Security and data residency
Our equipment stands in data centres inside the European Union, and EU data residency is the default on every plan we sell: production, backups and the replication target. What follows is a description of the controls we run and the duties we carry. It is deliberately not a list of certifications, because we do not hold any.
Written to be read by your auditor, not by your marketing team



Where the data sits
Three commitments, written the way we would want them written if we were the ones buying.
Facilities inside the European Union
Every machine we operate for customers is housed in a data centre in the EU, and so is the second site we replicate to. Nothing you store runs on hardware outside the Union. The one exception is the payment step: billing details you enter at checkout are handled by our payment provider under its own notice, which the privacy notice sets out in full.
Ask for a region when you order
If your policy or your own customers require a specific EU country or a specific pair of sites for the primary and the replica, say so before you pay, in the order notes or by email. We confirm in writing whether we can meet it, and if we cannot we say so before taking the money rather than after.
Nothing moves without asking you
We do not relocate customer data to another region, another provider or another country because it is cheaper or more convenient for us. A move happens only after a written agreement with you, and that includes copies made for support, debugging or testing.
Physical and platform controls
What we and the facilities that house our racks actually do. Each line is a practice, not a badge.



Access-controlled facilities
The halls that hold our racks are entered with a card and a logged visit, under camera coverage. Our cabinets are locked, and only our own engineers open them or handle the hardware inside.
Redundant power
Two independent power paths reach each rack, backed by UPS and a diesel generator whose autostart is tested rather than assumed. Dual-supply servers take one feed from each path.
Redundant network paths
More than one upstream carrier and more than one uplink per rack, so a single fibre cut or a single upstream fault degrades capacity instead of ending service. Filtering against volumetric attacks sits at the border.
Redundant storage in the machine
Customer data lands on NVMe in a RAID set, so a failed drive is a replacement job rather than an incident. RAID protects against a dead drive and nothing else, which is why the backup section below exists.
Isolated tenancy per customer
Virtual machines get their own kernel, their own storage volumes and their own network segment. Shared hosting accounts run under separate system users with their own PHP process pool and resource limits. Dedicated and private-cloud plans are single-tenant hardware.
Hypervisor and managed OS patching
We patch the virtualisation layer, the operating system of managed plans, the hosting panels and our own tooling on a weekly schedule, and sooner when a vulnerability is being exploited. Reboots that cannot be avoided are announced first.
What we do not claim
We are a small and young company. We hold no security certification of our own, and writing anything else here would cost you money later, when the certificate you assumed was in place is the one your auditor asks to see.
The data centres that house our equipment do hold their own certifications. We will name the facility and send its current certificates during procurement, under a mutual non-disclosure agreement if you need one. What we will not do is print somebody else's badge on our website and let it read as ours.
If a certification is a hard requirement for your purchase, tell us at the start. It is a better use of your time than discovering it at the contract stage, and we would rather lose the order than win it on a misunderstanding.
- We are not ISO 27001 certified.
- We have no SOC 2 report, of either type.
- We hold no other security or compliance certification, and we display no compliance badges.
- We publish no measured availability figure. Each plan carries a service target, which is a promise about the future and not a measurement of the past.
- We run no paid vulnerability bounty.
- We name no customers and quote nobody, because at our age we would have to invent them.
Everything above is a statement about us, not about the facilities we buy space in. Their certifications are real, and are theirs.
Backups and recovery
What each plan includes, taken from the same source as the plan pages, so the two cannot drift apart.
Copies live away from the machine
Backups are written to storage separate from the server that produced them, never only to the disk they are protecting. Off-site copies go to a second data centre in the European Union. The Backup & Object Storage plan adds immutable retention, meaning that for the period you set, an object cannot be altered or deleted, by you, by an attacker holding your keys, or by us.
| Plan | Backups included |
|---|---|
| Web Hosting Business | Daily, 30 days |
| Managed WordPress | Daily, 30 days |
| Cloud VPS Pro | Weekly snapshots |
| Backup & Object Storage | Immutable, your policy |
| Dedicated Cloud Server | Daily, 14 days |
| Kubernetes Platform | Daily volume snapshots |
| Enterprise Private Cloud | Daily + off-site copy |
CDN & Edge Delivery holds no primary data, only cached copies of your origin, so it has no backup line. Any plan can take the daily off-site backup add-on, which keeps 30 days of copies in a second EU data centre.
