Legal
Privacy Policy
What personal data we collect when you enquire, buy or use our hosting services, what we do with it, and the rights you have over it.
Last updated: 11 August 2026
Template document — not yet legal advice
This document is a template provided for information only. It has not yet been checked by a qualified legal adviser, and it must be reviewed by one before this site goes live. Nothing here is legal advice, and nothing here is a substitute for it. Where this document differs from the signed agreement, order form or statement of work between you and Coffee Cup Solutions Ltd, that signed agreement takes precedence.
Who we are
Coffee Cup Hosting Services is a trading name of Coffee Cup Solutions Ltd, a company registered in England and Wales under company number 08905462, with its registered office at Unit 3, Millars Brook, Wokingham, Berkshire RG41 2AD, United Kingdom. Our VAT registration number is GB185644476.
In this policy, “we”, “us” and “our” mean Coffee Cup Solutions Ltd. We are responsible for deciding how personal data described in this policy is handled, except where we say otherwise below.
What this policy covers
This policy explains how we handle personal data when you visit this website, make an enquiry, buy hosting or related services from us, or contact our support desk. It applies to personal data we handle as a controller — that is, where we decide why and how the data is used.
We also process personal data on behalf of our customers, as a processor, when that data sits inside websites, applications, mailboxes or servers that we host. That processing is governed by the data processing terms in the customer's service agreement rather than by this policy. The section Controller or processor: which role we are in explains the difference.
We handle personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The personal data we collect
Information you give us directly
When you complete an enquiry form, request a quote, email us or ring us, we collect the information you choose to provide. Typically that includes:
- your name and the organisation you work for;
- your email address and telephone number;
- your job title or role, where you tell us;
- the content of your enquiry, including any technical details you share about what you are running;
- notes taken by our team during calls, meetings and correspondence with you.
Please do not include special category data, security credentials or other sensitive material in a website enquiry form. If you need to send us something sensitive, ask us and we will arrange a more appropriate route.
Information we collect when we deliver services to you
If you become a customer, we hold the information needed to run your account and your services. That usually includes:
- account and contact details for the people authorised to raise requests or approve changes;
- billing details, purchase order references, invoices and payment records;
- support tickets, call records and correspondence relating to your services;
- technical records such as service configuration, domain and DNS records, change history, monitoring alerts and access logs;
- authentication records for any control panel, portal or administrative account we issue to you.
We do not store full payment card numbers. Where card payment is offered, it is handled by a regulated payment provider and we receive only a confirmation and a partial reference.
Information collected automatically by this website
Our web servers keep standard logs when a page is requested. These include the requesting IP address, the date and time, the page or file requested, the referring page and the browser user agent string. We use these logs to keep the site available, to diagnose faults and to detect and block abuse. They are not used to build marketing profiles.
Cookies and similar technologies
This website sets cookies that are strictly necessary for it to work — for example to maintain your session and to protect forms against cross-site request forgery. These do not require your consent.
Where we use analytics or other non-essential cookies, we will ask for your consent first and you can withdraw it at any time. You can also block or delete cookies through your browser settings, although parts of the site may then not work as intended.
Recruitment and supplier contacts
If you apply for a job with us, or you are a contact at one of our suppliers or partners, we hold the contact and correspondence details needed for that relationship. We keep recruitment data only for as long as we need it to run the recruitment process and to deal with any follow-up, unless you agree to us keeping it longer for future vacancies.
Controller or processor: which role we are in
We are the controller for the personal data of our own enquirers, customer contacts, suppliers and job applicants — the data described above.
We are a processor for personal data that our customers hold within the services we host on their behalf: the contents of their databases, websites, applications, mailboxes, backups and file storage. In that role we act only on the customer's documented instructions, except where UK law requires otherwise. Our customers remain the controller for that data and are responsible for having a lawful basis for it, for informing their own data subjects, and for responding to those individuals' requests. If you believe your personal data is held inside a system we host for one of our customers, please contact that organisation directly; we will support them in responding.
Why we use personal data, and our lawful bases
UK GDPR requires us to have a lawful basis for each purpose. Ours are as follows.
- To respond to enquiries and prepare quotes. Our legitimate interests in responding to people who approach us about our services, and taking steps at your request before entering into a contract.
- To provide, support and administer the services you buy. Performance of our contract with you, or with the organisation you represent.
- To invoice, take payment and manage debt. Performance of the contract, and our legitimate interests in being paid for work we have done.
- To keep our platforms secure and available. Our legitimate interests in protecting our infrastructure, our customers and ourselves from misuse, fraud and attack.
- To keep accounting, tax and statutory records. Compliance with our legal obligations.
- To send service messages — maintenance notices, incident updates, renewal reminders and changes to terms. Performance of the contract, and our legitimate interests in keeping customers informed.
