1. Who we are
Tudor Internet Ltd is a company registered in England and Wales. For data-protection
purposes, Tudor Internet Ltd is the controller for personal data used to manage our
website, Customer Portal, customer relationships, orders, billing, support, security,
communications and legal obligations.
- Company: Tudor Internet Ltd
- Company number: 08635676
- VAT number: GB214685994
- ICO registration number: ZC197476
- Privacy contact: privacy@tudornet.uk
2. Our controller and processor roles
The role Tudor Internet has under data-protection law depends on why and how personal
data is processed.
We normally act as a controller for customer-account, contact,
billing, payment, order, fraud-prevention, eligibility, support, complaint, marketing,
website-use and business-administration information because we determine why and how
that information is used.
Where we host, transmit, back up, monitor or otherwise process personal data contained
in a customer's website, mailbox, database, server, tenant or other service solely on
that customer's instructions, we may act as a processor. The customer
remains responsible for deciding the purpose of that processing, providing required
privacy information, identifying an appropriate lawful basis and responding to
individuals whose data they control.
A third-party cloud or online-service provider may act as a processor, subprocessor or
separate controller depending on the service and the provider's terms. Service-specific
data-protection terms may therefore also apply.
Contact privacy@tudornet.uk if you need help
identifying the role that applies to a particular Tudor Internet service.
3. Personal data we collect
We may collect and process personal data when you browse our website, register for
services, place an order, contact us, apply for a role, use the Customer Portal or
otherwise interact with Tudor Internet.
Personal data may include:
- name, company or organisation name, job title and contact details;
- billing address, service address, account details and customer identifiers;
- email address, telephone number and communication preferences;
- domain registration, registrant, ownership and technical-contact details;
- payment, invoice, transaction and tax information;
- support tickets, calls, messages, complaints, abuse reports and enquiries;
- IP addresses, browser and device information, login activity, system and service logs;
- fraud-prevention, payment-risk, identity, address and organisation-verification data;
- service configuration, domain, hostname, server, tenant, licence and subscription details;
- administrative-user, authorised-contact and licence-assignment information;
- website, mailbox, database, file, backup, message, monitoring and diagnostic data where required to deliver a selected service;
- records needed for security, misuse prevention, legal compliance and dispute resolution.
We do not intentionally collect special-category personal data unless it is necessary,
proportionate and lawful for a specific purpose, such as a reasonable-adjustment request
during recruitment.
4. How we collect personal data
We collect personal data directly when you:
- place an order, create an account or update account information;
- use the Customer Portal, website, checkout or support system;
- contact us by email, telephone, ticket, form or another communication channel;
- register, transfer, renew or manage a domain name;
- pay an invoice or update a payment method;
- use hosting, email, server, cloud, security, backup, monitoring or marketing services;
- apply for Charity Hosting or Non-Profit Hosting and provide eligibility information;
- apply for a role or other opportunity with Tudor Internet.
We may receive information from payment providers, fraud and identity-verification
services, domain registries and registrars, infrastructure providers, resellers,
upstream service providers, referees, public registers, law-enforcement bodies,
regulators and other persons involved in a transaction or service.
We also collect technical information automatically through website, portal, network
and service logs, security systems, cookies and similar technologies.
5. How we use personal data
We use personal data to:
- create and manage customer accounts and authorised users;
- process orders, eligibility checks, renewals, invoices, payments and refunds;
- register, transfer, renew and manage domain names;
- provision and administer hosting, servers, Microsoft 365, email, security, backup, monitoring and other online services;
- create tenants, subscriptions, licences, mailboxes and service configurations;
- respond to support tickets, calls, complaints, privacy requests and enquiries;
- diagnose faults, maintain services and investigate security incidents;
- prevent fraud, unauthorised access, payment misuse, spam and abuse;
- send renewal reminders, service notices and important account communications;
- meet legal, tax, accounting, registry, regulatory and law-enforcement obligations;
- protect customers, staff, suppliers, systems, services and networks;
- analyse and improve our website, systems, products and support;
- establish, exercise or defend legal claims.
