Data location and GDPR: where your data sits and who can access it

Your website, database, mailboxes, backups and server logs sit on JAAN bv's own servers in two Belgian data centers, in Brussels and Ghent, within the EU. There is no copy at a foreign cloud provider and no support layer outside Europe. Access to your environment is held by the administrators of the servers, and by the people you give a login to yourself.

This page is the compliance answer for your DPO, your customer or your own record of processing activities: where what sits, for how long, who can access it and what happens if something goes wrong. Why the location matters is on the page about Belgian web hosting; what is in the data centers, on the data center page.

Where what sits

One infrastructure, one country. Everything that belongs to your hosting sits on JAAN bv hardware in Brussels or Ghent. Below, component by component.

Website and database

The files of your site and your MySQL databases sit on our servers in a Belgian data center. Whatever your visitors fill in or upload stays there.

Mailboxes

Your mailboxes (IMAP and webmail) sit on our mail servers in Belgium. The spam filter is part of the mail hosting and runs on the same infrastructure; your mail does not pass through a third party's filtering service.

Backups

Every day we make a backup of files and database. We keep it for 14 days, on our own infrastructure in Belgium. After that it is overwritten.

Server logs

The web server logs visits (IP address, time, requested page) to deliver the service, trace errors and detect abuse. Those logs, too, sit on the server in Belgium.

About our data centers About backup and restore

Who can access your data

Two groups: the administrators of JAAN bv, and the people you give access to yourself. The first group is small and based in Zelzate; the second is entirely up to you.

At JAAN bv

Access to the servers is reserved for the administrators who maintain them. They look into your environment for maintenance, security or when you ask for support yourself, not otherwise. There is no external or foreign support layer with access to your account.

At your end: control panel and FTP

The control panel login stays with one responsible person. For anyone working on the site you create a separate FTP account; when that person leaves, you delete that account and the rest is untouched.

At your end: mailboxes

Every employee gets their own mailbox with their own password. A shared address such as info@ is handled with an alias or forwarding, not by passing one password around.

At your end: your CMS

Who can log in to your WordPress, Joomla or webshop, and with which rights, is something you arrange in the CMS itself. We do not see or manage that layer.

Sub-processors

Hosting, backup, mail and support are done by JAAN bv itself, on its own hardware. For a limited number of supporting services, such as the rack space in the data centers or the payment provider for your invoice, other companies may be involved. The current list forms part of the data processing agreement and is available on request; a new sub-processor is only engaged with notice to you.

If you request the list, you receive it in writing, with the role and country of processing for each party. We deliberately do not name them here: a list on a web page goes out of date, the document in your record does not.

What happens in the event of an incident

An outage is not the same as a data breach, and we treat them differently. In both cases you hear it from us, not from your visitors.

Outage

If a server or service is unreachable, the current status is on the status page, with updates until it is resolved. The SLA sets out what availability you can expect.

Data breach

If we detect a breach affecting your data, we report it to you without undue delay, with what we know about its nature, extent and the data affected. That way you can inform the supervisory authority and the data subjects within the legal deadline.

Restore

If something is lost or broken, we restore from the daily backup, up to 14 days back. Tell us when it still worked; that is the most important piece of information for a targeted restore.

View the status page Read the SLA

What is in your own hands

The location of the server is our job. What goes onto the server, how long it stays and who can access it is yours. These are the measures at your end.

Run your forms and logins over https only; the free SSL certificate is already in place and is renewed automatically.
Do not collect more than you need: a contact form does not need a date of birth.
Set retention periods in your CMS for form submissions, old accounts and orders, and clear out what has expired. What you leave on the server is also in the backup.
Give every person their own access (FTP, mailbox, CMS) and revoke it as soon as someone leaves.
Keep CMS, theme and plugins up to date: most data breaches at websites go through an outdated plugin, not through the server.
State in your privacy statement that your site and email are hosted with a processor in Belgium, and include the hosting in your record of processing activities.
About the SSL certificate Performing updates safely

Putting your hosting into use GDPR-ready

Four steps at the start, half a day's work in total, which you then only need to maintain.

1

Arrange access per person

Create a separate FTP account per web developer and a separate mailbox per employee. Keep the control panel login with one responsible person and note down who has what.

2

Check that everything runs over https

The SSL certificate is in place; make sure your CMS actually redirects to https, so that forms and logins do not travel unencrypted. Test one form from start to finish.

3

Set retention periods in your CMS

Decide how long submissions, accounts and orders stay and switch on automatic clean-up where possible. Write those periods down: they belong in your record of processing activities.

4

Request the data processing agreement and the sub-processor list

File both documents with your record of processing activities, together with the answer to the question where your data sits. That completes your file in case anyone asks.

Request the documents Ask your question

Further reading

This page says where your data sits and who can access it. Why that matters, what physically sits in the data centers and what the contract looks like, you can read on the neighbouring pages.

Why Belgian hosting matters About our data centers The data processing agreement

Frequently asked questions

On JAAN bv's own servers in our own rack space in two Belgian data centers, in Brussels and in Ghent. That applies to the files of your website, your databases, your mailboxes, the backups and the server logs. Everything stays in Belgium, within the EU.
Our processing and storage take place in Belgium. There is no copy at a foreign cloud provider and no support layer outside Europe. Which supporting parties are involved, with their role and country of processing, is in the sub-processor list you can request in writing.
The daily backup of files and database sits on our own infrastructure in Belgium and is kept for 14 days. After that it is overwritten. So a restore can go back up to 14 days.
At JAAN bv only the administrators who maintain the servers, for maintenance, security or when you ask for support yourself. In addition, everyone you give access to yourself: through an FTP account, a mailbox password, the control panel login or an account in your CMS. That second group is entirely up to you.
If we detect a breach affecting your data, we report it to you without undue delay, with what we know about its nature, extent and the data affected. That way you can inform the supervisory authority and the data subjects within the legal deadline. The arrangements for this are in the data processing agreement.
The status page shows the current situation, with updates until it is resolved. The SLA sets out what availability you can expect. An outage is not the same as a data breach; in the event of a data breach we notify you directly.
Yes, at any time. You download your files via FTP, export your database via the control panel and collect your mail via IMAP. You do not need to ask us for anything; it is your environment.
Call us
Send an email