This policy explains what personal data VirexNode Ltd collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it under UK data protection law.
VirexNode Ltd takes the privacy of your information seriously. This policy explains how we collect and use personal data when you visit our website, enquire about our services, open an account, or use our web hosting.
It also explains, in section 11, the different relationship that applies to personal data you store on our servers as part of your own website — where you are the controller and we act on your instructions.
We handle personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
For the personal data described in this policy, the data controller is:
We are not required to appoint a statutory Data Protection Officer. Privacy queries are handled by our team at the email address above.
We only use personal data where the law allows us to. The table below sets out what we use data for and the lawful basis we rely on.
| What we use it for | Lawful basis |
|---|---|
| Creating and administering your account | Performance of a contract |
| Providing hosting and support | Performance of a contract |
| Taking payment and issuing invoices | Performance of a contract |
| Sending service notices, maintenance and renewal reminders | Performance of a contract |
| Responding to sales enquiries and preparing quotes | Legitimate interests — responding to a request you made |
| Monitoring resource usage and enforcing fair usage | Legitimate interests — keeping the platform stable for all customers |
| Detecting, preventing and investigating abuse, fraud and attacks | Legitimate interests — network and information security |
| Improving our services and infrastructure planning | Legitimate interests — running and developing our business |
| Keeping accounting and tax records | Legal obligation |
| Responding to lawful requests from authorities | Legal obligation |
| Analytics on our marketing website | Consent |
| Marketing emails to non-customers | Consent |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by your rights and freedoms, and concluded they are not. You may object to processing based on legitimate interests at any time — see section 10.
We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not carry out profiling for advertising purposes.
Customer websites and account data are hosted in the United Kingdom.
Some of the business tools we use may process limited personal data outside the UK. Where that happens, we make sure an appropriate safeguard is in place — either the country is covered by UK adequacy regulations, or the transfer is governed by the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
You can ask us for details of the safeguards applying to any specific transfer.
We keep personal data only for as long as we need it, then delete it or make it anonymous.
| Data | Retention period |
|---|---|
| Account and contact details | Duration of the account, then 12 months |
| Invoices and accounting records | 7 years, as required by HMRC |
| Hosting account content and databases | 14 days after cancellation, then permanently deleted |
| Backups | Rolling retention, overwritten in the normal cycle |
| Server and access logs | Up to 12 months |
| Security and abuse records | Up to 24 months |
| Support tickets and correspondence | 3 years from closure |
| Sales enquiries that do not become accounts | 12 months |
We apply technical and organisational measures appropriate to the risk, including:
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell affected individuals directly where the risk is high.
Under UK data protection law you have the right to:
To exercise any of these rights, email [email protected]. We will respond within one month. If your request is complex we may extend that by up to two further months, and we will tell you if so. There is normally no charge, though we may charge a reasonable fee for manifestly unfounded or excessive requests.
We may ask you to verify your identity before acting, to make sure we do not disclose data to the wrong person.
This section is about personal data belonging to your visitors, customers or staff that you store on our servers — for example through a contact form, an online shop, or a membership area.
For that data, you are the data controller and VirexNode is a data processor acting on your behalf. You decide what is collected and why; we simply store and serve it as part of providing the hosting.
In that role we commit to:
As controller, you are responsible for:
If you need a formal data processing agreement for your own compliance records, contact us and we will provide one.
We may send existing customers occasional emails about services similar to those you already buy from us, as permitted under PECR. Every such email includes an unsubscribe link, and opting out takes effect immediately.
We will not send marketing to non-customers without consent, and we do not share contact details with third parties for their own marketing.
Opting out of marketing does not stop service messages such as invoices, renewal reminders, maintenance notices and security alerts, which we need to send you as part of providing the service.
Our services are intended for people aged 18 and over, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We review this policy regularly and may update it to reflect changes in the law, our services, or how we operate. The current version is always published here with the date it was last updated.
Where a change materially affects how we use your personal data, we will tell you by email before it takes effect.
For any question about this policy or about how we handle your data, contact us:
We would always prefer to resolve a concern with you directly. However, you also have the right to complain to the UK's data protection regulator: