Last updated: 1 January 2026
Template notice. This is a structured placeholder for a demonstration build. Have it reviewed by a qualified privacy practitioner before publishing on a live commercial site.
1. Who we are
Survival Hosting Ltd is the data controller for personal data described here. Contact [email protected] with any question or request.
2. What we collect
You give us: name, email address, billing address, and the contents of tickets and contact forms. Card details go directly to our payment processor — we never see or store a full card number.
Collected automatically: IP address, browser and device information, pages viewed, and server access and error logs.
From your service: the address and port of your instance, resource usage metrics, and panel action logs (who restarted what, and when).
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing and provisioning the service | Contract |
| Billing, invoicing and tax records | Contract and legal obligation |
| Support and incident response | Contract |
| Fraud prevention, abuse handling and security | Legitimate interests |
| Service notices and outage notifications | Legitimate interests |
| Marketing email | Consent — withdrawable at any time |
4. Cookies
We use cookies that are strictly necessary for sessions, security and cart state. We do not run advertising or cross-site tracking cookies. Optional analytics cookies are set only where you consent.
5. Sharing
We share data only with processors acting on our instructions:
- Payment processing — Stripe and PayPal
- Billing platform — WHMCS
- Infrastructure — our datacentre partners in the region you select
- Email delivery — our transactional email provider
We do not sell personal data. We disclose data to authorities only where legally required.
6. International transfers
Data is processed in the region you choose plus our EU management systems. Transfers outside the UK/EEA rely on the UK IDTA or EU Standard Contractual Clauses.
7. Retention
- Account and billing records: 7 years after closure (tax law)
- Support tickets: 3 years after resolution
- Server access and security logs: 90 days
- Server content and backups: deleted 14 days after termination
- Marketing consent records: until withdrawn, plus 2 years
8. Your rights
Under UK and EU data protection law you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Email [email protected]; we respond within one month. You may also complain to the UK Information Commissioner's Office or your local supervisory authority.
9. Security
Encryption in transit (TLS 1.3), encryption at rest for backups, role-based internal access with mandatory MFA, and least-privilege access reviewed quarterly. Personal data breaches affecting you are reported to the relevant authority within 72 hours and to you without undue delay where the risk is high.
10. Children
Services are not directed at children under 16. We delete data collected from a child under 16 without appropriate consent as soon as we become aware of it.