Έκπτωση Αστραπή 50% έκπτωση σε όλους τους servers Τελευταία Ημέρα!
Λήγει σε: 00D 00H 00M 00S

Last updated / effective date: July 1, 2026

1. Introduction

XIO Systems Co., doing business as Legion Hosting ("Legion Hosting", "we", "us", "our"), is committed to protecting the privacy of our users. This Privacy Policy (the "Policy") explains what personal information we collect, how we use and share it, how long we keep it, and the rights and choices available to you when you use our website, client area, control panels, servers and related services (the "Services").

XIO Systems Co. is a company registered in British Columbia, Canada. We are the controller (and, under Canadian law, the organization responsible) for the personal information described in this Policy. Our handling of personal information is governed principally by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (BC PIPA), and, where they apply to you, by the UK and EU General Data Protection Regulation and United States state privacy laws. Our contact details are in Section 15.

This Policy is an informational notice; it is not a contract and, except where we expressly ask for your consent for a specific purpose, we do not rely on your consent as the basis for processing. Your use of the Services is governed by our Terms of Service.

2. Scope

This Policy covers information we handle as a controller — the information you give us to open an account, buy and use the Services, and get support.

It does not cover information that you or your users place on servers you rent from us (for example player data, chat logs, world saves, plugin databases or Discord bot data). For that information you are the controller and we act as a processor on your instructions; you are responsible for having a lawful basis for it, for telling your own users about it, and for responding to their requests. Our obligations to you as processor are set out in Section 9 of the Terms of Service, which together with this Policy forms our data processing agreement. It also does not cover third-party websites or services we link to.

3. Information We Collect

  • Account and identity information — name, email address, company name (if any), postal address, phone number, and any username you choose.
  • Billing and transaction information — the products you buy, invoices, credits, refunds, tax status, billing address, and the last four digits, card type and expiry of your payment method. Full payment card numbers are collected and stored by our PCI-compliant payment processors, not by us.
  • Technical and usage information — IP addresses, browser and device type, operating system, referring pages, pages viewed, timestamps, login and administrative action logs, control panel activity, and server access, error and abuse logs.
  • Support information — the contents of support tickets, live chat, email and other correspondence, including any information you choose to include in them.
  • Fraud and abuse signals — information used to detect fraudulent orders, trial abuse and account sharing, including IP address, device and browser characteristics, and risk scores returned by our payment and fraud-prevention providers.
  • Affiliate information — referral links, click and conversion records, and payout details, if you join our affiliate program.
  • Cookie and similar data — see Section 5.

We do not intentionally collect special category data (such as health, biometric, religious or political information) and ask that you do not send it to us.

4. How We Use Information, and Our Legal Bases

We use personal information for the purposes below. Where the UK/EU GDPR applies, the legal basis for each purpose is shown in brackets.

  • Create and administer your account, provision servers, and provide the Services (performance of a contract).
  • Process payments, issue invoices and credits, handle refunds and chargebacks, and collect amounts owed (performance of a contract; legal obligation; legitimate interests in recovering debt).
  • Provide support and respond to your enquiries (performance of a contract; legitimate interests).
  • Monitor, secure, troubleshoot and improve the Services and our network, including capacity planning and diagnosing faults (legitimate interests in operating a secure, reliable service).
  • Detect, investigate and prevent fraud, trial abuse, network abuse and breaches of our Terms (legitimate interests in protecting our business, our network and our customers; legal obligation).
  • Send you service and transactional messages such as invoices, renewal notices, maintenance windows, incident notices and policy updates (performance of a contract; legitimate interests). You cannot opt out of these while you hold an account.
  • Send marketing messages about our products and offers (express or implied consent as required by CASL; consent or legitimate interests under the GDPR). You can unsubscribe at any time using the link in any marketing email or via the client area. See Section 11 for how we apply Canada's Anti-Spam Legislation.
  • Measure and improve our website and marketing, including analytics (consent where required by cookie law; otherwise legitimate interests).
  • Comply with legal obligations, respond to lawful requests, and establish, exercise or defend legal claims (legal obligation; legitimate interests).

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object as described in Section 11.

5. Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, remember your cart, currency and language, secure the client area against cross-site request forgery, and understand how the website is used. We use:

  • Strictly necessary cookies — session and authentication cookies set by our billing platform. These cannot be switched off without breaking the site.
  • Preference cookies — remember choices such as language and currency.
  • Analytics cookies — help us measure traffic and improve the site. Where required by law these are set only with your consent.

Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent you from logging in or placing an order. We honour Global Privacy Control signals where we are required to do so.

6. How We Share Information

We do not sell your personal information. We share it only as described here:

  • Service providers (processors) who help us run the business under contract and may process your information only on our instructions — payment processors and fraud screening, data centre and network providers, email delivery, ticketing and live chat, backup and monitoring, analytics, and accounting.
  • Licence and certificate vendors — where you purchase a third-party licence or an SSL certificate through us, we pass the details the vendor or certificate authority requires in order to issue and maintain it.
  • Legal and safety disclosures — where we believe in good faith that disclosure is required by law or legal process such as a subpoena or court order, or is necessary to protect the rights, property or safety of Legion Hosting, our customers or the public, to enforce our Terms, or to investigate suspected fraud or abuse.
  • Corporate transactions — in connection with a merger, acquisition, financing, reorganization or sale of assets, subject to the acquirer continuing to handle your information in accordance with this Policy.
  • With your direction — where you ask us to share information, for example with a third party working on your server.

