1. Introduction
Welcome to Astra Hosting Ltd (“Company”, “we”, “us”, or “our”). We deeply respect your privacy and are unconditionally committed to protecting your personal data. This Privacy Policy outlines comprehensively how we collect, use, process, transfer, and safeguard your information when you visit our website, communicate with us, purchase our web setup and technical implementation packages, or engage in our business-to-business (B2B) IT consultation services (collectively, the “Services”).
This policy is designed to comply with applicable global data protection laws, with a specific focus on the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By accessing our website or utilizing our Services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
For the purposes of the UK GDPR, Astra Hosting Ltd is the data controller and is responsible for your personal data. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our data compliance team using the details set out in Section 15 of this document.
3. The Data We Collect About You
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). To execute our technical setup concierge and consulting services effectively, we collect, use, store, and transfer different kinds of personal data about you, categorized as follows:
-
Identity Data: Includes your title, first name, last name, and company or business name.
-
Contact Data: Includes billing address, email address, and telephone numbers.
-
Technical Setup Data: Due to the unique nature of our concierge Services, this includes temporary administrative login credentials, usernames, passwords, API keys, and access tokens for third-party domain registrars, hosting panels, and Content Management Systems (CMS) required to fulfill your setup deliverables.
-
Financial Data: Includes billing information and payment records. Note: Astra Hosting Ltd does not store full credit card numbers or banking authentication details on our servers. All financial transactions are encrypted and processed securely by our PCI-compliant third-party fiat payment gateways.
-
Transaction Data: Includes details about upfront payments to and from you, invoices, and other specific details of the technical implementation and consulting services you have purchased from us.
-
Technical & Usage Data: Includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types, operating system, platform, and information about how you interact with our digital infrastructure.
-
Communication Data: Records of your correspondence with us via email, consulting calls, support tickets, or chat regarding your setups and post-handover technical inquiries.
4. How We Collect Your Data
We use different methods to collect data from and about you, including:
-
Direct Interactions: You provide us with your Identity, Contact, Financial, and Technical Setup Data by filling in onboarding forms, creating an account, or by corresponding with us via email, support channels, or during active corporate consultation calls.
-
Automated Technologies: As you interact with our website or configuration interfaces, we will automatically collect Technical & Usage Data about your equipment, browsing actions, and patterns using cookies, server logs, and similar technologies.
-
Third Parties: We may receive personal data about you from various third parties, such as analytics providers (e.g., Google) and our integrated, secure payment processing gateways (e.g., Stripe).
5. How We Use Your Personal Data & Legal Basis
We will only use your personal data when the law allows us to. Under the UK GDPR, we process your data based on the following legally defined grounds:
| Purpose/Activity | Data Category | Legal Basis for Processing |
| Service Execution: To configure third-party infrastructure on your behalf, install platforms (e.g., WordPress), schedule consultation calls, and deliver technical setups. | Identity, Contact, Technical Setup | Performance of a contract with you. |
| Billing & Corporate Administration: To process your upfront setup payments, manage secure transaction processing, and issue formal invoices. | Identity, Contact, Financial, Transaction | Performance of a contract; Necessary for our legitimate interests (debt recovery). |
| Customer Support: To provide the package-specific, post-handover technical email support included in your purchased tier. | Identity, Contact, Communication | Performance of a contract with you. |
| Security & System Maintenance: To ensure network security, prevent unauthorized access, mitigate fraud, and enforce our internal Acceptable Use Policy (AUP). | Identity, Technical & Usage | Necessary for our legitimate interests (protecting our digital infrastructure and business operations). |
| Regulatory Compliance: To comply with mandatory corporate, tax, or legal requirements. | Identity, Contact, Financial | Necessary to comply with a legal obligation. |
6. Disclosures of Your Personal Data
Astra Hosting Ltd strictly does not sell, rent, trade, or lease your personal data. We only disclose your information to specific, trusted third parties necessary to execute the Services, manage our business, and maintain legal compliance:
-
Infrastructure & Software Providers: We share necessary Identity and Contact Data with external domain registrars, third-party hosting networks, and Content Delivery Networks (CDNs) strictly to purchase, register, and license digital assets in your name as your authorized technical agent.
-
Payment Processors: Information required to facilitate secure fiat transaction processing, fraud prevention, and routine banking compliance checks.
-
Professional Advisors: Lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services to Astra Hosting Ltd.
-
Legal Authorities: Regulators, law enforcement, or legal counsel if required by law, court order, or to enforce our Terms of Use.
7. Handling of Sensitive Technical Credentials
Because our concierge setups involve taking temporary control of client digital assets, we enforce strict security protocols regarding your sensitive Technical Setup Data:
-
Temporary Retention: Administrative passwords, API keys, and access tokens are held securely in encrypted environments strictly for the duration of the technical installation process.
