Business hosting: shared, VPS, dedicated server, cloud or PaaS
Blog
Technology

Business hosting: shared, VPS, dedicated server, cloud or PaaS

Cost, performance, who administers the server and where the data lives across five hosting models, with a table of who is responsible for what

DualFroz - VulCode CEODualFroz - VulCode CEO·21 September 2026·22 min read

If your business hosting only has to serve an ordinary website with your services and a blog, good shared hosting or static file hosting is enough. A VPS makes sense when the project needs its own software on the server and there is someone who will administer that server. The public cloud works well for variable traffic and where managed services help, for example a database with automatic backups. A dedicated server pays off under steady, heavy load, and PaaS when the application should deploy straight from the repository with no system administration at all.

So you choose hosting by first asking who will be the administrator, and only then by counting CPUs and gigabytes. Below we compare five models on cost, performance, the split of responsibility and data location, and at the end we explain how to move a site to another host without downtime.

In short
  • The hosting invoice is often the smaller part of the cost. The bigger part is administrator time: system updates, backups and responding to incidents.
  • On an unmanaged VPS, you or your contractor are responsible for the operating system, updates, firewall and backups. The provider is responsible for hardware and network.
  • The cloud bills for usage, including outbound data transfer. Without budget alerts the bill can come as a surprise.
  • GDPR does not require data to be stored in Poland. It requires a legal basis for transfers outside the EEA and a data processing agreement with the provider.
  • A 99.9% SLA allows more than 43 minutes of downtime in a 30-day month, and the compensation is usually a partial refund of the fee, not coverage of your losses.

Five hosting models in one table

Names on provider websites can be misleading: "cloud hosting" may mean ordinary shared hosting, and a "virtual server" from one provider is something different from a "virtual server" from another. Instead of comparing names, compare what you actually get and who looks after the system.

Hosting models at a glance

ModelWhat you getWho administers the systemTypical use
Shared hostingAn account on a server shared with other customers, a control panel, PHP, a database, emailProviderCompany website, blog, small online store
VPSA virtual machine with administrator (root) accessYou, unless you buy a managed versionApplications with their own software, larger stores
Dedicated serverAn entire physical machineYou, the provider replaces hardwareSteady, heavy load, databases
Public cloudMachines, databases, file storage and other services billed by usageYou, and partly the provider for managed servicesVariable traffic, scaling, managed services
PaaS and application hostingA platform you deploy code or a container toProviderWeb applications and frontends deployed from a repository

There is a sixth, simplest option worth adding to this list: static file hosting, often combined with a CDN. It suits sites that are ready-made HTML files, with no database and no PHP. We covered when that architecture makes sense in our comparison of WordPress and a headless CMS.

Shared hosting: when it is enough and where it stops

With shared hosting you get an account on a server used by many customers at once. The provider administers the operating system, web server, PHP and database, and you manage whatever you upload: the CMS, plugins and content. The package usually includes a control panel, email, a TLS certificate and backups made by the provider.

For a company website, a blog or a small WordPress site, this is usually the best ratio of price to hassle. You do not need anyone who knows Linux, and the provider's team solves most server problems.

The limits are just as clear. You have no administrator access, so you can only use the software the provider offers. Resources such as CPU, memory and number of processes are capped per account, and load generated by other customers on the same server can affect your site. Shared hosting stops being enough when you need:

  • an environment the provider does not offer, for example a specific version of Node.js, Python or a database,
  • background processes, such as job queues, long imports or real-time communication,
  • your own server configuration, for example custom caching rules or web server modules,
  • predictable performance under steady, higher traffic that you earn money from.

VPS: your own server without the hardware, but with all the responsibility

A VPS is a virtual machine running on a physical server alongside other machines. They are separated by a virtualisation layer, for example KVM, which also underpins Proxmox VE, the open virtualisation platform we contribute to. From your point of view a VPS looks like a separate server: you have administrator access and install whatever you want.

That is exactly why you need to distinguish two kinds of offer. An unmanaged VPS means the provider is responsible for hardware, virtualisation and network, and everything above that is on your side. A managed VPS moves some of the duties to the provider, but the scope of that "some" differs between offers and always needs to be checked in writing.

On an unmanaged VPS, someone has to take care of the following on a regular basis:

  • system and software updates, including security patches that sometimes require a reboot,
  • access: SSH keys, disabling password login, accounts of people who no longer work on the project,
  • the firewall, meaning which ports and services are reachable from the internet,
  • off-server backups and checking that they can actually be restored,
  • monitoring: uptime, disk space, load, certificate expiry,
  • responding to incidents, including at night and at weekends if the server runs a store or serves customers.

A one-click snapshot in the provider's panel is handy before a risky change, but it is not a backup in the full sense, because it sits in the same infrastructure and on the same account. We explained why a backup should be out of reach of anyone who takes over the server or the account in our article on business website security.

