How to Choose Hosting: What to Compare Before You Sign
Hosting plans differ less than the contracts attached to them. Check what the second term costs, whether you can restore a backup yourself, and what the provider hands over on the day you leave.
Hosting plans differ less than the contracts attached to them. Check what the second term costs, whether you can restore a backup yourself, and what the provider hands over on the day you leave.
The hosting bill usually arrives in the inbox when nobody is thinking about it: in the first year it was thirty-six euros, in the second it is seventy-two, and in between nobody has changed anything on the site or on the plan. Visitor numbers are the same, the files are the same, and yet the price has doubled, even though nothing has gone wrong and nobody has tried to deceive anyone. The first term has simply ended, and what has started to apply is what stood on the same price page the whole time, only under a different heading and in smaller type.
A hosting choice is almost never decided on the technical specifications, because those are comparable, published, and for most company sites the difference between two plans is smaller than the difference between two years on the same plan. It is decided on what is written in the contract, and that is precisely what almost nobody looks at, because hosting is ordered as self-service, where the contract is accepted by ticking a box next to a link nobody opens. We have written separately about how the plan types themselves differ, comparing shared hosting, a VPS and a cloud server; this article is about what remains once the plan type has already been chosen, namely the promises, the price after the term ends, backups, and leaving.
The percentage measures availability, not your losses
The availability percentage is the most often quoted figure on a hosting price page and at the same time the least understood, because it is not a promise that the site will work, but the calculation base for compensation, which is almost always paid not in money but as a credit against future invoices. Hetzner's cloud-server terms put it as directly as it can be put, naming the compensation Cloud Credits, excluding cash and adding that there are no other remedies; Amazon Web Services and Google Cloud use different words in their documents, but the meaning is the same.
The other side that goes unnoticed is the exclusions list, and it tends to be longer than the promise itself. Scheduled maintenance of which the provider has given notice is not counted at all, and neither is anything caused by the customer's own software or configuration, which in practice is a much wider exclusion than it sounds: a plugin installed wrongly, an overloaded database or a mistaken setting remains the customer's responsibility regardless of how long the site was down and how many orders failed to arrive in that time. DigitalOcean names this in its terms, mentioning the customer's application code and configuration errors, and alongside that almost every contract excludes force majeure and third-party networks beyond the provider's boundary, which means the entire path from their router to your office.
OVHcloud's virtual-server terms have a further twist that deserves its own paragraph: availability there is measured by PING requests, and if the customer's configuration blocks those requests, the guarantee simply does not apply. A company that has closed ping replies for security reasons has itself switched off the measuring instrument on which the whole promise rests, and nobody warns about that separately, so it is a good example of why the technical details in the contract are not a legal formality but determine whether the figure will ever fire at all.
Finally, compensation is usually not received automatically: it has to be claimed, and the claim has a deadline, which in Hetzner's case is fourteen days after the end of the month, in Google Cloud's sixty days, while Amazon Web Services counts to the end of the second billing cycle. A company whose site was down is at that moment dealing with the consequences, not filling in a form, so the deadline passes quietly and the compensation that was formally due is paid to nobody. Before signing it is therefore worth establishing four things at once: who measures availability and with what instrument, what is on the exclusions list, how long you have to claim, and whether the guarantee covers backups at all, because Hetzner's cloud guarantee does not include them any more than it includes firewalls and load balancers.
Availability and response time are two different promises
Next to the availability percentage, contracts often show a second figure that looks similar and means something else entirely, namely response time, which sets how quickly the provider replies to a ticket, not how long the site runs. A company that has bought a four-hour response time has bought a promise that someone will write back in four hours, not a promise that the problem will be solved in four hours, and the difference between those two quantities at night on a Sunday is exactly the difference that decides everything: a ticket answered in thirty minutes with a counter-question about the domain name has, formally, been served.
A third figure, which appears less often but is the most important at the moment of recovery, is how long restoration takes together with how much data may be lost, namely how quickly the provider undertakes to restore the service after a serious outage and how many hours of work may disappear for good. Most shared-hosting contracts promise nothing on this, and it is not hidden, because the relevant clause simply is not there; if the contract does not say how long restoration takes and how much may be lost, then the honest answer is that neither is specified, and on the day both will be decided by how things turn out.
In practice that means three questions must not be collapsed into one: how long in a year the service may be down, how quickly someone replies, and how quickly everything is back in place, because each of them has its own line in the contract or else nobody has one, and the second case is the more common. For a company whose site is only a brochure site, that may be entirely acceptable, but for a company whose shop is a source of revenue, the answer about the availability percentage helps least of the three, because it talks about annual statistics at the moment when the next three hours are what matter. When we take on infrastructure maintenance, we agree all three separately for exactly this reason.
The first term ends, and the price changes
The advertised price in the hosting market is almost always the first-term price, and the second-term price sits on the same page, only less prominently. In September 2026 Hostinger was asking 2.99 dollars a month for the Premium plan on a forty-eight-month term and writing beside it that renewal is at 10.99, while GoDaddy's Economy plan cost 6.99 dollars and renewed at 11.99.
None of these companies is hiding anything, because the figures are published, they sit on one page and they can be read before you order; the problem is that the decision is made by comparing the first columns, and you pay on the second. The first term is long besides, so three or four years pass between the decision and its consequences, and at that point moving seems more expensive than the price difference even when it is not; it is exactly this time lag that makes the introductory price an effective sales instrument, and there is no trick in it.
The calculation that helps here is simple and takes five minutes: add up what you will pay over five years at the renewal price, not at the introductory price, and compare offers on that figure. Hostinger Premium for forty-eight months at the introductory price is a hundred and forty-four dollars, but the fifth year at the renewal price of 10.99 dollars a month adds another hundred and thirty-two, so the five-year total is two hundred and seventy-six dollars, not a hundred and eighty as a simple multiplication by the introductory price would show, and the difference arises not because anything has got worse, but because the promotional period has ended. The Latvian host Hostnet, with MINI at €2.99 against €5.99, is a different mechanism — that is thirty-six months prepaid against a monthly payment, not an introductory price that becomes €5.99 after the term.
Pay attention as well to whether the term renews automatically and how long before that you have to give notice of cancellation, because automatic renewal at the full price is exactly the mechanism that produces the doubled invoice, and the notice period tends to be longer than people remember. If the provider does not publish the full price at all, that is already an answer in itself, because a price you cannot find out before signing is a price you cannot agree.
A company is not a consumer, and that changes the conversation
This is where many people go wrong, and go wrong expensively, because the European Union's rules on unfair terms in consumer contracts — Council Directive 93/13/EEC — apply to contracts between a seller or supplier and a consumer, that is, a natural person acting for purposes which are outside their trade, business or profession. In the EU and the EEA that definition is transposed into each country's own consumer law, so a limited company that buys hosting for its site is not a consumer, and that changes almost everything a person intuitively expects from a contract.
Between traders, contractual freedom is substantially greater than in a consumer contract, while the right of withdrawal, unfair-terms control of the kind Directive 93/13 requires, and the consumer claim period for non-conformity remain consumer instruments in the reader's own member state — or in Norway. They do not attach to a company, and a provider is under no duty to offer them voluntarily, although some do for larger clients.
The practical meaning is direct and sometimes unpleasant: the jump from the introductory price to the full price is not an unfair term a company can challenge, but a contractual term the parties agreed when the box was ticked — and Article 4(2) of the Directive itself puts the price of the main subject-matter outside the unfairness test when the term is in plain, intelligible language, which a published price page is. Automatic renewal is not a trick the law protects a company from, and there is no general duty to warn about a price change in a particularly striking way if it is already published on the price page; a unilateral change of terms, where the contract provides for one, is harder to challenge in a commercial contract than in a consumer one, though some member states still control standard terms between businesses under their civil codes.
A company does not get the consumer unfair-terms list. Some member states still police standard terms between businesses — Germany, France, Sweden and Norway among them — so if the contract is governed by one of those laws, those codes are the next place to look; in every case the contract still has to be read before it is signed, and what is not acceptable has to be agreed then. Although that sounds obvious, this step is most often skipped, because the self-service form does not feel like a negotiation. For larger orders negotiations are entirely possible and providers go along if asked; for smaller orders there are no negotiations, but the choice between two providers remains, and you make it by reading both contracts, not both price pages.
