Privacy Policy
Last updated: 26 August 2026
AOIT Networks Ltd, trading as AOIT Cloud Hosting. Version 1.0, last updated 26 August 2026.
1. Introduction
This privacy notice explains how we collect and process your personal data when you use the aoitcloud.com website and our hosting, email, domain, VPS and managed cloud server services, including when you contact us, order services, or receive communications from us.
AOIT Networks Ltd is the data controller responsible for your personal data (referred to as “we”, “us” or “our” in this notice). AOIT Cloud Hosting is a trading name of AOIT Networks Ltd.
Contact details
- Full name of legal entity: AOIT Networks Ltd
- Company number: 10450071
- VAT number: GB253424912
- ICO registration number: ZB127610
- Email: support@aoitcloud.com
- Post: Jarrow Business Centre, Viking Industrial Estate, Jarrow, Tyne and Wear, NE32 3DT, United Kingdom
- Telephone: 0191 825 0808
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would be grateful if you would contact us first so we can try to resolve the issue for you.
Please keep the information we hold about you accurate and up to date by updating your account details or contacting us at support@aoitcloud.com.
An important distinction. This notice covers the personal data we hold about you, our customer or website visitor, as a data controller. It does not cover the content you host with us (your websites, databases and mailboxes): for that content you are the controller and we act only as your processor, as explained in Section 5 and in our Data Processing Agreement.
2. What data we collect about you
Personal data means any information capable of identifying an individual. It does not include anonymised data. We may process the following categories of your personal data:
- Identity data: first name, last name, username, company name.
- Contact data: billing address, email address and telephone numbers.
- Financial data: payment card details are handled by our payment partners; we do not record or store your full card details. We hold records of the payment methods registered to your account.
- Transaction data: details of payments and of services you have purchased.
- Technical data: internet protocol (IP) address, browser type and version, time zone setting, operating system, and other technology on the devices you use to access our website and services. We store the IP address associated with each order to help combat fraud and comply with VAT obligations, and we record the IP address and a timestamp of your acknowledgement of this privacy notice when you submit our contact form.
- Profile data: your username and password for your account, services purchased, support ticket history, preferences and feedback.
- Usage data: information about how you use our website and services, from standard server logs.
- Marketing and communications data: your preferences in receiving marketing from us.
We may also process aggregated data derived from your personal data (for example, feature usage statistics); aggregated data is not personal data unless re-linked to you.
Sensitive data. We do not intentionally collect any special category data about you (such as data about your health, beliefs or ethnicity), and we do not collect information about criminal convictions and offences. Content you host with us could contain such data; we process hosted content solely as your processor under our Data Processing Agreement and do not access, review or use it for our own purposes.
If we are required to collect personal data by law or under our contract and you do not provide it, we may not be able to provide the service, and will tell you at the time if so.
3. How we collect your personal data
- Direct interactions: when you create an account, order services, submit our contact form, raise a support ticket, telephone us, or otherwise communicate with us.
- Automated technologies: as you use our website, our servers automatically log standard access information (IP address, browser type, request times, URLs requested). Our contact form uses Cloudflare Turnstile to distinguish people from bots, which processes technical data about your browser for that purpose. Details of cookies and similar technologies are in our Cookie Declaration.
- Service delivery: our billing and account systems record the services you use, invoices, payments and support history.
- Third parties: our payment providers confirm payment outcomes to us; domain registries and registrars confirm registration details.
We do not run third-party advertising or behavioural analytics scripts on aoitcloud.com.
4. How we use your personal data
We only use your personal data when the law allows: usually to perform our contract with you, where it is necessary for our legitimate interests (and your interests and rights do not override them), or to comply with a legal obligation. We generally do not rely on consent, other than for sending email marketing to people who are not existing customers; you can withdraw consent, or opt out of any marketing, at any time via the unsubscribe link or by emailing support@aoitcloud.com.
