LEGAL
GDPR Compliance
Last updated: September 2026
01
Our commitment
Hostethics is a UK-based company subject to UK GDPR (equivalent to EU GDPR). We take data protection seriously and have designed our services and internal processes to be compliant by default.
02
Data Processing Agreement (DPA)
If you process personal data of EU/UK residents through your Hostethics service, you may need a Data Processing Agreement with us. Our standard DPA is available on request from privacy@hostethics.com and is executed automatically for all business customers as part of our terms.
03
Sub-processors
We use a small, curated list of sub-processors: Stripe / PayPal (payment processing, PCI-DSS Level 1), Postmark / SendGrid (transactional email delivery), Cloudflare (DDoS mitigation, optional CDN). Full list with locations available on request. All sub-processors have signed GDPR-compliant DPAs with us.
04
Data location
All customer account data is stored in the UK (London primary, Manchester backup). Your hosted content stays wherever your server is provisioned — you can choose the region at signup.
05
Data subject rights
We support all GDPR data subject rights: access, rectification, erasure, restriction, portability, and objection. Requests are handled within 30 days via privacy@hostethics.com.
06
Breach notification
In the unlikely event of a personal data breach affecting our platform, we will notify the UK Information Commissioner Office (ICO) within 72 hours and affected customers immediately, as required by law.
07
International transfers
We do not transfer personal data outside the UK/EU unless absolutely necessary and with appropriate safeguards (typically the UK International Data Transfer Agreement or EU Standard Contractual Clauses).
08
Data Protection Officer
For a small company we do not have a statutory obligation to appoint a DPO, but we have a named Privacy Contact who is responsible for GDPR matters. Reach them at privacy@hostethics.com.
09
Certifications and audits
We are working toward ISO 27001 and SOC 2 Type II certifications. Interim security documentation (penetration test summaries, infrastructure diagrams, incident response plan) is available under NDA for enterprise prospects.
Questions about this policy?
hello@hostethics.com