Privacy Policy
Last updated: 22 August 2026
This Privacy Policy explains how Everon d.o.o. ("Everon", "we", "us", "our") collects, uses, shares, and protects your personal data when you visit https://everon.one sign up for an account at https://panel.everon.one or use any of our services.
We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the BiH Law on Personal Data Protection, and all other applicable data-protection laws.
1. Data Controller
The data controller responsible for your personal data is:
Everon d.o.o. Registration number: 2738466293840 Registered office: Kožara 12A, Brčko distrikt, Bosnia and Herzegovina Email: info@everon.one Web: https://everon.one
For any privacy-related question, request, or complaint, contact us at info@everon.one.
2. What Personal Data We Collect
2.1. Data you provide directly
- Account data: full name, email address, postal address, phone number, country, company name (if applicable), tax/VAT ID (if applicable), preferred language, currency.
- Authentication data: password (stored as a salted hash; we never see it in clear text), two-factor-authentication secrets if enabled.
- Billing data: invoices, payment history, partial card data (last 4 digits, expiry) returned by the payment provider for receipt purposes. We do not store full card numbers or CVV codes — they are handled exclusively by PayPal.
- Support communications: emails, ticket content, attachments you send us.
- Domain registration data: WHOIS contact details required by the registry (name, address, email, phone). These are submitted to the registrar and may, depending on the TLD, be published in the public WHOIS database.
- Domain search text: the domain name or free-text description you type into the domain search. Our billing panel offers AI-generated name suggestions, so this text is sent to WHMCS to produce them. It is not stored as part of your account and is not used for advertising. If you would rather it were not sent anywhere, type an exact domain (for example example.com) instead of a description — an exact domain is looked up directly and no suggestions are generated.
2.2. Data collected automatically
- Server and service logs: IP address, request timestamps, HTTP user-agent, requested URLs, response codes, error messages. These are needed for security, abuse prevention, and troubleshooting.
- Account activity logs: login times, IP address of login, actions taken in the billing panel.
- Cookies and similar technologies: see Section 8.
2.3. Data we do not intentionally collect
We do not knowingly process special categories of personal data (race, religion, health, sexual orientation, biometric, etc.). If you choose to store such data on your hosting account as part of your own application, you are the controller of that data and we act as your processor (see Section 7).
3. Why We Process Your Data (Legal Bases)
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; providing the Services | Performance of a contract (GDPR Art. 6(1)(b)) |
| Processing payments and issuing invoices | Performance of a contract; legal obligation |
| Keeping accounting records | Legal obligation (BiH tax law) |
| Security, fraud prevention, abuse detection | Legitimate interests (GDPR Art. 6(1)(f)) |
| Sending service-critical emails (renewals, security, maintenance) | Performance of a contract |
| Sending newsletters / marketing emails | Consent (GDPR Art. 6(1)(a)) — only if you opt in, you can withdraw any time |
| Responding to support requests | Performance of a contract; legitimate interests |
| Complying with court orders, legal demands, registry policies | Legal obligation |
4. How Long We Keep Your Data
- Active account data: for as long as your account is open.
- After account closure: account data is retained for up to 12 months, then deleted or fully anonymised, except where a longer period is required by law (see below).
- Invoices and accounting records: retained for the period required by BiH tax/accounting law (currently 10 years).
- Server logs: typically up to 90 days.
- Backups: rolled over within our normal backup retention cycle and overwritten in due course.
- Marketing consents: until you withdraw consent.
5. Who We Share Your Data With (Sub-Processors)
We use the following carefully selected sub-processors. Each is bound by a data-processing agreement and provides appropriate safeguards.
