What is a data centre and how do you choose one?
A data centre is a facility where the power, cooling, network connectivity and physical security that servers need to run without interruption are provided under one roof. Your website, your email or the business software you use may seem to live "on the internet", but in reality it runs on a server in a data centre.
This guide first explains what is inside a data centre and which types of service are on offer; it then sets out the criteria to look at when choosing a provider, the questions to ask and the mistakes that are made most often. It can be used both by the managers who take the decision and by the technical team that prepares it.
In brief
- A data centre is a facility that provides the power, cooling, network and physical security servers need to run without interruption.
- Service types, from shared hosting to cloud, differ mainly in who is responsible for managing what.
- When choosing, weigh location, legal requirements, the SLA, the redundancy level, backups and exit terms together.
- Looking only at price and keeping the backup in the same place are the most common mistakes.
Note
This guide is not written for any particular provider; it contains no prices and no rankings. The remarks on legal requirements are general information, not legal advice.
On this page
What is a data centre and what should the choice be based on?
-
What is inside a data centre?
Unlike an office computer, a server has to run every day of the year and every hour of the day. A data centre provides the infrastructure that makes this possible:
- Power redundancy: When mains power fails, uninterruptible power supplies (UPS) take over the load at once and bridge the time until the generators start. The generators go on feeding the facility for as long as fuel is supplied.
- Cooling: Servers produce heat all the time. Air-conditioning systems keep temperature and humidity within set limits; if cooling stops, hardware may shut itself down to protect itself.
- Fire detection and suppression: Early-warning detection systems are used together with suppression systems suited to rooms that contain electronic equipment.
- Physical security: Access control, camera recording, visitor logs and locked racks make it clear who reached a server and when.
- Network connectivity: The facility is connected to the internet backbone over several lines and several carriers. Carrier diversity prevents a fault at a single operator from making the whole facility unreachable.
The same question is asked of each of these layers: what happens when a single part fails? The answer shows the redundancy level of the data centre.
: Enlarge -
Service types: which one suits whom?
The services you can buy from a data centre differ mainly in what is reserved for you and who does the managing:
Service What do you get? Who manages it? Who is it for? Shared hosting An account on a server shared with many other sites The provider manages the server; you manage only your site Brochure sites, small and medium-sized sites Virtual server (VPS) A virtual portion of a physical server reserved for you, with your own operating system The operating system and software are mostly yours to manage Sites and applications that need their own configuration Dedicated server A physical server reserved for you alone; the hardware belongs to the provider Hardware with the provider, software with you Constant, heavy load; those who do not want to share resources Colocation Rack space, power, cooling and network for your own hardware Everything, including the hardware, is yours Organisations with their own hardware and technical team Cloud Virtual resources switched on and off as needed; billed by usage Depends on the service model chosen Variable load, fast growth, short-term needs Most services also come in a managed version: the provider takes on tasks such as operating system updates, monitoring and backups. The contract should state clearly who does what; leaving the question "the server is ours, but who updates it?" unanswered is one of the most common causes of security holes. If you manage the server yourself, see the guide on server and hosting security.
: Enlarge -
Cloud, your own server room, or hosting in a data centre?
All three approaches have strengths and weaknesses; the right choice depends on the load of the application, on your team and on the nature of the data.
Criterion Cloud On-premises Hosting in a data centre Initial investment Low; no hardware is bought High; hardware, server room, power and cooling are yours to provide Low with a rented server; if you place your own hardware, the hardware is yours to buy Operational responsibility Infrastructure with the provider; configuration and data with you Entirely yours Facility with the provider; server management as agreed in the contract Scalability Resources can be increased or reduced at short notice New hardware has to be bought and installed A new server or more rack space is added Oversight and control Limited to the options the provider offers Highest; hardware and network are in your hands Choice of hardware and software is yours, the facility is the provider's Suitable when Load is variable or hard to predict Systems must run on the local network, and a capable team and a suitable room are available Load is constant and predictable; business applications In practice these options are also combined: for example, the main system may sit in a data centre while the backups are kept at another location. With the on-premises option, bear in mind that you have to set up and maintain the power, cooling and security conditions that a data centre would otherwise provide.
-
Location, latency and the country where the data is held
Location and latency: The greater the distance between user and server, the higher the latency. If the server is close to the country or region where most of your users are, pages and the application respond more quickly. If your visitors are spread over many countries, using a CDN for static content reduces the effect of distance.
