Data Security Statement
Last updated: August 19, 2026
Scope
The security page describes what keeps hosted websites safe. This page is narrower in scope: the personal data sitting behind the accounts, plus the technical and organisational measures Article 32 of the UK GDPR demands from us.
1. Encryption
Every request to this site and to the client area travels over TLS, with HTTP Strict Transport Security switched on, so no browser quietly drops back to plain HTTP. Certificates renew on their own.
Passwords on accounts are salted and hashed, so support cannot recover one and neither can anybody else in this company. Resetting is the only route open, which is precisely why nobody here will ever ask you for your password. Card data never touches our systems at all. The payment provider keeps it; what we hold is a token and the final four digits.
2. Access control
Access to systems holding personal data goes to a named individual, granted on need, and taken away the moment that need disappears. Administrative access requires two-factor authentication. We do not use shared credentials, because an action nobody can attribute is an action nobody can be held to account for.
Support can see your account, your services and your tickets. Reading the contents of a file or rows in a database is not routine. Where a request truly needs it, that happens with your knowledge, and only for that request.
3. Isolation and resilience
Accounts that share hardware are walled off from each other, so a breach on one site does not turn into a breach on all of them. Platform software gets patched, malware scanning runs without pause, and a web application firewall with network-level attack mitigation sits out in front.
Copies are taken daily and you can restore them yourself, no ticket needed. Treat them as a convenience, not a warranty. The service level agreement is explicit on this: it settles against availability, and never against data loss.
4. Location and sub-processors
The hosting infrastructure sits in the United Kingdom. Processing of personal data happens in the UK and EEA, and where a supplier works outside that, the transfer leans on the safeguards named in the privacy policy, where the sub-processors are listed too.
We assess a supplier before adopting them, then bind them by written terms no weaker than the ones we owe you. Where we act as your processor, the data processing addendum applies.
5. Retention
Retention periods appear in the privacy policy. Roughly speaking: account and billing records last for the life of the account plus six years, which is what tax law demands; support tickets keep for three years; server logs only weeks.
Cancel, and the data comes off live systems on the published schedule, then ages out of the backups behind them. We do not edit a backup to satisfy an erasure request, because editing one destroys its integrity. The backups expire instead, and the data stays unavailable the whole time.
6. Breach notification
Where a personal data breach is likely to put people at risk, we report it to the Information Commissioner's Office within 72 hours of us finding out. Where the risk runs high, the individuals affected are told directly by us, and without undue delay.
Where we process on your behalf, we notify you without undue delay, so you can meet your own obligations as controller. Your clock starts running whether or not anybody has got round to telling you.
7. Vulnerability reporting
Report weaknesses to info@hostingally.com before you disclose it anywhere else, leaving a reasonable window to remediate. The same contact appears at /.well-known/security.txt.
Test against your own account and nothing else. Do not read or alter anybody else's data, and run no denial-of-service tests. Research kept inside those bounds is welcome, and we will not come after you.
8. Customer obligations
Nothing above patches your extensions, picks your passwords, or strips out the credentials of a contractor who has left. Those live in the acceptable use policy and sit behind the majority of compromises witnessed here.
9. Contracting entity
HostingAlly does business as a trading name of Fairdeal Renovations Limited, a company registered in England and Wales under Company No. 15026869. Registered office: The Workspace Basildon, 7 High Pavement, Basildon, England, SS14 1EA. Security contact: info@hostingally.com.