How We Handle Your Personal Information
Last updated: 4 October 2026
This Privacy Policy explains how ALVORIT LTD, trading as Alvorit ("Alvorit", "we", "us" or "our"), collects, uses, stores and shares personal information when you visit alvorit.uk, create an account, purchase or use our services, contact our support team, or otherwise interact with us.
ALVORIT LTD is a company registered in England and Wales under company number 12841522, with its registered office at 5 Brayford Square, London, E1 0SG, England.
This Privacy Policy applies to our website and to services including web hosting, domain-related services, virtual private servers (VPS), dedicated servers, web design and development, technical services, billing and customer support.
1. Who Is Responsible for Your Personal Information?
For personal information used to operate customer accounts, process orders and payments, provide support, secure our systems, administer our business and communicate with customers, ALVORIT LTD generally acts as the data controller.
For personal information stored or processed within websites, servers, applications, databases or other content that a customer places on our infrastructure, we may act as a data processor on behalf of that customer. In those circumstances, the customer normally decides why and how the personal information is processed and is responsible for providing appropriate privacy information to the individuals concerned.
2. Personal Information We Collect
Depending on how you interact with Alvorit, we may collect the following categories of personal information:
- Identity information such as your name, company name and account username.
- Contact information such as your email address, telephone number, billing address and other contact details you provide.
- Account information such as account identifiers, authentication information, service preferences and account history.
- Billing and transaction information such as invoices, payment status, transaction references, selected payment method, billing history and tax-related information. Payment card details may be processed directly by our payment providers rather than stored by Alvorit.
- Service information such as the products you order, hosting packages, domains, VPS or dedicated server specifications, licence information, renewal dates and service configuration.
- Domain registration information where required to register, renew or transfer a domain name, including registrant and administrative contact information required by the relevant registrar or registry.
- Support and communications information including support tickets, emails, contact form messages, technical information, attachments and records of communications with us.
- Technical and security information such as IP addresses, login records, timestamps, browser and device information, operating system information, request logs, security events, abuse reports and diagnostic data.
- Website usage information such as pages visited, referring pages, session information and interactions with our website, where collected through permitted cookies or similar technologies.
- Web design project information such as project briefs, brand materials, business information, website content, credentials supplied for integrations and other information necessary to complete a project.
- Other information you choose to provide when contacting us, requesting a quotation or using our services.
3. How We Collect Personal Information
We may collect personal information:
- directly from you when you create an account, place an order, complete a form, request a quotation, open a support ticket or contact us;
- automatically when you use our website, client area, servers or network infrastructure;
- from payment processors when they confirm the status of a transaction;
- from domain registrars, registries and related service providers where necessary to provide domain services;
- from fraud-prevention, security, network or infrastructure providers where necessary to protect our services;
- from your organisation or another authorised person where they create or administer an account on your behalf; and
- from publicly available or lawful third-party sources where necessary for security, fraud prevention, legal compliance or business administration.
4. Why We Use Personal Information
We use personal information where necessary for the following purposes:
- to create and administer customer accounts;
- to process orders, payments, renewals and cancellations;
- to provision, operate and manage hosting, VPS, dedicated server, domain and related services;
- to deliver web design, development and technical projects;
- to communicate with you about your account, orders, invoices, renewals, service changes and support requests;
- to diagnose faults and provide technical support;
- to protect accounts, systems, infrastructure and customers from fraud, abuse, malware, attacks and unauthorised access;
- to investigate complaints, disputes, security incidents and Acceptable Use Policy violations;
- to maintain accounting, tax, corporate and legal records;
- to improve our website, products, services and customer experience;
- to send marketing communications where permitted by applicable law;
- to establish, exercise or defend legal claims; and
- to comply with legal, regulatory, court, law-enforcement, registry or network-provider requirements.
5. Our Lawful Bases for Processing
Under UK data protection law, we must have a lawful basis for processing personal information. Depending on the circumstances, we may rely on:
- Contract — where processing is necessary to enter into or perform a contract with you, such as creating your account, processing an order or providing a purchased service.
- Legal obligation — where processing is necessary to comply with applicable tax, accounting, regulatory, court or other legal requirements.
- Legitimate interests — where processing is necessary for legitimate business interests such as securing our systems, preventing fraud, managing our infrastructure, improving services, handling disputes and administering our business, provided those interests are not overridden by your rights and freedoms.
