Data Security Statement
Revised August 19, 2026
The security centre sets out what protects the websites we host. This page is narrower, and duller with it: the subject here is the personal data sitting behind the accounts, yours and your customers' alike, plus the measures Article 32 of the UK GDPR requires of us.
1. Moving data, and stored data
TLS carries every page on this site and every page in the client area, and HTTP Strict Transport Security is set so no browser drops back to an unencrypted connection. Renewal of certificates happens on its own. An expired certificate is an outage, and we do not plan on having one.
We keep account passwords as salted hashes, which means neither we nor support can read one back. Resetting is the only way in. That is the reason nobody here will ever ask you for yours. Card details never land on our systems at all: the payment provider takes the payment, and what stays with us is a token plus the last four digits.
2. Who can see what
Access to any system holding personal data goes out on need, attaches to a named individual, and comes back the moment that need ends. Administrative access carries two-factor authentication. We run no shared logins, since an action that cannot be traced to a person is an action nobody has to answer for.
Your account, your services and your tickets are visible to support staff. What sits inside your databases and files is not something they read as a matter of course. Where a request makes that necessary, you know it is happening, and it covers that one request.
3. Separation and resilience
On shared infrastructure each account is walled off from the rest, so one site falling over to an attacker does not take its neighbours with it. Platform software stays patched. Malware scanning runs without pause, and out in front sits a web application firewall with network-level denial-of-service mitigation.
A copy is taken each day, and you can restore from it yourself without opening a ticket. Treat that as a courtesy, not a guarantee, and never as a replacement for a backup of your own. The service level agreement states plainly that no payment falls due under this agreement for lost data.
4. Where the records are held, and who else handles them
The hosting infrastructure sits in the United Kingdom, while the company is federally incorporated in Canada. Processing of personal data happens in the UK and the EEA. Should a supplier operate outside that, the transfer runs under the safeguards named in the privacy notice, a document that also lists every sub-processor involved.
We assess a supplier before putting them to work, and written terms bind them to standards no weaker than the ones we owe you. The data processing addendum handles that point wherever we act as your processor.
5. Holding records only as long as needed
Retention periods are in the privacy notice. Put briefly: account and service records last as long as the account and then six years beyond it, which UK tax law demands; support tickets sit for three years; server logs survive a matter of weeks.
Cancel a service and its data comes off the live systems on the published schedule, after which it ages out of the backup sets. We do not edit a backup to satisfy a deletion request, since rewriting one wrecks its integrity. The set is left to expire on its own, and in the meantime nothing in it goes back into use.
6. If something goes wrong
Where a personal data breach looks likely to put people's rights at risk, we report it to the Information Commissioner's Office within 72 hours of the moment we learn of it. Should the risk to individuals run high, the people affected hear from us direct, without undue delay.
Where we act as your processor, word reaches you without undue delay, so you can meet the reporting duty you carry as controller. Otherwise you would be answerable for a clock running somewhere you cannot see it.
Telling you about an incident that turns out to be small beats holding it back while somebody works out how it will look.
7. Reporting a vulnerability
Spotted a weakness in something we run? Write to us at info@hosting-n-domains.com before word goes anywhere else, and leave us a fair window in which to fix it. Our /.well-known/security.txt file repeats the same contact, written for machines to read.
Keep your testing to your own account. Leave other people's data alone, neither reading it nor changing it, and run no denial-of-service tests. Research kept inside those bounds is welcome here, and we will not come after you for it.
8. What stays with you
Nothing written above will patch your plugins, pick your passwords, or strip the FTP login off an employee who has already left. Those duties are written down in the acceptable use policy, and they account for most of the compromises that reach us.
9. Who this is with
Hosting & Domains is a trading name of Azaanex Inc., a company registered in Canada under Company No. 1766541-5. Registered office: 5-145 1/2 Church St, Toronto, Ontario M5B 1Y4, Canada. Security contact: info@hosting-n-domains.com.