6. Recruitment and job applications
When you apply for a role, work placement, contractor position or other opportunity, we
process information for recruitment and selection.
This may include contact details, CV, employment and education history, application
correspondence, interview and assessment notes, references, reasonable-adjustment
information and information required for proportionate pre-employment checks.
Further details are in our
Recruitment Privacy Notice.
7. Lawful basis for processing
Depending on the circumstances, we rely on:
- Contract: to take steps at your request or provide and manage services you have ordered.
- Legal obligation: to meet tax, accounting, domain, data-protection, abuse-handling, regulatory and other legal requirements.
- Legitimate interests: to operate, secure and improve our business and services, communicate with customers, prevent fraud and misuse, recover debts and protect legal rights.
- Consent: where we rely on consent for optional cookies, selected communications or another specific activity.
Where we act as a processor, the customer is responsible for identifying the lawful
basis for the personal data they instruct us to process.
8. Sharing personal data
We share personal data only where there is a valid reason, such as delivering a service,
processing payment, registering a domain, preventing fraud, maintaining security,
providing support or meeting a legal obligation.
Recipients may include payment providers, domain registries and registrars, certificate
authorities, hosting and network suppliers, cloud and software providers,
communications providers, fraud and identity-verification services, professional
advisers, insurers, auditors, regulators, courts and law-enforcement agencies.
If our business or assets are reorganised, sold or transferred, relevant personal data
may be disclosed to professional advisers and a prospective or actual purchaser,
subject to appropriate confidentiality and legal requirements.
We do not sell personal data.
9. Third-party providers
We use selected third-party providers to deliver, secure, administer and support our
services. The providers used for a customer depend on the products ordered, service
configuration, location and availability.
Providers and product names may change. The following table describes providers or
service categories that may be involved.
| Provider or service |
Purpose |
Examples of data involved |
| WHMCS and MarketConnect |
Customer Portal, ordering, invoicing, support, automation and third-party service provisioning. |
Account and contact details, orders, invoices, service identifiers, domains, support information and provisioning data. |
| Stripe |
Card, digital-wallet and eligible alternative payment processing; payment authentication; fraud prevention; and identity verification where used. |
Payment and billing details, contact information, transaction data, device information, authentication and identity-verification data. |
| PayPal |
PayPal payment processing where selected. |
Payment, billing, PayPal-account and transaction data. |
| OVHcloud and infrastructure suppliers |
Hosting, server, network, storage, security, backup and infrastructure delivery. |
Service data, hosted data, IP addresses, hostnames, server configuration, backups, technical and security logs. |
| Nominet |
Registry services for eligible .uk domain names. |
Registrant, contact, ownership, technical and domain-lifecycle information. |
| Netistrar and other registrars or registries |
Domain registration, transfer, renewal and management. |
Registrant and contact details, domain data, billing references and technical records. |
| Microsoft |
Microsoft 365 tenant, licence, cloud productivity, collaboration, security and support services. |
Customer and administrator details, tenant and domain information, user and licence identifiers, configuration, diagnostics, support records and content processed within Microsoft 365. |
| Open-Xchange / OX App Suite |
Email, collaboration and productivity services. |
Account, domain, mailbox and user details, credentials or tokens, service configuration, message and file data, logs and support information. |
| SpamExperts / email-security providers |
Incoming and outgoing email filtering, security and archiving where ordered. |
Domains, routing details, email addresses, message metadata and content, filtering decisions, quarantine and delivery logs. |
| SiteLock and website-security providers |
Website scanning, malware detection, vulnerability monitoring and remediation where ordered. |
Domain and website details, access credentials where supplied, scan results, website files, malware samples, logs and support data. |
| CodeGuard / Website Backup providers |
Website and database backup, change monitoring and restoration. |
Domain, website and database details, credentials, files, database copies, backup archives, logs and restore information. |
