Skip to content
DebsHost
Menu

Effective Date: 01/01/2013 · Last Updated: 10/12/2025

DebsHost GDPR Policy (Data Protection Policy)

DebsHost (“DebsHost”, “we”, “our”, or “us”) is committed to protecting personal data and ensuring compliance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

This GDPR Policy explains how DebsHost collects, processes, stores, and protects personal data, and outlines the rights of data subjects.

1. Scope

This policy applies to:

  • All customers and users of DebsHost services
  • Visitors to debshost.com and related platforms
  • Personal data processed in connection with hosting, billing, domain registration, and support services

DebsHost acts as a Data Controller for customer account and billing data and may act as a Data Processor when hosting customer content.

2. Data Controller Information

Data Controller: DebsHost
128 City Road, London, United Kingdom, EC1V 2NX
Contact Email: [email protected]
Website: https://debshost.com

3. Principles of Data Protection

DebsHost processes personal data in accordance with the following UK GDPR principles:

Lawfulness, Fairness, and Transparency

Personal data is processed lawfully, fairly, and transparently.

Purpose Limitation

Data is collected for specified, explicit, and legitimate purposes.

Data Minimisation

Only data necessary for providing services is collected and processed.

Accuracy

Personal data is kept accurate and up to date.

Storage Limitation

Personal data is retained only as long as necessary.

Integrity and Confidentiality

Personal data is protected using appropriate security measures.

Accountability

DebsHost takes responsibility for ensuring compliance with GDPR.

4. Types of Personal Data Processed

DebsHost may process the following personal data:

  • Name and contact details
  • Email address
  • Billing information
  • Account login details
  • IP addresses
  • Domain registration details
  • Support communications
  • Service usage information

DebsHost does not collect unnecessary personal data.

5. Legal Basis for Processing

DebsHost processes personal data based on one or more of the following legal grounds:

Contractual Necessity

Processing required to provide hosting, billing, and domain services.

Legitimate Interests

Processing required to maintain service security, reliability, and performance.

Legal Obligation

Processing required to comply with applicable laws and regulations.

Consent

Processing based on user consent where applicable.

6. Role of DebsHost as Data Processor

When customers use DebsHost infrastructure to host websites, applications, or services, DebsHost acts as a Data Processor.

Customers remain the Data Controller of the data they host.

DebsHost processes hosted data only to:

  • Provide hosting services
  • Maintain infrastructure security
  • Ensure operational reliability

DebsHost does not access hosted customer data unless required for support or security.

7. Data Security Measures

DebsHost implements technical and organisational safeguards, including:

  • Secure infrastructure and server hardening
  • Network security and firewall protection
  • Access controls and authentication measures
  • Encryption where appropriate
  • Monitoring for unauthorized access

These measures help protect personal data against unauthorized access, loss, or misuse.

8. Data Retention

DebsHost retains personal data only as long as necessary to:

  • Provide services
  • Meet legal obligations
  • Resolve disputes
  • Maintain business records

Upon account termination, data may be deleted or anonymised unless required by law.

9. Data Subject Rights

Under UK GDPR, individuals have the right to:

  • Access their personal data
  • Request correction of inaccurate data
  • Request deletion of personal data
  • Restrict processing of their data
  • Object to processing
  • Request data portability

Requests may be submitted to [email protected].

DebsHost will respond within one month as required by law.

10. Data Breach Procedures

In the event of a personal data breach, DebsHost will:

  • Investigate the breach immediately
  • Take steps to mitigate risks
  • Notify relevant authorities if required
  • Notify affected individuals where required by law

11. Third-Party Data Processing

DebsHost may share personal data with trusted third parties, including:

  • Payment processors
  • Domain registrars
  • Infrastructure providers

These parties process data only as necessary to provide services and are required to protect personal data.

DebsHost does not sell personal data.

12. International Data Transfers

Personal data may be transferred outside the UK or EEA where necessary for service delivery.

DebsHost ensures appropriate safeguards are in place for such transfers.

13. Customer Responsibilities (When Acting as Data Controller)

Customers using DebsHost services to process personal data must ensure they comply with applicable data protection laws.

DebsHost provides infrastructure but customers remain responsible for their own data processing activities.

14. Policy Updates

DebsHost may update this GDPR Policy from time to time.

Updates will be published on our website.

15. Contact Information

For GDPR-related requests or questions:

Email: [email protected]

Website: https://debshost.com