Privacy Policy
How we collect, use and protect your personal data, and the rights you have under UK data protection law.
SERVERSLOT LTD is committed to protecting and respecting your privacy. This Privacy Policy explains what personal data we collect when you visit our website or use our services, why we collect it, how we look after it and the rights you have under UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
SERVERSLOT LTD (“ServerSlot”, “we”, “us”, “our”) is the data controller for the personal data described in this policy. We are a company registered in England and Wales under company number 17062538, with our registered office at 58A Tudor Road, Hayes, England, UB3 2QD. You can contact us about privacy matters at info[@]serverslot.com.
2. Scope of this policy
This policy applies to personal data we process about:
- visitors to serverslot.com and our blog;
- customers and prospective customers who create an account, place an order or contact us;
- people who submit support tickets, abuse reports or other enquiries.
It does not cover the data that customers store or process on the servers they rent from us. That data is described in section 9.
3. Information we collect
We may collect the following information:
- Identity and contact details: full name, email address, phone number and billing address.
- Account data: account login data, such as your username, an encrypted form of your password, security settings and records of logins.
- Technical data: IP address, browser type, device information and the date and time of visits to our website and client area.
- Transaction data: payment transaction details, such as the services purchased, invoice amounts, payment method type, transaction references and payment status.
- Communications: the content of support tickets, emails and other messages you send us.
- Verification data: where an order is selected for verification, information or documents we request to confirm your identity or the legitimacy of a payment.
Most of this information is provided directly by you. Some technical data is collected automatically when you use our website, and some transaction data is provided to us by our payment processors.
4. How we use information
We use collected information to:
- provide and manage hosting services, including setting up servers and sending access details;
- process payments, issue invoices and manage renewals;
- respond to support inquiries and communicate with you about your account and services;
- prevent fraud and abuse, including payment verification and the investigation of abuse reports;
- maintain the security and performance of our website, client area and network;
- comply with legal obligations, such as accounting, tax and law-enforcement requirements.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review. Fraud screening may flag an order for manual checking, but a member of our team reviews the result.
5. Lawful bases
We rely on the following lawful bases under the UK GDPR:
- Contract: to provide the services you order and manage your account.
- Legal obligation: to keep financial records and respond to lawful requests from authorities.
- Legitimate interests: to prevent fraud and abuse, secure our systems, handle enquiries and improve our services, where these interests are not overridden by your rights.
- Consent: for optional cookies or marketing messages, where required. You can withdraw consent at any time.
6. Payment processing
Payments are securely processed through third-party providers, including:
- Stripe (card payments);
- PayPal;
- banks (bank transfers);
- cryptocurrency payment providers, where you choose to pay in cryptocurrency.
We do not store full credit or debit card details on our servers. Card data is entered into and handled by the payment provider, which acts under its own terms and privacy policy. We receive only limited information, such as the transaction status, amount and a partial card reference.
7. Data sharing
We do not sell personal data. Information may be shared with trusted service providers strictly for operational purposes, including:
- payment processors and banks;
- data centre and infrastructure partners, where needed to provision or support your service;
- providers of our billing, ticketing, email and website hosting systems;
- professional advisers such as accountants and lawyers.
These providers may only use the data to perform services for us. We may also disclose information where required by law, court order or a lawful request from a public authority, or where necessary to protect our rights, our customers or the public, for example in connection with fraud or abuse.
8. International transfers
Because we provide services in many countries and use international service providers, your personal data may be transferred to or accessed from countries outside the United Kingdom. Where this happens, we take steps to ensure the data receives an appropriate level of protection, for example by relying on UK adequacy regulations or on contractual safeguards recognised under UK data protection law.
9. Data on your servers
Our services are unmanaged. We do not monitor, access or use the content you store on your server in the normal course of business. You are the controller of any personal data you process on your server and are responsible for meeting your own legal obligations, including security and backups. We may need to access a server or its network traffic data where you ask us to, to resolve a technical fault, or to investigate a credible report of abuse or illegal activity.
10. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration or disclosure. These include encrypted connections to our website and client area, access controls limited to staff who need the information, and the use of reputable processors. No system is completely secure, so we encourage you to use a strong, unique password and to enable any additional login protection offered in the client area.
11. Data retention
Personal data is retained only as long as necessary for service provision and compliance with legal obligations. In general:
- account and contact details are kept while your account is active and for a reasonable period afterwards, so that we can deal with any queries;
- invoices and transaction records are kept for the period required by UK accounting and tax law;
- support tickets and abuse records are kept for as long as they are needed to provide support, resolve disputes or prevent repeated abuse;
- server data is deleted when a service is cancelled or terminated and is not kept by us after that point.
12. Cookies
Our website and client area use a small number of cookies and similar browser storage. When you first visit, a banner lets you choose Accept all or Essential only. You can change your choice at any time with the Cookie settings link in the footer.
- Essential (always on): the client area session and security cookies that keep you signed in and protect forms, the contents of your basket, your cookie choice (
ss_consent) and your light or dark display setting (ss_theme). These are kept for up to 12 months and do not track you across other sites. - Optional (only with Accept all): our live chat, provided by Tawk.to, which sets its own cookies to keep a conversation open between pages. If you choose Essential only, the chat is not loaded and you can still reach us through support tickets or email.
We do not use advertising cookies. You can also block or delete cookies in your browser settings, although parts of the client area will not work without the essential ones.
13. Your rights
Customers may request access, correction or deletion of their personal data by contacting us. To close your account and delete your data, follow the steps on our Delete Account page. Under UK data protection law you also have the right to:
- request a copy of your personal data;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data, subject to legal retention requirements;
- object to, or ask us to restrict, certain processing;
- receive data you provided to us in a portable format;
- withdraw consent where processing is based on consent.
We may need to verify your identity before acting on a request. We aim to respond within one month. If you are not satisfied with how we handle your personal data, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.
14. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in our services or in the law. The current version will always be published on this page with its effective date. Where changes are significant, we will take reasonable steps to let customers know.
15. Contact for questions about this policy
For privacy-related inquiries, or to exercise any of your rights, please contact us:
- Email: info[@]serverslot.com
- Support ticket: control.serverslot.com/submitticket.php
- Post: SERVERSLOT LTD, 58A Tudor Road, Hayes, England, UB3 2QD