This policy describes how Citahost Ltd collects, uses, and protects your personal data when you visit citahost.com or use our services. It is written to align with UK GDPR and the Data Protection Act 2018.
Who we are
Citahost Ltd, registered in England & Wales, is the data controller for the personal data processed via citahost.com. Our Data Protection contact is privacy@citahost.com.
What we collect
- Account data: name, email, billing address, phone number (optional)
- Payment data: card details are handled by Stripe; we never see them
- Service data: domains, IP addresses, support tickets, server logs
- Marketing data: only if you opt in to our newsletter
Legal bases
We process personal data on the bases of: contract performance (delivering services you bought), legitimate interests (fraud prevention, security), legal obligation (tax records, abuse investigations), and consent (marketing emails).
Sharing
We share data only with sub-processors necessary to operate. We do not sell personal data, and we do not pass it to advertising or data-broker networks. International transfers use Standard Contractual Clauses or UK equivalent safeguards.
- Stripe Payments UK Ltd — card processing, billing portal, fraud screening.
- Cloudflare, Inc. — DNS and CDN in front of customer sites.
- Wholesale hosting provider — the licensed upstream operator that runs the physical cPanel / VPS / mail infrastructure on our behalf. Application data (accounts, orders, tickets) lives on the same infrastructure under our direct control.
Retention
Account data is kept for the life of your account plus 6 years for tax compliance. Support ticket bodies are retained 2 years. Marketing consent is honored indefinitely until you opt out.
Your rights
You may request access, correction, deletion, restriction, portability, or objection at any time. Email privacy@citahost.com. You may also complain to the UK Information Commissioner’s Office (ICO).
Security
Data at rest is encrypted on our database hosts. Data in transit uses TLS 1.2+. We log access to administrative interfaces and review suspicious activity. No system is perfectly secure; we publish incident reports within 72 hours of any breach affecting personal data.
Cookies
See our Cookie Policy for details on first- and third-party cookies used on citahost.com.