Skip to main content

Data Security Statement

Last updated: August 19, 2026

What this covers

Not the marketing version of security, and not what defends your website — this is about the personal data sitting behind the accounts, and the measures Article 32 of the UK GDPR expects of us. Cheap hosting does not mean a lower standard here; it means the same standard bought efficiently.

1. Encryption

Everything on this site and in the client area travels over TLS, with HTTP Strict Transport Security set so a browser will not quietly fall back to an unencrypted connection. Certificates renew themselves.

Passwords are stored salted and hashed, so support cannot read yours back and neither can anybody else here — a reset is the only route, which is why nobody from this company will ever ask you for one. Card numbers never reach our systems; the payment provider holds them and we keep a token and the last four digits.

2. Who can see what

Access to systems holding personal data is given to a named person on the basis of need and taken away when the need ends. Administrative access needs two-factor authentication. Nobody uses a shared login, because an action nobody can be tied to is an action nobody answers for.

Support can see your account, your services and your tickets. Reading through your files or database is not routine, and where a request genuinely needs it, it happens with your knowledge and for that request only.

3. Keeping accounts apart

Accounts sharing a machine are walled off from each other, so one site being broken into is not every site being broken into. Platform software is patched, malware scanning runs continuously, and a web application firewall with network-level attack mitigation sits in front.

A daily copy is taken and you can restore it yourself. It is a convenience rather than a guarantee — the service level agreement says plainly that it pays out on availability and never on lost data.

4. Where it lives and who else touches it

Hosting infrastructure is in the United Kingdom. Personal data is handled in the UK and the EEA, and where a supplier works elsewhere the transfer relies on the safeguards named in the privacy policy, which also lists who those suppliers are. Suppliers are checked before we use them and are held to written terms no weaker than the ones we owe you.

5. How long we keep things

Full periods are in the privacy policy. Roughly: account and billing records for the life of the account plus six years, because tax law requires it; support tickets three years; raw server logs a matter of weeks.

Cancel a service and its data leaves live systems on the published schedule, then ages out of backups. We do not surgically edit backups to satisfy a deletion request, because editing a backup destroys the thing that makes it a backup — they are allowed to expire instead, with the data unavailable in the meantime.

6. If something goes wrong

A personal data breach likely to put people at risk goes to the Information Commissioner's Office within 72 hours of us finding out. Where the risk to people is high, they hear from us directly and quickly.

Where the data is yours and we are only processing it, you are told without undue delay, because your own 72-hour clock starts whether or not anyone has told you it has.

We would rather tell you about something that turns out to be nothing than sit on something while working out how it looks.

7. Telling us about a weakness

Found a hole? info@hosting-cheap.com, before anywhere else, and give us a reasonable window to fix it. The same contact is published in machine-readable form at /.well-known/security.txt.

Keep the testing to your own account, leave other people's data alone, and no flooding. Stay inside that and you have our word there will be no legal consequences for looking.

8. The half that is yours

None of this updates your plugins, picks your passwords, or removes the freelancer who still has your FTP details. Those sit in the acceptable use policy, and they are behind most of the compromises we actually see.

9. The company

Hosting-Cheap is a trading name of Bohzo Ltd, a company registered in England and Wales under Company No. 15031604. Registered office: The Workspace Basildon, 7 High Pavement, Basildon, England, SS14 1EA. Security contact: info@hosting-cheap.com.