Privacy Policy
Last updated: 23 August 2026
This Privacy Policy explains how DOW MEDIA SRL, operating the DirektSupport service, collects, uses, stores and protects personal data when you visit DirektSupport.eu, contact us, request technical support or purchase our services.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 — GDPR, applicable Romanian data protection legislation, including Law no. 190/2018, and other applicable European Union legislation.
1. Data Controller
The data controller responsible for personal data collected directly through DirektSupport is:
DOW MEDIA SRL
Strada Johann Heinrich Pestalozzi, Nr. 3-5
Timișoara, Romania
European Union
Trade Register: J35/3199/03.11.2004
VAT / Tax ID: RO16906010
For privacy-related enquiries:
For technical support:
2. What Personal Data We May Collect
The personal data we process depends on how you interact with DirektSupport.
Contact & Support Information
When you contact us or request technical support, we may process:
- name;
- company name;
- email address;
- telephone number;
- country;
- communication history;
- information submitted through contact or support forms.
Billing & Contract Information
When you purchase services, we may process:
- customer or company name;
- billing address;
- tax or VAT identification information;
- contact details;
- ordered services;
- invoices;
- payment status;
- contractual information.
We do not intentionally store complete payment card details unless a payment system operated directly by us expressly requires this. Where third-party payment services are used, payment information may be processed directly by the relevant payment provider.
3. Technical Information
Because DirektSupport provides technical and Linux server administration services, support requests may contain technical information such as:
- server IP addresses;
- hostnames;
- domain names;
- Linux distribution;
- hosting provider;
- hosting control panel;
- DNS configuration;
- server logs;
- application logs;
- error messages;
- screenshots;
- configuration information;
- website information.
Some of this information may constitute personal data depending on the circumstances.
We process such information only as necessary to understand and provide the requested technical service.
4. Server Access & Administrative Credentials
Certain services may require temporary or ongoing administrative access to Customer infrastructure.
This can include:
- SSH;
- root or sudo access;
- hosting control panels;
- WordPress administration;
- DNS management;
- Cloudflare;
- hosting provider consoles;
- backup systems.
We recommend that Customers do not send passwords, private SSH keys or other sensitive credentials in their initial support request.
Where possible, temporary credentials, SSH keys or restricted administrative access should be used.
Credentials supplied to DirektSupport are used only for the purpose of providing the agreed technical services.
For one-time interventions, Customers are encouraged to revoke temporary access or rotate credentials after the work has been completed.
5. Data We May Access While Administering Your Server
Server administration may technically provide access to information stored on Customer infrastructure.
Depending on the server, this could include:
- website files;
- databases;
- user accounts;
- email metadata;
- mailboxes;
- server logs;
- customer records;
- application data;
- backups.
DirektSupport does not intentionally access Customer content that is unrelated to the requested technical work.
However, technical investigation can sometimes require access to files, logs, databases or configuration containing personal data.
In these situations, our role may be different from our role concerning data collected directly through DirektSupport.eu.
6. When DirektSupport Acts as a Data Processor
When we process personal data contained within a Customer’s infrastructure solely in order to provide server administration, technical support, backup, migration or similar services on the Customer’s instructions, the Customer will normally act as the data controller and DOW MEDIA SRL may act as a data processor.
Where required, this processing can be governed by a separate Data Processing Agreement (DPA).
Under Article 28 GDPR, processing carried out by a processor on behalf of a controller must be governed by an appropriate contract or other legally binding arrangement defining the processing and the responsibilities of the parties.
Customers remain responsible for determining:
- what personal data their infrastructure contains;
- why that data is processed;
- the lawful basis for processing;
- appropriate retention periods;
- access permissions;
- regulatory requirements applicable to their organisation.
7. Why We Process Personal Data
We process personal data only where we have an appropriate legal basis.
Depending on the circumstances, processing may be necessary for:
Providing Requested Services
We process information necessary to:
- respond to enquiries;
- prepare quotations;
- provide technical support;
- administer servers;
- perform migrations;
- provide consulting;
- deliver contracted services.
The legal basis is generally the performance of a contract or taking steps at your request before entering into a contract.
Legal & Accounting Obligations
Certain billing, contractual and transaction information must be processed and retained to comply with:
- accounting requirements;
- tax legislation;
- legal obligations;
- regulatory requirements.
The legal basis is compliance with a legal obligation.
Legitimate Business Interests
We may process limited personal data where necessary for legitimate interests such as:
- maintaining the security of our systems;
- preventing abuse or fraud;
- maintaining business records;
- protecting our legal rights;
- improving our services;
- responding to technical incidents.
