We're a small company. We hold what we need to run your account and support it, and nothing we can't justify. This page says plainly what that is, how long we keep it, who else touches it, and what you can make us do about it.
Some of this has to use the law's words because the law defines them. Where that happens we've tried to say what they mean in practice too.
Effective January 2026 · replaces all previous versions
fluent Ltd is a company registered in England and Wales, number 04690780. We provide email hosting, website hosting, dedicated and virtual servers, web design, programming and consultancy.
For the personal information described in this policy, fluent Ltd is the data controller — meaning we decide what is collected and why, and we are responsible for it. Section 04 covers the separate situation where we handle information on your behalf rather than our own.
We are registered with the Information Commissioner's Office under registration number ZA096384.
To open and run your account we ask for information that identifies you and lets us contact you:
We also hold records generated by running the service: invoices and payment records, the domains, mailboxes and servers on your account, support correspondence, and technical logs such as connection and delivery records.
We do not store card numbers, on paper or electronically. Card payments are handled by our payment provider; we see only the confirmation that a payment succeeded or failed.
Our contact form asks for your name and email address, and optionally your phone number and a message. It also records what your enquiry is about, how urgent you've said it is, and whether you're already a customer, so it reaches the right person quickly. We use this to answer you.
The form is protected against automated abuse by Google reCAPTCHA — see section 05.
Our web servers keep standard access logs, which include the IP address making the request, the time, the page requested, and your browser's user-agent string. These are used to keep the service running and secure, and to investigate faults and abuse.
We also record visits in Matomo, our own website statistics software, which stores your IP address alongside the pages you viewed. Matomo runs on our servers and the data goes nowhere else — see section 09, including how to opt out.
UK GDPR requires us to have a specific lawful basis for each thing we do with your information. Ours are:
| What we do | Lawful basis |
|---|---|
| Run your account — provisioning, mailboxes, hosting, support | Performance of a contract |
| Invoice you and take payment | Performance of a contract |
| Keep accounting and tax records | Legal obligation |
| Tell you about changes to your service, maintenance or incidents | Performance of a contract |
| Contact you about a support issue, including abuse of your account such as it being used to send spam | Legitimate interests — keeping the platform secure and usable for everyone |
| Answer an enquiry you send us | Legitimate interests — responding to someone who has asked us to |
| Keep server and mail logs for security and fault-finding | Legitimate interests — running a reliable, secure service |
| Count and analyse visits to this website | Legitimate interests — understanding which pages work so we can improve them |
We do not send marketing email to people who have not asked for it, and we do not use your information to build advertising profiles.
This is the part most hosting privacy policies leave out, and it matters.
The content of your mailboxes, your websites and your databases may contain personal information about other people — your customers, your staff, your contacts. For that information, you are the data controller and we are your data processor. We hold and transmit it so the service works; we do not decide what it is or what it's for.
In practice that means we do not read your mail or your files except where we have to in order to fix a fault you've reported, investigate abuse, or comply with the law. Where we do, it's limited to what the task needs.
If you are subject to UK GDPR yourself, you may need a written data processing agreement with us covering this. Ask and we'll provide one.
We do not sell your information, and we do not share it for anyone else's marketing.
We do use a small number of suppliers who process information on our behalf, under contract and only on our instructions:
Our datacentre houses our servers but has no access to the data on them, and our monitoring is run in-house on our own systems rather than by an outside supplier.
Our website statistics are collected with Matomo, which we run on our own servers — nothing about your visit is sent to a third-party analytics company. See section 09.
We may also disclose information where we are legally required to — for example in response to a valid court order or a lawful request from a regulator or law enforcement body. We do not hand over customer data on informal request.