A backup in the contract and a backup as a courtesy
The word backup on a price page can mean two entirely different things, and the difference shows up only on the day the copy is needed: the first meaning is a copy the provider makes for its own purposes, so that after an outage it can restore its infrastructure, and the second is a copy you can restore when you need to, and whose existence is a contractual obligation. On the price page both are called by the same name, and only in the contract can you see which of them has been bought.
OVHcloud names this difference openly in its documentation, writing that shared-hosting backups are not contractual, that they are offered as additional help in emergencies and that the customer is advised to make their own copies; in the same place there is also a detail that changes what restore means, namely that a restore from the control panel overwrites the whole storage space, not one file. For a company that wants to put back one page deleted by mistake, that means a choice between rolling the whole site back to the previous day and nothing.
Hostinger's hosting agreement goes further still, and it is worth reading literally: the customer is responsible for making their own archival copies, the provider's copy is made once a week and overwrites the previous one, is kept for two weeks, is provided as a courtesy and may be changed at any time, while accounts that exceed thirty gigabytes are removed from off-site copying altogether. That means it is precisely the largest sites that are left without an off-site backup, and all of this is written in the provider's own document, in which there is nothing unfair: it is simply not what the word backup leads you to expect.
There is another end of the range as well, and it is just as important to know, because on Hetzner's managed web hosting copies are made every night, kept for fourteen days in a separate data centre, and from the panel the customer can restore individual files, mailboxes or databases, which is already a copy you can work with. DigitalOcean, for its part, documents what many people learn too late, namely that its backups and snapshots cannot be downloaded, so the copy exists, but it lives inside the provider and at the moment of a move it is of no value.
The questions that settle this section are four and will serve for any provider: how long copies are kept, how finely you can restore, whether you can do the restore yourself or it is a paid ticket, and whether the copy can be taken out. We ourselves make copies every day, keep them for thirty days off the machine itself and test the restore regularly, because an untested copy is an assumption, not a copy, and the difference between the two is learned only once.
What happens on the day you leave
Incoming migration is advertised almost everywhere, because providers move sites to themselves free of charge, quickly and sometimes the same day, but outgoing migration appears in contracts much more rarely, and that is exactly where the costs hide that nobody calculates before signing. The asymmetry is entirely logical from the seller's point of view and equally expensive from the buyer's.
Hostinger's hosting agreement writes it unambiguously: the provider will not move or transfer the site or server content to another provider, and if the customer has not moved the content before the contract ends, the content is deleted and a copy can no longer be obtained. That is not an interpretation and not our assumption, but a section of the contract; likewise Hetzner cloud-server backups are deleted together with the server, so at the moment the account is closed the history disappears as well, and DigitalOcean's copies, as already mentioned, cannot be downloaded.
Put these three facts together and you get a situation in which leaving is possible only if it is planned in advance: the site has to be copied while the account is still running, the database dumped, the mailboxes moved, domain management taken over, and only then may the contract be ended. The order in which this is done matters more than the speed, because each of these steps on its own is simple, but in the wrong sequence they block one another, and the only time the sequence can no longer be repaired is the one in which the account is already closed.
Before signing it is therefore worth asking one question that reveals almost everything else, namely what exactly the provider hands over to a departing customer and in what form; the answer is usually quick and clear, and it lets you compare two offers far better than any technical specification. We answer that question by handing over configuration and data on request, and that is a deliberate point of choice, not a courtesy, because a customer who cannot leave is not a customer who has stayed.
When the provider processes personal data on your behalf
Hosting almost always means that someone else physically holds your customers' data, and in the sense of the General Data Protection Regulation the company whose site it is is usually the controller, while the hosting provider is the processor. Hostinger says this directly in its contract, stating that the customer remains the controller at all times, and that is not a formal detail, because that split gives rise to duties that have to be set out in the contract, and responsibility that stays with you regardless of who holds the server.
