LEGAL

Privacy Policy

Last updated: September 2026

01

Who we are

Hostethics Ltd. is a UK-registered company providing web hosting and domain services. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.
02

What data we collect

We collect: (1) account data (name, email, billing address, phone), (2) payment data (processed by our PCI-DSS-compliant payment provider — we never store card details), (3) service usage data (IP addresses, service configurations, logs), (4) support communications, (5) cookies (see our Cookie Policy).
03

Why we collect it

We use your data to: provide and improve our services, process billing, communicate with you about your account, provide support, comply with legal obligations (including tax and anti-money-laundering rules), and detect fraud or abuse of our infrastructure.
04

Legal basis for processing

Under UK GDPR and EU GDPR, we process personal data on the following bases: contract (to provide services you have purchased), legal obligation (accounting, fraud prevention), legitimate interests (improving our services, security), and consent (marketing communications, non-essential cookies).
05

Data sharing

We do not sell or rent your data. We share data only with: (1) our payment processor (Stripe / PayPal), (2) our email delivery provider, (3) UK/EU tax authorities as required by law, (4) domain registries (ICANN requirements). All processors have signed a Data Processing Agreement compliant with GDPR.
06

Data storage location

Customer account data is stored on our servers in London, UK. Backups are replicated to Manchester, UK. We do not transfer personal data outside the UK/EU without appropriate safeguards (Standard Contractual Clauses).
07

Data retention

Account data: kept for the duration of your service plus 7 years for tax record purposes. Server logs: 90 days. Support tickets: 3 years. Marketing lists: until unsubscribe. You can request earlier deletion via the rights below.
08

Your rights

Under GDPR you have the right to: access your data, correct inaccuracies, delete your data (right to erasure), restrict processing, data portability, object to processing, and withdraw consent. To exercise these rights, email privacy@hostethics.com. We will respond within 30 days.
09

Security

We implement industry-standard security measures including encryption at rest and in transit, network segmentation, regular security audits, DDoS mitigation, and access controls with 2FA for staff. In the event of a data breach affecting personal data, we will notify affected users and the ICO within 72 hours as required by law.
10

Marketing

We may send you occasional service updates and, if you have opted in, marketing emails. You can unsubscribe at any time via the link in every email or by updating preferences in your client area.
11

Complaints

If you are unhappy with how we have handled your data, please contact privacy@hostethics.com. You also have the right to lodge a complaint with the UK Information Commissioner Office (ICO) at ico.org.uk.
12

Changes to this policy

We may update this policy from time to time. Material changes will be notified via email at least 30 days in advance.
Questions about this policy?
hello@hostethics.com