Privacy Policy
This policy explains how HostFitter looks after personal information about our customers, prospective customers and website visitors, in line with UK data protection law.
1. Who is responsible for your data
[COMPANY NAME], trading as HostFitter, company number [NUMBER], registered office [REGISTERED ADDRESS], is the controller of the personal data described here. Contact us at [hello@hostfitter.com] or on 03300 88 2123. [ICO registration number, if registered]
2. What we collect and why
- Contact and account details (name, business name, address, email, phone) so that we can set up and manage your account and communicate with you. Basis: performing our contract with you.
- Billing and payment information (what you have bought, payment status and the details our payment provider shares with us). We do not store full card numbers. Basis: contract, and our legal obligation to keep accounting records.
- Domain registrant details (the name, address, email and phone of the registrant, and the administrative and technical contacts) so that we can register and manage domains. Basis: contract.
- Support and enquiry records (emails, calls and messages with us) so that we can answer questions and keep a record of what was agreed. Basis: contract and our legitimate interest in running and improving our service.
- Technical information such as IP addresses and server logs relating to our systems, for security, abuse prevention and fault-finding. Basis: legitimate interests.
- Marketing: if you ask to hear from us, or are an existing customer, we may send you information about similar services. You can opt out at any time. Basis: consent or legitimate interest, as allowed by the Privacy and Electronic Communications Regulations. [Confirm what marketing you will actually do.]
3. Who we share it with
We share personal data only where we need to, with:
- our hosting platform and infrastructure suppliers, to provide the Services [name suppliers, e.g. 20i]
- our payment provider, [PAYMENT PROVIDER], to take payment
- domain registries and registrars, as required to register and manage domains. Registrant details may be shared with them and, depending on the registry's rules, some information may be published or accessible in public registration data.
- professional advisers such as accountants and lawyers, and regulators or law enforcement where the law requires or allows it
- any business that takes over ours, subject to the same protections
We do not sell your personal data.
4. Transfers outside the UK
Some of our suppliers or domain registries may process data outside the UK. Where they do, we rely on safeguards recognised by UK law, such as an adequacy decision or approved contractual clauses. [Confirm with suppliers.]
5. How long we keep it
We keep personal data for as long as we need it for the purposes above. As a guide: account and billing records for [six] years after the end of the relationship, in line with accounting and tax requirements; support records for [two] years; and server logs for [a short period, e.g. 90 days]. We then delete or anonymise them. [Confirm retention periods.]
6. Your rights
You have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have data erased in some circumstances, to restrict or object to certain uses, to receive some data in a portable format, and to withdraw consent where we rely on it. To exercise any of these, contact us using the details above. We may need to verify your identity first. If you are unhappy with how we handle your data, please tell us, and you also have the right to complain to the Information Commissioner's Office at ico.org.uk.
7. Customer website data
If you host a website or systems with us that contain personal data about your own customers or users, you are normally the controller of that data and we act as your processor. We handle it only to provide the Services and on your instructions. Our Terms of Service explain more.
8. Cookies and this website
This website [does not currently use analytics or non-essential cookies. Confirm before launch, and update this section if you add them, or if your order and payment pages use them]. Our order and payment pages are provided by third parties and have their own cookie notices.
9. Security
We use appropriate technical and organisational measures to protect personal data, including access controls and encrypted connections. No system is completely secure. If a breach affects you, we will tell you and the regulator where the law requires.
10. Changes
We may update this policy from time to time. The date at the top shows when it last changed, and we will tell you about significant changes.