Skip to main content
Legal

Privacy Policy

This policy explains what personal data Apaxon Limited trading as ApaxonHost collects, why, how long we keep it, and what rights you have over it. It covers our website, the client area, and the services we supply.

1. Who is responsible

Apaxon Limited is the data controller for personal data about our customers and website visitors.

Apaxon Limited (trading as ApaxonHost) Piccadilly Business Centre, Aldow Enterprise Park, Manchester, M12 6AE Registered in England & Wales, company number 09784429 VAT registration number GB383 9183 59

General enquiries: info@apaxonhost.com Support: support@apaxonhost.com Billing: billing@apaxonhost.com Abuse reports: abuse@apaxonhost.com Data protection: privacy@apaxonhost.com

Data protection queries: privacy@apaxonhost.com

Where you host a website with us and that website collects personal data about your visitors, you are the controller for that data and we act as your processor. Section 9 covers that relationship.

2. What we collect

Account and billing data. Name, company name, email address, postal address, phone number, VAT number where supplied, and a record of your orders, invoices, payments and refunds.

Payment data. We do not store full card numbers. Card payments are handled by our payment provider; we retain only the card type, the last four digits, the expiry date, and the provider's token.

Authentication data. A bcrypt hash of your password (never the password itself), two-factor secrets and recovery codes, session identifiers, and a log of sign-ins including IP address and browser user-agent.

Support data. The content of tickets, emails and any attachments you send us.

Service data. The domains, websites, mailboxes and DNS records on your account, plus server logs — web access logs, mail logs, and error logs — which contain IP addresses.

Website analytics. Page-view counts collected by Google Analytics 4, and only where you have accepted analytics cookies. IP addresses are anonymised. We do not use advertising trackers, we do not build behavioural profiles, and we do not sell data to anyone.

3. Why we use it, and our lawful basis

PurposeLawful basis
Providing the services you orderedPerformance of a contract
Invoicing, taking payment, chasing arrearsPerformance of a contract
Keeping accounting and VAT recordsLegal obligation
Support tickets and correspondencePerformance of a contract
Security monitoring, abuse prevention, fraud checksLegitimate interests
Service notices — maintenance, incidents, renewalsPerformance of a contract
Marketing email about our own productsConsent, or soft opt-in for existing customers
Improving our services and websiteLegitimate interests

Where we rely on legitimate interests we have considered the impact on you and concluded it is proportionate. You can object at any time — see section 7.

4. Marketing

We send service notices — renewal reminders, invoices, maintenance windows, security alerts — for as long as you hold a service with us. These are part of the contract and cannot be unsubscribed from without closing the account.

Marketing email is separate. We send it only where you opted in, or where you are an existing customer and we are telling you about a similar product. Every marketing email has a one-click unsubscribe, and you can change your preference at any time in the client area.

5. Who we share it with

We share personal data only where it is necessary to run the service:

  • Domain registries and registrars — the registrant details required

to register a domain. Some registries publish parts of this in WHOIS; we enable WHOIS privacy free of charge where the registry permits it.

  • Payment providers — to take payment and handle refunds and

chargebacks.

  • Email delivery providers — to send transactional and support email.
  • Infrastructure providers — the data centres and cloud platforms

hosting our servers and databases.

  • Microsoft — where you buy Microsoft 365 mailboxes through us.
  • Certificate authorities — where you buy an SSL certificate.
  • Professional advisers — accountants and lawyers, under a duty of

confidence.

  • Law enforcement and regulators — where we are legally required to,

or where it is necessary to investigate an abuse report.

We do not sell personal data, and we do not share it for third-party advertising.

6. Where data is stored, and for how long

Our primary infrastructure is in the United Kingdom and the European Economic Area. Where a sub-processor operates outside the UK, the transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement/Addendum.

DataRetention
Account and contact detailsLife of the account, then 12 months
Invoices, payments and accounting records7 years from the end of the accounting period (HMRC requirement)
Support tickets3 years from closure
Web and mail server logs90 days
Authentication and audit logs12 months
Website and mailbox contentUntil the service ends, then deleted after the retention window in section 8
BackupsRolling, overwritten on the cycle in the SLA

7. Your rights

Under UK GDPR you have the right to: access your data; have inaccurate data corrected; have data erased where we no longer need it; restrict or object to processing; receive your data in a portable format; and withdraw consent where consent is the basis we rely on.

To exercise any of these, email privacy@apaxonhost.com. We respond within one month. We do not charge, unless a request is manifestly unfounded or excessive.

We may need to verify your identity first — this protects you from someone else asking for your data.

If you are unhappy with how we have handled a request you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you came to us first so we have a chance to fix it.

8. What happens when a service ends

When a service is cancelled or terminated we retain the content for 30 days, so an account closed by mistake can be recovered. After that, website files, databases and mailboxes are deleted and drop out of the backup rotation within a further 30 days.

Billing records are kept for seven years regardless — that is a legal obligation we cannot waive.

9. When we act as your processor

Where your website or mailbox holds personal data about your own customers, you are the controller and we are your processor. In that role we:

  • process that data only on your documented instructions;
  • keep it confidential and require the same of our staff;
  • apply the security measures in section 10;
  • engage sub-processors only as listed in section 5, and remain liable

for them;

  • assist you with data subject requests and with breach notification;
  • delete or return the data at the end of the service, per section 8.

If you need a signed Data Processing Agreement, ask privacy@apaxonhost.com and we will provide one.

10. Security

We protect data with encryption in transit (TLS on every site and every mailbox), encryption at rest for backups, bcrypt password hashing, optional two-factor authentication, role-based staff access on a least-privilege basis, audit logging of administrative actions, and network segregation between customer accounts.

If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify the ICO within 72 hours and tell affected customers without undue delay.

11. Cookies

See the Cookie Policy for what we set and why.

12. Children

Our services are sold to businesses and to adults. We do not knowingly collect data about anyone under 16. If you believe we hold such data, tell us and we will delete it.

13. Changes

We will post any change here and update the date at the top. Where a change materially affects how we use your data we will email you at least 30 days before it takes effect.