first month for £1 with code
Webfort

Privacy Policy

Last Updated: August 19, 2026

At Webfort, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web hosting services and visit our website.

🔒 Your Privacy Matters

We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this policy or our practices, please contact us at privacy@webfort.co.uk.

1. Information We Collect

We collect information that you provide directly to us, information we obtain automatically when you use our services, and information from third-party sources.

1.1 Information You Provide to Us

  • Account Information: Name, email address, billing address, phone number
  • Payment Information: Credit card details, billing information (processed securely through third-party payment processors)
  • Support Communications: Information you provide when contacting our support team
  • Domain Information: Domain registration details required by ICANN
  • Account Content: Files, databases, emails, and other content you upload to our servers

1.2 Information Collected Automatically

  • Usage Data: Server logs, access times, pages viewed, IP addresses
  • Device Information: Browser type, operating system, device identifiers
  • Performance Data: Resource usage, bandwidth consumption, server response times
  • Cookies and Tracking: Information collected through cookies and similar technologies

1.3 Information from Third Parties

  • Payment processors (payment confirmation and fraud prevention)
  • Domain registrars (domain registration verification)
  • Security services (threat detection and prevention)
  • Analytics providers (website usage statistics)

2. How We Use Your Information

We use the information we collect for various purposes, including:

2.1 Service Provision

  • Creating and managing your hosting account
  • Processing payments and maintaining billing records
  • Providing customer support and responding to inquiries
  • Monitoring and maintaining service performance
  • Managing domain registrations and renewals

2.2 Service Improvement

  • Analyzing usage patterns to improve our services
  • Developing new features and functionality
  • Conducting research and analytics
  • Optimizing website and server performance

2.3 Security and Fraud Prevention

  • Detecting and preventing fraud, abuse, and illegal activities
  • Protecting the security and integrity of our services
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Complying with legal obligations

2.4 Communications

  • Sending service-related notifications and updates
  • Providing customer support responses
  • Sending marketing communications (with your consent)
  • Notifying you of account or security issues

2.5 Our Lawful Basis for Each Purpose

UK GDPR requires us to have a lawful basis for everything we do with your personal data, and to tell you what it is. This is ours, purpose by purpose:

What we do Lawful basis Why that basis
Set up and run your hosting account, provide support, register and renew domains Contract We cannot deliver the service you bought without it. Art. 6(1)(b).
Take payment and keep billing records Contract, then legal obligation Taking the payment is contractual. Keeping the record for seven years is tax and company law. Art. 6(1)(b) and 6(1)(c).
Detect fraud and abuse, keep servers secure, enforce our Acceptable Use Policy Legitimate interests Protecting our network and every other customer on it. Art. 6(1)(f).
Send service notices — downtime, renewals, security warnings, policy changes Contract These are part of running the service and you cannot opt out of them while you hold an account. Art. 6(1)(b).
Email existing customers about similar hosting services Legitimate interests Sent under the PECR "soft opt-in" for existing customers. Every message carries an unsubscribe link and we stop the moment you use it. Art. 6(1)(f).
Market to people who are not yet customers Consent You opted in, and you can withdraw at any time. Art. 6(1)(a).
Website analytics Consent Nothing loads until you accept it in the cookie banner, and you can change your mind on our Cookie Policy page. Art. 6(1)(a).
Respond to law enforcement, courts and regulators; defend legal claims Legal obligation, legitimate interests Some disclosures we must make; others protect our legal position. Art. 6(1)(c) and 6(1)(f).

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. Ask us and we will share that assessment.

3. How We Share Your Information

✅ We Do Not Sell Your Data

We do not sell your personal information. We may share your information only in the circumstances outlined below.

3.1 Sub-Processors

These are the third parties who process personal data on our behalf, what each of them does, and where they do it. Every one of them is bound by a written contract that limits them to our instructions.

Provider What they do Where Transfer safeguard
Stripe Card payments and billing UK, EU, USA SCCs with UK Addendum
PayPal Alternative payment method EU, USA SCCs with UK Addendum
Cloudflare CDN, DDoS protection, and the Turnstile anti-spam check on our forms Global edge network, including the USA SCCs with UK Addendum
Crisp Live chat on this website European Union Not required — EU is covered by UK adequacy
Google Website analytics. Only runs if you accept analytics cookies EU, USA SCCs with UK Addendum
UK data centre operator Hosting infrastructure for services you place in our UK region United Kingdom Not required — data stays in the UK
US data centre operator Hosting infrastructure for services you place in our USA region Dallas, Texas, USA SCCs with UK Addendum — see 3.6

We do not publish the names of our data centre partners, for commercial reasons. Account holders can have the full named list, including those operators, by emailing privacy@webfort.co.uk — we will not ask you why you want it.

