Controller
The controller of your personal data is the operator of ImperialHost.cc:
- Name
- Antonín Zelený
- Registered address
- Lichnická 378, 538 43 Třemošnice, Czech Republic
- Company ID (IČO)
- 23870796
- [email protected]
- Phone
- +420 737 072 669
We process data under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Czech Act No. 110/2019 Coll., on the Processing of Personal Data.
We have not appointed a data protection officer, as we are not required to. Please send any questions or requests to the email above.
This policy covers data about customers and website visitors. Data that customers store on their own servers is processed by us as a processor under section 17 of the terms of service.
What data we process
- Identification and contact details: name, email, and for companies the company name, company ID, VAT ID and address.
- Account data: password (stored only as a cryptographic hash), language, account currency, role, registration date.
- Service and payment data: orders, service parameters, IP addresses of assigned servers, invoices, credit movements, payment status. Card details are processed directly by the Stripe payment gateway; we never see them.
- Communication: the content of tickets and emails with support.
- Technical data: IP address and browser identification for sign-ins (sessions), security records.
We get this data directly from you when you register, order and communicate with us, and from the payment gateway (the result of a payment).
Providing the data needed to conclude the contract and issue documents is a contractual and legal requirement. Without it we cannot provide the services.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Registration, account management, setting up and running services, support, service communication | Performance of a contract – Art. 6(1)(b) GDPR |
| Receiving payments, issuing and archiving tax documents | Performance of a contract and legal obligation (VAT Act, Income Tax Act) – Art. 6(1)(b) and (c) |
| Securing accounts and infrastructure, preventing fraud and misuse of the services, handling abuse complaints | Legitimate interest – Art. 6(1)(f) |
| Debt collection and defence of legal claims | Legitimate interest – Art. 6(1)(f) |
| Meeting obligations towards public authorities | Legal obligation – Art. 6(1)(c) |
We do not send marketing messages and do not use the data for profiling or automated decisions that would have legal or similarly significant effects on you. If we want to send newsletters in the future, we will ask for your consent or let you opt out easily.
How long we keep data
- Account and services: for as long as the account exists. After it is closed we delete or anonymise the data within 30 days, except for the data below.
- Tax documents and the data on them: 10 years from the end of the year in which the supply took place (section 35 of the Czech VAT Act).
- Data needed to defend claims (orders, payments, communication): up to 4 years after the contract ends, in line with limitation periods.
- Sign-ins (IP address, browser): while the session is valid, at most 30 days.
- Password reset links: at most 1 day after they expire.
- Data on customer servers: deleted when the service ends.
Recipients and processors
We do not sell your data. We share it only as far as necessary with:
- Stripe Payments Europe, Ltd. (Ireland): card and wallet payments. Stripe is an independent controller of payment data; see the Stripe privacy policy.
- The data centre operator in Prague: hosting of the servers and infrastructure running the website, client area and services.
- Our email provider: sending service emails (invoices, password resets, ticket replies).
- Google Ireland Ltd.: Google Fonts loaded by the website and client area; loading them sends your IP address to Google.
- Valve Corporation / Cloudflare, Inc.: game images on the website load from the Steam CDN; loading them sends your IP address.
- Our accountant or tax advisor: keeping tax records, bound by confidentiality.
- Public authorities: only where the law requires it.
Our processors are bound by contracts that require them to protect the data and use it only for the purpose we shared it for.
Transfers outside the EU
We mainly process data within the European Union. Some recipients (Stripe, Google, Cloudflare, Valve) belong to groups based in the United States and may transfer data there. Such transfers rely on the European Commission’s adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses under Article 46 GDPR.
Security
Passwords are stored only as scrypt hashes, server credentials are encrypted (AES-256-GCM), all communication runs over encrypted HTTPS, and only the operator can access the data, to the extent needed to provide the services.
Sign-in and password reset are protected against repeated attempts. If a security breach poses a high risk to your rights, we will inform you without undue delay.
Your rights
You have the right to:
- access your data and get a copy (Art. 15 GDPR),
- rectify inaccurate data; you can correct most of it yourself in your client area profile (Art. 16),
- erasure where we no longer need the data and are not required by law to keep it (Art. 17),
- restrict processing (Art. 18),
- data portability of the data you gave us, in a machine-readable format (Art. 20),
- object to processing based on legitimate interest (Art. 21),
- lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.
Send your request by email to [email protected] or by ticket from the client area. We will handle it without undue delay and within one month at the latest. So that we do not disclose data to the wrong person, we may verify your identity, usually by asking you to write from your account email.
Changes
We may update this policy, for example when services, processors or the law change. We will tell you about significant changes in advance by email or in the client area.
This English translation is for information; in case of any discrepancy the Czech version prevails.
This policy is effective from 30 September 2026.
Questions about your data? Email [email protected].