Scope and our different roles
The right contact and rules depend on why we have the information.
This policy applies to this website, quote and business communications, customer account administration, and personal information we handle for our own business purposes. In those contexts, HYPERHOSTGATE LLC generally decides why and how the information is used and acts as a controller or business.
When we host or otherwise process information that a customer places in a purchased service, that customer generally decides why and how the information is used. We act as its processor, service provider, or contractor to the extent stated in the applicable agreement. The customer's privacy notice, not this policy, explains its practices.
Information we handle
| Context | Information | How it reaches us |
|---|---|---|
| Website and infrastructure | IP address, request date and time, requested path or query, response status, referrer, browser or user-agent details, and security event information. For quote submissions, we also create a cryptographic IP pseudonym, rate-limit records, request and idempotency hashes, a receipt, and delivery status and timestamps. | Hosting, delivery, and security systems may create request logs when a page or asset is requested. The quote endpoint creates the additional records when a form is submitted. |
| Consent preferences | Your consent choice and the browser-level technical information Termly needs to display, apply, and remember that choice | You interact with the Termly consent interface or reopen it through the footer's consent-preferences control. |
| Quote and other communications | Name, email address, organization, domain or project, selected illustrative plan and billing cycle, location preference, launch timing, requirements, and anything else you choose to include | You submit the website quote form or send it by email, phone, or another agreed communication channel. |
| Customer relationship | Business contact details, order and support history, authorized-user information, service configuration, billing records, and transaction references | You, your organization, and systems used to administer an order or payment provide it. |
| Customer-hosted services | Content, logs, account information, and other data a customer submits to or generates through an ordered service | The customer or its users submit or generate it under the customer's instructions. |
Do not put passwords, access keys, health data, payment-card data, bank-account details, or other secrets in a quote request. The endpoint rejects likely payment-card and account data before storage, but that automated safeguard is not a substitute for leaving sensitive data out.
We use Termly to manage browser-level consent preferences, and that consent service may use strictly necessary cookies or browser storage to apply and remember a choice. We do not deliberately use analytics, advertising pixels, behavioral advertising tools, or browser fingerprinting on this site today, and we do not embed a payment SDK or collect card details here. Read our Cookie Policy for the current details.
Why we use information
Depending on the context, we use information to:
- respond to questions and prepare, negotiate, or fulfill an order;
- provide support and administer a customer relationship;
- operate, troubleshoot, protect, and improve services;
- authenticate authorized contacts and prevent fraud or abuse;
- record and apply consent preferences;
- keep business, tax, accounting, and dispute records; and
- comply with law and enforce our agreements.
Legal bases where GDPR or UK GDPR applies
| Purpose | Legal basis |
|---|---|
| Answering a request and taking steps toward an order | Steps at your request before a contract, performance of a contract, or our legitimate interest in responding to business inquiries |
| Delivering and supporting an ordered service | Performance of a contract and our legitimate interest in operating reliable services |
| Security, abuse prevention, and troubleshooting | Our and our customers' legitimate interests in protecting systems, users, and services; legal obligation where one applies |
| Required business and compliance records | Legal obligation or legitimate interests |
| An optional use that specifically asks for permission | Consent, which you may withdraw for future use |
We do not use information collected through this site to build advertising profiles or make decisions based solely on automated processing that produce legal or similarly significant effects.
When we disclose information
We disclose information only when reasonably needed for a stated purpose, subject to the recipient's role and appropriate restrictions. Recipients may include:
- Cloudflare infrastructure and D1, Resend, the configured business-mail provider, Termly, and other infrastructure, communications, support, billing, or service providers that help us run the business or fulfill an order;
- professional advisers such as lawyers, auditors, accountants, and insurers where their work requires it;
- a buyer, investor, lender, or successor involved in a proposed or completed business transaction, subject to suitable safeguards;
- courts, regulators, law enforcement, or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, services, or the public; and
- another party when you direct us or give valid permission.
