Privacy Policy

Privacy Policy of Yhost Hosting provider

Controller: Apefo Ltd trading as Yhost
Company number: 16610465  |  Address: 24-26 Regent Place, City Centre, Birmingham, United Kingdom, B1 3NJ
Privacy contact: [email protected]  |  General: [email protected]
Effective date: 17.03.2026  |  Version: 3.0

This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, create an account, purchase Services, or communicate with us. It also clarifies the roles and responsibilities where we process personal data in Customer Content as a hosting provider.

This policy applies alongside the Terms of Service, the Data Processing Addendum (DPA), and the Cookie Policy. Capitalized terms not defined here have the meanings given in the Terms of Service.

1. Scope and Roles

1.1 When we act as controller

We act as a "controller" (UK GDPR / EU GDPR) or "business" (CCPA/CPRA) for personal data we collect and use to operate our business, including account registration data, billing and payment data, support communications, security logs, and marketing preferences. This Privacy Policy applies to that processing.

1.2 When we act as processor

For personal data contained in Customer Content hosted on the Services (for example, your website database containing end‑user records), we typically act as a "processor" (UK GDPR / EU GDPR) or "service provider" (CCPA/CPRA) on behalf of the Customer. In this context, the Customer determines what data is collected and the purposes of processing. Our processing is limited to providing the hosting infrastructure and support and complying with legal obligations. The Data Processing Addendum (DPA) governs this processing.

1.3 Applicability

This policy applies to individuals who visit our website, create an Account, purchase or use our Services, or communicate with us. It does not apply to data that we process solely as a processor on behalf of Customers — for that, please refer to the relevant Customer's privacy policy.

2. Data We Collect

2.1 Data you provide directly

  • Account data: name, company name (if applicable), username, password (stored as a cryptographic hash — we cannot see your plaintext password), contact email, phone number, postal address, country.
  • Verification data (KYC): where needed for fraud prevention or legal compliance, copies of identification documents, proof of address, or business registration information. We minimize retention and may use third‑party verification services.
  • Billing data: invoices, subscription details, tax IDs (VAT/GST), and transaction references. Payment card details are processed directly by our payment processor(s) and are not stored on our servers.
  • Support data: ticket content, attachments you provide, chat transcripts, and call notes where applicable.
  • Marketing preferences: your opt‑in or opt‑out choices for marketing communications.

2.2 Data collected automatically

  • Device and log data: IP address, timestamps, user agent, referrer URL, and basic request data when you access our website or client portal.
  • Audit log data: all actions you perform in the client portal are recorded in an audit log (see Section 6).
  • Security logs: authentication events (login, logout, 2FA), suspicious activity indicators, and firewall/WAF events needed for security and fraud prevention.
  • Cookies and similar technologies: used for essential functions and, where you consent, analytics. See our Cookie Policy for details.

2.3 Data from third parties

  • Payment processors: transaction confirmation, payment status, and fraud signals from our payment processor(s).
  • Abuse and security feeds: IP reputation data, abuse reports from third parties (e.g., CERT teams, rights holders).
  • Domain registries: WHOIS data and registry verification for domain services.

3. How We Use Personal Data

PurposeExamplesLegal basis (GDPR)
Service deliveryCreate and manage Accounts, provision Services, authenticate users, provide customer supportContract
Billing and accountingProcess payments via our payment processor(s), issue invoices, handle taxes, maintain financial recordsContract; Legal obligation
Security and abuse preventionProtect the platform, investigate incidents, prevent fraud, enforce Terms/AUP, maintain audit logsLegitimate interests; Legal obligation
Identity verification (KYC)Verify identity and business details where required by law, payment processors, or risk assessmentLegal obligation; Legitimate interests
CommunicationsSend service notices, invoices, renewal reminders, policy updates, respond to requestsContract; Legitimate interests
Product improvementAnalyse usage and reliability trends, improve performance and user experienceLegitimate interests
Marketing (optional)Send product updates, offers, or newsletters. You may opt out at any timeConsent (where required); Legitimate interests (existing customers, soft opt‑in where permitted)

Where we rely on "legitimate interests", we have assessed that our interests do not override your fundamental rights and freedoms. You may request information about our balancing assessments by contacting us.