The country where the data is held, and the law: If you process personal data, the country in which it is stored is a legal matter. Data protection law (e.g. the GDPR) attaches additional conditions to transferring personal data to a third country. Ask the provider:
- In which country and in which facility are the servers and the backups located?
- Is the data accessed from another country for support or maintenance?
- Are subcontractors used and, if so, for which tasks?
There may also be additional rules specific to your sector. Consult your legal adviser to establish your obligations.
-
What does an availability commitment (SLA) mean?
An SLA (service level agreement) is the provider's written commitment that the service will be available for a certain proportion of the time. What it covers matters more than the percentage itself:
- Scope: Does the commitment apply to power and network, to the hardware, or to the server as a whole? Outages caused by your own software are generally excluded.
- Planned maintenance: Do maintenance periods announced in advance count as downtime or not?
- Measurement: For which period (monthly, yearly) is availability calculated, and on whose measurements?
- Compensation: What happens when the commitment is not met? Read how compensation is calculated, whether it is capped and whether there is a deadline for claiming it. Compensation may not cover the damage the outage does to your business.
The percentages differ only slightly on paper, but what they amount to differs a great deal. Calculated over an uninterrupted 365-day year:
Commitment Downtime allowed (per year, approximate) 99% 3.65 days 99.9% 8.8 hours 99.99% 53 minutes These values are purely arithmetical equivalents; an SLA is a commitment, not a measurement or a guarantee. To see what availability has actually been achieved in the past, look at the provider's status page and incident reports.
-
Redundancy levels (Tier I–IV) and certificates
Redundancy means that a second component or path is available to take over when one fails or is taken out for maintenance. The best-known scale for classifying data centre infrastructure is the Uptime Institute's four-level Tier classification. The higher the tier, the greater the redundancy:
- Tier I: Basic infrastructure; no redundant components.
- Tier II: Redundant components for power and cooling, but distribution runs over a single path.
- Tier III: Concurrent maintainability; a component or path can be taken out for maintenance without stopping the service.
- Tier IV: Fault tolerance; designed so that a single fault does not affect the service.
Tier certification is awarded separately for the design documents and for the constructed facility. Phrases such as "Tier III compliant" or "Tier III equivalent" do not mean certification; ask whether a certificate exists and for which stage it was awarded. A higher level is not necessary for every organisation; what you need is determined by the effect an outage has on your business.
Certificates: ISO/IEC 27001 is the standard for information security management systems and one of the certificates most often seen at data centres. Ask about the scope of the certificate (which facility and which services it applies to) and its validity date; also ask separately for any other certificates your sector requires. A certificate is a good indicator, but not an assurance on its own.
: Enlarge -
Backups and disaster recovery
Redundant infrastructure protects against hardware failure; it does not protect against data deleted by mistake, a corrupted database or ransomware. For that you need backups, and the backup must not sit in the same place as the main system.
- Is backup included in the service? In many services backup is a separate option or is left entirely to you. Do not assume; ask.
- Where is the backup kept? A backup on the same server or in the same facility can be lost together with the original data in an incident that affects the facility. At least one copy should be at a different location.
- RPO (recovery point objective): How much data, at most, can you afford to lose? This determines how often backups are taken.
- RTO (recovery time objective): How soon, at the latest, must the system be running again? This determines the restore method and whether a standby system is needed.
A backup whose restore has never been tested cannot be relied on. For details, see the guides on website backup and monitoring and on ransomware and the 3-2-1 backup rule.
: Enlarge -
Support, protection, growth and exit terms
- DDoS protection: Does the provider have protection at network level, and is it included in the service? Also ask whether a server under attack is temporarily taken offline to protect other customers. The subject is covered in detail in the guide on DDoS and bot attacks.
- 24/7 support and response time: Can a technical team really be reached at night and at weekends? "Response time" and "resolution time" are not the same thing; check which of them the contract commits to.
- Scalability: How easy is it to add resources or move to a larger service when demand grows, and is there downtime during the move? When the load has to be spread across several servers, software such as Nginx is placed in front of them.
- Contract and exit terms: The minimum term, the termination conditions and the form and time frame in which your data will be handed over when the contract ends should be set down in writing. Being able to move your data and your system to another provider (portability) is a selection criterion.