Asking for a restore
Write to hello@thebillboys.pl with the order reference, what you need back and the point in time you want. A restore is treated as a support request at the severity the situation deserves, and data at risk is the highest one. We restore to a location you choose, so a recovery does not overwrite a live system while you are still deciding.
Restores are tested
A backup nobody has restored is a hope, not a backup. We run a documented restore test every quarter on the backup platform and record the result. Ask and we will tell you when the last one ran.
Keep an independent copy
Keep your own copy of anything you could not rebuild, somewhere that is not us. We say the same in the terms. Our backups are good and we test them, and they are still a single supplier holding a single set of copies. A second, independent copy is the cheapest insurance in this industry.
Encryption and who holds the keys
- Certificates are issued and renewed automatically for the domains on your environment, and renewal is monitored so that an expiry becomes an alert rather than an outage.
- Administrative access to your systems runs over encrypted sessions only. Panels and consoles are served over TLS, and plain unencrypted management protocols are not offered.
- Every engineer has a named account with their own key. There is no shared operations login and no team password anyone could pass along.
- Access to a customer environment is granted for the work in hand: provisioning, an agreed change, an incident you reported. It is not standing access held by the whole team in case it is needed one day.
- Administrative actions are logged, and a departing engineer's keys are removed the day the access ends.
- Encryption of the data inside your application, and of anything you place in object storage, is yours to configure. Tell us what you need and we will help you set it up.
Your side of the line
Hosting is a split job. This is the split as we understand it, so nobody discovers the boundary during an incident.
What we look after
- The facility, power, network and hardware, including replacing what fails.
- The virtualisation layer and its patching.
- The operating system, panel and stack on managed plans.
- Backups where the plan includes them, and the quarterly restore test.
- Certificates, monitoring, and the border filtering in front of your service.
- Telling you when we change something that touches your environment.
What stays with you
- Your application: its code, its dependencies, its file permissions and how it handles input.
- Your CMS, its themes and its plugins, on any plan where you administer them. An unpatched plugin is the most common way a hosted site is taken over.
- Your passwords and SSH keys, and rotating them when somebody leaves.
- Who you grant access to, at what level, and removing that access when the work ends.
- Your own copy of important data, kept somewhere that is not us.
- Your legal duties towards the people whose data you store on the service.
On managed WordPress we apply core and plugin updates on a schedule as part of the plan, which moves that line. On plans with root access it stays with you unless we agree a managed arrangement in writing.
Reporting a vulnerability
If you have found a weakness in our infrastructure, our website or a customer environment we operate, we want to hear it.
Write to us
Send the details to hello@thebillboys.pl with "vulnerability" in the subject. It reaches the same people who run the platform. We do not run a separate reporting address, because a second inbox is a second place for a message to sit unread.
We acknowledge in one working day
You get a human reply within one working day confirming that the report arrived and who is looking at it. If the finding is serious we say so in that first reply rather than going quiet.
We investigate and keep you posted
We reproduce the issue, work out who is affected and tell you what we found, including when we conclude that it is not exploitable. Customers whose environments are affected are told directly.
We fix and report back
You hear what changed and when it shipped. If you would like credit for the finding we are glad to give it, in writing, wherever you would find it useful.
We do not pay for reports
There is no paid bounty programme, and we would rather say that here than let a researcher spend an afternoon on us expecting one. What we offer is a fast, honest answer, credit if you want it, and a reference for your own work.
Please test only what is yours
Test against your own environment, not another customer's. Avoid denial-of-service testing, avoid anything that would read or alter data that is not yours, and give us a chance to fix a finding before it is published. Report in good faith and we will treat you the same way.
Processing, agreements and deletion
The contractual half of the same subject, kept short here because the documents themselves are the authority.
We are the processor
Personal data that you or your users place on a hosted environment is processed by us only on your instructions. You remain the controller. What we do with your own data, as a customer of ours, is set out in the privacy notice.
A processing agreement on request
A data-processing agreement under article 28 GDPR is available before or after you order, at no charge. Ask by email and we send it for signature. If your own template must be used instead, send it and we will read it and say what we can sign.
When a service ends
Ask and we hand over a full copy of your data in a usable format, with no exit fee. Data is kept for 30 days after the term ends and is then deleted, or sooner if you ask for early deletion in writing. The full wording is in the terms.
Send us the hard questions
Security review, vendor questionnaire, a clause your legal team will not move on. An engineer answers, and where the answer is no, it will say no.