Skip to content
UK web hosting, domain names, email, website security and online services.

What this policy covers

How Tudor Internet handles personal data

This policy applies to personal data collected through our website, Customer Portal, services, billing, support, recruitment, domain registration, verification and security processes. It explains what we collect, why we use it, who we may share it with, how long we keep it and the rights available to individuals.

1. Who we are

Tudor Internet Ltd is a company registered in England and Wales. For data-protection purposes, Tudor Internet Ltd is the controller for personal data used to manage our website, Customer Portal, customer relationships, orders, billing, support, security, communications and legal obligations.

  • Company: Tudor Internet Ltd
  • Company number: 08635676
  • VAT number: GB214685994
  • ICO registration number: ZC197476
  • Privacy contact: privacy@tudornet.uk

2. Our controller and processor roles

The role Tudor Internet has under data-protection law depends on why and how personal data is processed.

We normally act as a controller for customer-account, contact, billing, payment, order, fraud-prevention, eligibility, support, complaint, marketing, website-use and business-administration information because we determine why and how that information is used.

Where we host, transmit, back up, monitor or otherwise process personal data contained in a customer's website, mailbox, database, server, tenant or other service solely on that customer's instructions, we may act as a processor. The customer remains responsible for deciding the purpose of that processing, providing required privacy information, identifying an appropriate lawful basis and responding to individuals whose data they control.

A third-party cloud or online-service provider may act as a processor, subprocessor or separate controller depending on the service and the provider's terms. Service-specific data-protection terms may therefore also apply.

Contact privacy@tudornet.uk if you need help identifying the role that applies to a particular Tudor Internet service.

3. Personal data we collect

We may collect and process personal data when you browse our website, register for services, place an order, contact us, apply for a role, use the Customer Portal or otherwise interact with Tudor Internet.

Personal data may include:

  • name, company or organisation name, job title and contact details;
  • billing address, service address, account details and customer identifiers;
  • email address, telephone number and communication preferences;
  • domain registration, registrant, ownership and technical-contact details;
  • payment, invoice, transaction and tax information;
  • support tickets, calls, messages, complaints, abuse reports and enquiries;
  • IP addresses, browser and device information, login activity, system and service logs;
  • fraud-prevention, payment-risk, identity, address and organisation-verification data;
  • service configuration, domain, hostname, server, tenant, licence and subscription details;
  • administrative-user, authorised-contact and licence-assignment information;
  • website, mailbox, database, file, backup, message, monitoring and diagnostic data where required to deliver a selected service;
  • records needed for security, misuse prevention, legal compliance and dispute resolution.

We do not intentionally collect special-category personal data unless it is necessary, proportionate and lawful for a specific purpose, such as a reasonable-adjustment request during recruitment.

4. How we collect personal data

We collect personal data directly when you:

  • place an order, create an account or update account information;
  • use the Customer Portal, website, checkout or support system;
  • contact us by email, telephone, ticket, form or another communication channel;
  • register, transfer, renew or manage a domain name;
  • pay an invoice or update a payment method;
  • use hosting, email, server, cloud, security, backup, monitoring or marketing services;
  • apply for Charity Hosting or Non-Profit Hosting and provide eligibility information;
  • apply for a role or other opportunity with Tudor Internet.

We may receive information from payment providers, fraud and identity-verification services, domain registries and registrars, infrastructure providers, resellers, upstream service providers, referees, public registers, law-enforcement bodies, regulators and other persons involved in a transaction or service.

We also collect technical information automatically through website, portal, network and service logs, security systems, cookies and similar technologies.