| NordVPN / Nord Security |
VPN subscription provisioning, account administration and support. |
Customer contact and account details, subscription identifiers, activation information, device or application data and support records as determined by the provider. |
| 360 Monitoring / monitoring providers |
Website, server, uptime and performance monitoring and alerting. |
Domains, URLs, server endpoints, IP addresses, performance metrics, availability history, diagnostics and alert-recipient details. |
| marketgoo / SEO Tools |
Search-engine-optimisation analysis, recommendations and reporting. |
Account and domain details, website data, search and performance information, reports, analytics and support data. |
| SocialBee |
Social-media management, scheduling, publishing and analytics where ordered. |
Account identifiers, connected social-account permissions or tokens, scheduled content, media, engagement analytics and support information. |
| SSL certificate authorities |
Certificate validation, issue, renewal and revocation. |
Domain, organisation, validation-contact, certificate-request and verification information. |
| Twilio |
SMS, telephone, authentication, service notifications and customer communications where used. |
Telephone numbers, call or message metadata, message content, recordings where expressly enabled, delivery and authentication logs. |
| hCaptcha / Intuition Machines, Inc. |
Protection of website and Customer Portal forms against bots, spam, fraud and automated abuse. |
IP address, browser and device data, network and security information, challenge responses and interaction information. |
| Google Maps Platform / Google Places |
Address search and autocomplete on selected forms. |
IP address, browser and device information, address-search text, selected address and technical usage data. |
| MaxMind |
Fraud prevention, risk scoring and order-security checks. |
IP address, billing and order details, location indicators, email and device signals and fraud-risk information. |
We may also use email-delivery providers, software vendors, security companies,
professional advisers, auditors, insurers and other service providers where necessary.
Where a provider handles personal data on our behalf, we take reasonable steps to use
appropriate contractual and security arrangements. Some providers also process
information under their own terms as separate controllers.
10. Customer content, cloud services and your responsibilities
Hosting, server, Microsoft 365, email, backup, monitoring and related services may
contain personal data about your customers, employees, members, users, suppliers or
other individuals.
You must only upload, collect, transmit, share or instruct us to process personal data
where you have authority and an appropriate lawful basis. You are responsible for your
own privacy notices, consent or other transparency requirements, retention rules,
access permissions and responses to individual rights requests.
You must not provide unnecessary special-category or criminal-offence data, identity
documents, payment-card data or confidential material through ordinary support tickets
or email. Use a secure route agreed with us where sensitive information is genuinely
required.
We and our providers may access customer content where reasonably necessary to
provision, maintain, secure, troubleshoot, restore, migrate or support a service; to
investigate abuse or fraud; to comply with law; or where you instruct or authorise us
to do so.
You are responsible for exporting required information before cancelling, transferring
or allowing a service to expire. Provider-specific retention and deletion periods may
apply after termination, and deleted data may not be recoverable.
11. Cookies and similar technologies
Our website and Customer Portal use cookies and similar technologies to operate the
site, support login and ordering, maintain security, remember choices and, with consent,
understand how the website is used.
Essential cookies
Essential cookies are required for functions such as sessions, login, shopping baskets,
payments, security, fraud prevention and consent storage. They cannot be switched off
through our cookie panel, although browser settings may block them and cause parts of
the website or portal not to work.
hCaptcha
We use hCaptcha on selected forms to distinguish genuine users from automated activity
and protect accounts, orders and systems. It may process IP address, browser, device,
network, challenge-response and interaction information and may use cookies or local
storage where required for security.
Optional cookies
Optional analytics, marketing or functional technologies are used only where enabled
and, where required, consented to. You can change optional-cookie choices at any time
through the Cookie Settings link in the footer.