Article 28 of the Regulation requires that the relationship between the controller and the processor be set out in writing and that the contract contain specific points on what data are processed, for how long, for what purpose, with what security measures and with which other processors. In practice this is called a data processing agreement, and serious providers offer it themselves, often as a separate document that has to be accepted at registration; if a provider does not offer such a document at all, that is a sign of how seriously the rest of the duties are taken there too.
The most interesting point sits at the very end, because Article 28(3)(g) of the Regulation requires that the processor, at the choice of the controller, delete or return all the personal data to the controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data. That is a duty that operates at the very moment of leaving and covers the personal data of your site's users, but does not cover the site's files, configuration or code, and it is exactly this boundary that is most often misunderstood: the Regulation gives you the customer list, not the site.
From that follows a practical step before signing, namely ask whether the provider has a data processing agreement, where it is to be found and what it says about returning and deleting data after the contract ends. Ask also where the servers physically sit, because although the Regulation does not require data to be kept in a particular member state, a named city in the contract is worth far more than the word Europe, and Germany and Finland are in the European Economic Area just as any EU member state is, so the choice between them is an operational question, not a compliance one.
What the Data Act gives and what it does not
From 12 September 2025, Regulation (EU) 2023/2854 of the European Parliament and of the Council, the Data Act, applies in the Union; in the EEA it applies only once incorporated, and it is not yet incorporated — still under assessment in the EEA-EFTA states — so it does not bind a Norwegian host. Chapter VI is headed "Switching between data processing services": Article 23 requires providers to remove obstacles which inhibit customers from switching to a data processing service of the same service type provided by a different provider, or to on-premises ICT infrastructure, or, where relevant, from using several providers at the same time. Article 25, headed "Contractual terms concerning switching", provides that the maximum notice period for initiation of the switching process shall not exceed two months and that there then follows a transitional period of 30 calendar days, while from 12 January 2027 providers of data processing services shall not impose any switching charges.
That is a strong instrument, and that is exactly why it is important to know its limits, because the Regulation applies to data processing services as defined in Article 2(8), namely a digital service that is provided to a customer and that enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources of a centralised, distributed or highly distributed nature that can be rapidly provisioned and released with minimal management effort or service provider interaction. A cloud server that can be switched on and off by the hour meets that, but a prepaid annual shared-hosting account that cannot be scaled or released on demand does not always meet it, and that has to be assessed case by case.
There is a second limit as well, which is easy to confuse and which has already been tried in sales: the recitals of the Regulation state expressly that standard service fees for the provision of the data processing services themselves are not switching charges. The Data Act does not prohibit an introductory price, does not cap the renewal price and does not abolish fixed-term contracts, and a proportionate charge for early termination of a fixed-term contract remains permitted, so a company that hopes the Regulation will solve the doubled invoice is expecting from it something it does not promise: it regulates switching, not pricing policy.
Nor does it help to invoke Article 20 of the General Data Protection Regulation, and that is a mistake that appears even in consultants' presentations, because the right to data portability belongs to the data subject in respect of personal data concerning him or her which he or she has provided to a controller. It does not give a company the right to receive its hosting account, database or site files, because the subject is different and the object is different, so a company's way out runs through the contract and, if the service meets the definition, through Chapter VI of the Data Act.
Questions to ask before you sign
Everything above comes down to a small set of questions that can be put to any provider and whose answers are comparable with one another: how many minutes the promised availability percentage amounts to and what is on the exclusions list, whether compensation has to be claimed and within how long, what the price is after the first term, whether the contract renews automatically and how long in advance you have to give notice of cancellation. The backup questions belong there too, namely how long they are kept, whether they are a contractual obligation or a courtesy, whether you can restore them yourself and whether they can be taken out.
Next come the questions about leaving, which are the most uncomfortable to ask and the most valuable: what the provider hands over if the customer moves, and in what form, whether it helps with the move or expressly refuses, what happens to the content after the contract ends and how long it is still available. It is also worth asking whether the service meets the Data Act's definition of a data processing service and, if it does not, what switching terms are written into the contract; the discomfort here is exactly what makes the questions valuable, because they are rarely asked in a sales conversation and the answers are therefore unrehearsed.
