Privacy Policy
What personal data we collect, why we collect it, and the choices you have.
Last updated October 8, 2026
1. Who we are and scope
Fonhost operates fonhost.com and the client area at billing.fonhost.com, and provides shared cPanel hosting, managed WordPress hosting and reseller hosting. We are the data controller for the personal data described here. Our registered office and registration details are published on this website. Contact support@fonhost.com with the subject line “Data protection request” for any privacy question, and abuse@fonhost.com for abuse or security reports. This policy covers our website, client area, support, billing and marketing. It does not cover the personal data you process inside the websites, databases and mailboxes you host with us: for that data you are the controller and we act only as your processor on your documented instructions, as explained on our GDPR and Data Processing page.
2. Personal data we collect
You give us: your name and company; email, phone and postal or billing address; your client area username, a hashed password and two-factor state; billing records and payment metadata such as the last four card digits, card brand, transaction reference and whether a payment succeeded; the domains and settings on your account; your support tickets and any attachments you send us; and your marketing preferences. Full card numbers, CVV codes and full bank details are entered on the payment processor’s own systems and are never transmitted to or stored on our servers.
We collect automatically: IP address, browser and device type, the pages you request, timestamps and results; login and failed-authentication events, firewall and abuse-detection output; and the resource, error and availability metrics we need to run and support the platform.
We receive from others: from payment processors and acquirers, the outcome of a transaction, a chargeback or a refund and the fraud signals returned with it; from fraud and sanctions screening services, risk scores and whether the details supplied matched; from registrars and registries, registration outcomes, verification status and the public WHOIS records for your domain; and from a partner who introduced you, the details needed to set up your account. We do not collect special category data, and our Services are not directed at children.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and administering your account, provisioning hosting, registering domains and delivering support | Performance of a contract |
| Taking payment, issuing invoices, handling refunds and chargebacks, and keeping accounting records | Performance of a contract; legal obligation |
| Preventing fraud, abuse, spam and attacks, and keeping the platform safe | Legitimate interests; legal obligation where a report must be made |
| Monitoring availability, capacity and performance and diagnosing faults | Legitimate interests |
| Service notices about maintenance, outages, renewals, price changes and legal terms | Contract; legal obligation; legitimate interests |
| Marketing and newsletters about our hosting services | Consent, or a soft opt-in where local law permits it for existing customers |
| Improving our website, products and support | Consent for optional analytics cookies; legitimate interests for aggregate measurement |
| Establishing or defending legal claims and answering lawful requests from authorities | Legal obligation; legitimate interests |
| Answering a sales enquiry you started | Steps taken at your request before a contract; legitimate interests |
Where we rely on legitimate interests we have balanced them against your rights, and you may ask us for that assessment. Where we rely on consent you may withdraw it at any time, without affecting processing already carried out.
4. Cookies
Essential cookies keep you logged in, protect forms against cross-site request forgery, remember your theme and cookie choice, and route requests to a healthy server. Optional analytics cookies, set only if you accept them, tell us which pages are read. You can accept, reject or change optional cookies at any time from the cookie preferences control or the banner, and blocking essential cookies will stop you logging in or completing an order. The full list, with names and lifetimes, is in our Cookie Policy.
5. Sharing and sub-processors
We never sell, rent or trade your personal data, and we do not share it with advertising networks or data brokers. We share it only with the providers we need to run the service: datacenter and infrastructure providers that host the servers and encrypted backup storage; payment processors and acquirers; domain registrars and registries, which receive the registrant data required to register and renew a domain and publish part of it in public WHOIS records as registry policy requires; email delivery providers that send account, invoice, security and marketing mail; support, helpdesk and monitoring tooling providers; fraud prevention and security services; our professional advisers; and authorities or rights holders where the law or a valid legal claim requires disclosure. Every processor is bound by a written contract to act only on our documented instructions, apply appropriate security measures, keep the data confidential, help us with data subject requests and breach notification, and delete or return the data when the engagement ends. Our current sub-processor list is on the GDPR and Data Processing page, and we notify customers before adding a new one. If we merge with or are acquired by another organisation, data may transfer to the successor under this policy.
6. International transfers
Our team, servers and providers may be in more than one country, so your data may be processed outside the country you live in. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland we rely on an appropriate safeguard: an adequacy decision for the destination country, or the approved standard contractual clauses or equivalent UK addendum with a transfer risk assessment and additional technical measures such as encryption in transit and at rest. You can request a copy of the safeguard by contacting support@fonhost.com. Where you choose a server location at checkout we store your Service data in that region, except for control, billing and backup copies held elsewhere under those safeguards.
