How we use your data
Drayton Digital Limited is committed to safeguarding and preserving the privacy of our website visitors, customers and users.
This Privacy Policy explains what personal data we collect, how we use it, why we use it, how long we keep it, who we share it with, and what rights you have.
We may update this Privacy Policy from time to time. The latest version will be published on our website.
1. Who we are
Drayton Digital Limited is a company registered in England and Wales under company number 04609887.
Our registered office is:
Drayton Digital Limited
Commer House
Station Road
Tadcaster
North Yorkshire
LS24 9JF
United Kingdom
Drayton Digital Limited trades as 4UHosting.
In this Privacy Policy, “we”, “us” and “our” mean Drayton Digital Limited. “You” and “your” mean our website visitors, customers, account users, contacts and other individuals whose personal data we process.
We are registered with the Information Commissioner’s Office under registration number ZA387736.
Our data protection contact is Chris Drayton. You can contact us using the contact details published on our website, through our support helpdesk, or by writing to the address above.
2. Our role as controller and processor
For personal data we collect about our customers, account users, website visitors, billing contacts and support contacts, we normally act as a data controller. This means we decide how and why that personal data is used.
For personal data that customers store, transmit, upload or process using our hosting, email, cloud server or related services, we normally act as a data processor. This means we process that data on behalf of the customer and in accordance with the customer’s instructions, our Terms of Service and applicable data protection law.
For example, if you host a website with us that collects personal data from your own customers, visitors or users, you will usually be the controller of that data and we will usually be your processor in relation to the hosting service.
3. Personal data we collect
We may collect and process the following categories of personal data.
Account and identity information
This may include:
- name;
- business name;
- job title;
- username;
- account ID;
- customer reference;
- company registration number, where relevant;
- VAT number, where relevant; and
- account contact details.
Contact information
This may include:
- email address;
- postal address;
- billing address;
- business address;
- telephone number;
- mobile telephone number;
- support contact details; and
- alternative account contacts or authorised users.
Billing and payment information
This may include:
- invoice details;
- payment status;
- billing history;
- transaction references;
- partial payment card details, such as the last four digits of a card;
- payment method references or tokens;
- fraud prevention information; and
- accounting and tax records.
We do not intentionally store full debit or credit card numbers on our own systems. Card payments are processed using third-party payment providers and tokenised payment systems.
Service information
This may include:
- hosting package details;
- domain names;
- DNS settings;
- email account information;
- server details;
- IP addresses;
- control panel usernames;
- service status;
- renewal dates;
- cancellation requests;
- support history;
- migration information;
- backup status;
- software or licence information; and
- other information required to provide and manage services.
Domain registration information
Where you register, renew, transfer or manage a domain name through us, we may process information required by domain registries, registrars and registration authorities. This may include:
- registrant name;
- organisation name;
- postal address;
- email address;
- telephone number;
- domain contact information;
- administrative, technical or billing contact information; and
- information required by the relevant domain registry or registrar.
Some domain registration data may be processed, shared or published through WHOIS, RDAP, registry, registrar or domain dispute systems, depending on the rules that apply to the domain name.
Technical and usage information
When you visit our website, use our client area, submit forms, use our services or contact us, we may collect technical and usage information such as:
- IP address;
- browser type and version;
- device type;
- operating system;
- pages visited;
- referring website;
- date and time of access;
- log files;
- security logs;
- authentication logs;
- error logs;
- email logs;
- server logs;
- cookie information; and
- information about how you interact with our website and services.
Communications and support information
When you contact us, we may process:
- support tickets;
- emails;
- telephone notes;
- live chat messages, where available;
- contact form submissions;
- complaint details;
- technical information supplied by you;
- screenshots or attachments supplied by you; and
- records of our responses.
Hosted and customer-controlled data
Where you use our hosting, email, cloud server or related services, you may upload, store, send, receive or process your own data. This may include website files, databases, emails, backups, logs, media, application data and personal data relating to your own users or customers.
We do not use customer-hosted data for our own purposes. We process it only as required to provide, secure, maintain, troubleshoot, back up or support the relevant service, or where required by law.
4. How we collect personal data
We may collect personal data when:
- you visit our website;
- you create an account;
- you place an order;
- you renew, upgrade, downgrade or cancel a service;
- you register, transfer or renew a domain name;
- you make a payment;
- you update your account details;
- you create additional contacts or users;
- you contact us by support ticket, email, telephone, form or other method;
- you use our hosting, email, cloud, domain, DNS or related services;
- our systems generate logs for security, billing, support or technical purposes;
- third-party providers send us service, billing, payment, domain, abuse, fraud or technical information; or
- we are required to process information for legal, regulatory, tax, accounting, security or contractual reasons.
