Privacy Policy

Last updated: February 2026

1. Introduction

Frantronics Hosting ("we", "our", "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our web hosting services.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable international data protection laws including the EU GDPR where relevant.

2. Data Controller

Frantronics Development is the data controller responsible for your personal data. If you have any questions about this policy or our data practices, contact us at: frantronicsdevelopment@gmail.com

3. Data We Collect

We collect the following types of personal data:

  • Account Information: Full name, email address, and encrypted password when you register an account.
  • Payment Information: Payment details are processed securely by Stripe. We do not store your full card details on our servers. We retain transaction records including amount, date, and payment status.
  • Hosting Data: Domain names, FTP credentials, and hosting configuration data required to provision and manage your hosting packages.
  • Usage Data: Subscription history, login activity, and service usage records.
  • Communications: Any correspondence you send to us, including support requests.
4. How We Use Your Data

We use your personal data for the following purposes under the lawful bases set out by UK GDPR:

  • Contract Performance (Article 6(1)(b)): To provide hosting services, process payments, provision hosting packages, and manage your account.
  • Legitimate Interests (Article 6(1)(f)): To improve our services, prevent fraud, and ensure platform security.
  • Legal Obligation (Article 6(1)(c)): To comply with tax, accounting, and regulatory requirements.
  • Consent (Article 6(1)(a)): To send marketing communications where you have opted in. You may withdraw consent at any time.
5. How We Store Your Data

Your data is stored securely using the following measures:

  • Encryption: Passwords are hashed using bcrypt. All data in transit is encrypted via TLS/SSL.
  • Database Security: Data is stored in secure MongoDB databases with access restricted to authorised personnel only.
  • Payment Security: All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store full card numbers on our servers.
  • Hosting Infrastructure: Hosting packages are provisioned through 20i, a UK-based hosting provider operating from UK and EU data centres.
  • Access Controls: Administrative access is restricted with role-based authentication and JWT-secured API endpoints.
6. Data Retention

We retain your personal data only for as long as necessary:

  • Account Data: Retained while your account is active and for up to 12 months after closure.
  • Transaction Records: Retained for 7 years to comply with UK tax and accounting regulations (HMRC requirements).
  • Hosting Data: Deleted within 30 days of hosting package termination.
  • Communication Records: Retained for up to 24 months for service improvement and dispute resolution.
7. Third-Party Data Sharing

We share your data only with trusted third parties necessary to deliver our services:

We do not sell your personal data to any third party.

8. International Data Transfers

Where your data is transferred outside the UK or EEA (for example, to service providers based in the United States), we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the ICO
  • UK International Data Transfer Agreement (IDTA) where applicable
  • Adequacy decisions recognised by the UK Government
9. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to Restrict Processing: Request limitation of how we process your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at frantronicsdevelopment@gmail.com. We will respond within one month as required by law.

10. Cookies

We use essential cookies and local storage to maintain your login session and theme preference. These are strictly necessary for the functioning of our service and do not require consent under the Privacy and Electronic Communications Regulations (PECR).

We do not use tracking cookies or third-party analytics cookies.

11. Security Breaches

In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, as required under UK GDPR Article 33. Affected individuals will be notified without undue delay where there is a high risk.

12. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.

Frantronics

By Frantronics Development