Privacy Policy
1. Introduction and Identity of the Data Controller
ABHOSTER LTD ("we", "us", "our", or "the Company") is a company registered in Scotland, United Kingdom, with its registered office at 17a Carnegie Drive, Dunfermline, KY12 7AN. ABHOSTER LTD operates as a full-service digital agency and AdTech solutions provider.
We are the data controller in respect of personal data collected through our website at abhoster.cloud, through our contractual engagements with clients, and through our business operations generally. This Privacy Policy explains how we collect, use, process, store, share and protect personal data, and it sets out the rights available to you under applicable data protection legislation.
This Privacy Policy applies to personal data collected about: visitors to our website; individuals who make enquiries or submit briefs through our contact form; clients and their authorised representatives; suppliers, contractors and professional contacts; and individuals whose data we process on behalf of our clients in the course of providing services.
We are committed to processing personal data lawfully, fairly and transparently, and to ensuring that personal data is collected only for specified, explicit and legitimate purposes, is adequate, relevant and limited to what is necessary, is accurate and kept up to date, is retained only as long as necessary, and is processed in a manner that ensures appropriate security.
2. Legal Basis and Applicable Legislation
Our data processing activities are governed by the United Kingdom General Data Protection Regulation (UK GDPR) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018 (DPA 2018). Where we process personal data in connection with services to clients who are established in the European Economic Area, we also take account of the EU GDPR as applicable.
We rely on the following lawful bases for processing personal data as specified in Article 6 of the UK GDPR:
- Contract performance: where processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract;
- Legitimate interests: where processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms;
- Legal obligation: where processing is necessary for compliance with a legal obligation to which we are subject;
- Consent: where you have given your explicit consent to the processing of your personal data for one or more specific purposes, in particular in relation to marketing communications and non-essential cookies.
Where we process special categories of personal data, we rely on the additional conditions specified in Article 9 of the UK GDPR and the DPA 2018 Schedule 1 as applicable. In practice, we do not routinely collect special category data in the course of our normal business operations.
3. Categories of Personal Data We Collect
Depending on the nature of your interaction with us, we may collect and process the following categories of personal data:
Identity and contact data: Full name, job title, company name, business address, email address, telephone number, and any other contact details you provide to us.
Communication data: The content of communications you send to us via email, our contact form, telephone or any other channel, including the nature of your enquiry, brief details and any supporting information you choose to share.
Technical and usage data: Internet Protocol (IP) address, browser type and version, device type and operating system, pages visited on our website, referring URLs, time and date of visits, duration of page views, and other diagnostic data generated by your use of our website. This data is collected through cookies and similar tracking technologies as further described in our Cookie Policy.
Client engagement data: Information relating to your business requirements, campaign objectives, performance data, budget parameters, and any other information you provide in the course of a client engagement with ABHOSTER LTD.
Financial and transactional data: Invoice records, payment references, bank account details provided for the purpose of receiving payment, and related transactional documentation. We do not store full payment card details; any card processing is handled by authorised third-party payment processors.
Professional data: Where relevant to our engagement, information about your professional background, organisation structure, industry sector, and relevant professional credentials or certifications.
Data processed on behalf of clients: In the course of providing digital marketing, AdTech, media buying, web development and IT consulting services to our clients, we may process personal data on their behalf as a data processor. In such cases, the client is the data controller and our processing is governed by the terms of our data processing agreement with that client.
4. How We Collect Personal Data
We collect personal data through the following means:
Directly from you: When you visit our website and voluntarily submit your details via our contact form; when you telephone or email us with an enquiry; when you attend a meeting or call with our team; when you engage us as a client and provide information necessary for service delivery; and when you respond to our communications.
Automatically through our website: We collect certain technical and usage data automatically when you visit abhoster.cloud, using cookies, server logs and similar technologies. The specific cookies we use and their purposes are described in our Cookie Policy, which is available at cookie-policy.html.
From third parties: Occasionally we may receive information about you from publicly available sources, business directories or professional networking platforms where this is relevant to a business enquiry; from clients who provide us with contact details for their employees or authorised representatives; and from our technology partners in the course of providing services.
Through our service delivery: In the course of providing digital marketing, AdTech and technology services, we may access or generate data as part of campaign management, analytics reporting, platform configuration and related service activities.
5. Purposes and Legal Bases for Processing
We process personal data for the following specific purposes:
Responding to enquiries and providing pre-contractual information (Legal basis: Contract / Legitimate interests): When you contact us with an enquiry or submit a brief, we use your contact details and the information you provide to review your situation, prepare a relevant response, and communicate with you about the possibility of entering into a client engagement.
Delivering contracted services (Legal basis: Contract): Where you are an existing client, we process your personal data and any relevant business information you share with us to the extent necessary to perform the contracted services. This includes campaign management, media buying, web development, AdTech configuration, IT consulting and related activities.
