Privacy Policy & Data
This policy (together with any ancillary documents referred to in it) sets out the basis on which any personal data we collect from you or provide will be processed.
Please read the following carefully to understand how we will treat and regard your personal data.
About us
A.I.H. (STRANRAER) LTD (allinclusivehosting.com) is a registered company in England & Wales (Company number SC777835). Our registered address is 1 Laundry Burn Close, Stranraer, Scotland, DG9 7NF
A.I.H. (STRANRAER) LTD may be both a data controller and data processor of personal data. Our designated Data Protection Officer can be contacted at our registered address.
What information do we collect?
Any personal information that you provide by filling in forms on our website. This includes information provided when registering an account, purchasing services from us or requesting further services. We may also ask you for information when you report a problem with our site or the services you have purchased.
If you contact us by letter or email, records of the correspondence may be kept.
Telephone conversations may be recorded for training purposes.
Details of transactions you carry through our site and the fulfilment and administration of your orders.
We also record technical data such as your operating system, browser type, referring / exit pages and URLs, number of clicks, domain names and pages viewed in our server logs. This information is used for marketing and security purposes.
In the circumstances where we are acting as a data processor, we shall only act on our customer’s instructions as the data controller. If you provide us with personal data about a third party (for example, when registering a domain on their behalf), you warrant that you have obtained express consent from the third party for the disclosure and use of their personal data.
How we use personal data
-
- To register a customer account.
- To process orders that you have placed with us.
- To handle customer service and career enquiries.
- To ensure that content from our site is presented most effectively for you and your computer.
- To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.
- To carry out our obligations arising from any contracts entered into between you and us.
- To allow you to participate in interactive features of our service when you choose to do so.
- To notify you about changes to our service.
- To carry out marketing and statistical analysis
A.I.H. (STRANRAER) LTD will never sell your personal data to third parties. Automatic decision making
We may use the information provided by you to perform automatic decisions about the acceptance of orders you place. Automatic decision making helps us combat fraud and abuse; this information never leaves our network.
Where we store your personal data
The personal data that we collect from you will be stored on our servers inside the European Economic Area (“EEA”). Occasionally, we may have to transfer personal data outside of the EEA. For example, domain registration data must be sent to our domain registrar outside the EEA. By submitting your personal data, you agree to this transfer, storing or processing of data outside the EEA. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with the GDPR and our data protection policies.
Data retention
- We only retain your personal data for as long as we need it to fulfil the purposes for which we have initially collected it unless otherwise required by law. We will retain and use information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements as follows:
- Invoice data is kept for a minimum of 6 years as required under UK Law
- Log files are rotated every 12 weeks. However, anonymised data may be kept for longer.
A.I.H. (STRANRAER) LTD (allinclusivehosting.com) infrastructure backups are kept for 12 months. Web Hosting data is kept for 30 days.
In the rare event backups containing personal information are restored post-deletion, allinclusivehosting.com will make every reasonable effort to ensure data that has been forgotten is not inadvertently restored, and all traces of data are removed within a maximum of 180 days unless additional retention obligations apply.
Your rights
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data: –
- The right to request a copy of your personal data which we hold about you.
- The right to request that we correct any personal data if it is found to be inaccurate or out of date. You can view, edit and remove your personal data through the allinclusivehosting.com control panel.
- The right to object to our use of your personal data and request your personal data is erased where it is no longer necessary for us to retain such data. This is known as your right to be forgotten. Please note that there may be legal reasons why we must keep your data, but please inform us if you think we are retaining or using your personal data incorrectly.
- You have the right to ask us not to process your personal data for marketing purposes. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by following the Unsubscribe link at the bottom of any emails we send, contacting Customer Services or writing to us at A.I.H. (STRANRAER) LTD, 1 Laundry Burn Close, Stranraer, Scotland, DG9 7NF
- The right to lodge a complaint with the Information Commissioners Office. Please see https://ico.org.uk/make-a-complaint/ for further information.
Who do we share your information with?