4. Sharing and Disclosure

We share personal data only as needed for the purposes above:

  • Infrastructure providers and subprocessors: datacenter operators, storage providers, monitoring, DDoS mitigation, and security vendors that help us deliver the Services. These are bound by data processing agreements.
  • Payment processors: currently Mollie B.V. (Netherlands) for payment processing and fraud prevention. We may add or change payment processors in the future (such as Stripe, GoCardless, or other providers) and will update this policy accordingly.
  • Domain registrars/registries: for domain registration services, registrant data is shared with the applicable registrar/registry as required by ICANN and registry rules.
  • Professional advisers: accountants, auditors, lawyers where needed for business operations.
  • Legal disclosure: regulators, law enforcement, or rights holders when required by law, when necessary to protect rights and safety, or to comply with a valid legal process. Where legally permitted, we will notify you before disclosure.

We do not sell your personal data. Where you consent to marketing cookies on our website or client portal (such as Facebook Pixel, Google Ads conversion tracking, and Bing UET), data about your visit may be transmitted to these advertising platforms, which may constitute "sharing" of personal information for cross‑context behavioural advertising under certain U.S. state privacy laws. This sharing occurs only with your consent and can be stopped at any time by declining marketing cookies through our cookie consent tool or by enabling a Global Privacy Control (GPC) signal in your browser. See our Cookie Policy for details.

5. Payment Processing NEW

We use third‑party payment processors to handle all payment transactions. Currently, our primary payment processor is Mollie B.V., registered in the Netherlands. When you make a payment, your payment details (such as card number, bank account, or other payment method data) are transmitted directly to the payment processor and are not stored on our servers.

Our payment processor(s) may collect and process data in accordance with their own privacy policies. We receive only the information necessary to confirm a transaction (such as transaction ID, payment status, last four digits of a card, and billing address for fraud checks).

We may add or change payment processors in the future to expand payment options or improve service. If we do, we will update this policy and, where required, the subprocessor list in the DPA. Current and future payment processors may include Mollie, Stripe, GoCardless, Cryptomus, or similar providers.

6. Client Portal Audit Log NEW

6.1 What is logged

All actions you perform in the client portal are automatically recorded in an audit log. This includes (by way of example): account login and logout events; changes to account settings, contact details, or payment methods; orders and cancellations; domain management actions; support ticket creation; password changes and 2FA configuration; and administrative actions such as billing or plan changes.

6.2 Why we log actions

Audit logging serves several purposes: security and fraud prevention (detecting unauthorized access), dispute resolution (verifying what actions were taken and when), compliance (maintaining records required by law or payment processors), and service improvement.

6.3 Your access to audit logs

You can view your own audit log at any time within the client portal. The audit log shows the action performed, the date and time, the IP address, and the user agent. This allows you to monitor your own account activity and detect unauthorized access.

6.4 Retention and deletion of audit logs

Audit logs are retained for the period described in Section 8 (Retention). You may request deletion of audit log data in accordance with your rights described in Section 9, subject to our legal obligations to retain certain records (for example, financial transaction records required by tax law, or security logs needed for ongoing fraud investigations). Deletion requests can be submitted online through the client portal or by contacting [email protected].

7. International Transfers UPDATED

We may process data in the United Kingdom, the European Union/EEA, and other locations where our subprocessors operate. Specifically:

  • Primary hosting infrastructure: located in the EU/EEA (currently Germany).
  • Corporate operations and support: United Kingdom.
  • Payment processing: Mollie B.V. processes data in the Netherlands (EU/EEA). Future processors may process data in other jurisdictions.
  • Other subprocessors: may be located in the EU/EEA, UK, or other jurisdictions as described in the subprocessor list maintained in the DPA.

Where personal data is transferred outside the UK or EU/EEA to a country that does not benefit from an adequacy decision, we implement appropriate safeguards as required by Applicable Law, including:

  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers from the EU/EEA;
  • UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs for transfers from the UK;
  • Supplementary measures (such as encryption, pseudonymisation, and access controls) where required by the circumstances of the transfer.

You may request a copy of the safeguards we rely on by contacting [email protected].

