Skip to content
Ellada Holdings
Privacy policy

How we handle personal data.

Ellada Holdings and its group companies process personal data to run their businesses: to serve customers, work with suppliers and partners, and meet their legal obligations.

Last updated 23 September 2026.

Who we are

Ellada Holdings, LLC and the companies it owns operate data center, network and hosting businesses in the Netherlands and the United States. For personal data processed in the course of a commercial relationship, the group company holding that relationship is the controller.

Questions, or a request about your data: [email protected], or Ellada Group B.V., Moezel 3, 2491 CV The Hague, The Netherlands.

Whose data, and what we hold

  • Customers, suppliers and partners — the business contact details of the people we deal with: name, role, work email and telephone number, together with the correspondence, contracts and invoices that relate to the agreement between our companies.
  • Visitors to our websites — what you send us through a contact form, and standard server and cookie data. Our cookie notice explains the rest.
  • Applicants and staff — what you provide when you apply or while you work with us, handled separately and described to you at the time.

We do not sell personal data, we do not use it for advertising, and we do not make it available to anyone for their own purposes.

Why we are allowed to hold it

Because it is necessary to perform the agreement between us, because the law requires it — invoicing and accounting records in particular — or because we have a legitimate interest in administering our commercial relationships and securing our systems. Where we rely on consent, you can withdraw it at any time.

How long we keep it

For as long as the relationship lasts, and after that for the period the law requires. In the Netherlands, accounting records are kept for seven years; comparable rules apply to our US entities. What is no longer needed is deleted.

Who else processes it

We use established service providers for the ordinary business functions of a company of our size — administration, accounting, communication, hosting and security. Each acts on our instructions under a data-processing agreement, and none is permitted to use the data for its own purposes. Where a provider retrieves data on our behalf using credentials we hold, that data is used solely for our own administration.

We also disclose data where the law obliges us to, and to our professional advisers where they need it.

International transfers

Our group operates in the European Union and the United States, and data moves between the two for ordinary business reasons. Transfers out of the EU rely on the European Commission's standard contractual clauses or another lawful transfer mechanism.

How we protect it

We apply appropriate technical and organisational measures, and review them regularly. Our operating companies hold ISO 9001 and ISO 27001 certification. We do not publish the details of our security arrangements.

Your rights

You may ask what we hold about you, ask us to correct it, ask for it to be deleted where no legal retention applies, ask us to restrict how we use it, object to our use of it, or ask for a copy in a portable form. Write to [email protected] and we will reply within 30 days. If you are in the EU and our answer does not satisfy you, you may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes

If this policy changes in a way that matters, we will update the date at the top of this page.