5. How we use personal data

We use personal data to:

  • create and manage customer accounts and authorised users;
  • process orders, eligibility checks, renewals, invoices, payments and refunds;
  • register, transfer, renew and manage domain names;
  • provision and administer hosting, servers, Microsoft 365, email, security, backup, monitoring and other online services;
  • create tenants, subscriptions, licences, mailboxes and service configurations;
  • respond to support tickets, calls, complaints, privacy requests and enquiries;
  • diagnose faults, maintain services and investigate security incidents;
  • prevent fraud, unauthorised access, payment misuse, spam and abuse;
  • send renewal reminders, service notices and important account communications;
  • meet legal, tax, accounting, registry, regulatory and law-enforcement obligations;
  • protect customers, staff, suppliers, systems, services and networks;
  • analyse and improve our website, systems, products and support;
  • establish, exercise or defend legal claims.

6. Recruitment and job applications

When you apply for a role, work placement, contractor position or other opportunity, we process information for recruitment and selection.

This may include contact details, CV, employment and education history, application correspondence, interview and assessment notes, references, reasonable-adjustment information and information required for proportionate pre-employment checks.

Further details are in our Recruitment Privacy Notice.

7. Lawful basis for processing

Depending on the circumstances, we rely on:

  • Contract: to take steps at your request or provide and manage services you have ordered.
  • Legal obligation: to meet tax, accounting, domain, data-protection, abuse-handling, regulatory and other legal requirements.
  • Legitimate interests: to operate, secure and improve our business and services, communicate with customers, prevent fraud and misuse, recover debts and protect legal rights.
  • Consent: where we rely on consent for optional cookies, selected communications or another specific activity.

Where we act as a processor, the customer is responsible for identifying the lawful basis for the personal data they instruct us to process.

8. Sharing personal data

We share personal data only where there is a valid reason, such as delivering a service, processing payment, registering a domain, preventing fraud, maintaining security, providing support or meeting a legal obligation.

Recipients may include payment providers, domain registries and registrars, certificate authorities, hosting and network suppliers, cloud and software providers, communications providers, fraud and identity-verification services, professional advisers, insurers, auditors, regulators, courts and law-enforcement agencies.

If our business or assets are reorganised, sold or transferred, relevant personal data may be disclosed to professional advisers and a prospective or actual purchaser, subject to appropriate confidentiality and legal requirements.

We do not sell personal data.

9. Third-party providers

We use selected third-party providers to deliver, secure, administer and support our services. The providers used for a customer depend on the products ordered, service configuration, location and availability.

Providers and product names may change. The following table describes providers or service categories that may be involved.

Provider or service Purpose Examples of data involved
WHMCS and MarketConnect Customer Portal, ordering, invoicing, support, automation and third-party service provisioning. Account and contact details, orders, invoices, service identifiers, domains, support information and provisioning data.
Stripe Card, digital-wallet and eligible alternative payment processing; payment authentication; fraud prevention; and identity verification where used. Payment and billing details, contact information, transaction data, device information, authentication and identity-verification data.
PayPal PayPal payment processing where selected. Payment, billing, PayPal-account and transaction data.
OVHcloud and infrastructure suppliers Hosting, server, network, storage, security, backup and infrastructure delivery. Service data, hosted data, IP addresses, hostnames, server configuration, backups, technical and security logs.
Nominet Registry services for eligible .uk domain names. Registrant, contact, ownership, technical and domain-lifecycle information.
Netistrar and other registrars or registries Domain registration, transfer, renewal and management. Registrant and contact details, domain data, billing references and technical records.
Microsoft Microsoft 365 tenant, licence, cloud productivity, collaboration, security and support services. Customer and administrator details, tenant and domain information, user and licence identifiers, configuration, diagnostics, support records and content processed within Microsoft 365.
Open-Xchange / OX App Suite Email, collaboration and productivity services. Account, domain, mailbox and user details, credentials or tokens, service configuration, message and file data, logs and support information.
SpamExperts / email-security providers Incoming and outgoing email filtering, security and archiving where ordered. Domains, routing details, email addresses, message metadata and content, filtering decisions, quarantine and delivery logs.
SiteLock and website-security providers Website scanning, malware detection, vulnerability monitoring and remediation where ordered. Domain and website details, access credentials where supplied, scan results, website files, malware samples, logs and support data.
CodeGuard / Website Backup providers Website and database backup, change monitoring and restoration. Domain, website and database details, credentials, files, database copies, backup archives, logs and restore information.
NordVPN / Nord Security VPN subscription provisioning, account administration and support. Customer contact and account details, subscription identifiers, activation information, device or application data and support records as determined by the provider.
360 Monitoring / monitoring providers Website, server, uptime and performance monitoring and alerting. Domains, URLs, server endpoints, IP addresses, performance metrics, availability history, diagnostics and alert-recipient details.
marketgoo / SEO Tools Search-engine-optimisation analysis, recommendations and reporting. Account and domain details, website data, search and performance information, reports, analytics and support data.
SocialBee Social-media management, scheduling, publishing and analytics where ordered. Account identifiers, connected social-account permissions or tokens, scheduled content, media, engagement analytics and support information.
SSL certificate authorities Certificate validation, issue, renewal and revocation. Domain, organisation, validation-contact, certificate-request and verification information.
Twilio SMS, telephone, authentication, service notifications and customer communications where used. Telephone numbers, call or message metadata, message content, recordings where expressly enabled, delivery and authentication logs.
hCaptcha / Intuition Machines, Inc. Protection of website and Customer Portal forms against bots, spam, fraud and automated abuse. IP address, browser and device data, network and security information, challenge responses and interaction information.
Google Maps Platform / Google Places Address search and autocomplete on selected forms. IP address, browser and device information, address-search text, selected address and technical usage data.
MaxMind Fraud prevention, risk scoring and order-security checks. IP address, billing and order details, location indicators, email and device signals and fraud-risk information.

We may also use email-delivery providers, software vendors, security companies, professional advisers, auditors, insurers and other service providers where necessary.

Where a provider handles personal data on our behalf, we take reasonable steps to use appropriate contractual and security arrangements. Some providers also process information under their own terms as separate controllers.

10. Customer content, cloud services and your responsibilities

Hosting, server, Microsoft 365, email, backup, monitoring and related services may contain personal data about your customers, employees, members, users, suppliers or other individuals.

You must only upload, collect, transmit, share or instruct us to process personal data where you have authority and an appropriate lawful basis. You are responsible for your own privacy notices, consent or other transparency requirements, retention rules, access permissions and responses to individual rights requests.

You must not provide unnecessary special-category or criminal-offence data, identity documents, payment-card data or confidential material through ordinary support tickets or email. Use a secure route agreed with us where sensitive information is genuinely required.

We and our providers may access customer content where reasonably necessary to provision, maintain, secure, troubleshoot, restore, migrate or support a service; to investigate abuse or fraud; to comply with law; or where you instruct or authorise us to do so.

You are responsible for exporting required information before cancelling, transferring or allowing a service to expire. Provider-specific retention and deletion periods may apply after termination, and deleted data may not be recoverable.

11. Cookies and similar technologies

Our website and Customer Portal use cookies and similar technologies to operate the site, support login and ordering, maintain security, remember choices and, with consent, understand how the website is used.

Essential cookies

Essential cookies are required for functions such as sessions, login, shopping baskets, payments, security, fraud prevention and consent storage. They cannot be switched off through our cookie panel, although browser settings may block them and cause parts of the website or portal not to work.

hCaptcha

We use hCaptcha on selected forms to distinguish genuine users from automated activity and protect accounts, orders and systems. It may process IP address, browser, device, network, challenge-response and interaction information and may use cookies or local storage where required for security.

Optional cookies

Optional analytics, marketing or functional technologies are used only where enabled and, where required, consented to. You can change optional-cookie choices at any time through the Cookie Settings link in the footer.