8. Retention UPDATED

We retain personal data only as long as necessary for the purposes described. The following table provides indicative retention periods:

Data categoryRetention periodReason
Account registration dataDuration of the Account + up to 12 months after closureService delivery; reactivation period; dispute resolution
Billing and transaction recordsUp to 7 years after the transactionUK/EU tax and accounting law (e.g., HMRC requirements)
Support communicationsDuration of the Account + up to 24 monthsService continuity; dispute resolution; legal claims
Security and authentication logsUp to 12 monthsSecurity incident investigation; fraud prevention
Client portal audit logsUp to 24 months (or longer where required by law or ongoing investigation)Security; compliance; dispute resolution
Verification (KYC) dataDuration of the Account + up to 5 yearsAnti‑money laundering obligations; fraud prevention
Customer Content (processor context)Deleted within 30 days after Service terminationContractual obligation (Terms of Service Section 9.4)
Marketing preferencesUntil you opt out or Account closureConsent / legitimate interests
Cookies and analytics dataAs described in the Cookie PolicySee Cookie Policy

Where we are required to retain data for legal, tax, or regulatory purposes beyond the periods above, we will do so for the minimum period required. Where data is no longer needed, it is securely deleted or anonymised.

9. Your Rights UPDATED

9.1 Rights under UK GDPR / EU GDPR

If the UK GDPR or EU GDPR applies to you, you have the following rights (subject to certain conditions and exceptions):

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): request deletion of your data where it is no longer necessary, you withdraw consent, or there is no overriding legal basis for retention.
  • Restriction: request that we restrict processing in certain circumstances (e.g., while we verify accuracy).
  • Data portability: receive your data in a structured, commonly used, machine‑readable format where processing is based on consent or contract and carried out by automated means.
  • Objection: object to processing based on legitimate interests, including profiling and direct marketing.
  • Withdraw consent: where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
  • Automated decision‑making: not be subject to a decision based solely on automated processing that produces legal effects or significantly affects you, except where necessary for a contract, authorised by law, or based on explicit consent.

9.2 How to exercise your rights

You can exercise many of these rights directly through the client portal:

  • View your data: your account data, billing history, audit logs, and support history are accessible in the client portal.
  • Correct your data: update your account information, contact details, and billing data directly in the client portal.
  • Request deletion: you can submit a data deletion request online through the client portal or by emailing [email protected].
  • Export your data: you can request an export of your personal data by contacting [email protected].
  • Opt out of marketing: use the unsubscribe link in any marketing email, or update your preferences in the client portal.

We will respond to rights requests without undue delay and in any event within one month of receiving the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within the first month. We may request verification of your identity to protect against unauthorized requests.

9.3 Rights under U.S. state privacy laws

See Section 14 for additional rights that may apply to U.S. residents.

10. Security

We implement technical and organizational measures designed to protect personal data, including: role‑based access controls and least‑privilege principles; encryption in transit (TLS) for website, client portal, and API connections; encrypted storage for sensitive data (such as KYC documents); monitoring of authentication events and suspicious activity; malware scanning and quarantining (where enabled); network firewalls, WAF, and DDoS mitigation; secure backup processes; and incident response procedures.

No system is perfectly secure. You are responsible for securing your own applications, credentials, and access to Self‑Managed Services. If you discover a security concern, please report it to [email protected].

11. Cookies and Tracking Technologies UPDATED

We use essential cookies to operate the website and client portal. Where required by law (including the UK Privacy and Electronic Communications Regulations and the EU ePrivacy Directive), we ask for your consent before setting non‑essential cookies (such as analytics cookies). You can manage cookie settings through our cookie consent tool and through your browser settings.

For full details on the cookies we use, their purposes, and how to control them, please see our Cookie Policy.

Where you consent, we use third‑party analytics cookies (Google Analytics, including Enhanced Ecommerce on the client portal) and marketing cookies / tracking pixels (Facebook Pixel, Google Ads, Bing UET) on our website and client portal. These are loaded only after you give consent. For full details, see our Cookie Policy.

