Skip to main content
.com from $2.99, and WHOIS privacy costs nothing

GDPR and Your Data Rights

Last updated: August 19, 2026

What this covers

The privacy policy sets out what we hold and the basis we hold it on. This page deals with the mechanics of making us act. Substance lives there, procedure lives here.

1. Controller or processor

One platform carries two separate relationships, and which of the two applies decides who actually has to answer you.

  • Data held about you, our customer — the account, the invoices, the tickets, the registrant records. We set the purposes, which makes us controller, so the request lands with us.
  • Data sitting inside a site you host — your members, your orders, your subscribers. That data exists because you put it there, and you decide what becomes of it. When one of your users asks, we point them back at you; the data processing addendum governs that relationship.

2. Available rights

  • Access — a copy of whatever personal data we hold about you.
  • Rectification — correction of inaccuracies.
  • Erasure — unless an overriding obligation gets in the way. Invoices are the usual example: six years is a statutory retention period, and that beats a preference.
  • Restriction — we suspend processing while accuracy remains in dispute.
  • Portability — the data you supplied yourself, in machine-readable form, where consent or contract applies.
  • Objection — to any processing resting on legitimate interests. Against direct marketing the objection is absolute, with no balancing exercise.
  • Withdrawal of consent — whenever you choose, where consent was the basis, and it carries no retrospective effect.

3. Filing

Email info@hostingally.com putting "Data request" into the subject line, or use the contact page. There is no form, no prescribed wording, and no need to quote the legislation at us. A plain sentence counts as a valid request, and we treat it as one.

Include:

  • what you want to happen;
  • which account or email address is involved;
  • any narrowing you can give us, such as one system or a date range. Optional, that, but it buys a sharper answer than asking for everything.

4. Identity

Handing an account's data to whoever happens to ask would be a breach, so we confirm identity before anything else. A request arriving from the registered address is normally enough on its own. Closed accounts, and requests made on somebody else's behalf, attract one further check, and we say why we are asking.

Identity documents get requested only where nothing lighter suffices, and they are destroyed immediately that check concludes.

5. Deadline

One calendar month, counted from the moment identity is established. A complex or repetitive request can stretch that by two further months, and where it does, the reason reaches you inside the first month rather than on its last day.

Nothing is charged. The legislation does allow a fee for manifestly unfounded or excessive requests, but we would sooner explain our assessment than send you an invoice for it.

6. Refusals

Some requests get declined in part: erasure that would wipe out records the law requires us to keep, or access that would hand over a third party's data along with your own. When that happens, you are told the reason, the exemption we relied on, and how to challenge the decision. Silence is never an outcome we use.

7. Escalation

Start with the complaints procedure — quicker, and the mistake may well have been ours. No obligation to do so exists, and going straight to the regulator costs you nothing.

The supervisory authority for England and Walesis the Information Commissioner's Office at ico.org.uk, and it accepts complaints directly from individual members of the public.

8. The controller

Fairdeal Renovations Limited, registered in England and Wales under Company No. 15026869, trading as HostingAlly. Registered office: The Workspace Basildon, 7 High Pavement, Basildon, England, SS14 1EA. Requests to info@hostingally.com.