Cookie or technology Provider Purpose Duration Type
Website session cookies Tudor Internet Website sessions and core functions. Session or short-term Essential
Customer Portal / WHMCS cookies Tudor Internet / WHMCS Login, account access, support, ordering, basket and portal sessions. Session or short-term Essential
Consent preference Tudor Internet Stores your optional-cookie choices. Until removed or replaced Essential
Security and fraud-prevention technologies Tudor Internet / security providers Protects websites, forms, accounts, checkout and services. Varies by provider Essential / security
Stripe technologies Stripe Payment processing, authentication, transaction security, fraud prevention and identity verification where used. Varies by Stripe Essential where used
PayPal technologies PayPal Payment processing, authentication and security where selected. Varies by PayPal Essential where used
hCaptcha security technologies Intuition Machines, Inc. Bot, spam, fraud and abuse protection on selected forms. Session or as determined by hCaptcha Essential / security
Google Maps Platform address lookup Google Address-search and autocomplete suggestions on selected forms. Varies by Google Functional
Analytics cookies Tudor Internet / analytics providers Helps us understand and improve website use where consented to. Varies by provider Optional analytics
Marketing cookies Tudor Internet / marketing providers Advertising, remarketing or promotional measurement where enabled and consented to. Varies by provider Optional marketing

Address autocomplete is optional. You can review or amend suggested information and manual address entry remains available.

Browser settings can also view, delete or block cookies. Blocking essential cookies may prevent login, ordering, payment or Customer Portal features from working.

12. Data security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures may include access controls, authentication, encryption where appropriate, monitoring, backups, logging, staff procedures and supplier due diligence.

Customers are responsible for protecting their account, administrator and service credentials, enabling multi-factor authentication where available, keeping authorised contacts current and applying suitable security to their own users, devices, websites, applications and data.

No system can be guaranteed completely secure, but we take reasonable steps to protect the information we process and respond to suspected incidents.

13. Data retention and deletion

We keep personal data only for as long as necessary for the purpose for which it was collected, including providing services, maintaining records, meeting legal obligations, resolving disputes, preventing fraud and protecting legitimate interests.

Retention varies by record and service. Account, transaction, invoice and tax records may be retained for the period required by accounting and tax law. Security, support, complaint, verification and abuse records are kept for periods proportionate to the relevant risk and legal requirements.

Service content is normally retained while the service is active. After cancellation, expiry or termination, hosting, server, mailbox, tenant, backup and related data may be deleted promptly or according to an upstream provider's deletion schedule. It may not be possible to recover data after deletion.

Fraud, identity and eligibility information is retained only for as long as reasonably necessary for verification, security, dispute, legal and regulatory purposes, taking account of the sensitivity of the information.

Where legal proceedings, a complaint, fraud, abuse, debt, regulatory enquiry or security incident is ongoing, relevant information may be kept until the matter and applicable retention period have ended.

14. International transfers

Some providers, support teams, infrastructure or systems may process or permit access to personal data outside the United Kingdom.

Where UK data-protection rules treat this as a restricted transfer, we take reasonable steps to use an approved transfer mechanism or other permitted basis. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, binding corporate rules or another lawful safeguard.

Contact privacy@tudornet.uk for further information about safeguards relevant to a particular service.

15. Your rights

Depending on the circumstances, you may have the right to:

  • request access to personal data we hold about you;
  • ask us to correct inaccurate or incomplete data;
  • ask us to delete personal data in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • object to processing in certain circumstances;
  • receive certain information in a portable format where applicable;
  • withdraw consent where processing is based on consent;
  • ask for information about certain international-transfer safeguards;
  • complain to a supervisory authority.

Rights are not absolute and may be limited where an exemption or competing legal obligation applies. Where we act only as a processor for customer-controlled content, we may direct the request to the relevant customer or assist them in responding.

Contact privacy@tudornet.uk to exercise a right. We may need to verify your identity and clarify the scope of a request.

16. Complaints about data protection

Contact us first if you are unhappy with how we have handled personal data so we can try to resolve the matter.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection.

ICO website: ico.org.uk

17. Changes to this policy

We may update this Privacy Policy to reflect changes in services, suppliers, systems, legal obligations or data-protection practices. The latest version and review date will be published on this page.

Questions about privacy?

Contact Tudor Internet

Contact us if you have a question about this policy or want to make a data-rights request.