We do not use personal information collected through the current public marketing site for sale or cross-context behavioral advertising, and the application code contains no advertising integration. We do not use customer-hosted data for our own advertising. These statements describe the current public site and must be reassessed if the service or business model changes.
Customer-hosted data
For customer-hosted data, we process on the customer's documented instructions as described in the order and applicable data-processing terms, unless law requires otherwise. The customer is responsible for giving notices, establishing a lawful basis, handling requests from its users, configuring the service appropriately, and ensuring the service is suitable for the information it chooses to process.
If your information appears on a website or application hosted for one of our customers, contact that customer first. We may refer your request to the customer because we generally cannot decide how its data should be used or deleted. We will assist the customer where the applicable agreement and law require it.
Retention and security
We retain personal information only for as long as reasonably needed for the purpose described above, taking account of the customer relationship, the nature and sensitivity of the information, security and continuity needs, legal recordkeeping duties, and the time in which claims may arise. We delete, anonymize, or restrict it when it is no longer needed, unless law permits or requires longer retention.
Website quote records are stored in D1 before notification delivery. Resend and the configured mail provider may retain delivery or mailbox copies under their service and account settings, and configured mail forwarding may create another mailbox copy. We do not state a fixed period here because the applicable operational, account, legal, and dispute requirements can differ; the factors above govern retention.
Customer-hosted data follows the retention, return, and deletion terms in the applicable order or data-processing agreement. Backups and security records may age out on separate operational cycles where the agreement allows.
We use administrative, technical, and organizational safeguards designed for the nature of the information and service. No method of transmission, storage, or security is risk-free, so this policy is not a guarantee that an incident cannot occur. See our Trust & Security page for our commitments and reporting channel.
International transfers
HYPERHOSTGATE LLC is based in the United States. Information may be processed in the United States and in other service locations confirmed for an order. Those places may have privacy laws different from those where you live.
Where transfer restrictions apply, we will use a lawful transfer mechanism appropriate to the circumstances and provide information about it when the applicable law requires. This statement does not claim that any particular transfer mechanism or data center applies to every service; the actual arrangement must be verified for the relevant order.
Your privacy rights
Depending on where you live, the law that applies, and our role, you may have rights to ask for access, correction, deletion, restriction, portability, or information about our use and disclosure of personal information. You may also have a right to object to certain processing, withdraw consent for future processing, appeal a request decision, or complain to a privacy regulator.
EEA, Switzerland, and United Kingdom
Where the relevant data-protection law applies, rights may include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may lodge a complaint with the supervisory authority responsible for your location. These rights have legal limits and exceptions.
California and other U.S. states
If a state privacy law applies to HYPERHOSTGATE LLC and to your information, rights may include knowing or accessing information, correction, deletion, portability, opting out of covered sale, sharing, targeted advertising, or profiling, limiting certain uses of sensitive information, and non-discrimination. Applicability depends on statutory scope and thresholds; this policy does not claim that every state law applies to us.
Because the current marketing site does not include a sale, cross-context behavioral advertising, or targeted-advertising integration, there is no such site activity for a preference control to change today. If a covered practice is introduced, we will add the notices and controls required by applicable law before it begins.
How to make a request
Email us with “Privacy request” in the subject and describe the right you want to exercise. We may ask for information reasonably necessary to verify your identity, authority, and the records involved. An authorized agent may submit a request where applicable law permits; we may verify the authorization. We respond within the period the applicable law requires and explain if an exception applies.
Children
Our website and hosting offers are directed to organizations and adults, not children. We do not knowingly seek personal information from children through this site. If you believe a child has provided personal information to us without the authorization required by applicable law, contact us so we can investigate and take appropriate action.
A customer that uses an ordered service for content or users involving children is responsible for confirming that use is permitted and for obtaining any required parental authorization before processing begins.
Changes and contact
We may update this policy when our practices, services, or legal obligations change. We will post the revised policy here and update its effective date. If a change materially affects information we already hold, we will provide any additional notice or choice required by applicable law.