Data Destruction Policy
D&V Global B.V.
Last updated: 16 August 2026 | Version 2.1
1. Introduction
D&V Global B.V. (KvK 69819718), also trading as GETSERVERS.NL and SERVERSMART.NL (“D&V Global”), is committed to the secure and compliant destruction of data in accordance with applicable law, including the GDPR, and industry best practices. This policy defines the procedures and standards applied to the destruction of data and data-bearing assets in the course of managed hosting and infrastructure services, server decommissioning engagements, and the end-of-life handling of our own equipment.
2. Scope
This policy applies to all data processed by D&V Global and to all data-bearing media under its control, including hard disk drives (HDD), solid-state drives (SSD) and other flash media, backup media, and servers and network equipment with persistent storage. It binds all employees, contractors, and authorized partners involved in data handling or destruction. For colocation customers who retain physical control of their own equipment, destruction is performed only upon the customer’s instruction as part of a decommissioning engagement.
3. Deletion upon Service Termination
When a hosting service ends, data handling follows Section 11.5 of our Terms & Conditions and Section 12 of our Data Processing Agreement:
- Retrieval window. The customer may retrieve their data within 14 days after the effective date of termination (subject to the exceptions stated in the Terms & Conditions).
- Deletion from active systems. After the retrieval window, customer data is deleted from active systems within 30 days.
- Backups. Data in backup systems is not individually deleted but expires through the regular backup rotation cycle, within a maximum of 90 days after deletion from active systems. Backups are protected by the same security measures as active systems until expiry.
- Statutory retention. Data we are legally required to retain (e.g. billing records) is retained only as long as required and then deleted.
- Media reuse. Storage media are sanitized in accordance with Section 5 before any reuse or disposal.
4. Destruction Methods
The method is selected based on media type, data sensitivity, customer requirements, and regulatory obligations:
- Logical sanitization (clear/purge): certified overwriting or cryptographic erase, in accordance with NIST SP 800-88 techniques appropriate to the media type, with verification of successful erasure. Standard for media intended for reuse.
- Physical destruction: shredding, crushing, or disintegration of media; degaussing for magnetic media where applicable. Applied where sanitization is not possible (e.g. defective drives) or where the customer or regulation requires it.
- Defective media: drives that cannot be reliably sanitized are physically destroyed and never leave controlled custody in a readable state.
5. Standards
D&V Global applies NIST SP 800-88 Rev. 2 (Guidelines for Media Sanitization), as amended or superseded from time to time, as its baseline standard, follows ISO/IEC 27001 principles for information security management, and complies with GDPR requirements for the erasure of personal data. Internal procedures are reviewed against the current revision of the standard.
6. Chain of Custody
For decommissioning engagements and internal media handling: all assets are documented upon receipt; unique identifiers (serial numbers, asset tags) are recorded; every transfer between locations or custodians is logged; media awaiting destruction is stored in secure, access-controlled areas; transport is conducted under secure, documented procedures; and access is restricted to authorized personnel.
7. Verification, Records, and Certificate
Each destruction activity is verified and logged (asset identifier, method, date, operator). Records are retained for audit purposes. Upon completion of a decommissioning engagement — and for other engagements upon request — D&V Global issues a Certificate of Data Destruction stating the date of destruction, a description of the assets (including serial numbers), the method used, and confirmation of completion. Customers may request supporting reports and audit information.
8. Customer Responsibilities
Customers are responsible for identifying the assets and data to be destroyed, issuing clear instructions, retrieving any data they wish to keep before destruction (see Section 3.1), confirming legal ownership of equipment submitted for destruction, and specifying any sector-specific regulatory requirements that apply to their data.
9. Personnel
Destruction activities are performed only by authorized, trained personnel bound by confidentiality obligations. Third-party destruction or recycling partners, where used, are contractually bound to equivalent standards and provide their own destruction documentation, which is included in the engagement records.
10. Incidents
If a security incident affects media awaiting destruction, we apply immediate containment measures, notify affected customers without undue delay in accordance with the Data Processing Agreement, and conduct an investigation with corrective actions.
11. Review
This policy is reviewed at least annually and updated to reflect changes in regulation, technology, and operations. The current version is always published on this page.
12. Contact
D&V Global B.V.
Microfoonstraat 10, 1322 BN Almere, the Netherlands
KvK: 69819718 | VAT: NL858025309B01
Email: office@dv-global.nl | Technical support: support@getservers.nl