- Consent — where we specifically ask for your consent, for example for certain marketing communications or non-essential cookies where consent is required.
Where we rely on consent, you can withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.
6. Hosting, VPS and Dedicated Server Data
Customers may store or process personal information within websites, databases, email accounts, applications, VPS instances or dedicated servers supplied by Alvorit. The customer remains responsible for determining whether that processing is lawful and for complying with data protection obligations applicable to its own users, customers, employees or other individuals.
Where Alvorit processes such information only on the customer's instructions in order to provide infrastructure or technical services, Alvorit acts as a processor or sub-processor as applicable.
We may access customer-hosted systems or data where reasonably necessary to provide requested technical support, maintain the service, investigate security or abuse incidents, comply with law, or protect the rights and security of Alvorit, our customers or third parties.
7. Domain Name Information
Domain registrations and transfers may require us to provide personal information to domain registrars, registries and other organisations involved in the domain name system. The information required and the way it is displayed or protected can vary depending on the domain extension and registry rules.
Some registrars and registries act as independent data controllers for information submitted as part of a domain registration. Their own privacy notices and policies may therefore also apply.
8. Payments and Fraud Prevention
Payments may be processed by third-party payment service providers. These providers may collect and process payment details, device information, transaction information and anti-fraud data under their own privacy policies.
Alvorit may receive transaction references, payment status, limited payment method information and other information needed for billing, reconciliation, refunds, chargebacks, accounting and fraud prevention.
We may use account, payment, network and technical information to identify suspicious activity and reduce the risk of fraud, chargebacks, abuse or unauthorised account access.
9. Support Tickets and Communications
When you contact support, we process the information contained in your ticket, email, attachments and related service records so that we can investigate the issue and respond to you.
Please avoid sending passwords, private keys, payment card numbers or other highly sensitive information unless we specifically request a secure method for providing it. Where temporary credentials are required for support, you should change them after the work is complete where appropriate.
10. Cookies and Similar Technologies
Our website and client area may use cookies and similar technologies to provide core functionality, maintain sessions, protect accounts, remember preferences, operate shopping or checkout functionality and understand how our website is used.
Cookies that are strictly necessary for a service requested by you may be used without consent where permitted by law. Non-essential cookies, including certain analytics, advertising or similar technologies, will be used only where the required consent or other lawful permission has been obtained.
Where a cookie consent tool is provided, you can use it to manage non-essential cookie preferences. You can also control cookies through your browser, although blocking strictly necessary cookies may prevent parts of our website or client area from working correctly.
More detailed information about specific cookies, providers and retention periods should be provided in our Cookie Policy or cookie preference tool.
11. Marketing Communications
We may send you service-related communications that are necessary to administer your account or provide a service. These are not marketing messages and may include invoices, renewal notices, security alerts, service notices and support communications.
We may send marketing communications where you have provided valid consent or where another lawful permission applies. Where permitted, existing customers may receive information about similar Alvorit products or services, provided the applicable requirements are met and an opportunity to opt out is provided.
You can unsubscribe from marketing communications at any time using the unsubscribe method included in the message or through available account preferences. Opting out of marketing does not prevent us from sending essential service or account communications.
12. Who We Share Personal Information With
We do not sell personal information as a mailing list or customer database.
We may share personal information with carefully selected third parties where necessary for the purposes described in this Policy, including:
- payment processors and financial service providers;
- data centres, hosting, cloud, connectivity and infrastructure providers;
- domain registrars, registries and domain service providers;
- software, licensing, control-panel and technical service providers;
- email, communications and customer-support service providers;
- security, anti-fraud, monitoring and abuse-prevention providers;
- accountants, auditors, legal advisers, insurers and other professional advisers;
- government bodies, courts, regulators, law-enforcement authorities or other competent authorities where disclosure is legally required or permitted; and
- a buyer, investor or successor organisation in connection with a genuine merger, acquisition, restructuring or sale of all or part of our business, subject to appropriate confidentiality and data protection safeguards.
Where a service provider processes personal information on our behalf, we require appropriate contractual and security protections where required by law.
13. International Data Transfers
Some suppliers, infrastructure providers or service providers may process personal information outside the United Kingdom.
Where a transfer is restricted under UK data protection law, we will use an appropriate transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another legally recognised safeguard.