| Purpose | Type of data | Lawful basis |
|---|---|---|
| Register you as a customer and respond to enquiries (including contact form submissions) | Identity, Contact, Technical | Performance of a contract; legitimate interests (communicating with existing and prospective customers) |
| Provide the services, manage payments and collect money owed | Identity, Contact, Financial, Transaction | Performance of a contract; legitimate interests (recovering debts) |
| Provide technical support and respond to tickets and calls | Identity, Contact, Technical, Profile | Performance of a contract |
| Send service communications (invoices, renewal reminders, maintenance and security notices) | Identity, Contact | Performance of a contract; legal obligation; legitimate interests (keeping customers informed about their services) |
| Manage our relationship with you, including notifying you of changes to terms or this notice | Identity, Contact, Profile | Performance of a contract; legal obligation; legitimate interests (keeping records updated) |
| Administer and protect our business, website and platform (security, fraud prevention, troubleshooting, logging) | Identity, Contact, Technical | Legitimate interests (running our business, network security, preventing fraud); legal obligation |
| Recommend services that may be of interest to you | Identity, Contact, Usage, Profile, Marketing | Legitimate interests (developing and growing our business) |
Marketing. You will receive marketing from us only if you have requested information, purchased services from us, or otherwise given us your details and not opted out. For existing customers we rely on the “soft opt-in” under the Privacy and Electronic Communications Regulations and our legitimate interests; for anyone else we ask for consent first. You can opt out at any time; opting out does not affect transactional and service emails, which are part of running your services. We will never sell or rent your contact details, and we will get your express consent before sharing your data with any third party for their marketing.
Change of purpose. We will only use your personal data for the purposes we collected it for, unless we reasonably consider we need it for a compatible reason. If we need to use it for an unrelated purpose we will notify you and explain the legal basis.
5. When we act as a data processor
For the content you host with us, you are the data controller and we act as your data processor. This includes your website files, databases, mailboxes and backups, and any personal data of your own customers, users and website visitors contained in them.
We only access hosted content when necessary for service delivery: responding to your support requests, automated security scanning (malware, spam and firewall filtering), checking content submitted for migration, platform health monitoring, and investigating suspected breaches of our Acceptable Use Policy or the law. We do not routinely review the content of your data, and we never use it for our own purposes.
Our obligations as a processor, including security measures, breach notification, subprocessor management, data subject request assistance, and deletion on termination, are set out in our Data Processing Agreement, which forms part of our Terms and Conditions and is available on our legal page. A list of our subprocessors is available on our legal page or on request. Where we receive a request from an individual whose data we process on your behalf, we will refer it to you promptly and assist you in responding.
6. Disclosures of your personal data
We may share your personal data with:
- Service providers and subprocessors who provide the infrastructure, platform, registrar, billing and payment services necessary to deliver our services, under contracts requiring them to protect your data and use it only on our instructions;
- Domain registries and registrars: when you register, renew or transfer a domain through us, we pass your registrant details (name, organisation, postal address, email address and telephone number) to the relevant registrar and registry so the domain can be registered and maintained in your name: Nominet for .uk domains, and our registrar partners Netistrar and OpenSRS (Tucows), together with the relevant registry, for other domain endings. Depending on the registry’s rules, some of those details may appear in the public WHOIS/RDAP directory for your domain (privacy protections are applied where the registry or registrar offers them), and registration data for many non-UK domains is also held in escrow arrangements mandated by ICANN. The registrar’s and registry’s own privacy policies apply to their processing;
- Professional advisers including lawyers, bankers, auditors and insurers;
- HM Revenue & Customs, regulators and other authorities where reporting is required;
- Third parties in a business restructure: if we sell, transfer or merge parts of our business or assets, the new owners may use your personal data in the same way as set out in this notice.
We will never sell your personal data. We do not allow third-party providers to use your personal data for their own purposes.
7. International transfers
We store and process the personal data we control (your account, billing and support data) in the United Kingdom wherever possible. The data you host with us is stored in the location you choose for your service, as described in our Data Processing Agreement; for shared hosting this is the United Kingdom. Domain registrant details are transferred to the relevant registrar and registry for the domain ending, some of which are outside the UK; this is inherent to registering the domain (see Section 6).
Where a transfer of your personal data outside the UK is necessary (for example, a service provider operating infrastructure elsewhere), we ensure appropriate safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or other approved mechanisms. Contact support@aoitcloud.com for details of the specific mechanisms used and, where applicable, a copy of the relevant safeguard.
