GDPR Compliance Policy

Effective Date: January 2025  ·  Last Updated: January 2025

Romoss Hosting ("Company," "we," "our," or "us") is committed to protecting personal data and complying with the General Data Protection Regulation (GDPR) and UK GDPR applicable to individuals located in the United Kingdom and the European Economic Area (EEA). This GDPR Policy explains how we collect, process, store, and protect personal data in accordance with these requirements.

1. Company Information & Data Controller

Romoss Hosting — Data Controller

21 Douglas Close, Wallington, SM6 9JS, United Kingdom
Owner: Mr Burgess William Martin

2. Scope of This Policy

This policy applies to visitors to our website, customers using our hosting services, and individuals located in the United Kingdom or the European Economic Area (EEA).

3. Lawful Basis for Processing

Romoss Hosting processes personal data under the following lawful bases:

  • Contractual necessity — To provide and manage hosting services you have purchased
  • Legal obligation — To comply with applicable UK and EU laws and regulations
  • Legitimate interests — To improve our services, maintain security, and prevent fraud
  • Consent — For marketing communications or non-essential cookies, where you have given explicit consent

4. Personal Data We Collect

We may collect name, email address, phone number, billing details, IP address, and account and usage information. We collect only data that is necessary to provide our services and fulfil our legal obligations.

5. How We Use Personal Data

We use personal data to deliver and manage hosting services, process payments, provide customer support, improve website performance, ensure security and prevent fraud, and comply with legal obligations. We do not sell personal data to third parties under any circumstances.

6. Your Rights Under UK GDPR & GDPR

If you are located in the UK or EEA, you have the following rights:

  • Right of Access — Request a copy of personal data we hold about you
  • Right to Rectification — Request correction of inaccurate or incomplete data
  • Right to Erasure — Request deletion of your personal data ("Right to be Forgotten")
  • Right to Restrict Processing — Request that we limit how we use your data
  • Right to Object — Object to processing based on legitimate interests
  • Right to Data Portability — Receive your data in a structured, machine-readable format
  • Right to Withdraw Consent — Withdraw consent at any time where processing is consent-based

To exercise any of these rights, contact us at abdussamadamazon@gmail.com. We will respond within the timeframe required by UK GDPR (typically 30 days).

7. International Data Transfers

Where personal data is transferred outside the United Kingdom or EEA, Romoss Hosting implements appropriate safeguards including standard contractual clauses and adequacy decisions to ensure your data is protected to an equivalent standard.

8. Data Security Measures

We implement technical and organisational security measures including secure server infrastructure, encrypted data transmission (SSL/TLS), access control and user authentication, regular system updates and vulnerability patching, and routine security audits.

9. Data Retention

We retain personal data only as long as necessary to provide services, meet legal obligations, resolve disputes, and enforce our agreements. When data is no longer required, it is securely and permanently deleted.

10. Data Breach Procedures

In the event of a personal data breach posing risk to individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours where required, inform affected individuals where necessary, and take immediate steps to contain and mitigate the breach.

11. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom at ico.org.uk, or with the relevant supervisory authority in your country.

12. Updates to This Policy

Romoss Hosting may update this GDPR Policy from time to time to reflect changes in law or our practices. Updates will be posted on this page with a revised effective date.