Legal
Privacy Policy
Last revised: August 8, 2026
Last updated: August 8, 2026
1. Information We Collect
Contact form submissions. When you fill out the contact form on vps1.dev, we collect your name, email address, phone number (optional), company name (optional), and message. This information is used solely to respond to your inquiry and provide the services you request.
Server logs. Like every website, our server automatically logs standard information including your IP address, browser type, referring page, pages visited, and timestamp. These logs are retained for 30 days for security and operational diagnostics and are never shared with third parties.
No tracking or profiling. We do not use tracking cookies, analytics scripts, fingerprinting, or any form of behavioral profiling. There is no advertising on vps1.dev and we have no ad partners.
2. How We Use Your Information
We use the information you provide exclusively to:
- Respond to your inquiries and service requests
- Deliver the managed hosting services you have engaged us for
- Send service-related communications (invoices, maintenance notices, security advisories)
- Improve our website based on aggregate, anonymized traffic patterns
We do not sell, rent, trade, or share your personal data with third parties for marketing purposes. Your contact form submissions are stored securely and accessed only by VPS1 staff involved in your service delivery.
3. Data Storage and Security
Where your data lives. Contact form submissions are stored in our self-hosted CRM (Strapi CMS) and transmitted via our self-hosted SMTP mail server. Both run on infrastructure we control. Client service data (configurations, backups, documentation) is stored on encrypted volumes with access limited to the VPS1 engineering team.
Security measures. We implement industry-standard security controls including:
- Encryption at rest for all stored data
- TLS encryption for all data in transit
- Strict firewall rules with whitelist-only access
- Intrusion detection via CrowdSec
- Regular security patching and vulnerability scanning
- Role-based access control for all internal systems
- Mandatory multi-factor authentication for administrative access
Data retention. Contact form submissions are retained for the duration of your relationship with VPS1 plus 12 months, after which they are securely deleted. Server logs are retained for 30 days. You may request earlier deletion at any time.
4. Cookies
vps1.dev does not use tracking cookies, third-party analytics cookies, or advertising cookies. We use local storage to remember your cookie consent preference. This preference contains no personal data and is not transmitted to any server. The site functions fully without it; the consent notice simply will not reappear once dismissed.
Our cookie consent banner appears on first visit until you click Accept. It includes a link to this Privacy Policy for full transparency.
5. Third-Party Services
We use a minimal set of infrastructure providers to operate the website and deliver services. No personal data is sold or shared with them for their own purposes.
Cloudflare. vps1.dev uses Cloudflare for DNS management only. Cloudflare does not proxy, cache, or process visitor traffic. DNS queries are resolved via standard DNS protocol without personal data collection.
Pangolin. Traffic is routed through Pangolin as a reverse proxy for internal network access control and encrypted tunneling. Pangolin does not store personal data or maintain access logs beyond what is necessary for connection routing.
Client infrastructure. For managed hosting clients, we may deploy and manage software on third-party cloud providers (Hetzner, DigitalOcean, Linode, etc.) at the client's direction. Data processed on those platforms is governed by the provider's respective privacy policies and the client's own data handling practices. VPS1 accesses client infrastructure solely for management and support purposes.
No AI training. We do not use your data to train machine learning models or AI systems.
6. Legal Basis and Jurisdiction
VPS1 Enterprise is based in Brunei Darussalam and operates under Bruneian law. We process personal data on the basis of legitimate interest, contractual necessity, or your consent, depending on the nature of the processing. For prospective and current clients, our primary lawful basis is legitimate interest and contract performance. While we are not directly subject to the GDPR, we have designed our data practices to align with its core principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, and confidentiality.
For clients in jurisdictions with specific data protection requirements (GDPR, CCPA, etc.), we are happy to execute a Data Processing Agreement (DPA) as part of your service contract.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Ask us to correct inaccurate or incomplete data
- Deletion: Request that we delete your personal data, subject to any legal obligations we may have to retain it
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your data in certain circumstances
To exercise any of these rights, email privacy@vps1.dev. We will acknowledge your request within 48 hours and respond substantively within 30 days. There is no fee for these requests. These rights are provided as a voluntary commitment; the specific rights available to you may vary depending on your jurisdiction.
8. Data Breach Notification
In the unlikely event of a data breach involving your personal information, we will notify affected individuals without undue delay via the contact information we have on file. While not required by Bruneian law, we voluntarily commit to a 72-hour notification window as a best practice. Our incident response plan includes containment, investigation, remediation, and a post-incident review to prevent recurrence.
9. Children's Privacy
vps1.dev is a business-to-business website. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The date at the top of this page indicates when it was last revised. Material changes will be communicated via a notice on our website. Continued use of the site after changes constitutes acceptance.
11. Contact
For any questions, concerns, or to exercise your data rights:
- Company: VPS1 Enterprise
- Email: privacy@vps1.dev
- Phone: +673 8125218
- Address:
No 4A, Spg 396-54-5,
Kg Tagap, Jln Jerudong,
Negara Brunei Darussalam, BG1521 - Online: Submit through our contact form