Skip to content
PIVIHOST
  • Hosting
  • VPS
  • Domains
  • Knowledge Base
  • Contact
Client Login Order Now
Menu
  • Hosting
  • VPS
  • Domains
  • Knowledge Base
  • Contact
  • Client Login
  • Order Now
  1. Home
  2. Privacy Notice
PRIVACY

Privacy Notice

How Pivi Website Ltd collects, uses, and protects personal data — mapped from how our systems actually work, not a generic template.

Effective
2026-09-17
Last updated
2026-09-17

On this page

  1. Who we are
  2. Scope
  3. Our role: controller and processor
  4. Data we collect
  5. Why we use your data, and our lawful basis
  6. Who we share data with
  7. International transfers
  8. How long we keep your data
  9. Security
  10. Cookies
  11. Google reCAPTCHA
  12. Data you host with us
  13. Children
  14. Marketing
  15. Automated decision-making
  16. Your rights
  17. Right to object
  18. Complaints
  19. Changes to this notice

Who we are

This notice is issued by Pivi Website Ltd (trading as PIVIHOST), a company registered in England and Wales under company number 13138238, registered office Office 7 Blackburn Road, Houghton Regis, Dunstable, England, LU5 5BQ. See our Company Details page for the full formal disclosure. You can contact us about privacy matters at admin@pivihost.com.

Scope

This notice covers personal data we process through our public website (pivihost.com) and our client area (panel.pivihost.com), where you create an account, place an order, and manage hosting, VPS or domain services. It does not cover the content of websites, applications, or data you choose to host with us — see §Customer-hosted data below for how we handle that separately.

Our role: controller and processor

For your own account, billing, and support data, we act as a data controller — we decide why and how it's processed, and this notice describes that processing.

Separately, if you host a website, application, database, or mailbox with us that itself contains personal data about other people (for example, your own customers' order details, or your mailing list), we act as a data processor for that content — you decide what's stored and why, and we process it only to provide the hosting service itself (storage, transmission, backup where applicable). We don't inspect, use, or make decisions about that content beyond providing and securing the service and enforcing our Acceptable Use Policy. See §Customer-hosted data.

Data we collect

Account and order data

Name, email address, and other contact/billing details you provide when you register or place an order; the services, plans, and billing cycles you order; your login credentials (stored securely, never in plain text).

Payment data

Our payment processor is Stripe. When you pay by card, your full card number and security code go directly to Stripe — we never see or store them. We receive and store only non-sensitive information Stripe returns to us: card brand, the last 4 digits, expiry date, and Stripe's own reference identifiers (customer ID, payment method ID, charge ID), which we use to manage your billing and process refunds. See Stripe's own privacy notice for how Stripe itself handles payment data.

Domain registration data

If you register, renew, or transfer a domain through us, the contact details you provide (name, address, email, phone) are shared with the relevant domain registry (for example, Nominet for .uk domains, or the applicable registry for other TLDs) and our accredited registrar partner, because that's a mandatory part of registering a domain — see Domain Terms.

Support and communications

The content of support tickets, contact-form messages, and any other correspondence you send us.

Security and access data

IP addresses, login timestamps, and similar technical data logged automatically when you use our client area, for account security and abuse prevention.

Why we use your data, and our lawful basis

Purposes and lawful bases for processing
PurposeLawful basis
Creating and managing your account, providing the services you order, billing and paymentPerformance of a contract with you
Responding to support tickets and enquiriesPerformance of a contract, or our legitimate interest in answering people who contact us if you're not yet a customer
Keeping accounting and tax recordsLegal obligation
Registering, renewing or transferring a domain on your behalfPerformance of a contract, and the relevant registry's own requirements
Detecting and preventing fraud, abuse, and security incidents (including reCAPTCHA)Legitimate interests — protecting our infrastructure, other customers, and you from fraud and attack

We don't use consent as a catch-all basis for processing that already has a clearer legal footing — where we do rely on consent for something specific in the future, we'll ask for it clearly and separately at that time.

Who we share data with

We share personal data only where it's genuinely needed to provide the services or meet a legal obligation — never sold, and never shared for third-party marketing.

  • WHMCS — our billing, account and support platform, which stores your account, order, ticket, and billing data on our behalf.
  • Stripe — our payment processor; see §Data we collect above for exactly what it sees.
  • Google (reCAPTCHA) — receives technical signals needed to assess whether a login or order request is automated; see §Google reCAPTCHA below.
  • Domain registries and our registrar partner — for any domain you register, renew, or transfer through us; see Domain Terms.
  • Law enforcement or regulators, where we're legally required to disclose data to them.

Software that runs on our own infrastructure to provide the service itself — for example, our hosting control panel and security tooling — is not a separate recipient of your personal data: it processes data on our own systems, under our own control, and doesn't independently receive or transmit your data to its vendor.

International transfers

Our hosting and VPS infrastructure is currently located in Poland, within the European Economic Area. The UK Government's current adequacy regulations recognise the whole EEA, including Poland, as providing an equivalent standard of data protection to the UK — so sending data to our infrastructure there is not a "restricted transfer" under UK GDPR, and no extra transfer safeguards (such as standard contractual clauses) are required for this.