- Transparency: A public status page, maintenance announcements made in advance and incident reports published after an outage show how the provider handles problems.
-
Questions to ask the provider
Ask for the answers to the following questions in writing and compare the offers on the basis of those answers:
- In which country and in which facility are the servers and the backups located?
- How is redundancy provided for power, cooling and network connectivity? How many carriers is the facility connected to?
- Is there a Tier certificate and, if so, is it for the design or for the constructed facility?
- What is the scope of the ISO/IEC 27001 certificate? Which other certificates are held?
- What does the SLA cover, does planned maintenance count, and how is compensation calculated if it is breached?
- Is backup included in the service? Where are the backups kept, for how long, and who carries out a restore?
- Is there DDoS protection, and what does it cover?
- During which hours and through which channel is support provided? What response time is committed to?
- Which of the update, monitoring and security tasks lie with the provider and which with us?
- How is the data handed over when the contract ends, and when is it deleted?
- Are the status page and past incident reports public?
: Enlarge
Common mistakes
- Looking only at price: Two offers may look alike while backup, support, protection and SLA scope differ. Compare offers item by item.
- Keeping the backup in the same place: A backup on the same server or in the same facility is hit by the same incident as the original data.
- Not reading the SLA: Looking at the percentage without reading the scope, the planned maintenance clause and the compensation terms leads to surprises when an outage occurs.
- Having no exit plan: How the data will be retrieved and how the system will be moved elsewhere should be thought through before the contract is signed.
- Access details held by one person: If the details for the server, the control panel and the domain accounts are held only by one employee or by one outside person, the system cannot be reached when that person cannot be reached. Accounts should be opened in the organisation's name, access details stored securely, and at least two people authorised.
Additional notes for organisations that host software
For organisations that offer online software (SaaS) to their customers or host a business application themselves, choosing the data centre is only one part of the job:
- Database backup and restore tests: The database should be backed up separately from the files and in a consistent state. At regular intervals, restore the backup to a separate environment and confirm that the application starts; measuring how long the restore takes shows whether your RTO target is realistic.
- Monitoring: Monitor not only whether the server is up, but also whether the application responds, how full the disks are, whether the backup was taken and when certificates expire. Alerts should reach more than one person.
- Separate test and production environments: Updates should first be tried in a test environment that is separate from production. Avoid using real customer data in the test environment; if you have to, apply the same safeguards as in production.
Which infrastructure does BYK Yazılım use?
BYK Yazılım works with Medyabim Datacenter for hosting its websites and software.
Frequently asked questions
Does the choice of data centre matter for a small website?
Yes, but the criteria are simpler. Shared hosting is usually enough for a small site; checking that backups are taken, that support can be reached and in which country the data is held is a sufficient start.
Is a data centre with a higher Tier level always better?
A higher level means more redundancy, but not every organisation needs it. Nor does a redundant facility mean that your application will run without interruption; software, configuration and backups call for the same care.
Does a 99.9% SLA mean my site will be up for that proportion of the time?
No. An SLA is a commitment and mostly covers only the infrastructure the provider is responsible for. Outages caused by your own software, and in most contracts planned maintenance periods, are not counted.
If I use the cloud, do I still need backups?
Yes. The provider keeps the infrastructure running; bringing back data that was deleted by mistake or corrupted is mostly your responsibility. Check in the contract who is responsible for backups.
Can my data be held in a data centre abroad?
If it contains personal data, this is a legal matter; data protection law (e.g. the GDPR) attaches additional conditions to transfers to a third country. Consult your legal adviser before deciding and ask the provider to confirm in writing the country where the servers and backups are located.
BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.
Related guides
- Website backup and monitoringFile and database backups, restore drills, file integrity, logs and uptime monitoring.
- Server and hosting securitySFTP/FTPS, file permissions, directory listing, error display, sensitive files and database access.
- What is a CDN (content delivery network)?What a CDN is, how it is put in place, and what to watch for with real IPs, caching and origin server security.
- DDoS and bot attacksSigns, CDN and WAF, rate limiting, caching and working together with your hosting provider.
Let us talk about your website infrastructure
BYK Yazılım builds corporate websites and works with Medyabim Datacenter for hosting its websites and software. Write to us with any questions about your site.
Contact us Our corporate website service