Our commitment to protecting your rights under the General Data Protection Regulation
The General Data Protection Regulation (GDPR) is a European Union regulation that came into force on 25 May 2018. The United Kingdom has retained equivalent legislation through the UK GDPR and the Data Protection Act 2018 following Brexit.
ETX Hosting is fully committed to GDPR compliance. This page explains our obligations as a data controller and data processor, your rights as a data subject, and how we handle personal data in accordance with the law.
We only collect data that is necessary for the purpose it is collected for.
Security and privacy are built into our services from the ground up.
We are clear about what data we collect and why.
We maintain records of our processing activities and are accountable for compliance.
ETX Hosting acts as the data controller for personal data collected from visitors to our website, registered account holders, and support contacts.
When you use ETX Hosting to host your own website or services that collect personal data from third parties, ETX Hosting acts as a data processor on your behalf. In this case, you are the data controller and are responsible for ensuring you have a lawful basis for processing your users' data.
As a data processor for your hosted services, we offer a Data Processing Agreement (DPA) that satisfies GDPR Article 28 requirements. The DPA covers:
To request a DPA, email [email protected].
We process personal data under one or more of the following lawful bases:
As a data subject under the UK GDPR / EU GDPR, you have the following rights:
You have the right to request a copy of the personal data we hold about you, along with information about how we use it.
If any of the personal data we hold about you is inaccurate or incomplete, you have the right to request correction.
You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you have withdrawn consent, or where we have no other lawful basis for processing.
You may request that we restrict how we process your data in certain circumstances, for example while a rectification request is being assessed.
Where processing is based on consent or contract, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit that data to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
ETX Hosting does not make solely automated decisions that have a significant legal or similarly significant effect on you.
To exercise any of your rights, submit a request to:
We will respond within 30 days of receiving your request. For complex or multiple requests, this may be extended by a further 2 months, in which case we will notify you.
We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests.
ETX Hosting primarily processes data within the UK and EEA. Where data is transferred to third countries, we ensure adequate safeguards are in place, including:
In the event of a personal data breach, ETX Hosting will:
If you believe your data has been compromised, please contact us immediately at [email protected].
ETX Hosting has appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with GDPR.
You can contact our DPO at:
ETX Hosting uses the following sub-processors to deliver our services. All sub-processors are bound by data processing agreements and GDPR-compliant safeguards:
We will notify customers of material changes to our sub-processor list with at least 30 days' notice.
We retain personal data only for as long as necessary. Our retention schedule:
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority:
We would, however, appreciate the opportunity to address your concerns directly first. Please contact our DPO at [email protected].