Such processing is performed only where those interests are not overridden by the fundamental rights and freedoms of the individual.
Consent
Where processing specifically relies on your consent, you may withdraw that consent at any time.
Withdrawal does not affect processing that was lawful before consent was withdrawn.
These legal bases are provided for by Article 6 GDPR.
8. Support Communications
When you contact DirektSupport, we may retain the communication and related technical information.
This can include communication through:
- email;
- support forms;
- telephone;
- quotations;
- invoices;
- other agreed communication channels.
Support history can be useful for:
- resolving the current incident;
- understanding previous server configuration;
- providing ongoing support;
- maintaining contractual records;
- handling disputes or legal claims.
9. Server Logs & Website Security
Like most internet services, DirektSupport.eu and the infrastructure supporting it may automatically process technical information when visitors access the website.
This may include:
- IP address;
- date and time of access;
- requested URL;
- browser information;
- operating system information;
- HTTP response information;
- referring website;
- security-related events.
These records may be used for:
- website operation;
- troubleshooting;
- security;
- prevention of abuse;
- investigation of malicious activity.
Server logs are not used to identify visitors unnecessarily.
10. Cookies
DirektSupport.eu may use cookies or similar technologies required for the technical operation and security of the website.
Depending on the website configuration, additional cookies may also be used for functionality or analytics.
Where consent is legally required for non-essential cookies, such cookies should only be activated in accordance with the applicable consent requirements.
More detailed information may be provided in a separate Cookie Policy or cookie management interface.
11. Analytics
Where website analytics services are used, we aim to limit the information collected to what is reasonably necessary to understand website usage and improve the service.
Where an analytics technology requires consent under applicable law, it will be used subject to the relevant consent requirements.
The specific analytics technologies used may change over time and, where required, will be identified in the website’s cookie information.
12. How We Use Your Information
Personal data may be used to:
- respond to enquiries;
- provide quotations;
- provide technical support;
- administer Customer infrastructure;
- manage Customer relationships;
- issue invoices;
- process payments;
- maintain accounting records;
- communicate regarding active services;
- investigate technical incidents;
- maintain website and infrastructure security;
- prevent abuse;
- comply with legal obligations;
- establish, exercise or defend legal claims.
We do not use information obtained through server administration for unrelated advertising purposes.
13. Marketing Communications
We do not automatically treat a technical support request as consent to receive unrelated marketing communications.
Where marketing communications require consent, they will only be sent where an appropriate legal basis exists.
If you receive optional marketing communications from us, you may unsubscribe or object to their continued use at any time.
Operational messages concerning:
- active services;
- security;
- billing;
- support incidents;
- contractual matters;
are not considered marketing communications.
14. Sharing Personal Data
We do not sell personal data.
Personal information may be disclosed only where reasonably necessary to:
- provide the requested service;
- operate our business infrastructure;
- process payments;
- provide accounting services;
- comply with legal obligations;
- protect our legal rights;
- respond to lawful requests from public authorities.
Third parties that process personal data on our behalf may include categories such as:
- hosting and infrastructure providers;
- email service providers;
- backup providers;
- payment processors;
- accounting providers;
- professional advisers;
- technical service providers.
Where required by GDPR, processors are subject to appropriate contractual and confidentiality obligations.
15. Hosting & Infrastructure Providers
When providing technical support, we may interact with infrastructure providers selected by the Customer.
These may include providers such as:
- Hetzner;
- OVHcloud;
- Netcup;
- Contabo;
- IONOS;
- Scaleway;
- DigitalOcean;
- Vultr;
- or another provider chosen by the Customer.
DirektSupport is independent from these providers.
If communication with a provider is necessary for a technical incident, we only disclose information reasonably necessary to investigate or resolve that incident.
16. International Data Transfers
We aim to use European Union or European Economic Area infrastructure where reasonably appropriate.
However, some suppliers or technical platforms may process information outside the European Economic Area.
Where personal data is transferred outside the EEA and the GDPR requires additional safeguards, we rely on an appropriate legal transfer mechanism, which may include:
- an adequacy decision of the European Commission;
- Standard Contractual Clauses;
- another transfer mechanism permitted by GDPR.
The appropriate mechanism depends on the service provider and the destination country.
17. Data Retention
We do not intend to retain personal data indefinitely.
Retention depends on the type of information and why it was collected.
Customer & Contract Information
Information relating to an active Customer relationship may be retained for the duration of the relationship and afterwards for the period reasonably required for legal, contractual and legitimate business purposes.
Financial & Accounting Records
Invoices and other accounting information are retained for the periods required by Romanian tax and accounting legislation.