7. International Transfers

We are based in Canada and we operate servers in multiple countries worldwide. Your personal information, and the data on any server you rent, may therefore be stored and processed outside your own country and outside Canada, including in the United States and elsewhere. You choose your server location at the time of order.

While information is located in another country it is subject to the laws of that country, and may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. We provide this notice to meet our obligations under PIPEDA and BC PIPA.

Wherever your information is held, we remain accountable for it and require our service providers by contract to protect it to a comparable standard. If you are in the United Kingdom, European Economic Area or Switzerland, we rely on appropriate safeguards for transfers, principally the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical and organisational measures. Canada benefits from a European Commission adequacy decision for commercial organizations subject to PIPEDA. You may request a copy of the relevant safeguards, or details of where your data is held, using the contact details in Section 15.

8. Data Retention

We keep personal information only as long as necessary for the purposes described in this Policy, and then delete or anonymise it. In general:

  • Account records — for as long as your account is open, and afterwards for as long as needed to resolve disputes and enforce our agreements.
  • Billing and tax records — 6 years from the end of the tax year to which they relate, which is the period Canadian tax law requires us to keep business records.
  • Server, access and security logs — approximately 6 months, or longer where retained for an ongoing abuse, security or legal investigation.
  • Support tickets — for as long as needed to provide continuity of support and to defend claims.
  • Customer server data — deletion of server content on termination is governed by Section 12 of the Terms of Service, not by this Policy.

9. Security

We take reasonable technical and organisational measures to protect personal information against unauthorized access, use, alteration or disclosure, including encryption in transit, access controls, and restricting staff access to what their role requires. However, no method of internet transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for enabling two-factor authentication where offered.

10. Children's Privacy

The Services are not directed to, and may not be purchased by, children under 13. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA and UK). Accounts must be held by a person who has reached the age of majority where they live, or opened with the involvement of a parent or legal guardian as described in the Terms of Service. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.

11. Your Rights — Canada (PIPEDA and BC PIPA)

Under Canadian federal and British Columbia privacy law you have the right to:

  • access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed;
  • request correction of inaccurate or incomplete personal information, and have the correction sent to anyone we disclosed it to in the past year;
  • withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent necessary to provide the Services means we can no longer provide them;
  • ask about our privacy practices and the identity of our privacy contact; and
  • complain about our handling of your personal information.

We will respond to an access or correction request within 30 days, or tell you if we need an extension permitted by law. There is no fee for a routine request; if a fee is permitted for a large request we will tell you the estimated cost before proceeding. We may refuse access in the limited circumstances the legislation allows, such as where disclosure would reveal another person's personal information or privileged material, and we will tell you the reason.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), or, for matters within its jurisdiction, the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).

Commercial electronic messages. We send marketing email in accordance with Canada's Anti-Spam Legislation (CASL). We send it only where we have your express consent or a form of implied consent that CASL recognises, such as an existing business relationship. Every marketing message identifies us, gives our mailing address, and includes a working unsubscribe mechanism that we action within 10 business days. Transactional and service messages about your account are not marketing and continue regardless of your marketing preferences.

12. Your Rights — UK and EEA (GDPR)

If you are in the United Kingdom or the European Economic Area, you have the right to:

  • request access to the personal information we hold about you, and a copy of it;
  • have inaccurate information corrected;
  • have your information erased in certain circumstances;
  • restrict our processing of your information in certain circumstances;
  • receive information you provided to us in a portable, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing carried out on the basis of legitimate interests, and to object at any time to processing for direct marketing;
  • withdraw consent at any time where we rely on consent, without affecting processing carried out before withdrawal; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions, although we do use automated fraud scoring to flag orders for human review.

To exercise these rights, contact [email protected]. We will respond within one month, extendable by two further months for complex requests. We may need to verify your identity first. You also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office.

13. Your Rights — California and Other US States

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or another state with a comprehensive privacy law, you may have the right to:

  • know the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collecting it, and the categories of third parties to whom we disclose it;
  • request deletion of your personal information, subject to exceptions such as completing a transaction, security, and legal compliance;
  • request correction of inaccurate personal information;
  • opt out of the sale or sharing of personal information, and of targeted advertising and certain profiling; and
  • not be discriminated against for exercising these rights. We do not deny services, charge different prices, or provide a different level of service because you exercised a privacy right.

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended. We have not sold or shared personal information in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.

The categories of personal information we collect are set out in Section 3, the purposes in Section 4, the recipients in Section 6, and our retention periods in Section 8. To exercise a right, email [email protected] from the address on your account, or write to us at the address in Section 15. You may use an authorised agent, in which case we will require written proof of authorisation. If we deny a request you may appeal by replying to our decision; we will respond to an appeal within the period required by your state's law. California residents may also request information under California's "Shine the Light" law.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy on this page and revise the effective date at the top. If the changes are material we will make reasonable efforts to notify you by email or through the client area before they take effect.

15. Contact Us

If you have questions about this Policy or about how we handle your personal information, or if you wish to exercise a right, contact us:

XIO Systems Co. (d/b/a Legion Hosting)
422 Richards St, Suite 170, Vancouver, BC V6B 2Z4, Canada
Privacy enquiries and rights requests: [email protected]
General support: [email protected]

Ready to Get Started?

The servers are booted, select your plan and become our latest satisfied client.