5. Why we use personal data and our lawful bases
We only use personal data where we have a lawful basis to do so.
To provide services and manage your account
We use personal data to create and manage customer accounts, process orders, provide services, manage hosting, configure services, register domains, provide support, send service notices and administer renewals.
Our lawful basis is usually performance of a contract or taking steps before entering into a contract.
To process payments and keep accounting records
We use personal data to issue invoices, process payments, manage failed payments, maintain financial records, calculate VAT, handle refunds and keep accounting records.
Our lawful basis is usually performance of a contract and compliance with legal obligations.
To register and manage domain names
We use personal data to register, renew, transfer, administer and support domain names.
Our lawful basis is usually performance of a contract. In some cases, we may also process domain-related data to comply with legal, registry, registrar or regulatory requirements.
To provide support
We use personal data to respond to support requests, investigate issues, verify account ownership, provide technical assistance and keep records of support communications.
Our lawful basis is usually performance of a contract and our legitimate interests in providing support, securing our services and maintaining accurate service records.
To secure our website, systems and services
We use personal data and technical data to monitor, protect and secure our website, servers, networks, email systems, customer accounts and services.
This may include fraud prevention, abuse prevention, malware investigation, spam prevention, intrusion detection, log analysis, rate limiting and security monitoring.
Our lawful basis is usually our legitimate interests in protecting our business, customers, systems and services. In some cases, we may also process this data to comply with legal obligations.
To communicate with you
We use personal data to send service notices, renewal reminders, invoices, support replies, security notices, maintenance notices, policy updates and other important customer communications.
Our lawful basis is usually performance of a contract, compliance with legal obligations, or our legitimate interests in operating and managing our services.
To improve our website and services
We may use website analytics, feedback, support trends and service information to improve our website, products, customer experience and service reliability.
Our lawful basis is usually our legitimate interests. Where required by law, we will ask for consent before using non-essential cookies or similar technologies.
To send marketing communications
We may occasionally contact customers or subscribers about our services, offers, updates or related products.
Where required, we will rely on consent. In some business-to-business or existing customer contexts, we may rely on legitimate interests where permitted by law.
You can opt out of marketing communications at any time.
To comply with legal obligations
We may use personal data to comply with tax, accounting, company law, data protection, court, regulatory, law enforcement, domain registry, registrar, fraud prevention or other legal obligations.
Our lawful basis is compliance with legal obligations.
6. Cookies and similar technologies
Our website uses cookies and similar technologies.
Cookies are small files placed on your device. They can be used to make a website work, keep you logged in, remember choices, secure forms, process orders, measure website usage, support affiliate or referral tracking and improve our services.
We use a cookie control system on our website to help you manage non-essential cookies where required.
We may use the following types of cookies.
Strictly necessary cookies
These cookies are required for the website, client area, ordering process, login system, security features, payment process, support tools or service management tools to work properly.
Strictly necessary cookies may be set without consent because they are needed to provide an online service you have requested.
Preference cookies
These cookies may be used to remember choices you make, such as cookie preferences, display options, login-related preferences or other website settings.
Analytics cookies
These cookies help us understand how visitors use our website, which pages are visited, how users find the site, and how the site can be improved.
Analytics cookies are not strictly necessary. Where required by law, we will ask for your consent before setting them.
Affiliate or referral tracking cookies
Where we use affiliate or referral tracking, cookies or similar technologies may be used to identify that a visitor came from a referral partner, affiliate link or promotional campaign.
Affiliate or referral tracking cookies are not strictly necessary. Where required by law, we will ask for your consent before setting them.
Managing cookies
You can manage non-essential cookies using the cookie control system on our website.
You can also control cookies using your browser settings. Most browsers allow you to block or delete cookies.
If you disable strictly necessary cookies, some parts of the website, ordering system, login area, payment process, support system or client area may not work properly.
7. Credit and debit card information
We use third-party payment providers and tokenised payment systems to process card payments.
We do not intentionally store full credit or debit card numbers on our own systems.
Our systems may store payment references, transaction records, tokenised payment identifiers and the last four digits of a payment card where required for billing, customer support, fraud prevention, accounting or payment administration.
Payment providers process payment data in accordance with their own legal obligations, security standards and privacy policies.
