Privacy Policy
Last updated: 25 July 2026 · Effective: 25 July 2026
Template notice: This policy is a starting template for a managed web-hosting business and is not legal advice. Replace the bracketed placeholders and confirm the disclosures match your actual data practices and applicable laws (e.g. GDPR, UK GDPR, CCPA/CPRA) with a qualified attorney before publishing.
This Privacy Policy explains how [Legal Entity Name], trading as ADhostCo, an AppanDesign company (“ADhostCo,” “we,” “us”), collects, uses, and protects personal data when you visit our website or use our web hosting and related services (the “Services”).
1. Who we are
For the purposes of applicable data-protection law, the data controller is [Legal Entity Name], [registered address]. For data that our customers store on our servers, we generally act as a data processor on the customer’s behalf (see section 12).
2. Information we collect
Information you give us
- Account & contact details — name, business name, email address, phone number, and postal/billing address.
- Billing information — processed by our payment provider; we receive limited details such as the last four digits of a card, card type, and transaction status. We do not store full card numbers.
- Support communications — messages, tickets, and any information you choose to share when contacting us.
Information we collect automatically
- Server & access logs — IP address, timestamps, requested URLs, referring pages, and user-agent, collected to operate and secure the Services.
- Usage & device data — pages viewed and general device/browser information when you use our website.
- Cookies & similar technologies — see section 7.
3. How we use information
- To provide, maintain, and secure the Services and your account;
- To process payments, renewals, and send billing and transactional notices;
- To provide support and respond to your requests;
- To monitor performance, prevent abuse, fraud, and security incidents;
- To send service updates and, where permitted, occasional product news (you can opt out at any time);
- To comply with legal obligations and enforce our Terms of Service.
4. Legal bases (GDPR)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to deliver the Services you order); legitimate interests (to secure and improve the Services and prevent abuse); consent (for non-essential cookies and marketing email); and legal obligation (for tax, accounting, and lawful requests).
5. How we share information
We do not sell your personal data. We share it only with:
- service providers and sub-processors who help us run the Services (section 6);
- professional advisers, and authorities where required by law or to protect our rights and users;
- a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy.
6. Sub-processors & payments
We use trusted third parties to deliver the Services, which may include: data-center and infrastructure providers, a payment processor (for example [Stripe / PayPal / processor]), an email/transactional provider, and a domain/SSL registrar. Each is bound by contract to handle personal data only on our instructions and to protect it. A current list of sub-processors is available on request.
7. Cookies & analytics
We use strictly necessary cookies to operate the website and, where you consent, analytics or preference cookies to understand usage and improve the site. You can control cookies through your browser settings and, where shown, our cookie banner. Blocking some cookies may affect site functionality. [If you use analytics such as Google Analytics or a privacy-friendly alternative, name it here and link its policy.]
8. Data retention
We keep personal data only as long as necessary for the purposes described here: account and billing records for the duration of your relationship with us plus any period required by tax and accounting law; server and security logs for [log retention period]; and backups for [backup retention period]. We then delete or anonymize the data.
9. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit (TLS/SSL), access controls, network firewalls, malware scanning, and continuous monitoring. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and any regulator of a qualifying breach as required by law.
10. International transfers
Your data may be processed in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognized under applicable law.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. If you are a California resident, you may have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the “sale” or “sharing” of personal information (we do not sell personal information). To exercise any right, contact us using the details below; we will respond within the timeframes required by law.
12. Data you host with us
When you use our Services to host a website or application, you may collect and store personal data about your own users. For that data we act as a processor and you are the controller: you are responsible for having a lawful basis and your own privacy notice, and for responding to your users’ requests. We process such data only to provide the Services and per our agreement with you. A Data Processing Agreement is available on request.
13. Children’s privacy
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date and, for material changes, provide additional notice where appropriate. Please review this page periodically.
15. Contact us
To exercise your rights or ask about this policy, reach us through the AppanDesign contact page or at [[email protected]], [Legal Entity Name, mailing address]. If applicable, our data protection contact is [DPO name/email].