Effective Date: 01/01/2013 · Last Updated: 10/12/2025
DebsHost GDPR Policy (Data Protection Policy)
DebsHost (“DebsHost”, “we”, “our”, or “us”) is committed to protecting personal data and ensuring compliance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
This GDPR Policy explains how DebsHost collects, processes, stores, and protects personal data, and outlines the rights of data subjects.
1. Scope
This policy applies to:
- All customers and users of DebsHost services
- Visitors to debshost.com and related platforms
- Personal data processed in connection with hosting, billing, domain registration, and support services
DebsHost acts as a Data Controller for customer account and billing data and may act as a Data Processor when hosting customer content.
2. Data Controller Information
Data Controller: DebsHost
128 City Road, London, United Kingdom, EC1V 2NX
Contact Email: [email protected]
Website: https://debshost.com
3. Principles of Data Protection
DebsHost processes personal data in accordance with the following UK GDPR principles:
Lawfulness, Fairness, and Transparency
Personal data is processed lawfully, fairly, and transparently.
Purpose Limitation
Data is collected for specified, explicit, and legitimate purposes.
Data Minimisation
Only data necessary for providing services is collected and processed.
Accuracy
Personal data is kept accurate and up to date.
Storage Limitation
Personal data is retained only as long as necessary.
Integrity and Confidentiality
Personal data is protected using appropriate security measures.
Accountability
DebsHost takes responsibility for ensuring compliance with GDPR.
4. Types of Personal Data Processed
DebsHost may process the following personal data:
- Name and contact details
- Email address
- Billing information
- Account login details
- IP addresses
- Domain registration details
- Support communications
- Service usage information
DebsHost does not collect unnecessary personal data.
5. Legal Basis for Processing
DebsHost processes personal data based on one or more of the following legal grounds:
Contractual Necessity
Processing required to provide hosting, billing, and domain services.
Legitimate Interests
Processing required to maintain service security, reliability, and performance.
Legal Obligation
Processing required to comply with applicable laws and regulations.
Consent
Processing based on user consent where applicable.
6. Role of DebsHost as Data Processor
When customers use DebsHost infrastructure to host websites, applications, or services, DebsHost acts as a Data Processor.
Customers remain the Data Controller of the data they host.
DebsHost processes hosted data only to:
- Provide hosting services
- Maintain infrastructure security
- Ensure operational reliability
DebsHost does not access hosted customer data unless required for support or security.
7. Data Security Measures
DebsHost implements technical and organisational safeguards, including:
- Secure infrastructure and server hardening
- Network security and firewall protection
- Access controls and authentication measures
- Encryption where appropriate
- Monitoring for unauthorized access
These measures help protect personal data against unauthorized access, loss, or misuse.
8. Data Retention
DebsHost retains personal data only as long as necessary to:
- Provide services
- Meet legal obligations
- Resolve disputes
- Maintain business records
Upon account termination, data may be deleted or anonymised unless required by law.
9. Data Subject Rights
Under UK GDPR, individuals have the right to:
- Access their personal data
- Request correction of inaccurate data
- Request deletion of personal data
- Restrict processing of their data
- Object to processing
- Request data portability
Requests may be submitted to [email protected].
DebsHost will respond within one month as required by law.
10. Data Breach Procedures
In the event of a personal data breach, DebsHost will:
- Investigate the breach immediately
- Take steps to mitigate risks
- Notify relevant authorities if required
- Notify affected individuals where required by law
11. Third-Party Data Processing
DebsHost may share personal data with trusted third parties, including:
- Payment processors
- Domain registrars
- Infrastructure providers
These parties process data only as necessary to provide services and are required to protect personal data.
DebsHost does not sell personal data.
12. International Data Transfers
Personal data may be transferred outside the UK or EEA where necessary for service delivery.
DebsHost ensures appropriate safeguards are in place for such transfers.
13. Customer Responsibilities (When Acting as Data Controller)
Customers using DebsHost services to process personal data must ensure they comply with applicable data protection laws.
DebsHost provides infrastructure but customers remain responsible for their own data processing activities.
14. Policy Updates
DebsHost may update this GDPR Policy from time to time.
Updates will be published on our website.
15. Contact Information
For GDPR-related requests or questions:
Email: [email protected]
Website: https://debshost.com