| Sub-processor | Purpose | Country | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting (physical data centres) | Germany (EU) | Inside EU/EEA |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payment processing | Luxembourg (EU) | Inside EU/EEA |
| Mailgun Technologies, Inc. | Transactional email delivery | EU region (Frankfurt) | EU-region endpoints + Standard Contractual Clauses |
| PublicDomainRegistry.com / LogicBoxes (ResellerClub) | Domain name registration | India / United States | Standard Contractual Clauses; transfer to registry as required by TLD policy |
| CloudLinux Inc. | Server OS / resource isolation (telemetry only) | United States | Standard Contractual Clauses |
| WHMCS Limited (WebPros) | Billing platform, and AI domain-name suggestions generated from text you enter in the domain search | United Kingdom / United States | Standard Contractual Clauses |
| JetBackup / JetApps | Backup management software (operates on our servers) | United States | Standard Contractual Clauses |
| Intuition Machines, Inc. (hCaptcha) | Bot and abuse prevention on the registration, contact and domain-search forms. Receives your IP address and interaction data in order to distinguish people from automated traffic. | United States | Standard Contractual Clauses |
| Cloudflare, Inc. | DNS, CDN, DDoS protection | United States / global | Standard Contractual Clauses |
We do not sell your personal data, and we do not share it with advertisers or data brokers.
We may disclose data to law enforcement or other authorities when required by a valid legal order, and to legal/financial advisors under confidentiality where necessary.
6. International Data Transfers
Some sub-processors are located outside the EU/EEA. When personal data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, additional technical and organisational safeguards.
7. When You Are a Controller and We Are a Processor
When you store personal data of your own end-users on your hosting account (for example, registered users of a WordPress site you host with us), you are the data controller for that data and we act as a data processor on your behalf. You are responsible for complying with the GDPR with respect to your end-users, including providing your own privacy notice and lawful basis. We process such data only to operate the hosting service, and pursuant to a data-processing agreement available on request.
8. Cookies
The everon.one website sets one cookie, and only if you ask it to. If you pick a language from the menu, that choice is stored in a cookie named everon_lang so your next visit opens in the same language. It holds two letters — en, de or bs — and nothing else, for one year. If you never touch the language menu, no cookie is set at all.
There is no analytics, no advertising and no tracking on this site. That single cookie exists only to carry out something you explicitly asked for, which is why it is exempt from consent requirements under the ePrivacy Directive and why you are not shown a cookie banner. It is never used to identify you, and it is not shared with anyone. Choosing English from the same menu undoes it, and clearing your browser's site data removes it.
The one thing on this site that would contact a third party is the map on the contact page, which is served by Google. It is not loaded unless you press the button on it. Until you do, nothing is requested from Google and no Google cookie is set. If you do press it, Google receives your IP address and may set cookies under its own terms — which is your choice to make, and the reason the button is there instead of the map loading on its own.
The client area at panel.everon.one is different, because a shopping cart and an account system cannot work without one. It uses strictly necessary cookies only. Browsing it sets a single session cookie, with a randomised name beginning WHMCS, marked Secure and HttpOnly, which exists so the site can remember your cart and keep you signed in. Signing in may set further cookies of the same strictly necessary kind. None of them are used for analytics, advertising or profiling.
These are exempt from consent requirements under the ePrivacy Directive because the service you asked for cannot be delivered without them. None of them are used to profile you, none are shared, and none survive beyond their purpose.
You can block or delete cookies through your browser settings at any time. Doing so will not affect the everon.one website, but it will prevent you from signing in to the client area.
9. Your Rights
Under the GDPR (and equivalent local laws), you have the right to:
- Access your personal data and obtain a copy;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), subject to our legal retention obligations;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests, including direct marketing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, without affecting processing already performed;
- Lodge a complaint with your local supervisory authority (in BiH, the Personal Data Protection Agency / Agencija za zaštitu ličnih podataka).
To exercise any of these rights, email info@everon.one from the email address on your account. We will respond within 30 days.
10. Security
We apply industry-standard technical and organisational measures to protect personal data, including:
- TLS/HTTPS for all data in transit;
- Encrypted storage of secrets and password hashes;
- Role-based access control and audit logging for staff access;
- Network segmentation, firewalls, and DDoS mitigation;
- Regular software patching and vulnerability monitoring;
- Restricted physical access at Hetzner data centres.
No system is 100% secure. In the event of a personal data breach affecting your data, we will notify you and, where required, the supervisory authority within 72 hours in accordance with GDPR Art. 33–34.
11. Children
Our Services are not directed at children under 16. If you are under 16, do not use the Services. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it.
12. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be notified by email or via your Account.
13. Contact
For any privacy question or to exercise your rights:
Everon d.o.o. — info@everon.one Kožara 12A, Brčko distrikt, Bosnia and Herzegovina