Managing our business operations (Legal basis: Legitimate interests / Legal obligation): We process personal data to manage invoicing and payments, maintain our business records, manage our supplier and contractor relationships, and comply with applicable legal and regulatory requirements.
Website operation and improvement (Legal basis: Legitimate interests / Consent): We process technical and usage data to ensure that our website functions correctly, to identify and resolve technical issues, and to understand how visitors use our website so that we can improve its structure, content and user experience. Where non-essential cookies are concerned, we rely on your consent.
Marketing communications (Legal basis: Consent / Legitimate interests): Where you are an existing client or have enquired about our services, we may occasionally send you relevant information about ABHOSTER LTD services, industry insights or relevant updates. Existing clients may receive such communications on the basis of legitimate interests; for all others we rely on consent. You may opt out of marketing communications at any time.
Legal and compliance obligations (Legal basis: Legal obligation): We process personal data where necessary to comply with applicable laws, including but not limited to our obligations under the Companies Act 2006, HMRC requirements, anti-money laundering regulations and other regulatory requirements applicable to our business in Scotland and the United Kingdom.
Security and fraud prevention (Legal basis: Legitimate interests / Legal obligation): We may process personal data for the purposes of detecting, preventing and investigating fraud, unauthorised access to our systems and other security incidents.
6. Data Sharing and Disclosure
We do not sell personal data to third parties. We do not share personal data with third parties for their own marketing purposes. We share personal data only in the following circumstances:
Service providers and sub-processors: We engage carefully selected third-party service providers to assist us in operating our business and delivering our services. These include hosting and infrastructure providers, email delivery services, analytics platforms, customer relationship management software, project management tools and payment processors. All such providers are required to process personal data only on our instructions and in accordance with a written data processing agreement that meets UK GDPR requirements.
Professional advisers: We may share personal data with our legal advisers, accountants, auditors and other professional advisers where this is necessary for the provision of their services to us, subject to professional obligations of confidentiality.
AdTech and media platforms: In the course of providing digital marketing and AdTech services to clients, we may interact with advertising platforms, demand-side platforms (DSPs), data management platforms (DMPs) and other AdTech infrastructure providers. Where such interactions involve the processing of personal data relating to end consumers on behalf of our clients, we act as a data processor and such processing is subject to the relevant client data processing agreement.
Legal and regulatory requirements: We may disclose personal data to law enforcement agencies, regulators, courts or other public authorities where we are legally required to do so, or where we believe in good faith that such disclosure is necessary to protect the rights, property or safety of ABHOSTER LTD, our clients or others.
Business transfers: In the event of a merger, acquisition, reorganisation, sale of assets or similar business transfer, personal data may be transferred to the relevant parties as part of that transaction, subject to appropriate protections and notice to affected individuals as required by law.
7. International Data Transfers
ABHOSTER LTD is based in Scotland, United Kingdom, and our primary data processing activities take place within the United Kingdom. Some of our service providers and technology partners may be located in countries outside the United Kingdom, including countries within the European Economic Area and, in some cases, countries that do not benefit from an adequacy decision by the UK authorities.
Where we transfer personal data outside the United Kingdom to countries that do not have an equivalent level of data protection, we ensure that appropriate safeguards are in place as required by Article 46 of the UK GDPR. These safeguards may include International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner's Office, Standard Contractual Clauses as adapted for UK use, or reliance on adequacy regulations made under section 17A of the DPA 2018.
You may request details of the safeguards we apply to international data transfers by contacting us at the details set out in Section 13 of this Privacy Policy.
8. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, taking into account our legal obligations, the nature of our contractual relationships and the reasonable expectations of the individuals concerned.
Our general retention periods are as follows:
- Enquiry data (no subsequent engagement): 12 months from the date of last communication, after which enquiry records are securely deleted unless you have consented to retention for marketing purposes.
- Client engagement records: 7 years from the date of the final invoice or the end of the contractual relationship, in line with HMRC record-keeping requirements and standard limitation periods under the Limitation Act 1980 as applicable in Scotland.
- Financial and transactional records: 7 years from the date of the relevant transaction, in compliance with HMRC requirements.
- Website analytics data: Aggregated analytics data is retained indefinitely as it does not identify individuals. Raw IP-level data collected through server logs is retained for a maximum of 90 days.
- Marketing communication records: Retained for the duration of your consent or until you withdraw consent, plus a reasonable period to maintain suppression records.
- Legal and compliance records: Retained for the period required by applicable law or regulatory guidance, which may extend beyond the periods noted above in specific circumstances.
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data disposal procedures.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These measures include:
- Encryption of personal data in transit using TLS/SSL protocols and at rest where appropriate;
- Access controls that limit access to personal data to authorised personnel on a need-to-know basis;
- Regular security assessments and penetration testing of our systems;
- Staff training and awareness programmes covering data protection obligations;
- Procedures for detecting, reporting and managing personal data breaches in accordance with Article 33 and 34 of the UK GDPR;
- Contractual security obligations imposed on all third-party data processors and sub-processors;
- Regular review and updating of our security measures in response to evolving threats and technological developments.