Also pay attention to how resources are described. Virtual CPUs are sometimes shared with other machines on the same physical server, and some providers sell more expensive variants with dedicated cores separately. If performance matters, ask which resources are guaranteed and which are only available when nobody else is using them.

Dedicated server: an entire machine for one company

A dedicated server is a physical computer in the provider's data centre, entirely at your disposal. There are no neighbours, so performance is predictable, and under steady, heavy load, such as a large database, the price per unit of computing power can be lower than in the cloud.

Responsibility looks the same as with an unmanaged VPS, with one difference: hardware can fail, and you need to know what happens then. The provider replaces a failed disk or power supply, but the replacement time depends on the contract, and the server may be down in the meantime. A RAID array protects against the failure of a single disk, but not against deleted data, an application bug or a compromised server, so it does not replace backups.

A single dedicated server is also a single point of failure. If downtime is expensive, you need a second machine or a plan to bring the system up elsewhere quickly, which raises the cost and requires an administrator who can maintain it. Scaling means ordering a new, bigger machine and migrating, not moving a slider in a panel.

Public cloud: you pay for usage, including the unplanned kind

The public cloud, meaning AWS, Google Cloud, Microsoft Azure and European providers among others, offers virtual machines billed by the hour or by the second, plus dozens of managed services: databases with automatic backups, file storage, queues, load balancing, automatically adding machines when traffic grows. The biggest advantage is flexibility: you add resources in a minute and pay only for what is running.

That same flexibility demands discipline. The bill is made up of many small items: machine running time, disks, snapshots, IP addresses, logs, service requests and outbound data transfer to the internet, which can be a significant item under heavy traffic. A forgotten test machine or badly configured logging generates costs without anyone noticing. Budget alerts, available from the major providers, should be set up on day one, not after the first surprise.

The cloud does not remove administrative duties either. AWS says so plainly in its shared responsibility model: the provider is responsible for the security of the infrastructure, and a customer using EC2 virtual machines is responsible for the operating system, including its updates and security patches, for the installed software and for the firewall configuration. Part of that responsibility moves to the provider only with managed services, such as a database offered as a service.

Cloud lock-in has two sources. The first is services that have no equivalent elsewhere: the more of them you use, the more expensive it is to move. The second is exit fees. This is where the EU Data Act changes things: according to the European Commission, from 12 January 2027 providers of data processing services may not charge switching fees, including fees for transferring data to a new provider. Until that date they may charge, but only up to the costs linked to the switch.

If being close to your users matters, the major providers have infrastructure in Poland. Google Cloud opened a region in Warsaw in 2021, Microsoft opened an Azure region in Poland in 2023, and AWS has a local zone in Warsaw, an AWS Local Zone, which is not a full region with the complete set of services.

PaaS and application hosting: you deploy code, not administer a server

PaaS platforms such as Vercel, Netlify, Render or Fly.io take over system administration entirely. You connect a repository, and every change pushed to the main branch deploys itself, often with a preview for every working branch. The platform handles the certificate, CDN and scaling, and nobody on the team needs to know Linux administration.

The limitations come from the model. The platform imposes limits, for example maximum function run time, deployment size or number of invocations per plan, and bills you for exceeding them. Long-running background processes, connections held open for hours or large databases do not always fit that model and often end up with another provider. The bill grows with traffic, and platform-specific features make moving harder.

Read the terms of free plans. For example, according to the documentation, Vercel's Hobby plan is intended for personal, non-commercial use only, so a company website needs a paid plan there. Clauses like that are easy to miss when a contractor launches a project "for free for now".

Who is responsible for what

This table is the most important part of the article. "You" means you or the contractor you hand the job to. If nobody is assigned to an item marked "You", that item is not getting done.

Split of responsibility across hosting models

AreaSharedUnmanaged VPSDedicatedCloud (virtual machines)PaaS
Hardware and networkProviderProviderProviderProviderProvider
Operating system and its updatesProviderYouYouYouProvider
Web server, PHP, databaseProviderYouYouYou or a managed serviceProvider, database often separate
Firewall and administrative accessProviderYouYouYouProvider
TLS certificateUsually providerYouYouYouProvider
BackupsProvider, your own copy is on youYouYouYou, with the provider's toolsYou, for the data
Application, CMS and their dependenciesYouYouYouYouYou
Monitoring and incident responseProvider for the server, you for the siteYouYou, provider for hardwareYouProvider for the platform, you for the application

One row is identical in every column: you are always responsible for the application. No hosting model will update your WordPress plugins or the libraries in your application code for you.

Costs: the bill and the administrator's time

We gave indicative annual market ranges for shared hosting and a VPS in our article how much does a website cost. When choosing a model, what you need to add on top of the subscription matters more than the subscription price itself.

