Effective date: 29th August 2026 | Last reviewed: 29th August 2026
1. Who we are and what this notice covers
1.1 Smudge Limited is a company registered in Guernsey under company number 57266, whose registered office is at Rivendell, 9 La Neuve Rue Estate, St Peter Port, Guernsey, GY1 1SF. We trade as Smudge Hosting and provide website hosting and domain name registration services.
1.2 This notice explains what personal data we collect, why we use it, who we share it with, how long we keep it, and what rights you have. It covers visitors to smudgehosting.com, people who register an account with us, and our customers and their staff.
1.3 We are the data controller for the personal data described in this notice. If you have any questions about it, or want to exercise any of your rights, contact us at support@smudgehosting.com.
2. Which data protection law applies to us
2.1 We are established in the Bailiwick of Guernsey, so our processing of personal data is governed by the Data Protection (Bailiwick of Guernsey) Law, 2017. Our supervisory authority is the Office of the Data Protection Authority (the “ODPA”), and we are registered with it under registration number 01161195.
2.2 Guernsey has been recognised as providing an adequate level of data protection by the European Commission, and is treated as adequate for the purposes of United Kingdom data protection law. This means personal data can flow to us from the UK and the European Economic Area without any additional transfer safeguards being needed.
2.3 Where the UK GDPR or the EU GDPR applies to a particular activity — for example because we are offering services to people in the United Kingdom or the European Union — we comply with the applicable requirements of that legislation as well.
3. When we are responsible for data, and when your provider is
3.1 Data we control. When you register an account, buy a service, contact our support team or browse our website, we decide how that information is used. We are the controller of it, and this notice describes what we do with it.
3.2 Data our customers control. Our customers use our hosting to run their own websites, applications and email. Any personal data they store on our servers — for example their own customers’ details — belongs to them. They decide what is collected and why; we simply host it on their instructions. For that data we act as a processor, not a controller, and our obligations are set out in Schedule 1 (Data Processing Terms) of our Terms of Service, not in this notice.
3.3 This matters if you are an individual whose data sits on a website we host. We are not the right people to ask — we have no right to access, correct or delete that data on our own initiative. Please contact the operator of that website directly. If you contact us, we will tell our customer promptly and point you to them, but we cannot act on your request ourselves.
4. The personal data we collect
|
Category |
What it includes |
Where it comes from |
|
Account data |
Name, business name, email address, postal address, telephone number, username and password (stored hashed). |
You, when you register or update your account. |
|
Order and billing data |
Services purchased, invoices, payment records, billing address, and the last four digits and expiry of your payment card. We do not store full card numbers. |
You and our payment processor. |
|
Support data |
Support tickets and live chat transcripts, and any information you choose to include in them. |
You, when you contact us. |
|
Technical data |
IP address, browser type and version, operating system, and server and access logs generated when you use our website or control panel. |
Collected automatically. |
|
Usage data |
Which services you use, resource consumption, and login activity. |
Collected automatically. |
|
Marketing data |
Your preferences about receiving marketing from us, and whether you have opted out. |
You. |
|
Domain data |
The registrant details you provide for a domain name registration, which registries may publish or hold. |
You. |
4.1 We do not deliberately collect special category data (such as data about health, race, religion or political opinions) about our customers, and you should not send it to us in a support ticket.
4.2 Our services are not offered to children, and we do not knowingly collect personal data about anyone under 18.
5. Why we use your data, and our lawful basis
|
Purpose |
Data used |
Lawful basis |
|
Setting up your account and providing the services you have ordered |
Account, order, technical |
Performance of our contract with you |
|
Taking payment and chasing unpaid invoices |
Order and billing |
Performance of our contract; legitimate interests in recovering money owed |
|
Providing support and responding to your questions |
Support, account, technical |
Performance of our contract |
|
Sending service messages — billing, maintenance, security and changes to our terms |
Account |
Performance of our contract; legal obligation |
|
Keeping our platform secure, investigating abuse and preventing fraud |
Technical, usage |
Legitimate interests in protecting our infrastructure and our other customers |
|
Registering and renewing domain names on your behalf |
Domain, account |
Performance of our contract |
|
Sending marketing about our own similar services |
Marketing, account |
Legitimate interests, subject to your right to opt out at any time |
|
Keeping accounting records and meeting our legal and tax obligations |
Order and billing |
Legal obligation |
|
Establishing, exercising or defending legal claims |
Any of the above |
Legitimate interests in protecting our legal position |
5.1 Where we rely on legitimate interests, we have considered whether our interest is overridden by your interests and rights. You can ask us for details of that assessment, and you have the right to object — see section 11.
6. Cookies and similar technologies
6.1 Our website uses cookies and similar technologies. Some are strictly necessary for the site and control panel to work — for example to keep you logged in and to protect against cross-site request forgery. These are always set.
6.2 Other cookies help us understand how the site is used, or remember your display preferences. Under the Privacy and Electronic Communications Regulations as amended by the Data (Use and Access) Act 2025, we are not required to obtain your consent for purely statistical or appearance cookies, but you can opt out of them at any time using the cookie controls on our website.
6.3 Any cookie used for advertising or cross-site tracking is only set with your consent, which you can withdraw at any time.
7. Marketing
7.1 If you buy services from us, we may send you occasional information by email about our own similar products and services. You can opt out when you register, and in every message we send, using the unsubscribe link or by raising a support ticket.
7.2 Opting out of marketing does not stop service messages. We will still email you about billing, planned maintenance, security matters and changes to our terms, because those are part of providing the service and you cannot opt out of them while you hold an account with us.