Where required, we also assess whether additional measures are appropriate to protect personal information in the destination country.
14. How Long We Keep Personal Information
We keep personal information only for as long as reasonably necessary for the purposes for which it was collected, including the provision of services, account administration, security, dispute resolution, legal claims and compliance with tax, accounting and other legal obligations.
Retention periods vary depending on the type of information:
- Account and service records may be retained for the life of the customer relationship and for an appropriate period afterwards to handle disputes, security issues and legal claims.
- Invoices and accounting records are retained for the period required by applicable tax and accounting law.
- Support records may be retained where they are relevant to service history, troubleshooting, security, disputes or legal obligations.
- Security and server logs are retained for periods appropriate to security monitoring, incident investigation, abuse prevention and operational requirements.
- Marketing preference records may be retained as necessary to demonstrate consent or to respect an unsubscribe or objection request.
- Backups may remain for a limited period until they are overwritten or securely deleted through the normal backup lifecycle.
When personal information is no longer required, we will delete, anonymise or otherwise securely dispose of it where reasonably practicable and legally appropriate.
15. How We Protect Personal Information
We use appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure.
Measures may include access controls, authentication controls, network and system security, logging and monitoring, encryption where appropriate, backups, vulnerability management, supplier controls and internal processes designed to limit access to people who need the information for legitimate business purposes.
No internet-connected system can be guaranteed to be completely secure. You are also responsible for using strong passwords, protecting your credentials and maintaining appropriate security for devices and systems under your control.
16. Personal Data Breaches
If we become aware of a personal data breach, we will assess the circumstances and take appropriate steps to contain, investigate and mitigate the incident.
Where required by applicable data protection law, we will notify the Information Commissioner's Office and affected individuals within the applicable legal timeframes.
17. Your Data Protection Rights
Depending on the circumstances and applicable law, you may have rights including:
- the right to be informed about how your personal information is used;
- the right to request access to your personal information;
- the right to ask us to correct inaccurate or incomplete personal information;
- the right to request erasure of personal information in certain circumstances;
- the right to request restriction of processing in certain circumstances;
- the right to receive certain personal information in a portable format where the right to data portability applies;
- the right to object to processing in certain circumstances, including certain processing based on legitimate interests;
- the right to object to direct marketing at any time;
- rights relating to certain solely automated decisions and profiling; and
- the right to withdraw consent where processing is based on consent.
These rights are not absolute and exemptions may apply. We may need to verify your identity before fulfilling a request in order to protect your information from unauthorised disclosure.
To exercise a data protection right, please contact us using the details in the Contact section below.
18. Automated Decision-Making
We may use automated tools to assist with security, fraud detection, spam prevention, service monitoring or account protection.
If we use solely automated decision-making that produces legal effects or similarly significant effects on an individual in circumstances covered by data protection law, we will provide the information and safeguards required by applicable law.
19. Children's Personal Information
Our commercial hosting, infrastructure and web services are not specifically designed for children. If personal information relating to a child is processed through a customer's website or hosted service, the customer is responsible for ensuring that its processing complies with applicable law.
If we become aware that we directly collected a child's personal information in circumstances where we do not have an appropriate lawful basis to retain it, we will take reasonable steps to address the situation.
20. Third-Party Websites and Services
Our website may contain links to third-party websites, products or services. Those organisations are responsible for their own privacy practices, and their privacy policies apply when you interact directly with them.
We encourage you to review the privacy information provided by third parties before submitting personal information to them.
21. Data Protection Complaints
If you have concerns about how Alvorit has handled your personal information, please contact us first so that we have an opportunity to investigate and respond.
You also have the right to raise a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator. Information about making a complaint is available at ico.org.uk.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, technology, suppliers, legal requirements or data protection practices.
The current version will be published on our website and will show the date on which it was last updated. Where a change materially affects how we use personal information, we will provide additional notice where required by law.
23. Contact Us
If you have a privacy question, wish to exercise a data protection right or want to make a data protection complaint, please contact:
ALVORIT LTD
Company number: 12841522
5 Brayford Square
London
E1 0SG
England
Privacy email: contact@alvorit.uk
If Alvorit appoints a Data Protection Officer or other formal privacy contact in the future, the relevant contact details will be published here.







