Cheap Host · Legal
GDPR
1. Order acceptance and terms
All orders are created only on acceptance of our full terms and conditions and privacy policy. You will be prompted to read and accept these prior to any order being accepted, or new account being created.
Please ensure you have fully read and accept our terms and conditions in full prior to using any of our services.
2. Viewing and updating profile information
Our client area provides a self-service portal for you to update, modify and view your profile / account data. This same client portal also provides your customers with access to update their personal information, including name, email address, postal address and phone number, as well as any other profile-related information.
3. Your right to erasure ("the right to be forgotten")
Under UK GDPR, you have the right to request that we erase your personal data. Please see the "Formal Data Removal" section below for more information, or to process a Data Removal Request.
This right is not absolute. Where we have a legal obligation to retain certain records, such as financial and invoicing data required by HMRC for up to 7 years, we will retain that data for the required period even where an erasure request has otherwise been accepted. All other data outside of this legal retention period will be erased on request.
4. Email marketing, status updates and general communications
You will only be contacted by us for marketing, product or status updates on the basis that you signed up via Cheap Host. Upon doing so, you accepted our terms and conditions, which state communication will be made via email using the data stored within your customer profile.
We use two methods for sending marketing, newsletters and status / product updates:
MailChimp
We use MailChimp to contact customers regarding status updates, product announcements or general marketing. Our mailing list is generated on the basis that you have registered to our site. Upon registering, you automatically become enrolled in our Marketing List via MailChimp. You can choose to remove yourself from our listing by clicking "unsubscribe" within the email received. Once unsubscribed, we will no longer contact you via our MailChimp marketing.
WHMCS / Client Portal
We may from time to time contact you via our client area. By using our service, you agree to be contacted via this method, however you will not be sent anything for "general marketing" — as such, we retain the right to contact you for the purposes of status updates and similar service communications.
5. Formal data removal request
UK GDPR gives you more control over what data is collected about you and how long that data is stored, including the ability to request the removal of your data. This right applies to anyone whose personal data we hold, regardless of nationality.
If you wish to have your data removed as part of your "right to be forgotten", you are able to request this if the following criteria apply to you:
- You have no currently active services with us;
- You must not have made any payments to us within the last 7 years;
- You are the original account owner.
If you meet all of these criteria, simply email us at info@cheapwebhosting-uk.co.uk to request your data be removed.
We will provide an answer to this request within 2 weeks. From here we may ask you for proof of identity as well as a few security questions. After this you will be provided with a final confirmation page that you must agree to before the data can be deleted.
If your request is successful, you will not receive a response to your original request, but a final automated email confirming that your personal information has been purged from our databases.
If you are unhappy with how we have handled your request, you have the right to complain to the Information Commissioner's Office (ICO), the UK's independent regulator for data protection: ico.org.uk.
You may also raise a data removal request directly via a ticket to our Support System, using the following format:
Example request format
Dear Cheap Host,
I hereby formally request that all physical or digital personal data is either destroyed and purged from your databases.
I acknowledge this request may take up to 4 weeks to process.
I also confirm I am the original account owner and have not used your services in the last 7 years.
Best Regards,
INSERT NAME HERE
6. Formal data request
UK GDPR gives you more control over what data is collected about you and how long that data is stored, including the ability to request a copy of this data. Requesting your data is a simple process that only takes a few seconds — just email us at info@cheapwebhosting-uk.co.uk.
Please be aware that we may ask for additional proof of identity before we can hand over the requested data; this is a standard security procedure that we carry out from time to time.
We will reply to your request within 4 weeks. From here we may ask for further proof of identity as well as a few security questions. Once complete, we will hand over the data in standard format (.txt or .pdf), whereby you can review the collected information.
You may also raise this request directly via a ticket to our Support System, using the following format:
Example request format
Dear Cheap Host,
I hereby formally request that a copy of all physical or digital personal data is provided to myself in a readable format.
I acknowledge this request may take up to 4 weeks to process.
I also confirm I am the original account owner and will be subject to additional identity checks.
Best Regards,
INSERT NAME HERE
7. Storage of personal data and account / profile information
The following data is stored for the mandatory 7 years required by HMRC in the event of an account audit (the 7-year countdown starts from when you no longer have any active services and have opted to close your account):
- Full name
- Full address
- Email address
- Phone number
- Country
- Company name
- VAT number
- Order records
- Invoices
- Transactions (IDs, amounts, timestamps)
All other data is stored for 6 months before being purged from our databases. This includes, but is not limited to:
- General logging (actions carried out on the control panel)
- Email logs
- Ticket attachments
- Tickets and replies
- API logs
- Abuse reports
- Live chat conversations, etc.
All of our client information / profile data is stored and replicated across multiple UK locations for redundancy, as follows:
- London, United Kingdom
- Coventry, United Kingdom
We employ a high level of encryption for stored passwords, including:
- CRYPT_BLOWFISH two-way encryption;
- Unique salts on a per-user basis, resulting in zero password hash clashing.