9. International transfers
Some of our suppliers, systems or service providers may process personal data outside the United Kingdom.
Where personal data is transferred internationally, we will take steps required by applicable data protection law. This may include using adequacy regulations, approved contractual safeguards, transfer risk assessments or other appropriate safeguards.
Domain name registrations, DNS, email delivery, cloud infrastructure, security systems and payment processing may involve international processing depending on the supplier, registry, registrar or service involved.
10. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction.
Measures may include access controls, encryption, firewalls, malware protection, monitoring, backups, password controls, multi-factor authentication where appropriate, staff access controls and supplier due diligence.
No system can be guaranteed to be completely secure. Customers are responsible for keeping their own account details, passwords, devices, websites, scripts, applications and users secure.
If you believe your account, website, mailbox, server or personal data has been compromised, you should contact us immediately.
11. Hosted data and customer responsibility
Where you use our hosting, email, Managed Cloud Server or related services to store or process data, you are responsible for the data you choose to store or process.
You are responsible for ensuring that you have the right to collect, upload, store, publish, process and otherwise use any personal data contained in your websites, databases, emails, files, backups, applications or other Hosted Materials.
You are also responsible for providing your own privacy notices to your users, customers, visitors or contacts where required by law.
We do not routinely access customer-hosted data. We may access it where necessary to provide support, investigate faults, maintain services, perform backups, protect security, prevent abuse, comply with law or act on your instructions.
12. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods may vary depending on the type of data, the service provided, legal requirements, accounting rules, support needs, security requirements and whether there is an ongoing dispute or investigation.
Typical retention periods include:
- customer account information: for as long as the account remains active and for a reasonable period afterwards;
- invoices, payment records and accounting records: normally at least six years after the end of the relevant financial year;
- support tickets and customer communications: for as long as needed to provide support, maintain records and resolve disputes;
- domain registration data: for as long as required by the relevant registry, registrar or domain provider;
- server, security and access logs: for a limited period appropriate to security, troubleshooting and abuse prevention;
- marketing preferences: until you opt out or withdraw consent, and then as required to maintain suppression records;
- hosted data: for the duration of the service and for any backup or deletion period described in our Terms of Service or service description.
When data is no longer required, we will delete, anonymise or securely archive it where appropriate.
13. Marketing
We may occasionally contact you with information about our services, offers, updates or related services.
You can opt out of marketing at any time by using the unsubscribe option where available, changing your communication preferences, or contacting us.
We will still send non-marketing service messages where necessary, including invoices, renewal notices, security notices, support replies, maintenance notices and important account information.
14. Your data protection rights
Depending on the circumstances and the lawful basis for processing, you may have the following rights.
Right of access
You can ask for a copy of the personal data we hold about you.
Right to rectification
You can ask us to correct inaccurate or incomplete personal data.
Right to erasure
You can ask us to delete personal data in certain circumstances.
Right to restrict processing
You can ask us to restrict the use of your personal data in certain circumstances.
Right to object
You can object to processing in certain circumstances, including processing based on legitimate interests and processing for direct marketing.
Right to data portability
You may have the right to receive certain personal data in a structured, commonly used and machine-readable format.
Right to withdraw consent
Where we rely on consent, you can withdraw that consent at any time.
Withdrawing consent does not affect processing that took place before consent was withdrawn.
Rights relating to automated decision-making
You have rights relating to certain automated decisions that produce legal or similarly significant effects. We do not normally make such decisions about customers using solely automated processing.
15. Exercising your rights
You can exercise your rights by contacting us using the contact details on our website, through the support helpdesk, or by writing to us.
We may ask you to verify your identity before responding to a request.
We will respond within the time required by applicable data protection law.
Some rights are subject to exemptions or limitations. For example, we may need to keep certain information for legal, accounting, security, contractual or dispute-resolution reasons.
16. Consequences of not providing personal data
You are not required to provide personal data to us.
However, some personal data is necessary for us to provide services, create accounts, process payments, register domains, provide support, meet legal obligations and manage security.
If you do not provide required information, we may be unable to provide some or all of our services.
17. Children
Our services are intended for business users and individuals capable of entering into contracts for hosting, domain and related services.
Our services are not directed at children, and we do not knowingly collect personal data from children.
18. Complaints
If you have a concern about how we use your personal data, please contact us first so that we can investigate and try to resolve the issue.
You also have the right to complain to the Information Commissioner’s Office.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: ico.org.uk
19. Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, suppliers, legal obligations, technology or business practices.
The latest version will be published on our website.
