This policy explains what happens to personal data when you visit isbaremetal.com, use the free tools on it, write to us, or rent a server from IsBareMetal.
It is written to be checked rather than admired: everything below describes what the site and the service actually do, and where a third party is involved we name it and link to its own policy.
1. What this site does not do
Start here, because it removes most of the usual questions. This website sets no cookies at all. It runs no analytics, no tag manager, no pixels, no session recording and no advertising scripts. There is nothing to opt out of and no consent banner, because there is nothing to consent to.
Web fonts are served from our own domain rather than a font CDN, so loading a page does not announce your visit to a third party.
2. What the web server records
Like any web server, ours writes an access log. Each line contains your IP address, the time of the request, the page requested, the response status and size, the page you came from if your browser sent one, and your browser’s user-agent string.
We use these logs to keep the site up, to investigate errors and to spot abuse. We do not build profiles from them and do not share them for marketing.
Logs rotate daily and are kept for 14 days, after which they are deleted automatically.
Lawful basis: our legitimate interest in operating and securing the site (GDPR Article 6(1)(f)).
3. When you write to us
The contact form does not submit anything anywhere. It assembles what you type into a message inside your own browser, and the button either hands that text to your mail client or copies it to your clipboard. Nothing reaches us until you send it yourself, from your own mailbox.
Once you do send it, we use what you wrote to answer you, and keep the correspondence for as long as there is a business reason to: an open question, an ongoing relationship, or a legal obligation to retain records.
Lawful basis: taking steps at your request before entering into a contract, or our legitimate interest in answering enquiries (GDPR Article 6(1)(b) and (f)).
4. When you use the tools page
The /tools page runs entirely in your browser, but three of the utilities need an external service to answer, and your browser contacts that service directly:
- the NS lookup sends the domain you type to Google Public DNS;
- the IP tools send the address you ask about — or, for “my IP”, nothing but the request itself — to ipapi.co;
- the QR generator sends the text you enter to api.qrserver.com, which renders the image.
Those requests carry your IP address to the service concerned and are governed by its policy, not ours. The password and hash generators do not leave your browser at all: they use the browser’s own cryptography API, and nothing you type there is transmitted anywhere.
Nothing you enter on the tools page is stored by us or logged beyond the ordinary page request described in section 2.
5. When you become a customer
Ordering a server requires more: your name or company name, billing address, email address, and the payment details needed to take payment. Depending on the order and the payment route, sanctions and anti-fraud obligations may require identification documents and information about ownership and control.
Customer accounts, invoicing and payment are operated by the HostiServer group, of which IsBareMetal is a brand. Card details are handled by the payment provider; we do not store full card numbers.
We also process technical data about the service itself — the addresses assigned to you, traffic volumes, abuse reports naming your server, and support correspondence.
Lawful bases: performance of the contract (Article 6(1)(b)); compliance with legal obligations, including sanctions and accounting law (Article 6(1)(c)); and our legitimate interest in preventing fraud and network abuse (Article 6(1)(f)).
7. Transfers outside the EEA
Some of the services above are established in the United States, and we operate infrastructure in the United States as well as in the Netherlands. Personal data may therefore be processed outside the European Economic Area.
Where that happens, transfers rely on the European Commission’s Standard Contractual Clauses or another mechanism recognised under Chapter V of the GDPR. You may ask us which mechanism applies to a specific transfer.
8. How long we keep things
- Web server logs — 14 days, then deleted automatically.
- Enquiries and support correspondence — while the matter is open and for as long as there is a business or legal reason afterwards.
- Customer and billing records — for the retention period required by accounting and tax law in our jurisdiction, counted from the end of the relationship.
- Identification documents collected for sanctions or anti-fraud checks — for as long as the applicable rules require, and not longer.
- Data on a terminated server — deleted with the server. Keep your own copy before you cancel.
9. Your rights
If the GDPR applies to you, you have the right to ask for a copy of your personal data, to have it corrected, to have it erased where we have no overriding reason to keep it, to restrict or object to certain processing, and to receive data you gave us in a portable form. Where processing rests on consent, you may withdraw it at any time.
Send the request through the contact form at isbaremetal.com and say what you want. We answer within one month; if a request is complex we will tell you that, and why, inside that month.
Some rights have limits. We cannot delete an invoice that tax law requires us to keep, and we cannot erase a sanctions check we are obliged to retain. Where we refuse, we will say which obligation we are relying on.
You also have the right to complain to a supervisory authority — in the first instance the one in our jurisdiction, or the one where you live or work.
10. Security
The site is served over HTTPS with HSTS. Access to systems that hold personal data is limited to staff who need it, and administrative access is restricted by network and by credential.
No one can promise perfect security, and we will not pretend otherwise. What we can promise is that if a breach affects your personal data and the law requires us to tell you, we will tell you — plainly, and without waiting to see whether anyone noticed.
11. Children
The service is sold to businesses and to adults. We do not knowingly collect personal data from children, and the site holds nothing directed at them.
12. Changes to this policy
When the site or the service changes what it does with data, this page changes with it — the date and version at the top tell you when it last did. Where a change materially affects you as a customer, we tell you by email rather than relying on you to re-read the page.
13. Contact
Privacy questions, rights requests, abuse reports and compliance matters all reach us through the contact form at isbaremetal.com while the dedicated mailboxes are being set up.