Privacy Policy
How we collect, use, and protect your personal data.
1. Data Controller
The data controller responsible for your personal data is:
- Bluix Group LTD
- Company No. 17097946 (England and Wales)
- 41 Devonshire Street, London W1G 7AJ, United Kingdom
- Email: privacy@bluix.net
- Phone: +44 7459 329416
2. Data We Collect
2.1 Information You Provide
- Account data: name, email address, postal address, phone number, company name
- Billing data: payment method details (processed by Stripe; we do not store full card numbers)
- Support data: information you provide in support tickets, live chat, or emails
- Domain registration data: registrant contact information required by ICANN
2.2 Information Collected Automatically
- Technical data: IP address, browser type, operating system, device type
- Usage data: pages visited, time spent, referral source, click patterns
- Cookie data: as described in our Cookie Policy
- Log data: server access logs, error logs for troubleshooting and security
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing and managing your services | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and billing | Performance of a contract (Art. 6(1)(b)) |
| Customer support | Performance of a contract (Art. 6(1)(b)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
| Service improvement and analytics | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) — opt-in only |
4. How We Use Your Data
- To create and manage your account
- To provision, maintain, and support your hosting and domain services
- To process payments and send invoices
- To communicate about your services (renewal reminders, service updates, outage notifications)
- To respond to support requests
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal obligations (e.g., tax records, law enforcement requests)
- To improve our services and website based on aggregated usage patterns
5. Data Sharing
We never sell your personal data to third parties.
We may share your data with:
- Payment processors (Stripe) — to process your payments securely
- Domain registrars (RealTimeRegister) — to register and manage domains as required by ICANN
- Infrastructure providers (Netcup, Contabo) — only to the extent necessary to provision servers
- Legal authorities — when required by law or to protect our rights
All third-party processors are bound by data processing agreements that ensure GDPR compliance.
6. Data Location and Transfers
Your data is primarily stored and processed in the European Economic Area (EEA). Our servers are located in Tier III+ European data centres.
Where data is transferred outside the EEA (e.g., to payment processors), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions.
7. Data Retention
We retain your personal data only for as long as necessary:
- Active account data: for the duration of your account
- Billing and invoice data: 7 years after the transaction (legal/tax requirement)
- Support tickets: 3 years after resolution
- Server logs: 90 days
- Deleted accounts: personal data is anonymised within 30 days of account deletion, except where retention is required by law
8. Your Rights
Under the UK GDPR and the Data Protection Act 2018, you have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure | Request deletion of your personal data ("right to be forgotten") |
| Restriction | Request that we limit how we use your data |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests |
| Withdraw Consent | Withdraw consent at any time where processing is based on consent |
To exercise any of these rights, email privacy@bluix.net. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- SSL/TLS encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Tier III+ European data centres with physical security
- Regular security audits and vulnerability assessments
- Access controls and authentication for all systems
- 24/7 infrastructure monitoring and intrusion detection
10. Children
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. We will notify active customers of material changes via email.
12. Contact
For any questions or requests regarding your personal data:
- privacy@bluix.net
- +44 7459 329416
- Bluix Group LTD, 41 Devonshire Street, London W1G 7AJ, UK
Last updated: March 2026. Bluix Group LTD, Company No. 17097946.