Our billing and support system (WHMCS) runs on our own infrastructure, so your tickets and invoices are not handed to a third-party helpdesk provider. We do not use a third-party bulk email service; service and marketing mail is sent from our own mail servers.

If we add or replace a sub-processor that handles data on behalf of business customers, we will give at least 30 days' notice as set out in our Data Processing Agreement.

3.2 Domain Registration Partners

When you register, transfer, or renew a domain name through Webfort, we are required to share your information with domain registry operators and related organisations. This data sharing is a contractual and legal necessity to complete your domain registration.

Organisations We Share Data With:

  • Nominet UK – Registry operator for .uk, .co.uk, .org.uk, .me.uk domains
  • Verisign Inc. – Registry operator for .com and .net domains
  • Public Interest Registry (PIR) – Registry operator for .org domains
  • ICANN – The Internet Corporation for Assigned Names and Numbers, which oversees the global domain name system
  • Other TLD Registries – Respective registry operators for other domain extensions you register

Information Shared:

  • Registrant name (or organisation name)
  • Postal address
  • Email address
  • Telephone number
  • Domain name and nameserver details

WHOIS/RDAP Data Publication:

Domain registration information may be published in public WHOIS or RDAP directories as required by registry policies and ICANN regulations. However:

  • Many registries now redact personal data from public WHOIS under GDPR
  • Nominet (.uk domains) does not publish registrant addresses for individuals
  • We offer WHOIS privacy protection where available to mask your personal details

International Data Transfers:

Some registry operators (such as Verisign and ICANN) are based outside the UK and European Economic Area. By registering a domain, you acknowledge that your data may be transferred to and processed in countries with different data protection laws, including the United States. These transfers are necessary to fulfil your domain registration request.

Legal Basis:

We share this information on the basis of contractual necessity (to provide the domain registration service you have requested) and legal obligation (compliance with ICANN policies and registry requirements).

ℹ️ Registry Data Retention

Domain registries maintain their own data retention policies. Even after your domain expires or is transferred away, registries may retain historical registration data in accordance with their policies and legal obligations. Please refer to the respective registry's privacy policy for details.

3.3 Legal Requirements

We may disclose your information if required by law or in response to valid requests by public authorities, including:

  • Complying with legal processes (subpoenas, court orders)
  • Enforcing our Terms of Service
  • Protecting the rights, property, or safety of Webfort, our users, or the public
  • Preventing fraud or illegal activities

3.4 Business Transfers

If Webfort is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

3.5 With Your Consent

We may share your information for any other purpose with your consent.

3.6 International Transfers of Your Hosted Data

We run hosting infrastructure in the United Kingdom and in Dallas, Texas. Which one your data sits in is your choice, made when you order and changeable afterwards, and we do not move it between regions without telling you.

Choose UK and your data stays in the UK

If you select our UK region, your websites, databases, files, backups and mailboxes are stored and processed in the United Kingdom. Nothing about that data leaves the UK in the ordinary course of running it.

If you choose the USA region

The United States has no UK adequacy decision covering transfers generally, so we cannot simply send data there and call it done. We rely on the following:

  • Contractual safeguard: our contract with the US data centre operator incorporates the European Commission's Standard Contractual Clauses together with the ICO's UK International Data Transfer Addendum (the "UK Addendum"), which is the mechanism the ICO recognises for restricted transfers under Art. 46.
  • Transfer risk assessment: we have assessed whether those clauses give protection that is materially equivalent to UK standards in practice, taking account of US surveillance law and the nature of the data. Business customers can request a copy of that assessment.
  • Technical measures: data is encrypted in transit, and access to the infrastructure is restricted to named Webfort staff.
  • Your control: you chose the region, and you can move to our UK region at any time. Ask support and we will arrange it.

Some of the sub-processors listed in 3.1 also process limited data outside the UK — payment details with Stripe and PayPal, and traffic at Cloudflare's edge. Those transfers rely on the same combination of Standard Contractual Clauses and UK Addendum.

Business customers who need the detail in contractual form should read our Data Processing Agreement, which covers transfers, sub-processors, security and breach handling as binding terms rather than a description.

