How we collect, use, protect, retain, and share personal data when you use our websites, client portal, hosting, domain, email, and support services.
This Privacy Policy applies to Z4Host websites, client accounts, orders, hosting, servers, domains, email, technical support, and related services. “Z4Host”, “we”, “us”, and “our” refer to the Z4Host contracting entity shown on your order or invoice.
For account, billing, sales, security, and support information, Z4Host generally acts as controller or business. For personal data that a customer uploads to or processes through a hosted service, the customer controls the purposes and means of processing and Z4Host acts only as processor or service provider to the extent applicable.
We collect data from you, authorised account users, service use, payment and identity providers, domain registrars and registries, infrastructure providers, fraud-prevention sources, and public or lawful sources.
Depending on the location and context, we rely on performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, compliance with legal obligations, protection of vital interests, or consent. Where consent is the basis, it may be withdrawn without affecting earlier lawful processing.
Our cloud infrastructure is distributed so that services may be placed in, or delivered through, the nearest suitable available region. Principal locations include nine European countries, Singapore, Canada, the United States, and Dubai. Routing, resilience, capacity, product availability, customer selection, and incident response can result in processing in another region.
Where data crosses borders, we use applicable contractual, organisational, or legal safeguards. Customers remain responsible for selecting a lawful service location for their content and for giving required notices to their own users.
Routine operational and activity logs are normally limited to essential events and retained for up to 10 days, subject to platform capability and lawful operational need. We do not promise detailed or forensic logging unless a specific service says so.
Account, invoice, payment, tax, domain, support, abuse, incident, security-audit, backup, dispute, and legally required records may be retained longer for the contract, accounting rules, limitation periods, fraud prevention, legal claims, or regulator and registry obligations. Data is deleted or anonymised when no longer reasonably required, subject to backup rotation and legal holds.
We use proportionate access controls, encryption in transit where supported, credential hashing or encryption provided by established hosting and billing platforms, monitoring, patching, and least-privilege practices. No internet service can guarantee absolute security.
Customers must use unique passwords, protect devices and recovery channels, restrict authorised users, and enable two-factor authentication wherever offered. A person who successfully authenticates with valid credentials may be treated as authorised. The customer bears the increased risk caused by credential disclosure, password reuse, insecure devices, or choosing not to enable two-factor authentication.
Email mailbox security is the customer’s responsibility after credentials are issued. Our responsibility is to apply the configured authentication and access controls and not knowingly disclose credentials except where legally or operationally necessary. We are not responsible for compromise caused outside systems under our control.
Customers are responsible for the legality, accuracy, security, retention, and backup of content they host. On unmanaged servers, the customer is solely responsible for system administration, patching, access control, application security, backup testing, and recovery. Managed services cover only the tasks expressly listed in the order.
Unless a separate backup product or written managed-backup commitment is included, backups are not guaranteed and must not be the customer’s only copy. Z4Host may access hosted data only as needed to fulfil instructions, support the service, protect systems, investigate misuse, or comply with law.
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; opt out of marketing; or complain to a supervisory authority. Rights can be limited by identity verification, another person’s rights, legal retention duties, security, or valid legal claims. Submit requests to info@z4host.com. We may ask for reasonable verification before acting.
Services are intended for persons able to enter a binding contract and are not directed to children. Do not submit a child’s data unless you have lawful authority and all required consent.
We may update this policy for legal, technical, or service changes. The effective date will be updated, and material changes will be notified through the website, client portal, or account contact where appropriate.
Privacy questions and rights requests: info@z4host.com. The responsible contracting entity is the entity identified on the customer’s order or invoice.