Skip to content

GDPR & Data Protection

Last updated: 30 June 2026

This statement explains how Vastrox complies with the EU General Data Protection Regulation (GDPR) and the UK GDPR. It supplements our Privacy Policy.

1. Roles

For the personal data of our account holders, Vastrox acts as a data controller. Where you use our Services to process personal data of your own end users (for example, visitors to a website you host), you are the controller and Vastrox acts as your data processor.

2. Your rights

If you are in the EU/EEA or the UK, you have the right to access, rectify, erase, restrict and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time. To exercise these rights, contact privacy@vastrox.com. We respond to verified requests within one month.

3. Lawful bases

We process personal data on the bases of contract performance, legitimate interests (security and fraud prevention), legal obligation, and consent (for optional marketing and analytics cookies). See the Privacy Policy for detail.

4. Sub-processors and transfers

We use vetted sub-processors (payment, infrastructure, security and email providers) under data processing agreements. Personal data is processed primarily in the EEA/UK. Where transfers outside these regions occur, we rely on Standard Contractual Clauses or an adequacy decision.

5. Data Processing Agreement

Business customers who act as controllers and require a Data Processing Agreement (DPA) can request one from privacy@vastrox.com.

6. Breach notification

In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals without undue delay.

7. Complaints

You have the right to lodge a complaint with your local data protection authority. We would, however, appreciate the chance to address your concerns first — please contact privacy@vastrox.com.