Nephelo
WordPress HostingA separate server for every siteWooCommerce HostingFast, secure online storesLanding Page HostingIdeal for campaignsLaravel HostingComing soon · for developers
LiveSee the dashboardEvery one of your clients' sites in a single dashboard.Open
For agenciesMany client sites, one dashboardFor freelancersYou set the price your client pays
Free migration
Features
Pricing
Log inStart free
HostingWordPress HostingWooCommerce HostingLanding Page HostingLaravel Hosting Coming soonWho it's forFor agenciesFor freelancersFree migrationFeaturesPricing
Log inStart free
Legal · Nephelo

Privacy Policy

Last updated: 19 August 2026Applies to the Nephelo service · DL Software L.P.
This policy explains in plain language what data we process, why we need it and what rights you have. The items marked for confirmation must be verified before publication.

Contents
  1. Who is responsible for your data
  2. What data we collect
  3. Why we use the data
  4. Cookies and local storage
  5. Providers and sub-processors
  6. Location and international transfers
  7. How long we keep data
  8. Your rights
  9. Complaint to the supervisory authority
  10. Security
  11. Changes to this policy
  12. Contact and data requests
Contents
  1. Who is responsible for your data
  2. What data we collect
  3. Why we use the data
  4. Cookies and local storage
  5. Providers and sub-processors
  6. Location and international transfers
  7. How long we keep data
  8. Your rights
  9. Complaint to the supervisory authority
  10. Security
  11. Changes to this policy
  12. Contact and data requests

01 Who is responsible for your data

DL Software L.P., the company providing the Nephelo service, is the data controller for your account data, billing, communications and the operation of the platform.

The controller is DL Software L.P., a limited partnership trading as DL Software, VAT number 802945681, GEMI number 185924103000 and EUID ELGEMI.185924103000. Its registered office is at 13 Doiranis Street, Kypseli, 113 62 Athens, Greece.

For personal data you store inside your sites, email or your clients' databases, you or your client determine the purpose of the processing. In that case Nephelo acts as a processor and follows your lawful instructions.

This policy covers nephelo.gr, your account, the management dashboard, the public forms and the provision of the service.

02 What data we collect

We collect only the data needed to create your account, provide the service, keep it secure and communicate with you.

  • Account details: name, email, a password stored as an irreversible hash, teams, roles and security settings.
  • Billing details: company name, VAT number, address, country, plan, invoices and transaction identifiers.
  • Service details: domains, site and server settings, email accounts, resource usage, management actions and support requests.
  • Contact details: whatever you submit through the contact, agency partnership or waiting list forms, such as phone number, website and message.
  • Technical data: IP address, device and browser type, connection time, log files, security events and diagnostic information.
  • Hosted data: files, databases, backups, email accounts and correspondence. This data is stored on the isolated server of the relevant site, and we process it only to provide the service and in accordance with your instructions.

We neither receive nor store your full card number or security code. Those are submitted directly to the payment provider.

03 Why we use the data

Every processing activity rests on a specific purpose and a lawful basis.

  • Performance of a contract: for registration, identification, hosting, technical support, site migration, and managing your subscription and payments.
  • Legal obligation: for tax records, invoices, accounting obligations and responding to lawful requests from authorities.
  • Legitimate interest: for security, preventing fraud and abuse, diagnosing problems, improving the service and protecting legal claims.
  • Consent: when you sign up for optional updates, or when you choose to enable non-essential tools such as Google Analytics 4. You can withdraw it at any time.

We do not use automated decision-making or profiling that produces legal or similarly significant effects for you.

04 Cookies and local storage

We use necessary cookies so that the site and your account work securely.

Strictly necessary cookies do not require consent, because without them the service cannot work properly. You can block them in your browser, but your account or certain features may then not work.

Google Analytics 4 stays inactive until you choose “Accept all” or enable the “Statistics” category in the cookie settings. Before you consent, the tool is not loaded and no data is sent to Google.

We do not use advertising or targeting cookies. If we add new non-essential analytics or marketing tools in future, we will update this policy and ask for prior consent where required.

  • A session cookie for signing in, navigating and keeping your session active.
  • A CSRF protection cookie for the security of forms and requests.
  • A remember-me cookie, only when you choose that option.
  • Preference settings, such as language and the state of the sidebar.
  • Google Analytics 4: the _ga and _ga_V3T0R2ELTT cookies help us measure traffic and use of the public pages. They last up to 2 years and are only set with your consent.

