Web Hosting
Web Hosting

GDPR

1. Who We Are

Host.Wales (“we”, “us”, or “our”) provides web hosting and related services.

  • For personal data relating to our website visitors, customers, and billing, we act as a data controller.
  • For customer data hosted on our servers (including websites, email, and databases), we act as a data processor, and the customer is the data controller.

You can contact us about data protection at: privacy@host.wales.


2. What Data We Collect

We may collect the following personal data:

  • Account & billing information – name, email address, phone number, billing address, payment details.
  • Technical information – IP address, device type, browser type, access logs, error logs.
  • Support information – correspondence via email, chat, or ticketing systems.
  • Website usage data – through cookies and analytics tools.

We do not access or process the personal data that our customers store on their hosting accounts, except when necessary to provide support, maintain services, or comply with legal obligations.


3. How We Use Your Data

We process your personal data to:

  • Provide, manage, and secure our hosting services.
  • Process payments and send invoices.
  • Respond to technical and customer support requests.
  • Improve our website and services.
  • Comply with legal, tax, and regulatory requirements.

4. Legal Basis for Processing

We process your personal data on the following bases:

  • Contract – to provide the hosting services you purchase.
  • Consent – where you have opted in to marketing or cookies.
  • Legal obligation – to comply with tax, accounting, and regulatory laws.
  • Legitimate interest – to improve services, prevent fraud, and secure our network.

5. International Data Transfers

Some of our infrastructure and service providers (including Cloudflare and various data centres/servers outside the UK and EU) may process data internationally.

  • Where data is transferred outside the UK/EU, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the ICO/EU Commission.
  • Cloudflare provides GDPR-compliant data protection and security services.

6. Data Sharing

We share data only when necessary to deliver our services:

  • With trusted third-party providers (e.g., payment processors, domain registrars, Cloudflare, server/data centre providers).
  • With legal or regulatory authorities when required by law.

We do not sell personal data to third parties.


7. Security of Your Data

We take appropriate technical and organisational measures to protect your data, including:

  • Encryption of data in transit (SSL/TLS).
  • Firewalls, DDoS protection (via Cloudflare), and intrusion prevention.
  • Access controls and staff confidentiality agreements.
  • Regular backups and monitoring of our systems.

8. Data Retention

  • Account and billing data: retained for up to 7 years to meet tax and legal obligations.
  • Support communications: retained for as long as necessary to provide service and resolve issues.
  • Hosting data: retained only for the lifetime of your hosting account and deleted after account closure.

9. Your GDPR Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion of your data.
  • Restrict or object to processing.
  • Request data portability.
  • Withdraw consent where processing is based on consent.

To exercise these rights, contact us at privacy@host.wales.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).


10. Cookies and Tracking

We use cookies and similar technologies to improve website functionality, security, and analytics. For more information, please see our Cookie Policy.


11. Children’s Data

Our services are not directed to individuals under the age of 16, and we do not knowingly collect their personal data.


12. Data Processing Agreements

When acting as a data processor, Host.Wales enters into a Data Processing Agreement (DPA) with customers, setting out our GDPR responsibilities, security measures, and limitations on processing.


13. Automated Decision-Making

We do not carry out fully automated decision-making that has a legal or significant effect on individuals.


14. Contact Us

If you have any questions about this policy or how your data is handled:

Host.Wales
Email: privacy@host.wales
Website: https://host.wales

Web Hosting