No method of transmission over the internet or method of electronic storage is completely secure. While we take all reasonable steps to protect your personal data, we cannot guarantee its absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
10. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic and, with your consent, to support our marketing activities. A full description of the cookies we use, their purposes, their duration and your choices regarding them is provided in our Cookie Policy, available at cookie-policy.html.
When you first visit our website, you will be presented with information about our use of cookies and the opportunity to accept or decline non-essential cookies. You may update your cookie preferences at any time through your browser settings or by contacting us.
11. Your Rights Under UK GDPR
Subject to the conditions and limitations set out in applicable data protection legislation, you have the following rights in relation to your personal data:
Right of access: You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with supplementary information about our processing activities. This is known as a Subject Access Request (SAR). We will respond to a valid SAR within one calendar month of receipt.
Right to rectification: You have the right to require us to correct any inaccurate personal data we hold about you and to complete any incomplete personal data, taking into account the purposes of processing.
Right to erasure: Also known as the "right to be forgotten", you may request that we delete your personal data where: the data is no longer necessary for the purposes for which it was collected; you withdraw consent on which processing is based and there is no other legal basis; you object to processing and there are no overriding legitimate grounds; the data has been unlawfully processed; or erasure is required to comply with a legal obligation. This right is subject to certain exceptions, including where processing is necessary for the establishment, exercise or defence of legal claims, or for compliance with a legal obligation.
Right to restriction of processing: You may request that we restrict our processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful and you prefer restriction to erasure, or where we no longer need the data but you require it for legal claims.
Right to data portability: Where processing is based on consent or on contract performance, and is carried out by automated means, you have the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another controller.
Right to object: You have the right to object to processing based on legitimate interests or the performance of a task in the public interest, on grounds relating to your particular situation. Where personal data is processed for direct marketing purposes, you have an absolute right to object at any time.
Rights in relation to automated decision-making: You have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects on you. ABHOSTER LTD does not carry out automated decision-making of this type in our own business operations.
Right to withdraw consent: Where we process your personal data on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise any of these rights, please contact us using the details set out in Section 13. We will respond to all valid requests within one calendar month of receipt. In complex or multiple cases, we may extend this period by up to two further months, in which case we will notify you of the extension and the reasons for it within one month of receiving your request.
You will not be charged a fee for exercising your rights in ordinary circumstances. However, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive, particularly where they are repetitive.
12. Children's Data
Our website and services are directed at business professionals and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected personal data from a person under 18, we will take steps to delete such data promptly. If you believe that we have collected personal data relating to a child under 18, please contact us immediately.
13. How to Contact Us and Exercise Your Rights
For all data protection enquiries, requests to exercise your rights, or complaints about our processing of your personal data, please contact us as follows:
By email: about@abhoster.cloud
By telephone: +44 7782 554321
By post: ABHOSTER LTD, 17a Carnegie Drive, Dunfermline, KY12 7AN, Scotland, United Kingdom
Please mark correspondence clearly as a data protection request or enquiry to ensure it is directed to the appropriate member of our team.
14. Right to Lodge a Complaint
If you are dissatisfied with how we have handled your personal data or have responded to the exercise of your rights, you have the right to lodge a complaint with the supervisory authority responsible for data protection in the United Kingdom, which is the Information Commissioner's Office (ICO).
The ICO can be contacted at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. The ICO helpline number is 0303 123 1113. Their website is at ico.org.uk.
We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO, and we encourage you to contact us in the first instance.
15. Third-Party Links
Our website may contain links to third-party websites, platforms or services that are not operated by ABHOSTER LTD. This Privacy Policy does not apply to those third-party sites. We have no control over and accept no responsibility for the content or privacy practices of any third-party website or service. We recommend that you review the privacy policy of any third-party site you visit.
16. Changes to This Privacy Policy
We review and update this Privacy Policy periodically to reflect changes in our data processing activities, applicable law, regulatory guidance or best practice. When we make material changes, we will update the "last updated" date at the top of this document and, where appropriate, notify affected individuals by email or by prominent notice on our website.
We encourage you to review this Privacy Policy periodically. Your continued use of our website or services after any changes to this Privacy Policy have been published constitutes your acceptance of the updated terms, to the extent permitted by applicable law.
The current version of this Privacy Policy is always available at abhoster.cloud/privacy-policy.html.
17. Data Protection Officer
ABHOSTER LTD does not meet the threshold requiring the mandatory appointment of a Data Protection Officer under Article 37 of the UK GDPR. However, we have designated a senior internal contact responsible for data protection compliance. Data protection enquiries should be directed to about@abhoster.cloud, clearly marked as a data protection matter.
