LEGAL
Privacy Policy
Last updated: September 2026
01
Who we are
Hostethics Ltd. is a UK-registered company providing web hosting and domain services. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.
02
What data we collect
We collect: (1) account data (name, email, billing address, phone), (2) payment data (processed by our PCI-DSS-compliant payment provider — we never store card details), (3) service usage data (IP addresses, service configurations, logs), (4) support communications, (5) cookies (see our Cookie Policy).
03
Why we collect it
We use your data to: provide and improve our services, process billing, communicate with you about your account, provide support, comply with legal obligations (including tax and anti-money-laundering rules), and detect fraud or abuse of our infrastructure.
04
Legal basis for processing
Under UK GDPR and EU GDPR, we process personal data on the following bases: contract (to provide services you have purchased), legal obligation (accounting, fraud prevention), legitimate interests (improving our services, security), and consent (marketing communications, non-essential cookies).
05
Data sharing
We do not sell or rent your data. We share data only with: (1) our payment processor (Stripe / PayPal), (2) our email delivery provider, (3) UK/EU tax authorities as required by law, (4) domain registries (ICANN requirements). All processors have signed a Data Processing Agreement compliant with GDPR.
06
Data storage location
Customer account data is stored on our servers in London, UK. Backups are replicated to Manchester, UK. We do not transfer personal data outside the UK/EU without appropriate safeguards (Standard Contractual Clauses).
07
Data retention
Account data: kept for the duration of your service plus 7 years for tax record purposes. Server logs: 90 days. Support tickets: 3 years. Marketing lists: until unsubscribe. You can request earlier deletion via the rights below.
08
Your rights
Under GDPR you have the right to: access your data, correct inaccuracies, delete your data (right to erasure), restrict processing, data portability, object to processing, and withdraw consent. To exercise these rights, email privacy@hostethics.com. We will respond within 30 days.
09
Security
We implement industry-standard security measures including encryption at rest and in transit, network segmentation, regular security audits, DDoS mitigation, and access controls with 2FA for staff. In the event of a data breach affecting personal data, we will notify affected users and the ICO within 72 hours as required by law.
10
Marketing
We may send you occasional service updates and, if you have opted in, marketing emails. You can unsubscribe at any time via the link in every email or by updating preferences in your client area.
11
Complaints
If you are unhappy with how we have handled your data, please contact privacy@hostethics.com. You also have the right to lodge a complaint with the UK Information Commissioner Office (ICO) at ico.org.uk.
12
Changes to this policy
We may update this policy from time to time. Material changes will be notified via email at least 30 days in advance.
Questions about this policy?
hello@hostethics.com