And finally the resource questions hidden under the word unlimited: on Hostnet's price page this word refers to traffic and sits in the same table as a file-count limit, which on the MINI plan is four hundred thousand, while on Hostinger's plan, whose name itself is Unlimited, there are still caps on CPU, memory, disk and file count. The same company's documents moreover write that unlimited applies to hosting websites, not to file storage or archiving, so the word names one parameter, not all of them, and the question that reveals this is quite direct: which parameters are limited, and at what figure.
If these questions seem too many for one hosting invoice, it is worth remembering what the alternative is, because a site you cannot move is a site whose price is set by someone else, and that dependence shows up at exactly the moment when it is most inconvenient. A conversation about moving is always easier to have while the contract is not yet signed, because that is the moment when you have the only argument the provider cares about; if you would like us to ask these questions, write to us, and we will read the contract with you.
Frequently asked questions.
What does 99.9% availability actually mean in a hosting contract?
It means the calculation base for compensation, not a promise that the site will work. If availability is below what was promised, the provider usually grants a credit against future invoices, not cash, and most contracts name this credit as the only remedy available. Compensation almost always has to be claimed by you within a set deadline: Hetzner gives fourteen days after the end of the month, Google Cloud sixty days. The exclusions list is at least as important as the percentage itself, because it usually includes scheduled maintenance and everything caused by the customer's own software or configuration.
Why is the hosting bill higher in the second year than in the first?
Because the advertised price is the first-term price, and the full price sits on the same page less prominently. GoDaddy's Economy plan in September 2026 cost 6.99 dollars a month in the first year and renewed at 11.99. Hostinger's Premium plan after forty-eight months renewed at 10.99 dollars from an introductory price of 2.99. Hostnet MINI at €2.99 against €5.99 is payment frequency, not a first-year and second-year price. Nobody is hiding anything, but the decision is made on the first column and you pay on the second. Calculate the five-year total at the renewal price and compare offers on that.
Do consumer rights protect a company if the hosting price jumps sharply?
No. Directive 93/13/EEC, as transposed in the reader's member state or in Norway, protects natural persons acting outside their trade, business or profession. A company that buys hosting for its site is not a consumer. The jump in price after the first term is not challengeable as an unfair term of the 93/13 kind; Article 4(2) of the Directive itself puts the price of the main subject-matter outside that test when the term is in plain, intelligible language. A company does not get the consumer unfair-terms list; some member states still control standard terms between businesses under their civil codes, so if the contract is governed by one of those laws, those codes apply. In every case the contract has to be read before it is signed, and what is not acceptable has to be agreed then.
How does the provider's backup differ from a copy of my own?
By whether you can restore it when you need to, and whether it is a contractual obligation at all. OVHcloud writes in its documentation that shared-hosting backups are not contractual and that a restore overwrites the whole storage space. In Hostinger's contract the copy is a courtesy that may change at any time, is kept for two weeks, and accounts above thirty gigabytes are removed from off-site copying. DigitalOcean's copies cannot be downloaded. Ask how long copies are kept, how finely you can restore, whether you can do it yourself and whether the copy can be taken out.
Does the Data Act let me switch to another host at any time?
Only if the service meets the definition of a data processing service in Article 2(8) of Regulation (EU) 2023/2854. A cloud server that can be switched on and off on demand usually meets it; a prepaid annual shared-hosting account does not always. Where the Regulation applies — in the Union, and in the EEA only once incorporated — the notice period for initiation of the switching process shall not exceed two months and the transitional period 30 calendar days, but switching charges will disappear only from 12 January 2027. The Regulation does not cap the price after the term ends, because a standard service fee is not a switching charge.
Servers, hosting and maintenance in the EU — Frankfurt, Helsinki or Riga, with 24/7 monitoring. Full management: updates, security and performance, automated backups with tested restores, SSL certificates, CDN and DDoS protection. We migrate you from your current host with no downtime and scale with the load.