Skip to main content
HostingSeller
Shop plans

GDPR and Your Data Rights

Revised August 19, 2026

What this page is for

The privacy policy covers what is held and why. This page hands you the machinery for making us act on it, which is a matter of procedure rather than substance.

1. Who replies when a reseller stands in between

Two roles is what most hosting companies bother to describe. A good deal of what runs here has been resold, so in practice three positions exist, and which one you occupy changes the answer:

  • You buy from us, and the question concerns your own data. Account records, invoices, support tickets, registrant particulars. Controller is us, so we reply.
  • You buy from us and ask about data sitting in your site. Members, orders, whatever else you have collected. Controller is you, processor is us, and the data processing addendum governs it.
  • Your hosting came from a reseller instead. Your contract in that case runs with them rather than with us. Controller for your account data is the reseller, and we hold that data on their instruction. Send requests to whichever company invoiced you. We will point you in that direction and, where the reseller can be identified, let them know you have asked.

2. The rights

  • Access — a copy of whatever records exist about you.
  • Rectification — inaccuracies corrected.
  • Erasure — unless a stronger duty overrides it. Invoices raise that most often: six years is statutory, and statute beats a preference.
  • Restriction — processing put on hold while accuracy is disputed.
  • Portability — whatever you supplied, in machine-readable form, where consent or contract holds it.
  • Objection — against legitimate-interests processing. Where direct marketing is concerned it is absolute, with no balancing exercise.
  • Withdrawal of consent — at any moment, with no retrospective effect.

3. Filing

Email info@hosting-seller.com putting "Data request" in the subject line, or use the contact page. There is no form to fill in and no legal phrasing to get right. One plain sentence counts as a valid request, and we treat it as one. Say what you want, name the account or address it concerns, and narrow it down if you can.

4. Confirming identity

Handing account data to anyone who asks would itself be a breach. A request sent from the registered address usually settles matters; with closed accounts, or a request made on behalf of someone else, we ask for one more check and explain why. Identity documents come into it only when nothing lighter will serve, and are destroyed once checked.

5. Timing and cost

One calendar month, counted from the point identity is settled. Genuinely complex or repetitive requests can stretch that by two further months, and you hear the reason within the first month. Nothing to pay. The law does allow a charge for manifestly unfounded or excessive requests, though we would sooner explain how we reached that view than send you an invoice.

6. Refusals

Part of a request sometimes gets refused: erasure that would wipe records the law obliges us to keep, or access that would hand over a third party's data. When that happens you get the reason, the exemption we lean on, and the route to challenging it. We never simply go quiet.

7. Escalating

Start with the complaints procedure, or take it straight to the regulator, which costs you nothing and requires no permission from this end. For England and Wales that means the Information Commissioner's Office, which sits at ico.org.uk.

8. The controller

IGI Security Services Ltd, registered in England and Wales under Company No. 15881180, trading as Hosting Seller. Registered office: 60 Tottenham Court Road, Suite 4944a, Fitzrovia, London, United Kingdom, W1T 2EW. Requests to info@hosting-seller.com.