8. Data retention
We keep personal data only as long as necessary for the purposes we collected it for, including legal, accounting and reporting requirements. In particular:
- Customer records (identity, contact, financial and transaction data) are kept for 6 years after you cease to be a customer, to comply with tax and accounting obligations.
- Contact form submissions and enquiries are kept while we deal with your enquiry and for a reasonable period afterwards, and are reviewed periodically and deleted when no longer needed.
- Support tickets and communications are kept for as long as you remain a customer and for a reasonable period afterwards, for service continuity and dispute resolution.
- Server and security logs are retained until no longer needed for security and compliance purposes, typically between 90 days and 12 months depending on the log type.
- Hosted content (your websites, databases, mailboxes and backups) is deleted when you cancel the relevant service, as described in our Terms and Conditions and Data Processing Agreement.
In some circumstances you can ask us to delete your data (see Section 10), and in some circumstances we may anonymise it, in which case we may use the anonymised information indefinitely.
9. Data security
We have appropriate security measures in place to prevent your personal data being accidentally lost, used or accessed in an unauthorised way, altered or disclosed, including: encryption of data in transit (TLS); multi-factor authentication and role-based access controls on systems containing personal data, following the principle of least privilege; logging and monitoring of access; regular security assessment of our systems; staff confidentiality obligations and data protection training; documented incident response procedures; and UK data centres with ISO 27001 certification and physical access controls. AOIT Networks Ltd holds Cyber Essentials certification.
We aim to notify the ICO within 72 hours of becoming aware of a reportable breach, in accordance with UK GDPR requirements, and to notify you without undue delay where a breach affects data we process on your behalf.
No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we protect your data using appropriate and proportionate measures.
10. Your legal rights
Under data protection law you have rights in relation to your personal data: to request access to it; to have it corrected; to have it erased; to object to our processing of it; to restrict processing; to have it transferred in a structured, commonly used, machine-readable format; and to withdraw consent where consent is our basis for processing. More detail on each right is available from the ICO at www.ico.org.uk. We do not make any decision about you based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these rights, email support@aoitcloud.com. You will not usually have to pay a fee, though we may charge a reasonable fee or decline a request that is clearly unfounded, repetitive or excessive. We may need to verify your identity before acting on a request; this is a security measure. We aim to respond to all legitimate requests within one month, and will keep you updated if a complex request takes longer.
Where we process personal data on your behalf as a processor (for example, data belonging to your customers), requests from those individuals should be directed to you as the controller; if we receive one directly we will refer it to you promptly.
11. Cookies
You can set your browser to refuse all or some cookies, or to alert you when websites set or access them; if you disable cookies, some parts of our website (particularly your account area) may not function properly. Details of the cookies we use and how to manage your preferences are in our Cookie Declaration on our website.
12. Third-party links and embedded content
Our website includes a small number of third-party embeds: a green hosting verification badge served by the Green Web Foundation, our Cyber Essentials certificate verification widget served by the certification registry, and, on our contact page, the Cloudflare Turnstile bot-protection widget. Loading these involves your browser making a request to the relevant third party. Our website may also link to third-party sites; we do not control them and are not responsible for their privacy practices, so please read the privacy notice of every site you visit.
13. Changes to this privacy notice
We may update this notice from time to time. Changes will be posted on this page with an updated “Last updated” date, and material changes affecting how we process your data or your rights will be notified to you by email in advance where required.
14. Children’s privacy
Our services are for business and personal use by people aged 18 or over, and are not directed at children. We do not knowingly collect personal data from children; if you believe we have, contact us at support@aoitcloud.com and we will delete it as soon as possible.
15. Questions and complaints
Questions about this notice or how we handle your data: support@aoitcloud.com, 0191 825 0808, or AOIT Networks Ltd, Jarrow Business Centre, Viking Industrial Estate, Jarrow, Tyne and Wear, NE32 3DT, United Kingdom.
You have the right to complain at any time to the ICO (www.ico.org.uk, helpline 0303 123 1113, Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). We would appreciate the chance to address your concerns before you approach the ICO, so please contact us first.