๐ Overview
KloHost ("we," "us," or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
Please read this policy carefully. If you disagree with its terms, please discontinue use of our site and services. This policy applies to all information collected through our website at klohost.io, our client portal, and any related services, sales, marketing, or events.
Key Principles
- Transparency: We tell you exactly what data we collect and why.
- Minimisation: We only collect data that is necessary for the stated purpose.
- Security: We use industry-standard encryption and security practices.
- Control: You can access, correct, or delete your data at any time.
- No selling: We never sell your personal data to advertisers or data brokers.
๐ Data We Collect
We collect information you provide directly to us, information collected automatically when you use our services, and information from third-party sources.
Information You Provide
| Data Type | Examples | When Collected |
|---|---|---|
| Account Information | Name, email address, password (hashed) | Account registration |
| Billing Information | Credit card details (tokenised), billing address | Purchase checkout |
| Domain WHOIS Data | Registrant name, address, phone, email | Domain registration |
| Support Communications | Ticket messages, chat transcripts, emails | Support interactions |
| Profile Information | Company name, website URL, preferences | Account settings |
Information Collected Automatically
| Data Type | Examples | Purpose |
|---|---|---|
| Log Data | IP address, browser type, pages visited, timestamps | Security & analytics |
| Device Information | Operating system, screen resolution, device type | Optimise user experience |
| Cookies & Tracking | Session cookies, preference cookies, analytics IDs | Functionality & analytics |
| Usage Data | Features used, clicks, time on page | Product improvement |
๐ How We Use Your Data
We use the information we collect for the following purposes, each grounded in a lawful basis under applicable data protection law:
- Service Delivery: To register domains, provision hosting accounts, issue SSL certificates, and fulfil all purchased services.
- Account Management: To create and manage your client account, authenticate logins, and maintain your service history.
- Billing & Payments: To process transactions, issue invoices, handle renewals, and manage refunds.
- Customer Support: To respond to your enquiries, resolve technical issues, and provide assistance via ticket, chat, or email.
- Service Communications: To send essential notifications such as renewal reminders, downtime alerts, and security notices.
- Marketing (with consent): To send promotional emails, newsletters, and special offers โ only if you have opted in.
- Legal Compliance: To comply with ICANN domain registration requirements, tax obligations, and applicable laws.
- Fraud Prevention: To detect, investigate, and prevent fraudulent transactions and abuse of our services.
- Product Improvement: To analyse usage patterns and improve our website, products, and customer experience.
๐ค Data Sharing & Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your data only in the following limited circumstances:
Service Providers
We share data with trusted third-party vendors who assist us in operating our business. These providers are contractually bound to protect your data and may only use it to perform services on our behalf:
- Payment Processors: Stripe, PayPal โ for secure payment handling
- Domain Registrars: Enom, ResellerClub, Namecheap โ for domain registration and WHOIS data
- Cloud Infrastructure: AWS, Cloudflare โ for hosting, CDN, and DDoS protection
- Analytics: Google Analytics (anonymised), Plausible โ for website analytics
- Email Services: Mailgun โ for transactional email delivery
- Support Platform: WHMCS โ for billing and ticket management
Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency), or to protect the rights, property, or safety of KloHost, our customers, or others.
WHOIS & ICANN Requirements
Domain registration data is subject to ICANN's policies. Registrant contact information may be published in the public WHOIS database unless you enable WHOIS Privacy Protection (available free on all eligible domains). We strongly recommend enabling this feature during checkout.
Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website prior to your data being transferred.
๐ช Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our website. Here's a breakdown of the types we use:
| Cookie Type | Purpose | Duration | Can Opt Out? |
|---|---|---|---|
| Essential | Login sessions, shopping cart, security tokens | Session / 30 days | No โ required for service |
| Functional | Language preference, UI settings, remembered choices | 1 year | Yes |
| Analytics | Page views, traffic sources, user behaviour (anonymised) | 2 years | Yes |
| Marketing | Retargeting ads, conversion tracking | 90 days | Yes |
You can manage your cookie preferences at any time through your browser settings or our cookie consent banner. Note that disabling essential cookies may affect the functionality of our services.
๐๏ธ Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & profile data | Duration of account + 3 years | Service continuity, legal disputes |
| Billing & transaction records | 7 years | Tax and accounting obligations |
| Support tickets & communications | 3 years after resolution | Quality assurance, dispute resolution |
| Server & access logs | 90 days | Security monitoring |
| Marketing preferences | Until opt-out + 1 year | Compliance with opt-out requests |
| Deleted account data | 30 days after deletion request | Accidental deletion recovery |
When data is no longer required, we securely delete or anonymise it in accordance with our data destruction procedures.
โ๏ธ Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data. We honour all valid requests within 30 days.
Rights Under GDPR (EU/UK Residents)
- Right of Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements.
- Right to Restriction: Request that we limit how we process your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
Rights Under CCPA (California Residents)
- Right to Know: Know what personal information we collect, use, disclose, and sell.
- Right to Delete: Request deletion of personal information we have collected.
- Right to Opt-Out: Opt out of the sale of personal information (we do not sell data).
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights.
๐ก๏ธ Security Measures
We implement appropriate technical and organisational security measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction.
Technical Safeguards
- โ TLS 1.3 encryption for all data in transit
- โ AES-256 encryption for sensitive data at rest
- โ Bcrypt hashing for all stored passwords
- โ Two-factor authentication (2FA) available for all accounts
- โ Regular third-party security audits and penetration testing
- โ DDoS protection via Cloudflare
- โ Automated vulnerability scanning and patching
- โ PCI-DSS compliant payment processing
Organisational Safeguards
- โ Role-based access controls โ staff only access data they need
- โ All staff complete annual data protection training
- โ Data processing agreements with all third-party vendors
- โ Incident response plan with 72-hour breach notification
๐ถ Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@klohost.io.
If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to remove that information from our servers promptly.
๐ International Data Transfers
KloHost operates globally and your data may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your own.
When we transfer personal data from the European Economic Area (EEA) or United Kingdom to countries outside these regions, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where the destination country has been deemed to provide adequate protection
- Binding Corporate Rules for intra-group transfers
- Data Processing Agreements with all international sub-processors
Our primary data centres are located in the United States and the European Union. You may request information about the specific safeguards in place for your data by contacting our Data Protection Officer.
๐ Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Send an email notification to all registered account holders
- Display a prominent notice on our website for 30 days
- For significant changes, request renewed consent where required by law
We encourage you to review this policy periodically. Your continued use of our services after any changes constitutes your acceptance of the updated policy.
Previous Versions
Previous versions of this Privacy Policy are available upon request. Contact us at privacy@klohost.io to request a copy of a prior version.
๐ฌ Contact Our Privacy Team
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us. We are committed to resolving any privacy concerns promptly and transparently.
Data Protection Officer
KloHost Ltd. ยท 123 Server Street, Tech City, TC1 2AB, United Kingdom
Email: privacy@klohost.io ยท Phone: +44 (0) 20 1234 5678
Response time: within 30 days of receipt of your request.