05 Providers and sub-processors

We use a limited number of providers to run the service. They receive only the data they need for their particular purpose.

  • Stripe: processing payments, subscriptions, tax details and fraud prevention.
  • Hetzner and, where applicable, DigitalOcean: server infrastructure, storage and backups.
  • Cloudflare: DNS, SSL, traffic delivery, security and DDoS protection.
  • Sentry, where enabled: recording technical errors and performance data to diagnose problems.
  • Google Analytics 4: measuring traffic and use of the public pages, only after you have given consent.
  • Google Fonts: loading the typefaces used on the public pages.
  • Resend: sending the platform's operational emails, such as account confirmations and notifications, and delivering submissions from public contact forms. It is not used for the mailboxes or correspondence of hosted sites.
  • Professional advisers or public authorities: only where required for accounting, legal or regulatory obligations.

Our providers are contractually bound to protect the data and use it only for the services they provide to us. An up-to-date list of sub-processors is available on request.

06 Location and international transfers

The core hosting data and the sites themselves are stored in data centres inside the European Union.

Some international providers, such as payment processors or network security services, may process limited data outside the European Economic Area.

Where such a transfer takes place, we use an appropriate GDPR mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You can ask us for more information or a copy of the relevant safeguards.

07 How long we keep data

We keep data only for as long as needed for the purpose for which it was collected and to meet our legal obligations.

  • Account and service details are kept while the account is active and for up to 90 days after it closes, unless a longer period is required by a legal obligation or claim.
  • Invoices and tax records are kept for the period set by tax and accounting law.
  • Technical logs and security events are usually kept for up to 12 months. They may be kept longer where they relate to an active security incident or legal claim.
  • Google Analytics 4 cookies last up to 2 years, unless you delete them from your browser sooner. Your cookie choice is stored for 6 months, after which we ask you to choose again.
  • Details from public forms and partnership enquiries are kept for up to 24 months from the last contact, unless you ask us to delete them sooner or an active partnership begins.
  • The data of a deleted site is removed from active systems, and any residual copies are usually deleted within 30 days.

08 Your rights

Depending on the processing, you can exercise the rights the GDPR gives you.

To protect your data, we may ask for information confirming your identity and authorisation. We reply without undue delay and within one month. If a complex request requires an extension, we will tell you within that first month.

Where we process hosted data solely on behalf of one of our customers, we may refer you to the relevant controller.

  • Access to your personal data and to information about how it is processed.
  • Rectification of inaccurate data, or completion of incomplete data.
  • Erasure or restriction of processing, where the legal conditions are met.
  • Objection to processing based on legitimate interest, and withdrawal of consent at any time.
  • Receiving the data you gave us in a structured format and, where applicable, having it transmitted to another provider.

More about personal data rights

09 Complaint to the supervisory authority

If you believe the processing of your data breaches the law, you can lodge a complaint with the competent supervisory authority.

For Greece, that is the Hellenic Data Protection Authority. We would encourage you to contact us first, so that we can look into the matter and put it right.

Lodge a complaint with the Hellenic DPA

10 Security

We apply technical and organisational measures appropriate to the nature of the service and the risk to the data.

  • Access control, user roles and optional two-factor authentication.
  • An isolated server environment per site, and restricted access to the infrastructure.
  • Encrypted data transfer where supported, network protection and event monitoring.
  • Daily backups and recovery procedures.
  • Restricted access for staff and partners according to their role and their need to know.

No system is completely secure. If you notice suspicious activity or a possible breach, please tell us immediately.

11 Changes to this policy

We update this policy when the service, our providers or the law changes.

The new version is published on this page with an updated date. If a change materially affects how we use your data, we will notify you by an appropriate means before it takes effect.

We recommend reviewing this policy periodically, particularly when new features are added to the service.

12 Contact and data requests

A request about your data?

For questions about your data, or to exercise your rights under the GDPR, please get in touch.

Email
[email protected]to be confirmed
Data controller
DL Software L.P.
Nephelo

Managed WordPress hosting for agencies and freelancers. Every site on its own isolated server, in European Union data centres.

Product
WordPress HostingWooCommerce HostingLanding PagesLaravel · Coming soonPricing
Solutions
For agenciesFor freelancersFree migration
Company
AboutTerms of servicePrivacy policyCookie settings
Help
ContactFAQService status
© 2026 Nephelo · nephelo.gr
ΕΛEN
European infrastructure ✦