By entering into this agreement, you agree to data processing by the third parties listed below. When we introduce any new or change any existing third-party agreements, we will ensure this policy is updated at least 30 days before the new third party processes any data.
| Company | Service |
| Worldpay | Credit/Debit Card Payments |
| MasterCard Payment Gateway Services | Direct Debit Payments |
| Nominet | Domain Names |
| Tucows (OpenSRS) | Domain Names |
| GeoTrust (Symantec) | SSL/TLS Certificates |
| Slack | Internal communication of support issues/service incidents. |
| Google: including Adwords, Google Analytics, Youtube, Drive, Data Studio, and Google My Business. | Site analytics, targeting and exclusion from PPC advertising, purchasing data. Reporting on anonymised data. |
| Facebook & Instagram | Targeting and exclusion from PPC advertising and purchasing data. |
| Targeting and exclusion from PPC advertising | |
| Microsoft: Bing and Office 365 | Site analytics, targeting and exclusion from PPC advertising, purchasing data. |
| Mailchimp | Sending email and email analytics. |
| Hotjar | Testing of site optimisations (All personal data is anonymised). |
| OptinMonster | Newsletter signup forms and other models. |
Data breaches
We may obtain information about your general Internet usage by using a cookie file stored on your computer’s hard drive. Cookies contain information that is transferred to your computer’s hard drive. They help us to improve our site and to deliver a better and more personalised service. They enable us:
- To estimate our audience size and usage pattern;
- To store information about your preferences and so allow us to customise our site according to your individual interests;
- To speed up your searches;
- To recognise you when you return to our site.
- Remarketing – For example, once you have visited our website, you may see allinclusivehosting.com adverts to remind you of our products. We also use cookies to exclude existing customers from seeing our adverts.
You may refuse to accept cookies by activating the setting on your browser, which allows you to refuse the setting of cookies. However, if you select this setting, you may be unable to access certain parts of our site. Unless you have adjusted your browser setting to refuse cookies, our system will issue cookies when you log on to our site.
Third-party links
Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
Changes to this policy
We keep our privacy policy under regular review and will place any updates on this web page. This privacy policy was last updated on 9th August 2023.
How to contact us
Please contact us if you have any questions about our privacy policy or information we hold about you: aih@allinclusivehosting.com – You can also write to our registered address: 1 Laundry Burn Close, Stranraer, Scotland, DG9 7NF
GDPR Data Processing Agreement
This Data Processing Agreement (“DPA”) is an addendum to the Terms & Conditions between A.I.H. (STRANRAER) LTD – allinclusivehosting.com (“AIH”) and you (“Customer”). The DPA will be effective and replace any previously applicable data processing and security terms as of 25th May 2018 and will continue for as long as AIH provides the services as set out in AIH Ltd Terms & Conditions.
Definitions
“Customer Data” means data provided by or on behalf of the Customer or Customer End Users via the Services under the account.
“Data Controller” means the entity that determines the purposes and means of processing Personal Data.
“Data Processor” means the entity that processes Personal Data on behalf of the Data Controller.
“Data Protection Laws” means all data protection and privacy laws and regulations applicable to processing Personal Data under the Agreement, including the GDPR.
“Data Subject” means the individual to whom the Personal Data relates.
“EEA” means the European Economic Area.
“GDPR” means EU General Data Protection Regulation 2016/679.
“Personal Data” means any Customer Data relating to an identified or identifiable natural person to the extent that such information is protected as personal data under GDPR.
“Processing” has the meaning given to it in the GDPR, and “process”, “processes”, and “processed” shall be interpreted accordingly.
“Sub-Processor” means any third party authorised under this DPA to have logical access to and process Customer Data to provide parts of the Services.
“Services” means any product or service provided to Customer and as described in A.I.H. (STRANRAER) LTD (allinclusivehosting.com) Terms & Conditions.
Data Processing
AIH will only act and process Customer Data in accordance with the documented instruction from Customer (the “Instruction”), unless required by law to act without such Instruction. The Instruction at the time of entering into this DPA is that AIH may only process Customer Data with the purpose of delivering Services as described in its Terms & Conditions and any product-specific agreements. Subject to the terms of this DPA and with the parties’ agreement, Customer may issue additional written instructions consistent with the terms of this Agreement. The customer is responsible for ensuring that all individuals who provide instructions are authorised to do so.
AIH will inform the customer of any instruction it deems to be violating GDPR and will not execute the instructions until they have been confirmed or modified.
When AIH processes Customer Data, both parties acknowledge and agree that:
– AIH is a Data Processor of Customer Data under the GDPR
– Customer is a Data Controller of Customer Data under GDPR.
