This policy explains what personal data Apaxon Limited trading as ApaxonHost collects, why, how long we keep it, and what rights you have over it. It covers our website, the client area, and the services we supply.
1. Who is responsible
Apaxon Limited is the data controller for personal data about our customers and website visitors.
Apaxon Limited (trading as ApaxonHost) Piccadilly Business Centre, Aldow Enterprise Park, Manchester, M12 6AE Registered in England & Wales, company number 09784429 VAT registration number GB383 9183 59
General enquiries: info@apaxonhost.com Support: support@apaxonhost.com Billing: billing@apaxonhost.com Abuse reports: abuse@apaxonhost.com Data protection: privacy@apaxonhost.com
Data protection queries: privacy@apaxonhost.com
Where you host a website with us and that website collects personal data about your visitors, you are the controller for that data and we act as your processor. Section 9 covers that relationship.
2. What we collect
Account and billing data. Name, company name, email address, postal address, phone number, VAT number where supplied, and a record of your orders, invoices, payments and refunds.
Payment data. We do not store full card numbers. Card payments are handled by our payment provider; we retain only the card type, the last four digits, the expiry date, and the provider's token.
Authentication data. A bcrypt hash of your password (never the password itself), two-factor secrets and recovery codes, session identifiers, and a log of sign-ins including IP address and browser user-agent.
Support data. The content of tickets, emails and any attachments you send us.
Service data. The domains, websites, mailboxes and DNS records on your account, plus server logs — web access logs, mail logs, and error logs — which contain IP addresses.
Website analytics. Page-view counts collected by Google Analytics 4, and only where you have accepted analytics cookies. IP addresses are anonymised. We do not use advertising trackers, we do not build behavioural profiles, and we do not sell data to anyone.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the services you ordered | Performance of a contract |
| Invoicing, taking payment, chasing arrears | Performance of a contract |
| Keeping accounting and VAT records | Legal obligation |
| Support tickets and correspondence | Performance of a contract |
| Security monitoring, abuse prevention, fraud checks | Legitimate interests |
| Service notices — maintenance, incidents, renewals | Performance of a contract |
| Marketing email about our own products | Consent, or soft opt-in for existing customers |
| Improving our services and website | Legitimate interests |
Where we rely on legitimate interests we have considered the impact on you and concluded it is proportionate. You can object at any time — see section 7.
4. Marketing
We send service notices — renewal reminders, invoices, maintenance windows, security alerts — for as long as you hold a service with us. These are part of the contract and cannot be unsubscribed from without closing the account.
Marketing email is separate. We send it only where you opted in, or where you are an existing customer and we are telling you about a similar product. Every marketing email has a one-click unsubscribe, and you can change your preference at any time in the client area.
5. Who we share it with
We share personal data only where it is necessary to run the service:
- Domain registries and registrars — the registrant details required
to register a domain. Some registries publish parts of this in WHOIS; we enable WHOIS privacy free of charge where the registry permits it.
- Payment providers — to take payment and handle refunds and
chargebacks.
- Email delivery providers — to send transactional and support email.
- Infrastructure providers — the data centres and cloud platforms
hosting our servers and databases.
- Microsoft — where you buy Microsoft 365 mailboxes through us.
- Certificate authorities — where you buy an SSL certificate.
- Professional advisers — accountants and lawyers, under a duty of
confidence.
- Law enforcement and regulators — where we are legally required to,
or where it is necessary to investigate an abuse report.
We do not sell personal data, and we do not share it for third-party advertising.
6. Where data is stored, and for how long
Our primary infrastructure is in the United Kingdom and the European Economic Area. Where a sub-processor operates outside the UK, the transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement/Addendum.
| Data | Retention |
|---|---|
| Account and contact details | Life of the account, then 12 months |
| Invoices, payments and accounting records | 7 years from the end of the accounting period (HMRC requirement) |
| Support tickets | 3 years from closure |
| Web and mail server logs | 90 days |
| Authentication and audit logs | 12 months |
| Website and mailbox content | Until the service ends, then deleted after the retention window in section 8 |
| Backups | Rolling, overwritten on the cycle in the SLA |
7. Your rights
Under UK GDPR you have the right to: access your data; have inaccurate data corrected; have data erased where we no longer need it; restrict or object to processing; receive your data in a portable format; and withdraw consent where consent is the basis we rely on.
To exercise any of these, email privacy@apaxonhost.com. We respond within one month. We do not charge, unless a request is manifestly unfounded or excessive.
We may need to verify your identity first — this protects you from someone else asking for your data.
If you are unhappy with how we have handled a request you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you came to us first so we have a chance to fix it.
8. What happens when a service ends
When a service is cancelled or terminated we retain the content for 30 days, so an account closed by mistake can be recovered. After that, website files, databases and mailboxes are deleted and drop out of the backup rotation within a further 30 days.
Billing records are kept for seven years regardless — that is a legal obligation we cannot waive.
9. When we act as your processor
Where your website or mailbox holds personal data about your own customers, you are the controller and we are your processor. In that role we:
- process that data only on your documented instructions;
- keep it confidential and require the same of our staff;
- apply the security measures in section 10;
- engage sub-processors only as listed in section 5, and remain liable
for them;
- assist you with data subject requests and with breach notification;
- delete or return the data at the end of the service, per section 8.
If you need a signed Data Processing Agreement, ask privacy@apaxonhost.com and we will provide one.
10. Security
We protect data with encryption in transit (TLS on every site and every mailbox), encryption at rest for backups, bcrypt password hashing, optional two-factor authentication, role-based staff access on a least-privilege basis, audit logging of administrative actions, and network segregation between customer accounts.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify the ICO within 72 hours and tell affected customers without undue delay.
11. Cookies
See the Cookie Policy for what we set and why.
12. Children
Our services are sold to businesses and to adults. We do not knowingly collect data about anyone under 16. If you believe we hold such data, tell us and we will delete it.
13. Changes
We will post any change here and update the date at the top. Where a change materially affects how we use your data we will email you at least 30 days before it takes effect.