We keep information for as long as we need it for the purpose it was collected, and then dispose of it securely.
| What | How long |
|---|---|
| Your account and contact details | For as long as your account is open |
| Invoices, payment records and accounting data | Six years, as HMRC requires |
| Mailbox content — your messages and folders | 30 days after the account is cancelled, then deleted |
| Website files and databases | 30 days after the account is cancelled, then deleted |
| Backups containing a cancelled account | Up to two months in total, then overwritten |
| Server and mail logs | Two weeks live, then archived for two months and deleted |
| Quarantined spam | Fourteen days, then deleted |
| Contact-form enquiries that did not become accounts | Kept with our business correspondence — deleted on request |
| Website statistics — raw visit records | Three months, then deleted |
| Website statistics — aggregated reports | Kept indefinitely (no longer identifies anyone) |
Enquiries sent through our contact form reach us as email, and are kept alongside our ordinary business correspondence rather than in a separate system with its own clock. If your enquiry became an account, it forms part of your customer record and follows the rows above. If it did not, and you would rather we did not still hold it, ask us and we will delete it — see section 10.
Website statistics work in two layers. The raw visit records — which include your IP address — are deleted after three months. The aggregated reports built from them, which are counts and trends with nothing identifying anyone, we keep so we can compare one year with another.
You have 30 days from cancelling to retrieve anything you want to keep. After that, mailboxes, websites and databases are deleted from our live systems and we cannot get them back for you. A copy may persist in our backups for up to a further month before it is overwritten, but that is a disaster-recovery copy and not something we can restore from on request. If you would like help exporting your mail or your site, ask us during that window — or before you cancel — and we will help you do it.
Our servers are in the United Kingdom, in our London datacentre.
Our website statistics are also kept here, because we run Matomo on our own servers rather than sending them to an analytics provider.
Some of our suppliers do process information outside the UK — Stripe and Google reCAPTCHA are the clearest examples, and managed Microsoft 365 or Google Workspace mailboxes may be held in those companies' own regions. Where that happens we rely on the safeguards UK data protection law requires for international transfers, such as the UK's adequacy regulations or the International Data Transfer Agreement.
We treat your data as something to be protected against loss and unauthorised access, and we take appropriate technical and organisational measures to do that. In practice this includes firewalling, encrypted connections (TLS) for mail and web traffic, access controls limiting which of our staff can reach what, and monitoring for unusual activity.
No information sent over the internet can be guaranteed completely secure, and anyone who tells you otherwise is overselling. What we can say is that we take it seriously, we keep our platforms patched, and the people who run them are the same people who answer the phone.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and tell you where the law requires us to.
This website uses cookies sparingly.
Cookies that are strictly necessary for a service you have asked for do not require your consent, and the two above are in that category.
We use Matomo to understand which pages people read and which ones fail them. It sets cookies in your browser and records your IP address.
What matters about how we run it: Matomo is installed on our own servers in the UK. Nothing about your visit is sent to Google, to an advertising network, or to any analytics company. We use it solely to count and understand visits so we can improve the site — never for advertising, remarketing, profiling, or following you across other websites — and we do not share the data with anyone else for their purposes.
Because it is used purely for statistics of that kind, we rely on the statistical-purposes exception in the Data (Use and Access) Act 2025 rather than asking you to click through a consent banner. That exception comes with an obligation on us to tell you plainly what we are doing — which is what this section is for — and to let you opt out easily.
To opt out of our website statistics, use the control below. It takes effect immediately and we will not count your visits from this browser.
You can also block or delete cookies through your browser's settings. If you block them, signing in to the control panel will stop working.
Under UK data protection law you have the right to:
Much of this you can do yourself: the control panel lets you review and update your details at any time. For anything else, write to us using the details below. We will respond within one month, and we will not charge you for it unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk or on 0303 123 1113. Complaining to us does not affect your right to go to the ICO.
We update this page when what we do changes, or when the law does. The effective date at the top tells you which version you're reading. If we make a change that materially affects how we handle your information, we will tell existing customers by email rather than relying on you to check.
For any question about this policy, about the information we hold, or to exercise any of the rights in section 10:
Privacy ContactOr call us on 01296 329 200, or use the contact form. If your enquiry is about data protection specifically, say so and it will go to the right person.