12. Children

The Services are not directed to children. We do not knowingly collect personal data from children under 16 in the EU/EEA/UK, or under 13 in the United States (or the relevant minimum age required by local law). If you believe a child has provided personal data to us, please contact us at [email protected] and we will take appropriate steps to delete the data promptly.

13. Subprocessors and Service Providers UPDATED

We use service providers ("subprocessors" when acting as a processor) to help operate the Services. Current categories include:

CategoryExample provider(s)Location
Payment processingMollie B.V.Netherlands (EU)
Datacenter / cloud infrastructure[Provider name(s)]Germany (EU)
Support ticketing / email delivery[Provider name(s)][Location]
Monitoring and security tooling[Provider name(s)][Location]
Domain registrars/registriesResellerClub / applicable registriesVarious
Identity verification (KYC)[Provider name(s), if applicable][Location]

Note: placeholders marked [Provider name(s)] and [Location] should be replaced with actual provider details before publication.

We contractually require all providers to protect data and use it only for our instructions. The full, up‑to‑date subprocessor list (including entity names, purposes, and locations) is maintained as part of the DPA. Changes to subprocessors are notified in accordance with the Terms of Service (Section 7.6). Where we act as a processor, customers may request a current subprocessor list at any time.

14. Additional Information for U.S. Residents UPDATED

This Section provides additional disclosures required by U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), and other applicable state privacy laws (collectively, "U.S. State Privacy Laws").

14.1 Categories of personal information collected

In the preceding 12 months, we have collected the following categories of personal information (using CCPA categories):

CCPA categoryExamplesSourcesBusiness purpose
A. IdentifiersName, email, postal address, phone, IP address, Account IDYou; automatic collectionService delivery; billing; security
B. Personal information (Cal. Civ. Code § 1798.80(e))Name, address, phone, financial information (transaction references)You; payment processorBilling; accounting; KYC
D. Commercial informationPurchase history, subscription details, invoicesYou; our systemsBilling; service delivery
F. Internet or network activityLog data, IP address, user agent, audit log events, cookie dataAutomatic collectionSecurity; product improvement
G. Geolocation dataApproximate location derived from IP addressAutomatic collectionSecurity; fraud prevention; tax compliance
K. InferencesFraud risk scores, abuse pattern detectionOur systemsSecurity; fraud prevention

We do not collect sensitive personal information (such as Social Security numbers, precise geolocation, racial/ethnic origin, health data, biometric data, or sexual orientation data) in our capacity as controller.

14.2 Sale, sharing, and disclosure

We do not sell personal information as defined under CCPA/CPRA.

Sharing for advertising: Where you consent to marketing cookies on our website or client portal, certain personal information (such as online identifiers, browsing activity, and conversion events) may be transmitted to third‑party advertising platforms (Meta/Facebook, Google, and Microsoft/Bing) for purposes of measuring ad effectiveness and remarketing. Under CCPA/CPRA, this may constitute "sharing" of personal information for cross‑context behavioural advertising. In the preceding 12 months, we have shared the following categories of personal information with advertising platforms, but only where users provided consent through our cookie consent tool:

  • Category A (Identifiers): online identifiers (cookie IDs, device IDs, IP address) — shared with Meta, Google, Microsoft for ad measurement and remarketing.
  • Category F (Internet/network activity): browsing history on our site, page views, conversion events — shared with Meta, Google, Microsoft for ad measurement.

Your right to opt out: You can opt out of this sharing at any time by: (a) declining marketing cookies in our cookie consent tool; (b) enabling the Global Privacy Control (GPC) signal in your browser; or (c) contacting us at [email protected]. When marketing cookies are declined or GPC is detected, no sharing occurs — advertising scripts do not load and no data is transmitted to advertising platforms.

We disclose personal information to service providers and contractors for business purposes as described in Section 4 (Sharing and Disclosure). In the preceding 12 months, we have disclosed categories A, B, D, F, and G to the following categories of recipients: Infrastructure Providers, payment processors (Mollie B.V.), support tooling providers, and domain registrars/registries. Additionally, where users consented to marketing cookies, we have shared categories A and F with advertising platforms (Meta/Facebook, Google, Microsoft/Bing) as described in Section 14.2.