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption: SSL/TLS encryption for data transmission
  • Access Controls: Restricted access to personal information on a need-to-know basis
  • Security Monitoring: 24/7 monitoring for security threats and vulnerabilities
  • Firewalls: Network security measures to protect against unauthorized access
  • Regular Audits: Security assessments and vulnerability testing
  • Employee Training: Security awareness training for all staff

⚠️ Important

While we strive to protect your information, no security system is impenetrable. We cannot guarantee the absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials.

4.1 If There Is a Breach

Breaches happen to careful companies too, so here is exactly what we will do rather than a promise that nothing will go wrong.

  • Where we are the controller — data about your account, billing and support — we will report a breach to the ICO within 72 hours of becoming aware of it, unless it is unlikely to risk your rights and freedoms. If the risk to you is high, we will tell you directly and without undue delay.
  • Where we are your processor — the data inside your websites, databases, files and mailboxes — we will notify you without undue delay and in any event within 24 hours of becoming aware, so that you have time to make your own 72-hour report as controller.
  • We will tell you what happened, which data was involved, what we think the consequences are, and what we are doing about it — including the parts we do not yet know.
  • We keep a record of every personal data breach, including ones we conclude are not notifiable, and the reasoning behind that conclusion.

To report a suspected breach or vulnerability to us, email security@webfort.co.uk.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

5.1 Account Data

We retain your account information for the duration of your active account plus a reasonable period thereafter for backup and legal compliance purposes (typically 30-90 days after account closure).

5.2 Billing Records

We retain billing and transaction records for at least 7 years to comply with tax and accounting regulations.

5.3 Support Communications

Customer support communications are typically retained for 2-3 years for quality assurance and training purposes.

6. Your Privacy Rights

If you are in the UK, UK GDPR gives you the following rights over your personal data. They are free to use, and using them will never affect the service you get from us.

✓ Access & Portability

Get a copy of the personal data we hold about you, and receive it in a portable format you can take elsewhere

✓ Correction

Have inaccurate or incomplete personal data put right

✓ Deletion

Have your personal data erased, where we have no overriding reason to keep it

✓ Restriction

Tell us to pause what we do with your data — for example while we look into a correction you have asked for

✓ Objection

Object to processing we base on legitimate interests. For direct marketing there is no balancing test — object and we stop

✓ Withdraw Consent

Where we rely on consent — analytics cookies, prospect marketing — withdraw it at any time. Doing so does not undo processing already carried out

✓ Marketing Opt-Out

Stop marketing email at any time, through the unsubscribe link or by emailing us

✓ Automated Decisions

We make no decisions about you by automated means alone, and we do not profile you. If that changes, you will have the right to human review

Exercising Your Rights

To exercise any of these rights, email privacy@webfort.co.uk. We will respond within one calendar month. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if that happens, and why.

We may need to confirm who you are before we act, so that we do not hand your data to someone else.

Complaining to the ICO

If you think we have handled your personal data badly, please tell us first — we would rather fix it. But you have the right to complain to the UK's data protection regulator at any point, and you do not need our permission or to come to us first.

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Helpline: 0303 123 1113

ico.org.uk/make-a-complaint

7. Cookies and Tracking

We use cookies and similar technologies on this website. Our Cookie Policy names every one of them individually; this is the short version.

7.1 Types of Cookies We Use

  • Essential: Required for the site to work — sessions, security checks, and storing your cookie choice
  • Functional: Live chat and your preferences, such as the currency you chose
  • Analytics: Google Analytics, which does not load at all unless you accept it
  • Marketing: None. We run no advertising, retargeting or conversion tracking cookies

7.2 Managing Cookies

Non-essential cookies stay off until you accept them in the banner shown on your first visit. You can change your choice whenever you like from the Cookie Preferences link in the footer of any page, or in section 4 of the Cookie Policy. Withdrawing consent is as easy as giving it, and your browser settings remain a further backstop.

8. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Updating the "Last Updated" date
  • Sending an email notification for significant changes

Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Inquiries

For privacy-related questions or to exercise your privacy rights:

privacy@webfort.co.uk

Data protection contact: privacy@webfort.co.uk

Webfort Ltd, Company No. 15981490

128 City Road, London EC1V 2NX, United Kingdom

ICO registration: ZB946780

We are the data controller for the personal data described in this policy. We are not required to appoint a statutory Data Protection Officer, and have not done so; the address above reaches the people responsible for data protection at Webfort.

Contact Support