Skip to main content
HostingSeller
Shop plans

Data Security Statement

Revised August 19, 2026

Scope

The security page covers what defends hosted websites. Personal data sitting under those accounts is a different question: your own, whatever your customers hold, and whatever their customers handed over. Article 32 of the UK GDPR sets the measures expected.

1. Encryption

TLS carries all traffic here, the public site and the client area, with HTTP Strict Transport Security set, so no browser gets talked down to plain HTTP. Certificate renewal needs nobody's attention.

Passwords are salted and hashed, so support cannot read one back and neither can anyone else working here. Resetting is the only way in, which is why nobody from this company will ever ask you for yours. Card numbers never reach our systems at all: the payment provider keeps them, and what we hold is a token plus the last four digits.

2. Access control

Named individuals get access because a particular task requires it, and lose it once that need disappears. Administrative work sits behind two-factor authentication. Shared logins we avoid entirely: an unattributable action is an action nobody answers for.

Accounts, services and open tickets are what support can see. Nobody opens your files or reads database rows as a matter of routine; where a request cannot be answered without it, you know, and it goes no further.

3. Isolation between accounts

On a reseller platform this weighs heavier than almost anywhere. Accounts sharing the same hardware are isolated from each other, so a breach at one of your customers is not a breach at all of them. Platform software gets patched, malware scanning runs continuously, and a web application firewall with network-level mitigation sits in front of the whole arrangement.

Copies run every day and you can restore one yourself, without raising a ticket. A convenience, then, not a warranty: the service level agreement pays out only against availability, never against lost data.

4. Location and sub-processors

Hosting runs on infrastructure inside the United Kingdom. Personal data gets processed within the UK and the EEA, and any supplier working further afield falls under the safeguards set out in the privacy policy, which names every one. We check a supplier before taking it on, and the contract signed is no weaker than what we promise you.

5. Retention

Periods are in the privacy policy. The short version: account and billing records stay for as long as the account lives, plus the six years tax law demands; support tickets, three years; server logs, a matter of weeks.

Cancel, and your data leaves the live systems on schedule, then ages out of the backups behind them. We will not edit a backup to satisfy an erasure request, since cutting into one destroys its integrity. So it expires on its own, and the data stays unavailable throughout.

6. Breach notification

Where a personal data breach is likely to risk real people, we report it to the Information Commissioner's Office within 72 hours of us realising it happened, and wherever the risk runs high, affected individuals are told without undue delay.

Where the processing is done on your behalf, we tell you without undue delay, so that your own controller clock can still be met. Resell, and it also gives you room to get word to your customers in time.

7. Reporting a weakness

info@hosting-seller.com, before telling anybody else, and allow a fair window for the repair. That same contact also appears at /.well-known/security.txt. Keep testing to the account you pay for, leave anyone else's data alone, and no denial-of-service work at all. Stay inside those boundaries and the research is welcome; nobody will chase you for it.

8. What remains yours

None of it patches your extensions, picks your passwords, or strips the access of a contractor who has already moved elsewhere. On a reseller plan, it does none of those things for your customers either. Responsibility for that sits in the acceptable use policy and lie behind most of the compromises encountered here.

9. Contracting entity

Hosting Seller is a trading name of IGI Security Services Ltd, a company registered in England and Wales under Company No. 15881180. Registered office: 60 Tottenham Court Road, Suite 4944a, Fitzrovia, London, United Kingdom, W1T 2EW. Security contact: info@hosting-seller.com.