Privacy Policy (GDPR Compliant)
Last Updated: [23/11/2025]
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our web hosting, domain registration, and related services. We are committed to complying with the UK GDPR and Data Protection Act 2018.
1. Who We Are
[Hex Hosting] (“we”, “us”, “our”) is a web hosting and domain services provider based in the United Kingdom.
Data Controller:
[Hex Hosting]
[nic@hexhosting.uk]
2. What Personal Data We Collect
We collect and process the following categories of personal data:
a) Information you provide directly
- Name
- Address
- Email address
- Phone number
- Payment information (processed securely by our payment provider; we do not store full card details)
- Account login details
- Support tickets and communications
b) Information collected automatically
- IP address
- Browser type and version
- Device information
- Access logs
- Usage data related to hosting services
c) Domain registration data
If you register a domain through us (via eNom or other registrars), we collect WHOIS information required for domain registration.
3. How We Use Your Data
We process your personal data for the following purposes:
- To set up and manage your hosting or domain account
- To provide technical support
- To process payments and invoices
- To send service updates, security alerts, or important account notifications
- To comply with legal and regulatory requirements (e.g., ICANN, Nominet, HMRC)
- To prevent fraud, abuse, or security threats
- To improve our website and services
4. Legal Basis for Processing
We process your data under the following legal bases:
- Contractual necessity – to deliver hosting, domains, and support
- Legitimate interests – security, service optimisation, prevention of abuse
- Consent – for marketing communications (if opted in)
- Legal obligation – accounting, domain registration rules, fraud prevention
5. How We Share Your Data
We may share your information with:
a) Service partners
- Domain registrars (eNom, Nominet, etc.)
- Payment processors (Stripe, PayPal, etc.)
- Hosting infrastructure providers
- Email or notification delivery providers
b) Legal/Regulatory bodies
- If required by law, court order, or regulatory authority
We never sell your data to third parties.
6. International Data Transfers
Some partners (e.g., domain registrars or cloud providers) may operate outside the UK or EEA. When this happens, we ensure appropriate safeguards such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Contractual data protection guarantees
7. Data Retention
We keep personal data only for as long as necessary:
- Account and billing data: 6 years (legal requirement)
- Support tickets: up to 3 years
- Hosting logs: typically 30–90 days, depending on service
- Domain WHOIS data: as required by registry rules
8. Your Rights (UK GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion (right to be forgotten)
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent (for marketing or optional features)
To exercise your rights, contact us at:
[nic@hexhosting.uk]
9. Cookies
We use cookies to:
- Maintain login sessions
- Analyse site usage
- Improve performance
You can manage cookies through your browser settings.
10. Security
We take data security seriously and use:
- Encryption (HTTPS, secure storage)
- Firewalls and malware scanning
- Access controls
- Full server security hardening
However, no system is 100% secure, and users should keep passwords safe.
11. Automated Decision Making
We do not use automated decision-making or profiling that significantly affects you.
12. Contact Details
If you have any questions about this Privacy Policy or your data rights, contact:
[Hex Hosting]
Email: [nic@hexhosting.uk]
If you are unhappy with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
13. Updates to This Policy
We may update this policy from time to time. Any changes will be posted on this page with an updated “Last Updated” date.
Thank you for trusting us with your data.