- To send marketing about related services to business contacts. Our legitimate interests, or your consent where the law requires it. Every marketing message includes an unsubscribe link and you can opt out at any time without affecting the service you receive.
- To establish, exercise or defend legal claims. Our legitimate interests in protecting our legal position.
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms. You can ask us for more detail about that assessment, and you can object to that processing — see Your rights.
How long we keep personal data
We keep personal data only for as long as we need it for the purpose we collected it for, and then for any period we are required to keep it by law. In practice that means:
- Enquiries that do not become customers — kept for a limited period so we can pick the conversation back up if you return to us, then deleted.
- Customer account, contract and support records — kept for the life of the relationship and then for a further period to cover queries, warranties and the limitation period for legal claims.
- Invoices and accounting records — kept for the period required by UK tax and company law.
- Server, access and security logs — kept on a short, rolling cycle sized to what we need for troubleshooting and security investigation.
- Customer data inside hosted services and backups — retained for the retention period agreed in the customer's service agreement, and removed on the timescale set out there after the service ends.
The specific retention period that applies to your services is set out in your service agreement. If you would like to know how long we hold a particular record, ask us and we will tell you.
Who we share personal data with
We do not sell personal data, and we do not share it for other organisations' marketing. We do share it in these limited circumstances:
- Sub-processors and suppliers who help us deliver the service — for example data centre and connectivity providers, backup and monitoring platforms, email delivery, our support ticketing and CRM systems, and our accounting and payment providers. Each is bound by a written contract that restricts them to acting on our instructions and requires appropriate security.
- Domain registries and registrars, certificate authorities and licensors, where a service you have asked for requires it.
- Professional advisers such as our accountants, auditors, insurers and lawyers, where they need it to advise us.
- Law enforcement, regulators and courts, where we are legally required to disclose or where disclosure is necessary to protect our rights or the safety of others.
- A buyer or successor, if our business or the relevant part of it is reorganised, sold or transferred.
A current list of the sub-processors used to deliver your services is available on request, and is provided as part of the data processing terms in your service agreement. We will give customers advance notice of any intended change to that list so that objections can be raised.
Where personal data is held, and international transfers
Our hosting services are delivered from data centres in the United Kingdom, and we design our services so that customer data stays in the UK by default. Some of the business tools we use to run the company — for example email, ticketing or accounting platforms — may involve processing outside the UK.
Where personal data is transferred outside the UK, we make sure it is protected by an appropriate safeguard recognised under UK data protection law. That will normally be UK adequacy regulations for the destination country, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures the transfer risk assessment shows are needed. You can ask us for details of the safeguard used for a particular transfer.
How we protect personal data
We maintain technical and organisational measures appropriate to the risk, including access control on a least-privilege basis, multi-factor authentication for administrative access, encryption of data in transit and of backups, network filtering and hardening, patching on a defined cycle, monitoring and alerting, logging of administrative activity, staff training, and confidentiality obligations in our contracts of employment and supplier agreements.
No system can be made completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office within the statutory timescale, and we will notify affected customers without undue delay so that they can meet their own obligations.
Your rights
Under UK GDPR you have the following rights in relation to personal data we hold about you as controller. Some of them apply only in particular circumstances.
- Access — to be told whether we hold data about you and to receive a copy of it.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have data deleted where we no longer have a good reason to keep it.
- Restriction — to ask us to pause our use of data while a concern is resolved.
- Portability — to receive certain data in a structured, commonly used, machine-readable format, or to have it sent to another provider.
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Withdrawal of consent — where we rely on consent, to withdraw it at any time, without affecting processing already carried out.
- Automated decision-making — not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. We do not make decisions of this kind.
To exercise any of these rights, contact us using the details below. We will not charge you, and we will respond within one month. If your request is complex or you have made several requests we may extend that by up to two further months, and we will tell you if that happens. We may need to verify your identity before we act.
How to complain
If you are unhappy with how we have handled your personal data, please raise it with us first — we would rather put it right. Email hello@coffeecupsolutions.com or ring 0118 384 2175.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint or on 0303 123 1113. Complaining to us first does not affect that right.
Changes to this policy
We review this policy periodically and will update it when our practices change or the law requires it. The date at the top of this page shows when it was last updated. Where a change is significant and affects customers, we will tell them directly.
How to contact us
For any question about this policy or about how we handle personal data, including data protection requests, contact us at:
- Email: hello@coffeecupsolutions.com
- Telephone: 0118 384 2175
- Post: Coffee Cup Solutions Ltd, Unit 3, Millars Brook, Wokingham, Berkshire RG41 2AD, United Kingdom
We have not appointed a statutory Data Protection Officer, as we are not required to. Data protection questions are handled by our directors, who can be reached using the details above.