Confidentiality
AIH shall treat all Customer Data as strictly confidential information. Customer Data may not be copied, transferred or otherwise processed in conflict with the Instruction from Customer unless required by law.
AIH employees shall be subject to an obligation of confidentiality that ensures that the employees shall treat all Customer Data under this DPA with strict confidentiality and only process Customer Data in accordance with the Instruction.
Sub-Processing
The customer authorises AIH to engage third parties to process Customer Data (“Sub-Processors”) without obtaining any further written, specific authorisation. AIH will restrict Sub-Processor access to Customer Data to what is necessary to provide the Services.
AIH shall complete a written agreement with any Sub-Processors. Such an agreement shall, at minimum, provide the same data protection obligations as the ones applicable under this DPA. It remains accountable for any Sub-Processor in the same way as for its own actions and omissions.
AIH will inform the customer of any new Sub-Processor engagements at least 30 days before the new Sub-Processor processes any Customer Data. Notifications of such engagements will be delivered to the account email address and/or through the control panel interface. The customer’s responsible for ensuring account information is correct and kept up to date.
The customer has the right to object to the use of a Sub-Processor by terminating this Addendum and Services in accordance with AIH Terms and Conditions. A list of current Sub-Processors can be found in Annex 1.
Security
AIH will implement and maintain technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access as set out in Annex 2 of this Addendum and in accordance with GDPR, article 32. The security measures are subject to technical progress and development, and Customer acknowledges that AIH may update or modify the security measures from time-to-time, provided that such updates and modifications do not result in the degradation of the overall security. In addition, AIH will make controls available to Customers to secure Customer Data inside the control panel further.
Data Breach Notifications
If AIH becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, Customer Data on systems managed by or otherwise controlled by AIH, AIH agrees to notify the customer without hesitation or delay. Notifications of such incidents will be sent to the account email address as set by the customer. The customer’s responsible for ensuring this information is correct and kept up to date inside the control panel.
AIH will make reasonable efforts to identify the cause of any breach and take necessary steps to prevent such a breach from reoccurring.
The customer agrees that Data Breach Notifications will not include unsuccessful attempts or activities that do not compromise the security of Customer Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.
Data Subject Rights
If AIH directly receives a request from a Data Subject to exercise such rights in relation to Customer Data, it will forward the request to the customer. The customer must respond to such requests within the timeframes specified within GDPR.
AIH will assist the customer in fulfilling any obligation to respond to requests by data subjects, which may include providing controls via the control panel to help comply with the commitments set out under GDPR.
Data Transfers
AIH stores and processes data in secure datacentres located inside the European Economic Area (“EEA”). Data may be transferred and processed outside the EEA to countries where Sub-Processors maintain their own data processing operations. The customer hereby agrees to transfer, store or process data outside the EEA. AIH will take all necessary steps to ensure that Customer Data is treated securely and per the relevant Data Protection Laws.
Compliance and Audit Rights
AIH agrees to maintain records of its security standards and, upon written request by Customer, AIH shall make available all relevant information necessary to demonstrate compliance with this DPA. The customer agrees any audit or inspection shall be carried out with reasonable prior written notice of no less than 30 days and shall not be conducted more than once in any 12-month period. If AIH declines the request, the customer can terminate this addendum and Services.
Return or Deletion of Data
AIH only retains Customer Data for as long as required to fulfil the purposes for which it was initially collected. Termination of this Addendum or Services in line with AIH Terms & Conditions will result in all Customer Data being deleted unless otherwise required by law. For Customer Data archived on backup systems, AIH shall securely isolate and protect from any further processing.
Limitation of Liability
The total liability of each part under this addendum shall be subject to the limitation of liability as set out in AIH Terms & Conditions. For the avoidance of doubt, AIH will not be liable for any losses or damages suffered by Customer where Customer is using Services in violation of its Terms & Conditions, regardless of whether it terminates or suspends an account due to such violation.
Annex 1 – Sub-Processors
| Company | Service |
| Worldpay | Credit/Debit Card Payments |
| MasterCard Payment Gateway Services | Direct Debit Payments |
| Nominet | Domain Names |
| Tucows (OpenSRS) | Domain Names |
| GeoTrust (Symantec) | SSL/TLS Certificates |
| Google Analytics | Control panel analytics. Reporting on anonymised data. |
| Xero | Financial Accounting |
Annexe 2 – Security Measures Available upon request.


