Data Security Statement
Revised August 19, 2026
The security centre describes what protects the websites we host. This page is narrower and duller: it is about the personal data behind the accounts — yours, and your customers' — and the measures required of us under Article 32 of the UK GDPR.
1. In transit and at rest
Every page on this site and in the client area is served over TLS, with HTTP Strict Transport Security set so a browser will not fall back to an unencrypted connection. Certificates renew automatically; an expired certificate is an outage we do not intend to have.
Account passwords are stored as salted hashes and cannot be read back by us or by support — a password reset is the only route, which is why nobody here will ever ask you for yours. Card details never touch our systems: payment is handled by the payment provider, and what we hold is a token and the last four digits.
2. Who can see what
Access to systems holding personal data is granted on need, tied to a named individual, and removed when the need ends. Administrative access requires two-factor authentication. Shared logins are not used, because an action nobody can be attributed to is an action nobody is accountable for.
Support staff can see your account, services and tickets. They do not routinely read the contents of your databases or files, and where a support request requires it, it is done with your knowledge and for that request only.
3. Separation and resilience
Accounts on shared infrastructure are isolated from one another, so a compromise of one site is not a compromise of its neighbours. Platform software is kept patched, malware scanning runs continuously, and a web application firewall with network-level denial-of-service mitigation sits in front.
A daily copy is taken and is restorable by you without a ticket. It is a courtesy rather than a guarantee, and it is not a substitute for your own backup — the service level agreement is explicit that this agreement does not pay out on data loss.
4. Where data lives, and who else touches it
Hosting infrastructure is in the United Kingdom. Personal data is processed in the UK and the EEA, and where a supplier operates elsewhere the transfer is covered by the safeguards named in the privacy notice, which also lists the sub-processors involved.
Suppliers are assessed before they are used and are bound by written terms no weaker than the ones we owe you. The data processing addendum covers this where we act as your processor.
5. Keeping data no longer than needed
Retention periods are in the privacy notice. The short version: account and service records for the life of the account and six years afterwards, because UK tax law requires it; support tickets for three years; server logs for a matter of weeks.
When a service is cancelled its data is removed from live systems on the published schedule and then ages out of backups. Backups are not edited to satisfy a deletion request, because rewriting a backup destroys its integrity — they are allowed to expire instead, and the data stays out of use in the meantime.
6. If something goes wrong
A personal data breach likely to risk people's rights is reported to the Information Commissioner's Office within 72 hours of us becoming aware of it. Where the risk to individuals is high, we tell the people affected directly and without undue delay.
Where we are your processor, you are told without undue delay so that you can meet your own reporting duty as controller — you would otherwise be on the hook for a clock you could not see.
We would rather tell you about an incident that turns out to be minor than sit on one while deciding how it looks.
7. Reporting a vulnerability
Found a weakness in our systems? Tell us at info@hosting-n-domains.com before you tell anyone else, and give us a reasonable window to fix it. Our /.well-known/security.txt file carries the same contact in machine-readable form.
Test only against your own account, do not access or alter other people's data, and do not run denial-of-service tests. Research done on those terms is welcome and we will not pursue you for it.
8. What stays with you
None of the above patches your plugins, chooses your passwords or removes the ex-employee who still has an FTP login. Those obligations are set out in the acceptable use policy, and they are the source of most compromises we see.
9. Who this is with
Hosting & Domains is a trading name of UK Health Care Support Ltd, a company registered in England and Wales under Company No. 15042717. Registered office: Office 4648, 58 Peregrine Road, Ilford, England, IG6 3SZ. Security contact: info@hosting-n-domains.com.