Privacy policy
Version 1.0, effective 18 September 2026. What we store, why, for how long, and with whom. Written for the GDPR (AVG).
Controller
RealFreeHosting. Contact for privacy questions: support@realfreehosting.com.
What we process and why
| Data | Purpose | Legal basis | Kept |
|---|---|---|---|
| E-mail address, username, name, password (hashed) | Your account and single sign-on to GitLab, servers and billing | Contract | Until you close your account |
| Two-factor secret and recovery codes (hashed) | Account security | Contract | Until you disable 2FA or close the account |
| IP address, browser type, time of sign-ins and security-relevant actions | Abuse prevention, security notifications, audit trail | Legitimate interest | 12 months |
| Repositories, issues, wiki and CI data | The hosting service itself | Contract | See the fair use policy |
| Company name, address, VAT number, invoices, payment references | Billing of Cloud plans, tax obligations | Contract, legal obligation | 7 years (Dutch tax law) |
| SSH public keys | Access to Git and to your servers | Contract | Until you remove them |
| Server logs (web, mail) | Operations and security | Legitimate interest | 30 days |
Who else sees your data
- Hetzner Online GmbH (Germany): our servers and encrypted backups are located in a Hetzner data centre. Backups are encrypted before they leave our server.
- Payment provider (Mollie B.V. or Stripe Payments Europe Ltd., depending on the method you choose): processes your payment; we never see your full card or bank details.
- Nobody else. We do not use analytics trackers, advertising networks or third-party cookies.
Cookies
We set one strictly necessary session cookie per site to keep you signed in. GitLab and Grafana set their own session cookies for the same purpose. No tracking cookies.
We send transactional mail only: verification, password resets, security notifications, invoices, and warnings about inactive projects. No newsletters unless you opt in later.
Your rights
You can view and correct your account data on the account page, export your repositories with Git at any time, and delete your account by e-mail. You also have the right to access, rectification, erasure, restriction, portability and objection under the GDPR, and to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
Passwords are stored with scrypt, two-factor authentication is available to everyone and required for administrators, all traffic is encrypted (TLS), and backups are encrypted with a key that is not stored with the backups.