7.3 We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
8. Who we share your data with
8.1 We share personal data with the following categories of recipient, each of which acts on our instructions unless stated otherwise:
(a) 20i Ltd (England and Wales), which provides the hosting infrastructure and platform on which our services run, and which processes data in datacentres in the United Kingdom and the European Economic Area. 20i in turn uses Stripe for payment processing, Nominet and Tucows/OpenSRS for domain names, GeoTrust/Symantec for TLS certificates, Google Analytics for control panel analytics, and Xero for accounting.
(b) Domain name registries and registrars, where you ask us to register or renew a domain name. Registries act as controllers in their own right and may publish or hold registrant details in accordance with their own rules and the applicable WHOIS policy.
(c) Our payment processor, which handles card payments and holds the card details we never see. Stripe: https://stripe.com/privacy
(d) Our billing, email and business systems. (20i, Microsoft & Google)
(e) Professional advisers — our accountants, auditors, insurers and lawyers, where they need the information to advise us.
(f) Law enforcement, regulators and courts, where we are legally required to disclose information, or where disclosure is necessary to establish, exercise or defend legal claims.
8.2 If our business is sold or transferred, personal data may be transferred to the buyer. We will tell you before that happens and explain what it means for you.
8.3 We impose contractual obligations on every processor we use, requiring them to keep personal data secure and to use it only for the purposes we specify.
9. Where your data is stored
9.1 Personal data we hold is stored in the Bailiwick of Guernsey, the United Kingdom and the European Economic Area.
9.2 Where a provider we use processes data outside those areas, we make sure an appropriate safeguard is in place — an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism. You can ask us which safeguard applies to a particular transfer.
10. How long we keep it
|
What |
How long |
Why |
|
Your websites and other hosted material |
Deleted from live systems on cancellation |
It is your data and you have asked us to stop holding it |
|
Backups of hosted material |
Recoverable for 30 days after cancellation, then permanently deleted |
So an accidental cancellation can be reversed |
|
Account records |
1 year after cancellation of all your services |
To deal with questions and disputes arising shortly after you leave |
|
Accounting records, including invoices and payment records |
6 years |
Required by section 239 of the Companies (Guernsey) Law, 2008 and by tax legislation |
|
Support tickets and chat transcripts |
2 years |
To maintain a service history and resolve recurring problems |
|
Server and access logs |
90 days |
Security, abuse investigation and troubleshooting |
|
Marketing preferences and opt-outs |
Indefinitely |
So we do not contact you again after you have asked us not to |
10.1 Where we are required by law to keep information for longer than the periods above, we will do so, and we will use it only for the purpose that requires us to keep it.
11. Your rights
11.1 You have the following rights in relation to your personal data:
(a) Access — to be told whether we hold data about you and to receive a copy of it.
(b) Rectification — to have inaccurate data corrected and incomplete data completed.
(c) Erasure — to have data deleted, where we no longer have a good reason to keep it.
(d) Restriction — to ask us to stop using data while a question about it is resolved.
(e) Portability — to receive data you gave us in a structured, commonly used and machine-readable format, and to have it sent to another provider where technically feasible.
(f) Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time, which we will always honour.
(g) Withdrawal of consent — where we rely on consent, to withdraw it at any time, without affecting anything we did beforehand.
11.2 To exercise any of these rights, contact us at support@smudgehosting.com. We will respond within one month. If your request is complex we may extend that by up to two further months, and we will tell you within the first month if we need to.
11.3 We do not charge for handling a request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, and we will explain why.
11.4 We may need to confirm your identity before acting on a request, to make sure we do not disclose your data to somebody else.
12. How to complain
12.1 Please come to us first. If you are unhappy with how we have handled your personal data, contact us at support@smudgehosting.com. We will acknowledge your complaint within 30 days and work to resolve it without undue delay, keeping you informed as we go.
12.2 If you are not satisfied with our response, you can complain to our supervisory authority, the Office of the Data Protection Authority in Guernsey. Its contact details and complaints procedure are at odpa.gg.
12.3 If you are in the United Kingdom and the UK GDPR applies to the processing you are complaining about, you may also complain to the Information Commissioner’s Office at ico.org.uk. If you are in the European Economic Area, you may complain to the supervisory authority in your country.
12.4 Complaining to a supervisory authority does not affect any other legal remedy you may have.
13. Automated decision-making
13.1 We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. Automated checks are used in fraud prevention and payment authorisation, but a person reviews the outcome before we refuse or suspend a service on that basis.
14. How we keep data secure
14.1 We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. These include encrypted connections, access controls limited to named individuals using multi-factor authentication, logging of administrative access, and confidentiality obligations on anyone who handles personal data.
14.2 The infrastructure our services run on is operated by 20i Ltd, which maintains its own security measures. A description is available from us on request.
14.3 No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ODPA and, where the risk is high, tell you directly and explain what you should do.
15. Changes to this notice
15.1 We keep this notice under review. Where we make a material change, we will update the version number and effective date above, publish the revised notice on our website, and tell you by email if the change materially affects how we use your data.
15.2 Previous versions are available from us on request.
16. How to contact us
Smudge Limited (trading as Smudge Hosting)
Rivendell, 9 La Neuve Rue Estate, St Peter Port, Guernsey, GY1 1SF
Registered in Guernsey no. 57266
Privacy enquiries: support@smudgehosting.com
ODPA registration number: 01161195
This notice should be read alongside our Terms of Service. Where we process personal data on a customer’s behalf, Schedule 1 of those Terms applies.