Who this page covers
The General Data Protection Regulation protects people who are in the European Union and the European Economic Area, whatever passport they hold, and the UK GDPR does the same for people in the United Kingdom. It has applied since 25 May 2018. If you are reading this from anywhere else, you are not outside it: Hostinium for Information Technology LLC applies the same standards to every customer, because running two sets of rules produces a worse service for everyone.
This page sits alongside the privacy policy, which is the document that describes in detail what we collect, why we collect it, who else sees it and how long we keep it. Read that one first; this page covers the parts the GDPR adds.
Our two roles
The GDPR separates the organization that decides what happens to personal data (the controller) from the organization that holds and handles it on instructions (the processor). Hostinium is both, depending on which data you mean.
- Controller of your account data. The contact and billing details you give us when you order, the tickets you send, the records of what you bought. We decide what is collected and why, so the responsibility is ours.
- Processor of the data on your account. Your site's visitors, your customers, your mailing list, the rows in your database, the messages in your mailboxes. You decide what is collected there; we hold it, protect it and act on your instructions.
The two halves of this page follow that split.
Your account data: minimum, and yours to control
We collect the minimum an order needs. Signing up means giving us contact and billing details, because we cannot process an order, warn you about scheduled maintenance or send you critical notices about a live service without them. Domain registrations additionally need registrant details, which ICANN requires to be accurate and which go to the registrar and registry.
The legal bases we rely on are:
- Contract — setting up, running, renewing and supporting the services you bought, and billing for them.
- Legal obligation — tax and accounting records, ICANN domain requirements, and lawful requests from authorities.
- Legitimate interests — keeping the platform secure and working: rate limits, abuse investigation, fault finding. We weigh these against your rights, and we do not use them as cover for marketing.
- Consent — tips, offers and product announcements by email. Consent is never a condition of buying anything, and you can withdraw it under My Details in the client area at any time.
You can view and edit your contact details, billing details and email preferences yourself in the client area, and you can ask us for a copy of your data or for its deletion using the routes at the end of this page.
Your rights
Under the GDPR and the UK GDPR you have the right to:
- be informed about what we do with your data — that is the privacy policy;
- access the personal data we hold about you;
- rectify anything inaccurate or incomplete;
- erase data we no longer have a reason to keep;
- restrict processing while a dispute about accuracy or legitimate interests is resolved;
- portability — a copy of the data you gave us, in a structured, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent you previously gave, without affecting what was done before you withdrew it.
Ask by any route at the end of this page. The regulation gives us one month to answer, we work to that, and we charge nothing for it. Expect an identity check before we release anything.
Two limits are worth knowing before you ask: we cannot erase invoices and tax records the law requires us to keep, and we cannot erase registration data that a domain registry controls rather than us. Everything else we can act on.
Data you store on our servers
When your site collects personal data, it lands on our servers, and the GDPR puts obligations on us as the processor. These are the commitments we make, and they are repeated in the terms of service so that they form part of your contract:
- We process on your instructions. We use the data on your account to deliver the service you bought and for nothing else of our own.
- Minimum access. Staff open customer data only as far as delivering or fixing the service requires, and only the people directly involved in that work have access.
- Real security measures. TLS encryption in transit, firewalls and monitoring around the servers, access control and separation between accounts, and credentials for third-party services held server-side only.
- Breach notification within 72 hours. If we detect a personal data breach affecting the servers your account runs on, we tell affected customers within 72 hours at the latest. The terms of service hold us to shorter deadlines still: one for the first alert, and one for each written report after it.
- Help with requests. We help you respond to access, correction, deletion and portability requests from your own users where the data sits on our platform.
- Deletion at the end. When the contract ends we delete or return the data, unless a law requires us to keep it. Cancelling an account removes the website and email files on it, so take your copy first — see the backup policy.
Who we give access to
Some of the work around a hosting account cannot be done by us alone. Data reaches these categories of partner, and no others:
- Data center partners, who operate the facilities the servers sit in;
- Domain registrars and registries, who hold the registration for a domain you buy;
- Certificate authorities, who issue SSL certificates for your domains;
- The payment provider that processes your card payment;
- Google, whose API generates the answers in the site assistant. Assistant questions carry no account details and are not stored by us — the privacy policy explains that in full.
Each partner is either subject to data protection law in its own right or bound by a contract with us that holds it to the standards on this page, and access is given only to partners whose protection matches or exceeds our own. For the data you store on your account, we engage no new sub-processor without your written consent, as the terms of service set out.
Requests from your users
If someone who used a website we host asks us directly to access, correct or delete their data, we do not act on it. That data belongs to your site, which makes you the controller of it, so we point the person to you as the owner of the site and let you know that the request came in. You then answer it. If the data is on our platform and you need help pulling it out or removing it, open a ticket and we will do our part.
Transfers to the United States
Hostinium is a Wyoming limited liability company, and our billing system and much of our infrastructure are in the United States. Buying a service from us therefore involves transferring personal data out of the EU or the UK.
We rely on the European Commission's Standard Contractual Clauses for those transfers, and we carry out a transfer impact assessment covering the safeguards that surround them. Ask and we will send you the documentation; if your own compliance file needs it signed, say so in the request.
If you need a written agreement
The processor commitments on this page and the data protection clauses in the terms of service are the agreement between us, and they apply from the moment you order. If your own compliance work needs those terms in a separate signed document, open a ticket in the client area and tell us what your auditor expects to see.
Tracking, cookies and the assistant
This website sets no advertising cookies, runs no third-party analytics or ad scripts, and builds no profile of you. Web fonts are hosted by us rather than fetched from a third party. There is no consent banner on this site because there is nothing on it to consent to.
The assistant sends the question you type to Google's API to generate an answer, with no name, email or account attached to it. We store no conversations; your chat lives in your browser tab's session storage until you close the tab. We use Google's paid API, where it does not use your questions or the answers to improve or train its products; it keeps a short log of them only to detect abuse of its service. The privacy policy sets out every step.
The client area is separate billing software and sets a session cookie when you sign in, which is what keeps you signed in while you work.
Contact and complaints
To make a request, or to ask how any of this applies to you:
- WhatsApp — +1 202 505 2888;
- Email — info@hostinium.com, with "data protection request" in the subject line;
- A support ticket — open one in the client area. Best for anything that needs us to look inside an account.
If you are not satisfied with how we handled a request, you can complain to the data protection authority in the EU or EEA country where you live or work, or to the Information Commissioner's Office in the United Kingdom. That right does not depend on coming to us first, but coming to us first is usually the quicker way to get the problem fixed.
Questions
Questions about this policy? Message us on WhatsApp at +1 202 505 2888 or open a ticket in the client area.