7. Retention
| Category | Retention |
|---|---|
| Account, identity and contact records | While the Account is active, plus 24 months after closure |
| Invoices, payment and accounting records | The period required by the tax and accounting law that applies to us, typically 6 to 10 years |
| Support tickets and email | 36 months from closure of the ticket |
| Website, security and access logs | Up to 12 months; longer where abuse or fraud evidence is under investigation |
| Service and usage telemetry | Up to 13 months, aggregated where possible |
| Blocked or fraudulent order records | 24 months |
| Marketing consent and unsubscribe records | Until consent is withdrawn, plus 24 months |
Customer files, databases and mailboxes are kept while the Service is active and then deleted on the schedule in the Terms of Service, normally within 30 days of termination, with courtesy backups following their own cycle. Where a legal hold, dispute, abuse investigation or regulatory requirement applies we keep the relevant data until that matter closes, and then delete it.
8. Security
Our measures include encryption in transit (TLS 1.2 or better, with HSTS) for our website, client area, control panel and mail; encryption at rest for backups with separate credentials; salted one-way password hashing, so we can never read your password; role-based internal access on a least-privilege basis with no shared admin logins; mandatory multi-factor authentication for staff who can reach customer systems, and optional MFA for you; firewalling, rate limiting, brute-force and intrusion detection, malware scanning and a web application firewall; 24/7 monitoring with administrative actions logged; and a documented incident response procedure. No system is perfectly secure, so use a strong unique password, enable MFA, keep your own site, themes and plugins updated, and tell us immediately if you suspect a compromise.
9. Data breaches
If a personal data breach is likely to risk your rights, we will contain it, assess the risk, notify the relevant supervisory authority without undue delay and within 72 hours where the law requires it, and notify affected customers and individuals without undue delay where the risk is high, explaining what happened, what data was involved, what we have done and what you should do. We keep a record of every breach and our response. Where we act as your processor, we notify you without undue delay so you can meet your own obligations.
10. Your rights
Depending on where you live you have the right to access your data and information about how we use it; to rectify inaccurate or incomplete data; to erasure, which is not absolute because we must keep records the law requires, such as invoices; to restrict processing while a question is resolved; to portability of the data you gave us in a structured, machine-readable format; to object to processing based on legitimate interests and at any time to direct marketing; to withdraw consent as easily as you gave it; and to complain to the supervisory authority in the country where you live, work or where the alleged breach occurred. To exercise a right, open a ticket or email support@fonhost.com with the subject line “Data protection request”. We may ask you to confirm your identity, usually by replying from the address on your Account, so we never disclose data to the wrong person. There is no fee for a normal request, and we respond within one month, extended by up to two further months for a complex or repeated request, telling you why within the first month. You can also correct your details, change your marketing preferences and close your Account directly in the client area.
11. Marketing and automated decisions
Service messages (invoices, renewal reminders, maintenance and security notices, and replies to your tickets) are part of running your Account and cannot be opted out of while you hold one. Marketing email is separate: unsubscribe from the link in every message or from your client area preferences, and we will act promptly and within the period the law allows. We do not use automated decision-making or profiling to make decisions with legal or similarly significant effects: no automated process terminates your Service, refuses you service permanently or sets your price. We do use automated tools to score new orders and payment attempts for fraud, to scan mail and files for spam and malware, to rate-limit automated traffic, and to segment customers on aggregate data only. A human reviews any flag before significant action is taken, and you may ask us to explain or reconsider a decision at support@fonhost.com.
12. Children
Our Services are for adults and businesses and are not intended for anyone under 18. We do not knowingly collect personal data from children; if you believe a child has given us data, contact support@fonhost.com and we will delete it promptly. If you host a website aimed at children, you are the controller of the data it collects and are responsible for any parental consent and age verification the law requires.
13. Changes and contact
We may update this policy to reflect changes in our Services, providers, security practices or the law. The current version is always published here with an effective date, and where a change materially affects how we use your data or your rights we give reasonable advance notice by email and in the client area. If we intend to use your data for a new purpose that needs consent, we ask for it first. For any privacy question or request use support@fonhost.com (subject line “Data protection request”), or a billing ticket from the client area; abuse and security incidents go to abuse@fonhost.com; sales questions to sales@fonhost.com; and postal enquiries to the registered office address published on this website. If you are not satisfied with our response you may complain to the supervisory authority in the country where you live, work, or where the alleged breach took place.