GDPR and Your Data Rights
Revised August 19, 2026
The privacy notice sets out what we collect, the reason for it, and the lawful basis behind it. This page covers the other half: how you make us act on any of it. Reading only for the substance? Go and read that one. Filing a request? Stay on this page.
1. Which role we occupy here
The same platform carries two separate relationships, and which one you happen to be in changes the rights you hold.
- Data about you: here we are the controller. That covers your account, your invoices, your tickets and the domain records standing in your name. Send a request about any of it here and we answer it.
- Visitor data, where the processor role is ours. Anything living in the database of a site you host with us falls here. We keep it on your instruction, and no decision about it is ours to make. Should one of your own customers write to us asking for their data, we send them back to you. What governs that arrangement is the data processing addendum.
2. Rights that are yours to use
- Access — a copy of every piece of personal data we hold on you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion, so long as nothing overriding requires us to keep the data. Invoices supply that override most of the time: UK tax law demands six years, and the duty beats any request to erase.
- Restriction — processing put on hold until an accuracy dispute settles.
- Portability — whatever data you handed us, delivered in a machine-readable form, wherever consent or a contract is the basis we rely on.
- Objection — aimed at any processing we run on legitimate interests. Object to direct marketing and it simply stops; no balancing test has to be argued out.
- Withdrawal of consent — whenever you choose, in any case where consent was the basis we leaned on. Nothing lawful done before that point is undone.
3. Making a request
Email info@hosting-n-domains.com putting "Data request" in the subject line, or go via the contact form. There is no set form of words, and no need to quote the legislation at us. One plain sentence saying what you want counts as a valid request, and it gets treated as one.
Tell us:
- the right you mean to use, or just the outcome you are after;
- which email address or account the request relates to;
- a date range, or a named system, where you already know the request is a narrow one. Nobody insists on it, though a tight ask tends to bring back something useful sooner than a sweep of everything.
4. Proving it is you
Passing an account's data to whoever happens to ask would be a breach in itself, so identity gets confirmed before anything moves. A request arriving from the address registered on the account usually settles that. Where it does not, say on a closed account, or on a request made for somebody else, we ask for one further check and tell you the reason for it.
Identity documents are asked for only when nothing lighter would work, and they get deleted the moment the check finishes.
5. How long it takes
One calendar month, counted from the day we hold enough to identify you. A complex or repetitive request may stretch that by a further two months, and when it does you hear from us inside the first month, with the reason given.
Making a request costs nothing. The law does allow a fee where a request is manifestly unfounded or excessive, but we would sooner explain our reasoning to you than put a charge on the invoice.
6. When we say no
A request can be refused, either wholly or in part: a deletion that would wipe records the law obliges us to keep, or an access request that would expose another person's data alongside your own. Where that happens, you receive the reason, the exemption we relied on, and the route open to you for challenging it. What you will never get is silence.
7. Complaining
Start with us, through the complaints procedure — that route runs faster, and there is every chance we simply got it wrong. No obligation binds you to it, and going straight to the regulator costs nothing.
The Information Commissioner's Office, reachable at ico.org.uk, supervises anything falling under the UK GDPR; in Canada the role belongs to the Office of the Privacy Commissioner of Canada, at priv.gc.ca. Either will take a complaint straight from the public.
8. Who this is with
The controller is Azaanex Inc., a company registered in Canada under Company No. 1766541-5, trading as Hosting & Domains. Registered office: 5-145 1/2 Church St, Toronto, Ontario M5B 1Y4, Canada. Data requests go to info@hosting-n-domains.com.