Support Communications
Technical support correspondence may be retained for a reasonable period where it remains useful for:
- future support;
- security investigations;
- documenting work performed;
- handling disputes;
- protecting legal rights.
Technical Credentials
Temporary credentials should not be retained longer than necessary for the technical purpose for which they were supplied.
Server Logs
Website and infrastructure logs are retained according to operational and security needs and may be retained longer where necessary to investigate a security incident.
When personal data is no longer required, it may be deleted, anonymised or securely archived where continued retention is legally required.
GDPR requires individuals to be informed of the retention period or, where an exact period cannot be given, the criteria used to determine it.
18. Data Security
We use reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- accidental loss;
- unlawful disclosure;
- alteration;
- destruction;
- misuse.
Measures may include, where appropriate:
- restricted administrative access;
- SSH key authentication;
- access controls;
- firewall protection;
- encrypted connections;
- backups;
- software updates;
- logging;
- security monitoring.
No internet-connected system can be guaranteed to be completely secure.
19. Personal Data Breaches
If we become aware of a personal data breach affecting information for which DOW MEDIA SRL acts as controller, we will assess the incident and take the measures required by applicable data protection law.
Where DirektSupport acts as a processor for a Customer, we will handle relevant incidents in accordance with the applicable Data Processing Agreement and GDPR obligations.
20. Your GDPR Rights
Depending on the circumstances, GDPR gives individuals rights including:
- right of access to personal data;
- right to rectification of inaccurate data;
- right to erasure where applicable;
- right to restriction of processing;
- right to data portability where applicable;
- right to object to certain processing;
- right to withdraw consent where processing relies on consent;
- right not to be subject to certain solely automated decisions.
These rights are not absolute and may be subject to conditions or exceptions under applicable law.
The Romanian supervisory authority also identifies access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making among the rights available to data subjects under GDPR.
21. Exercising Your Rights
To exercise a data protection right regarding information for which DOW MEDIA SRL is the controller, contact:
Please provide enough information for us to identify the relevant data and understand your request.
We may request reasonable information to verify your identity before releasing, modifying or deleting personal information.
Where the request relates to personal data contained inside infrastructure operated by one of our Customers, you may need to contact that Customer directly because they may be the relevant data controller.
22. Right to Object
Where processing is based on legitimate interests, you may have the right to object to that processing based on your particular circumstances.
Where personal data is used for direct marketing, you may object to that use at any time.
23. Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
It also does not affect processing that is necessary under another valid legal basis, such as contractual or legal obligations.
24. Automated Decision-Making
DirektSupport does not use personal data collected through the website or technical support service to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
We do not use technical information obtained from Customer servers to create advertising profiles of their users.
25. Children
DirektSupport is a professional technical service intended primarily for businesses, professionals, web agencies, website owners and organisations managing internet infrastructure.
Our services are not specifically directed at children.
We do not knowingly seek to collect children’s personal information through DirektSupport.eu for marketing purposes.
26. Links to Other Websites
DirektSupport.eu may contain links to third-party websites, including infrastructure providers and technology vendors.
Those websites operate under their own privacy policies.
DOW MEDIA SRL is not responsible for the privacy practices of independent third-party websites.
27. Independent Provider Disclaimer
DirektSupport is an independent technical support provider and is not affiliated with, endorsed by or sponsored by the hosting providers and technology vendors referenced on this website.
All trademarks are the property of their respective owners.
This independence also means that third-party providers process information according to their own privacy policies when Customers use their platforms.
28. Complaints
If you have concerns about how we process personal data, we encourage you to contact us first:
You also have the right to lodge a complaint with the competent data protection supervisory authority.
In Romania, the supervisory authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP
Bd. G-ral Gheorghe Magheru nr. 28-30
Sector 1, Bucharest, Romania
Postal Code 010336
ANSPDCP provides procedures for GDPR complaints and accepts complaints concerning personal data processing.
If you live or work in another European Economic Area country, you may also have the right to contact the competent supervisory authority in that jurisdiction.
29. Changes to This Privacy Policy
We may update this Privacy Policy when necessary to reflect:
- changes to our services;
- changes to the website;
- new technical providers;
- changes to data processing practices;
- legal or regulatory requirements.
The current version will be published on DirektSupport.eu together with the date of the latest revision.
Material changes may be communicated through additional means where appropriate.
30. Contact
For privacy and data protection matters:
For technical support:
DOW MEDIA SRL
Strada Johann Heinrich Pestalozzi, Nr. 3-5
Timișoara, Romania
European Union
Trade Register: J35/3199/03.11.2004
VAT / Tax ID: RO16906010
DirektSupport — Independent Linux Server Administration.