With a VPS or a dedicated server, the first add-on is administrator time. Updates, reviewing logs, checking backups and responding to alerts take time every month, and an incident can take a whole day. Multiply those hours by the rate of the person doing them and add the result to the subscription. The cheapest unmanaged VPS often ends up more expensive than managed hosting if someone has to look after it.

The second add-on is items not included in the server price: backup storage with a different provider, a control panel licence if you want a panel like the one on shared hosting, extra IP addresses, monitoring tools, and business email, which on a VPS usually needs a separate service, because running your own mail server with good deliverability is a specialism of its own.

In the cloud you also get variability. The same project can cost different amounts from month to month, depending on traffic and how much data leaves the infrastructure. For a company that sets its budget once a year, a predictable subscription can matter more than a lower average price.

Performance: what really determines how fast a site is

Server response time is the first segment of the LCP metric we wrote about in Core Web Vitals in practice. It comes down to three things: the distance between the visitor and the server, how long the application takes to build the response, and whether the server has free resources.

You can measure time to first byte from a terminal:

ttfb.sh · bash
curl -o /dev/null -s -w 'DNS: %{time_namelookup}s  connect: %{time_connect}s  TLS: %{time_appconnect}s  first byte: %{time_starttransfer}s\n' https://example.com/

The output shows times in seconds, counted from the start of the request. If the gap between the end of the TLS handshake and the first byte is large, the time is being spent by the application or the database, not the network. Measure several times and on different pages, because the first request after a longer pause can be slower when the cache is empty.

For sites running on PHP and a database, single-core speed usually matters more than the number of cores, as do a supported PHP version with code caching (OPcache) enabled and full-page caching. A well-configured WordPress with page caching on average hosting can be faster than the same WordPress without caching on a powerful VPS.

Distance matters mainly for responses that cannot be cached. Static files, images and pre-rendered pages can be served by a CDN from a node close to the visitor, regardless of where the server is. For a site whose customers are in Poland, a server in Poland or a neighbouring EU country is a sensible choice, but with good caching and a CDN the difference users notice gets smaller.

Data location and GDPR

GDPR does not require personal data to be stored on a server in Poland. Data can flow freely within the European Economic Area. A transfer outside the EEA requires a basis under Chapter V of the GDPR, for example a European Commission decision finding an adequate level of protection, or standard contractual clauses.

For the United States, that basis is currently the EU-US Data Privacy Framework, Commission Decision 2023/1795 of 10 July 2023, covering US companies that have joined the programme. On 3 September 2025 the General Court of the European Union dismissed an action against that decision in case T-553/23 Latombe v Commission, and on 31 October 2025 an appeal against that judgment was lodged with the Court of Justice (case C-703/25 P). The Court of Justice struck down the two previous mechanisms, Safe Harbor and Privacy Shield, in 2015 and 2020, so if you choose a US provider it is worth having a plan for the case where the transfer basis falls again.

Choosing a European region with a US provider does not switch off US law. The CLOUD Act of 2018 requires providers subject to US law to disclose to US authorities, in the manner that law provides, data in their possession or control, regardless of whether the data is stored inside or outside the United States. For most company websites this does not change the decision, but for particularly sensitive data or requirements from public sector clients it can be an argument for a European provider.

Regardless of location, a hosting provider that stores personal data from your website processes it on your behalf. Article 28 GDPR then requires a data processing agreement with that provider. With larger providers it is a standard document available in the panel or on their website. Also check where backups are stored, because the server region and the backup region are not always the same, and which subprocessors the provider uses. This section is not legal advice, and in sectors with their own regulations, such as healthcare or finance, additional requirements may apply.

SLA and a plan for a data centre failure

An SLA, the guaranteed level of availability, is given as a percentage, and percentages that sound similar mean very different things:

How much downtime an SLA allows

SLAIn a 30-day monthIn a year
99%7 hours 12 minutesabout 3.65 days
99.9%43 minutes 12 seconds8 hours 46 minutes
99.95%21 minutes 36 seconds4 hours 23 minutes
99.99%4 minutes 19 seconds52 minutes 34 seconds

When reading an SLA, three details matter more than the number: what the provider counts as downtime, whether announced maintenance is included, and what the compensation is. Most often it is a partial refund of the fee for the period, and only if the customer requests it. For an online store, a day of downtime can cost more than a year's subscription, so an SLA is not insurance. It tells you how the provider designs its infrastructure.

A good illustration of a risk no SLA covers is the fire at the OVHcloud data centre in Strasbourg on 10 March 2021. The SBG2 building burned down, and some customers who kept their backups in the same complex lost their data for good. The lesson is simple: at least one backup should be stored in a different location, ideally with a different provider, and the procedure for bringing the site up elsewhere should be written down before you need it.