-
Internal Access Controls: Access to your temporary credentials is strictly limited to the specific engineer or technician assigned to your configuration project.
-
Mandatory 7-Day Purge: Upon the final technical handover of the project and notification of completion to the client, Astra Hosting Ltd systematically purges your access credentials from our active records within seven (7) days.
-
Client Security Mandate: It is the client’s sole responsibility to update and change all administrative passwords immediately upon project handover to ensure long-term isolated security.
8. International Data Transfers
Astra Hosting Ltd is registered in the United Kingdom, but we operate globally and utilize an international workforce. Consequently, your personal data may be transferred to, stored, and processed outside the United Kingdom or the European Economic Area (EEA)—including in regions where our operating teams are located.
Whenever we transfer your personal data internationally out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
-
We will only transfer your personal data to countries that have been officially deemed to provide an adequate level of protection for personal data.
-
Where we utilize global service providers or remote teams, we implement specific, legally binding contracts approved for use in the UK, such as the International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO).
9. Data Security & Breach Notification
We have implemented robust technical, administrative, and physical security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed. These measures include SSL/TLS encryption protocols for data in transit, encrypted storage layers, and strict internal access barriers.
Data Breaches: We have established rigid internal procedures to deal with any suspected personal data breach and will notify you and any applicable regulator (such as the UK Information Commissioner’s Office) of a breach where we are legally required to do so, typically within 72 hours of identification.
10. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
-
Corporate and Financial Auditing: By law, we must keep basic information about our customers (including Contact, Identity, Financial, and Transaction Data) for six (6) years after they cease being customers for corporate tax and financial auditing compliance.
-
Technical Setup Data: As detailed in Section 7, all sensitive access credentials and passwords are permanently deleted within seven (7) days of project completion.
-
Communication Logs: Support tickets, email correspondence, and consultation records are generally retained for three (3) years to facilitate ongoing service quality and potential contract reviews.
11. Cookies and Tracking Technologies
Our website utilizes cookies and similar tracking technologies to distinguish you from other users, optimize platform navigation, and analyze web traffic patterns.
-
Strictly Necessary Cookies: Required for the baseline operation of our website, including processing checkouts and secure billing interactions.
-
Analytical/Performance Cookies: Allow us to recognize and count website visitors to assess the performance of our digital infrastructure.
-
Managing Cookies: You can configure your internet browser to refuse all or some browser cookies, or to alert you when websites attempt to set or access them. If you disable cookies, please note that certain components of our website may become inaccessible or fail to function optimally.
12. Children’s Privacy
Our website and Services are intended strictly for adult business operators and established corporate entities. We do not knowingly collect, request, or maintain personal data from anyone under the age of 18. If we discover that a minor has provided us with personal information, we will immediately delete that data from our infrastructure.
13. Your Legal Data Protection Rights
Under UK data protection laws, you possess specific, clear rights in relation to your personal data, which include the right to:
-
Request Access: Receive a copy of the personal data we hold about you (commonly known as a “data subject access request”).
-
Request Correction: Request the rectification of any incomplete or inaccurate personal data we maintain.
-
Request Erasure: Request the deletion or removal of your personal data where there is no overriding legal or regulatory reason for us to continue processing it.
-
Object to Processing: Object to the processing of your personal data where we are relying on a legitimate interest, or where we are processing data for direct marketing purposes.
-
Request Restriction: Request the suspension of processing your personal data in specific legal scenarios.
-
Request Data Portability: Request the structured, machine-readable transfer of your automated personal data to you or a designated third party.
-
Withdraw Consent: Withdraw your consent at any time where we are explicitly relying on consent to process your data.
Response Timeframe: We aim to respond to all legitimate, verified requests within one calendar month. If a request is exceptionally complex or multiple requests are made, it may take longer; in such cases, we will formally notify you and keep you updated.
Right to Lodge a Complaint: You maintain the right to file a complaint at any time with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, welcome the opportunity to resolve your concerns directly before you approach the ICO, so please contact us in the first instance.
14. Changes to This Privacy Policy
We reserve the right to modify or update this Privacy Policy at any time to reflect adjustments in our corporate structure, technical operations, or international regulatory compliance mandates. Any updates will be published openly on this page with a revised “Last Updated” date at the top of the document.
15. Contact Details
If you have any questions about this Privacy Policy, our corporate data handling practices, or if you wish to formally exercise any of your legal rights, please contact our dedicated data compliance team:
-
Company Name: Astra Hosting Ltd
-
Email Address: contact@astra-hosting.com
-
Registered Corporate Postal Address: 128 City Road, London, United Kingdom