Privacy Policy
This policy explains what personal data HostPowr collects, why, where it is stored, who can access it and what rights you have. It is written to be read rather than skimmed past: if you are assessing us for a procurement review, sections 9 and 10 are the ones you want.
1. Who we are
HostPowr is a hosting service trading under the name BizPowr. Neither is a registered company at present, and neither should be read as identifying an incorporated legal entity. The controller for the personal data described in section 3 — the data we collect about you as our customer or as a visitor to this website — is the operator of HostPowr, trading under that name.
Controller legal name and company registration number: pending completion of registration. We will publish both here as soon as they exist, and notify account holders when we do.
EU contact address: Geraardsbergse Steenweg 120, 9090 Melle (near Ghent) Belgium. Email: hello@hostpowr.com.
For personal data that you store on our servers — your own customers' data, in your database or mailboxes — you are the controller and we are your processor. That relationship is governed by our Data Processing Agreement, not by this policy.
2. Where your data is stored
In EU Tier-III data centres. Account data, hosted files, databases, mailboxes and backups are stored in the European Union and are not replicated to any other region. There is no setting that changes this.
Where the data is stored and who can reach it are two different questions. The second is answered in section 9, in full, because it is the one that matters for an Article 28 assessment and the one most hosting policies leave vague.
3. What we collect
- Account and billing data — name, email address, billing address, company name, VAT number where supplied, and the services on your account. Handled in our WHMCS billing system.
- Payment data — processed by Paddle, our merchant of record, through our WHMCS billing system. We receive confirmation of payment and the last four digits of a card; we never see or store full card numbers.
- Technical and log data — IP addresses, access and error logs, resource usage. Generated automatically by the servers and needed to run and secure them.
- Support data — the contents of tickets and emails you send us, and our replies.
- Contact form submissions — the name, email address, subject, message and department you enter on our contact page.
- Newsletter data — your email address, if you subscribe. Only if you subscribe.
- Domain tool queries — the domain names and, for the AI name generator, the business description you type into our WHOIS, DNS, SSL and name-suggestion tools.
- Assistant messages — what you type into the chat assistant on this website, together with the page you are reading when you ask, so that "how much is this?" can be answered about the right product. The conversation is held in your browser tab for the length of your visit and is not stored on our servers or linked to your account. Your IP address is not stored: it is used to rate-limit abuse and, where our platform supplies it, reduced to a country code, with the final part of the address discarded before anything else sees it.
- Analytics data — only if you accept optional cookies. Nothing analytics-related is collected before you do.
4. What we do with it
- Create and administer your account, and give you access to the services you bought.
- Bill you, take payment and handle renewals, refunds and cancellations.
- Provide support, which necessarily means our engineers can see the account and server involved.
- Keep the platform running and secure — monitoring, abuse prevention, incident response, capacity planning.
- Send service notices you cannot opt out of, such as maintenance windows, security incidents and billing failures.
- Meet legal, tax and accounting obligations.
- Understand how the website is used — only with your consent, and only in aggregate.
We do not sell personal data, we do not share it for third-party advertising, and we do not profile you for marketing purposes.
5. Legal basis
- Performance of a contract (Art. 6(1)(b)) — account, billing, provision of the service, support.
- Legitimate interests (Art. 6(1)(f)) — platform security, abuse prevention, fraud detection, and keeping the service reliable. We have assessed that these do not override your rights; you may object under section 12.
- Legal obligation (Art. 6(1)(c)) — retaining invoices and tax records, and responding to lawful requests.
- Consent (Art. 6(1)(a)) — analytics cookies and the newsletter. Withdrawable at any time, with no effect on the service.
6. How long we keep it
- Account data — for the life of the account, then deleted within 90 days of closure, except where retention is legally required.
- Invoices and accounting records — retained for the statutory period applicable to the controller. This is a legal obligation and cannot be waived by request.
- Server and access logs — retained for up to 12 months for security and abuse investigation, then deleted.
- Support tickets — retained for 24 months after closure so that recurring issues have history.
- Contact form submissions — retained for 12 months.
- Newsletter — until you unsubscribe.
- Backups — overwritten on the cycle described in our Backup Policy. Data deleted from a live system may persist in backups until that cycle completes.
7. Hosted data (our processor role)
When you host a website, application or mailbox with us, you may store personal data about your own users. We do not inspect it, index it or use it for any purpose of our own. We access it only to deliver the service, respond to a support request you raise, or act on a legal obligation.
