Data location and GDPR: where your data sits and who can access it
Your website, database, mailboxes, backups and server logs sit on JAAN bv's own servers in two Belgian data centers, in Brussels and Ghent, within the EU. There is no copy at a foreign cloud provider and no support layer outside Europe. Access to your environment is held by the administrators of the servers, and by the people you give a login to yourself.
This page is the compliance answer for your DPO, your customer or your own record of processing activities: where what sits, for how long, who can access it and what happens if something goes wrong. Why the location matters is on the page about Belgian web hosting; what is in the data centers, on the data center page.
Where what sits
One infrastructure, one country. Everything that belongs to your hosting sits on JAAN bv hardware in Brussels or Ghent. Below, component by component.
Website and database
The files of your site and your MySQL databases sit on our servers in a Belgian data center. Whatever your visitors fill in or upload stays there.
Mailboxes
Your mailboxes (IMAP and webmail) sit on our mail servers in Belgium. The spam filter is part of the mail hosting and runs on the same infrastructure; your mail does not pass through a third party's filtering service.
Backups
Every day we make a backup of files and database. We keep it for 14 days, on our own infrastructure in Belgium. After that it is overwritten.
Server logs
The web server logs visits (IP address, time, requested page) to deliver the service, trace errors and detect abuse. Those logs, too, sit on the server in Belgium.
Who can access your data
Two groups: the administrators of JAAN bv, and the people you give access to yourself. The first group is small and based in Zelzate; the second is entirely up to you.
At JAAN bv
Access to the servers is reserved for the administrators who maintain them. They look into your environment for maintenance, security or when you ask for support yourself, not otherwise. There is no external or foreign support layer with access to your account.
At your end: control panel and FTP
The control panel login stays with one responsible person. For anyone working on the site you create a separate FTP account; when that person leaves, you delete that account and the rest is untouched.
At your end: mailboxes
Every employee gets their own mailbox with their own password. A shared address such as info@ is handled with an alias or forwarding, not by passing one password around.
At your end: your CMS
Who can log in to your WordPress, Joomla or webshop, and with which rights, is something you arrange in the CMS itself. We do not see or manage that layer.
Sub-processors
Hosting, backup, mail and support are done by JAAN bv itself, on its own hardware. For a limited number of supporting services, such as the rack space in the data centers or the payment provider for your invoice, other companies may be involved. The current list forms part of the data processing agreement and is available on request; a new sub-processor is only engaged with notice to you.
If you request the list, you receive it in writing, with the role and country of processing for each party. We deliberately do not name them here: a list on a web page goes out of date, the document in your record does not.
What happens in the event of an incident
An outage is not the same as a data breach, and we treat them differently. In both cases you hear it from us, not from your visitors.
Outage
If a server or service is unreachable, the current status is on the status page, with updates until it is resolved. The SLA sets out what availability you can expect.
Data breach
If we detect a breach affecting your data, we report it to you without undue delay, with what we know about its nature, extent and the data affected. That way you can inform the supervisory authority and the data subjects within the legal deadline.
Restore
If something is lost or broken, we restore from the daily backup, up to 14 days back. Tell us when it still worked; that is the most important piece of information for a targeted restore.
What is in your own hands
The location of the server is our job. What goes onto the server, how long it stays and who can access it is yours. These are the measures at your end.
Putting your hosting into use GDPR-ready
Four steps at the start, half a day's work in total, which you then only need to maintain.
Arrange access per person
Create a separate FTP account per web developer and a separate mailbox per employee. Keep the control panel login with one responsible person and note down who has what.
Check that everything runs over https
The SSL certificate is in place; make sure your CMS actually redirects to https, so that forms and logins do not travel unencrypted. Test one form from start to finish.
Set retention periods in your CMS
Decide how long submissions, accounts and orders stay and switch on automatic clean-up where possible. Write those periods down: they belong in your record of processing activities.
Request the data processing agreement and the sub-processor list
File both documents with your record of processing activities, together with the answer to the question where your data sits. That completes your file in case anyone asks.
Further reading
This page says where your data sits and who can access it. Why that matters, what physically sits in the data centers and what the contract looks like, you can read on the neighbouring pages.