Google reCAPTCHA is provided by Google, a US-based company, and some processing of the technical signals it collects may take place outside the UK/EEA as part of Google's own infrastructure. See Google's own documentation on reCAPTCHA for more detail on how it processes this data.

We're preparing UK-based infrastructure for the future. If and when that migration completes, this section will be updated to reflect it — see our Company Details page for the current, factual infrastructure location.

How long we keep your data

We don't keep personal data indefinitely. How long depends on what it is and why we have it:

How long we keep different kinds of personal data
Data categoryHow long we keep itWhy
Account, billing and invoice records6 years from the end of the relevant financial yearUK statutory minimum for company accounting records
Hosted service data (files, databases, mailboxes) after a service endsDeleted within 30 days of the service ending, unless we're legally required to keep it longerProportionate operational default — see your own backup obligations in our Terms
Support tickets and contact-form enquiriesUp to 24 months after resolution, or account closureHandling follow-up questions or disputes
Security, abuse and access logs12 months, unless needed longer for an active investigationDetecting and investigating abuse (legitimate interests)
Domain registration (registrant) dataWhile the domain is registered through us, per the relevant registry's own rules, plus our standard account/billing retention afterwardsRequired to register and maintain the domain

Security

We use reasonable technical and organisational measures to protect personal data, including access controls, encrypted connections (HTTPS), and the security tooling described on our Hosting page (CloudLinux isolation, Imunify360 malware protection). No system is completely secure, and we don't promise one that is — if we become aware of a security incident affecting your personal data, we'll handle it in line with our legal obligations, including notifying the ICO and affected individuals where the law requires it.

Cookies

Our public website sets no cookies at all. Our client area sets one strictly-necessary session cookie, and Google reCAPTCHA sets its own cookie on login/order pages. See our Cookie Notice for the full detail.

Google reCAPTCHA

We use Google reCAPTCHA on login and order forms in our client area to reduce automated fraud and abuse. Google's current published position is that it acts as a data processor for this purpose, with the site using reCAPTCHA (us) as the controller — Google processes the technical signals reCAPTCHA collects only as necessary to provide and secure the reCAPTCHA service itself. See Cookie Notice §Google reCAPTCHA for what data this typically involves.

Data you host with us

If you host a website, application, or mailbox with us, any personal data within that content (about your own customers, visitors, or contacts) belongs to and is controlled by you, not us. We process it only to provide, secure, and — where included in your plan — back up the hosting service, and we don't access, use, or share it beyond that except where required by law, by our Acceptable Use Policy, or at your request (for example, support access to fix an issue). If your own use of our services involves processing personal data on behalf of your own customers, you're responsible for having your own lawful basis and your own privacy notice for that processing — this notice covers our relationship with you, not your relationship with your own users. Our Data Processing Terms set out the full, Article 28-compliant contract terms that apply to us as your processor for this content — this section is a summary, not the complete legal position.

Children

Our services are business/technical hosting products aimed at adults setting up websites, applications, and domains — they aren't designed for, marketed to, or likely to be accessed by children. If you're under 18 you shouldn't place an order — see Terms §Who can use the services.

Marketing

We don't currently send marketing emails, run remarketing campaigns, or use analytics/tracking technology on our public website — there's nothing to opt out of today. If that ever changes, we'll update this notice and give you a clear way to control it before it starts.

Automated decision-making

We don't currently use automated decision-making that produces legal or similarly significant effects about you without human involvement (for example, automatically and permanently terminating an account with no human review). Where automated tools like reCAPTCHA flag a request as suspicious, that informs — it doesn't replace — a human response.

Your rights

Under UK data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure of your data, in some circumstances.
  • Restriction of how we use your data, in some circumstances.
  • Object to processing based on our legitimate interests — see below.
  • Portability of data you gave us, where we process it by automated means under a contract.
  • Withdraw consent at any time, for any processing that relies on it.

None of these rights are absolute — for example, we may need to keep billing records despite an erasure request, to meet our legal obligations. To exercise any of these rights, contact us at admin@pivihost.com.

Right to object

Where we process your data based on our legitimate interests (for example, fraud and abuse prevention), you can object at any time. We'll stop unless we can show a compelling, overriding reason to continue, or we need to continue to establish, exercise, or defend a legal claim. We don't currently carry out direct marketing, so the specific, stronger right to object to marketing doesn't currently apply to anything we do — if that changes, we'll make this section, and how to exercise that right, much more prominent.

Complaints

If you're unhappy with how we've handled your personal data, we'd like the chance to put it right — contact us first, using the details above. You also have the right to complain directly to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint.

Changes to this notice

We'll update this notice if what we collect, why, or who we share it with changes — including when our infrastructure moves from Poland to the UK. We'll update the "Last updated" date below whenever we do, and for a material change, we'll take reasonable steps to make sure it's noticeable, not just quietly dated.

PIVIHOST

Pivi Website Ltd · company no. 13138238

Products

  • Shared Hosting
  • Hosting — Unlimited Domains
  • VPS
  • Domains

Support

  • Knowledge Base
  • Submit a Ticket
  • Contact

Company

  • About / Contact
  • Company Details

Legal

  • Terms of Service
  • Privacy Notice
  • Acceptable Use Policy
  • Domain Terms
  • Cookie Notice
  • Data Processing Terms
© 2026 Pivi Website Ltd. All rights reserved. Client Login