14.3 Your rights under U.S. State Privacy Laws

Depending on your state, you may have the following rights:

  • Right to know / access: request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to delete: request deletion of personal information we have collected, subject to certain exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt out of sale/sharing: we do not sell personal information. We share personal information with advertising platforms only where you consent to marketing cookies. You can opt out of sharing at any time by declining marketing cookies, enabling GPC, or contacting us. See Section 14.2 for details.
  • Right to limit use of sensitive personal information: we do not process sensitive personal information beyond what is necessary for the Services.
  • Right to non‑discrimination: we will not discriminate against you for exercising your privacy rights.

14.4 How to exercise your rights

You may submit requests by: (a) using the online request mechanism in the client portal; (b) emailing [email protected]; or (c) contacting support. We will verify your identity before processing your request (for example, by matching your request with your Account credentials). You may designate an authorized agent to make a request on your behalf; we may require written authorization and identity verification of both you and the agent.

We will respond to verifiable requests within 45 days of receipt. This period may be extended by an additional 45 days where reasonably necessary, with notice to you.

14.5 Opt‑out preference signals

We respect browser‑based opt‑out preference signals (such as the Global Privacy Control, "GPC") where required by Applicable Law. If we detect such a signal, we will treat it as a valid request to opt out of the sale or sharing of personal information associated with that browser.

14.6 Data retention

We retain each category of personal information for the period described in Section 8 (Retention) or for the period reasonably necessary to fulfil the business purpose for which it was collected, whichever is longer, subject to legal retention requirements.

14.7 Annual update

We review and update the disclosures in this Section at least once every 12 months.

15. Identity Verification (KYC) Data

When we request identity or business verification, we use the data to prevent fraud, comply with payment provider requirements, and protect platform integrity. Verification data may be processed by third‑party verification services. We restrict access to verification data on a need‑to‑know basis, encrypt it at rest where supported, and store it for the shortest period necessary, subject to legal obligations and fraud prevention needs (see Section 8 for retention periods).

16. Automated Decision‑Making UPDATED

We may use automated systems to detect fraud, abuse, or security anomalies (for example, login risk scoring, payment fraud detection, or abuse pattern detection). These systems may lead to temporary restrictions or requests for manual verification.

We do not make solely automated decisions that produce legal effects or significantly affect you without human review, except where: (a) necessary for entering into or performing a contract (e.g., automated fraud checks during payment processing); (b) authorized by law; or (c) based on your explicit consent.

You may contact support at any time to request human review of a decision that materially affects your access to the Services, and we will provide meaningful information about the logic involved.

17. Data Subject Requests for Hosted Content

If you are an end user of a website hosted by one of our customers and you want to exercise data rights regarding that website's content, you should contact the site operator (our customer) because they control the content and purposes of processing. We can assist the customer as a processor upon their instruction. We cannot independently respond to requests from end users of Customer Content without our customer's authorization.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on our site and update the effective date/version number. If changes are material, we will notify you via email or the client portal at least 30 days before the effective date. We encourage you to review this policy periodically. Your continued use of the Services after the effective date of an updated policy constitutes acceptance of the changes. For Consumers, where required by Applicable Law, material changes that adversely affect your rights require your affirmative acceptance.

19. Contact and Complaints UPDATED

19.1 Contact us

For privacy‑related questions, data subject requests, or complaints, please contact:

  • Email: [email protected]
  • Post: Apefo Ltd (Yhost), 24-26 Regent Place, City Centre, Birmingham, United Kingdom, B1 3NJ
  • Client portal: submit a request via the support/privacy section

19.2 Data Protection Officer

Given the nature and scale of our processing activities, we have not appointed a formal Data Protection Officer (DPO) at this time. Privacy matters are handled by our privacy contact at [email protected]. We will appoint a DPO if and when required by Applicable Law.

19.3 Supervisory authorities

If you are in the UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

If you are in the EU/EEA, you have the right to lodge a complaint with the data protection authority in your Member State of habitual residence, place of work, or place of the alleged infringement. A list of EU data protection authorities is available at edpb.europa.eu.

If you are in the EU and we have not yet designated an EU legal representative (see the Terms of Service, Section 18.3), we will publish the

transportation