Business hosting: which model for which project

The table collects sensible starting points. Any project can start simpler and move later, as long as the application is not tied to a single provider.

Hosting matched to the project

ProjectSensible startWhen to think about changing
Brochure site or static websiteStatic hosting with a CDN, or shared hostingUsually no need
Company website on WordPressGood shared hosting with a supported PHP versionThe site slows down despite caching, or you need custom configuration
Online storeHigh-performance shared hosting or a managed VPSSales peaks overload the server, the catalogue and number of integrations grow
Admin panel or web application with a backendManaged VPS, or PaaS with a managed databaseUser numbers grow, you need background processes and scaling
Platform with growing, variable trafficPublic cloud with managed servicesCloud costs at steady traffic exceed the cost of your own servers
Steady, heavy load, large databasesDedicated server with a second machine or a recovery planYou need flexibility that hardware does not give you

Whatever you choose, take care of one thing in every project: that it can be moved. Code in a repository, configuration described in documentation or in files, data in a standard format and a domain registered to the company turn a hosting change into a project of days, not months.

Moving to another host without downtime

Changing hosting does not have to mean the site going offline or losing Google rankings, as long as page URLs stay the same. A proven sequence looks like this:

1
Shorten DNS record lifetimes

A few days before the move, set a low TTL on the domain's records so that traffic reaches the new server quickly after the switch.

2
Run the site on the new server in parallel

Copy the files and database, configure the certificate and test the site through an entry in the hosts file on your computer before you change DNS.

3
Freeze changes and sync the data

Pause content editing for the switchover, and for a store plan the switch for the quietest hours and do a final database sync.

4
Switch DNS

Point the domain's records at the new server and watch traffic and error logs on both servers.

5
Keep the old server for a few days

Some users and bots may still reach the old address for a while. Shut it down only once traffic to it has died out.

6
Remember email

If email was on the old hosting, the MX, SPF and DKIM records have to be moved separately, and mailboxes copied before the old account is closed.

Questions to ask a hosting provider before signing

  1. What exactly does the provider administer and what does the customer administer, and is that written into the contract?
  2. How often are backups made, where are they physically stored, how long are they kept and how much does a restore cost?
  3. What is the SLA, what counts as downtime and how do you claim compensation?
  4. In which country are the servers and backups located, and does the provider offer a data processing agreement?
  5. Which resources are guaranteed and which are shared with other customers?
  6. How do you get in touch during an outage: which channels, during which hours and with what response time?
  7. How do you export all your data, and how much does leaving the provider cost?
  8. Can the account be protected with two-factor authentication, and can several people be given separate access?

Frequently asked questions

Is shared hosting enough for a business?

For most company websites, blogs and small stores, yes, provided the provider offers a supported PHP version, backups and reasonable resource limits. Shared hosting stops being enough when you need your own software on the server, background processes or predictable performance under heavy traffic.

VPS or cloud: which should I choose?

A VPS gives you a predictable monthly cost and the simplicity of a single server. The cloud gives you flexibility, managed services and scaling, but you have to keep an eye on costs. With steady traffic and a simple application a VPS is usually cheaper, while with variable traffic or a need for a managed database the cloud can be more convenient. Either way, someone has to administer the system unless you use managed services.

Does the server have to be in Poland?

No. GDPR allows data to flow freely within the European Economic Area, and a transfer outside the EEA requires a legal basis, such as an adequacy decision. A location in Poland or a neighbouring EU country matters mainly for response speed for users in Poland.

What is managed hosting?

It is a service where the provider takes over server administration: system updates, configuration, monitoring and often backups. The scope differs between offers, so always check in writing which tasks are included in the price and which remain on the customer's side.

Is free hosting suitable for a business?

Rarely. Free plans have limits, often restrictions on commercial use, and no availability guarantee or support. They are fine for tests and prototypes, but for a website the company wins customers through, it is better to pay for a plan with clear terms.

Does moving to another host mean the site goes offline?

It does not have to. If the site is running in parallel on the new server before you change the DNS records, and those records' lifetime was shortened in advance, visitors move to the new server without interruption. Downtime usually happens when the old hosting is shut down before the DNS switch, or when email and the certificate are moved only after the fact.

Start with the question of who administers it

Before you compare hosting offers, write down what will run on the server, how much traffic you expect and who will be responsible for the items marked "You" in the responsibility table. If there is no answer to that last question, the simplest model that meets the project's requirements is almost always the best choice.

If you are choosing hosting for a new project or want to check whether your current one is still enough, get in touch through the contact form. The quote and advice are free. We hand projects over with full rights to the code and documentation, so you can change hosting later without us. You will find the scope of our services on the offer page, and our work on open source projects, including Proxmox VE, on the open source page.