- You are the controller. You are responsible for having a lawful basis, for your own privacy notice, and for the consents you collect.
- We are the processor and act on your documented instructions.
- Our Data Processing Agreement applies automatically to every account under Article 28 — there is nothing to sign before you start.
- The access disclosed in section 9 applies to this data too. Read that section before you assess us.
8. Security
Encryption in transit for all services, encryption at rest for backups, role-based access control with individual accounts for staff, multi-factor authentication on administrative systems, and logging of administrative access. Servers sit in Tier-III facilities with redundant power, cooling and network, and physical access controls operated by the data centre.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay, as Articles 33 and 34 require.
9. Access from outside the EEA
We would rather state this plainly than bury it. HostPowr's engineering and support team works from our office in Lahore, Pakistan. To provide support, administer servers and respond to incidents, those engineers can access production systems — and therefore the personal data on them, including data you host as a controller.
Your data is not copied to Pakistan or stored there. It remains on servers in EU Tier-III data centres. But under the GDPR, making personal data accessible to someone in a third country is itself a restricted transfer, and Pakistan is not covered by a European Commission adequacy decision. We therefore treat this as a Chapter V transfer rather than pretending it is not one.
- The transfer is governed by the European Commission's Standard Contractual Clauses.
- A transfer impact assessment is maintained and is available to customers on request.
- Access is limited to named engineering staff, requires individual authenticated accounts, and is logged.
- Contractual confidentiality obligations apply to every person with access.
10. Subprocessors and third parties
This is the complete list of third parties that receive personal data through the service. It is maintained alongside the code, not separately.
- Paddle.com Market Ltd — our merchant of record, integrated into our WHMCS billing system. Receives your name, email and billing details, and holds the card data we never see. Acts as an independent controller for its own compliance and tax purposes, under its own privacy policy.
- Google Analytics 4 (Google Ireland Limited / Google LLC) — website analytics. Loaded only after you accept optional cookies; nothing is sent before that. IP addresses are truncated and Google Consent Mode is enabled. Involves a transfer to the United States under the EU–US Data Privacy Framework.
- OpenAI, L.L.C. (United States) — receives the business description you type into our AI domain name generator, and nothing else. Used only when you use that tool. If you would rather it were not sent, the tool also runs on a local heuristic engine; do not enter personal data into it.
- OpenAI, L.L.C. (United States) — the chat assistant can optionally send your message to a language model to phrase its answer. That enhancement is switched off unless we configure a key for it, and the assistant answers from our own documentation either way. Do not type personal data into it.
- RDAP registry services (rdap.org) — receives domain names you look up in our WHOIS and DNS tools. No account data is sent.
- UptimeRobot — monitoring data for our public status page. No customer personal data.
- ExchangeRate-API — currency conversion rates only. No personal data is sent.
- Domain registrars and registry operators — when you register or transfer a domain, the registrant details you provide are passed to the registrar and, where the TLD requires it, to the registry. This is a requirement of domain registration and cannot be avoided; see our Domain Registration Agreement.
- Our engineering team in Pakistan — see section 9.
Billing runs on WHMCS and outbound email on our own mail servers; both run on our own infrastructure and are not third parties. We will tell customers in advance of any addition to this list, and you may object on reasonable data protection grounds.
11. Cookies
Essential cookies keep the site and the client portal working, including your consent choice itself. Analytics cookies load only after you accept them, and withdrawing consent stops the collection and clears the identifiers. See our Cookie Policy for the full list.
12. Your rights
Under the GDPR you may request access to your personal data, correction of it, erasure, restriction of processing, or portability in a machine-readable format. You may object to processing based on legitimate interests, and withdraw consent at any time where consent is the basis.
Email hello@hostpowr.com to exercise any of these. We respond within one month, as Article 12 requires, and we do not charge for it. If we need more time for a complex request we will tell you why within that month.
If you are unhappy with how we handle your data, you can complain to the data protection authority in your country of residence or work. Our own lead supervisory authority is pending completion of registration; your right to complain to your local authority does not depend on it.
13. Children
Our services are sold to businesses and to adults. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
14. Changes
We will post any change here with a new effective date. Where a change materially affects how we process your personal data — a new subprocessor, a new transfer, a new purpose — we will notify account holders by email before it takes effect, not afterwards.
15. Contact
Email: hello@hostpowr.com. EU contact address: Geraardsbergse Steenweg 120, 9090 Melle (near Ghent) Belgium. Data protection officer: not currently appointed. We will appoint and name one here if our processing reaches the threshold in Article 37.