| Cookie or technology |
Provider |
Purpose |
Duration |
Type |
| Website session cookies |
Tudor Internet |
Website sessions and core functions. |
Session or short-term |
Essential |
| Customer Portal / WHMCS cookies |
Tudor Internet / WHMCS |
Login, account access, support, ordering, basket and portal sessions. |
Session or short-term |
Essential |
| Consent preference |
Tudor Internet |
Stores your optional-cookie choices. |
Until removed or replaced |
Essential |
| Security and fraud-prevention technologies |
Tudor Internet / security providers |
Protects websites, forms, accounts, checkout and services. |
Varies by provider |
Essential / security |
| Stripe technologies |
Stripe |
Payment processing, authentication, transaction security, fraud prevention and identity verification where used. |
Varies by Stripe |
Essential where used |
| PayPal technologies |
PayPal |
Payment processing, authentication and security where selected. |
Varies by PayPal |
Essential where used |
| hCaptcha security technologies |
Intuition Machines, Inc. |
Bot, spam, fraud and abuse protection on selected forms. |
Session or as determined by hCaptcha |
Essential / security |
| Google Maps Platform address lookup |
Google |
Address-search and autocomplete suggestions on selected forms. |
Varies by Google |
Functional |
| Analytics cookies |
Tudor Internet / analytics providers |
Helps us understand and improve website use where consented to. |
Varies by provider |
Optional analytics |
| Marketing cookies |
Tudor Internet / marketing providers |
Advertising, remarketing or promotional measurement where enabled and consented to. |
Varies by provider |
Optional marketing |
Address autocomplete is optional. You can review or amend suggested information and
manual address entry remains available.
Browser settings can also view, delete or block cookies. Blocking essential cookies may
prevent login, ordering, payment or Customer Portal features from working.
12. Data security
We use technical and organisational measures designed to protect personal data against
unauthorised access, loss, misuse, alteration or disclosure. Measures may include
access controls, authentication, encryption where appropriate, monitoring, backups,
logging, staff procedures and supplier due diligence.
Customers are responsible for protecting their account, administrator and service
credentials, enabling multi-factor authentication where available, keeping authorised
contacts current and applying suitable security to their own users, devices, websites,
applications and data.
No system can be guaranteed completely secure, but we take reasonable steps to protect
the information we process and respond to suspected incidents.
13. Data retention and deletion
We keep personal data only for as long as necessary for the purpose for which it was
collected, including providing services, maintaining records, meeting legal obligations,
resolving disputes, preventing fraud and protecting legitimate interests.
Retention varies by record and service. Account, transaction, invoice and tax records
may be retained for the period required by accounting and tax law. Security, support,
complaint, verification and abuse records are kept for periods proportionate to the
relevant risk and legal requirements.
Service content is normally retained while the service is active. After cancellation,
expiry or termination, hosting, server, mailbox, tenant, backup and related data may be
deleted promptly or according to an upstream provider's deletion schedule. It may not
be possible to recover data after deletion.
Fraud, identity and eligibility information is retained only for as long as reasonably
necessary for verification, security, dispute, legal and regulatory purposes, taking
account of the sensitivity of the information.
Where legal proceedings, a complaint, fraud, abuse, debt, regulatory enquiry or security
incident is ongoing, relevant information may be kept until the matter and applicable
retention period have ended.
14. International transfers
Some providers, support teams, infrastructure or systems may process or permit access
to personal data outside the United Kingdom.
Where UK data-protection rules treat this as a restricted transfer, we take reasonable
steps to use an approved transfer mechanism or other permitted basis. Depending on the
destination and provider, this may include UK adequacy regulations, the UK International
Data Transfer Agreement, the UK Addendum to approved contractual clauses, binding
corporate rules or another lawful safeguard.
Contact privacy@tudornet.uk for further
information about safeguards relevant to a particular service.
15. Your rights
Depending on the circumstances, you may have the right to:
- request access to personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to delete personal data in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing in certain circumstances;
- receive certain information in a portable format where applicable;
- withdraw consent where processing is based on consent;
- ask for information about certain international-transfer safeguards;
- complain to a supervisory authority.
Rights are not absolute and may be limited where an exemption or competing legal
obligation applies. Where we act only as a processor for customer-controlled content,
we may direct the request to the relevant customer or assist them in responding.
Contact privacy@tudornet.uk to exercise a
right. We may need to verify your identity and clarify the scope of a request.
16. Complaints about data protection
Contact us first if you are unhappy with how we have handled personal data so we can
try to resolve the matter.
You also have the right to complain to the Information Commissioner's Office, the UK
supervisory authority for data protection.
ICO website:
ico.org.uk
17. Changes to this policy
We may update this Privacy Policy to reflect changes in services, suppliers, systems,
legal obligations or data-protection practices. The latest version and review date will
be published on this page.