, in aggregate and anonymous form.

03

Let us measure how well our campaigns perform. Off by default.

Read the privacy policy →