Data Security Statement
Revised August 19, 2026
Scope
The security page covers what defends the websites we run. This is the less exciting companion: the personal data sitting behind the accounts — yours and your customers' — and the measures Article 32 of the UK GDPR expects of us.
1. Encryption
Everything on this site and in the client area travels over TLS, with Strict Transport Security set so browsers refuse to downgrade. Certificates renew themselves; an expiry is an outage nobody should be having in 2026.
Passwords are salted and hashed, so support cannot read yours back and neither can we — a reset is the only path, and that is why no one from this company will ever ask you for one. Card numbers never arrive on our systems at all: the payment provider holds them and we keep a token plus the last four digits.
2. Access
Systems holding personal data are opened to named individuals on the basis of need, and closed when the need ends. Administrative access carries two-factor authentication. Nobody uses a shared login, because an action that cannot be traced to a person cannot be answered for by one.
Support can see your account, your services and your tickets. Reading through your files or your database is not routine, and where a request genuinely needs it, it happens with your knowledge and for that request alone.
3. Isolation, patching, resilience
Accounts sharing a machine are walled off from one another, so one site being breached is not five hundred sites being breached. Platform software is kept current, malware scanning runs continuously, and a web application firewall with network-level attack mitigation sits in front of everything.
Daily copies are taken and you can restore them yourself. They remain a convenience rather than a warranty — the service level agreement says plainly that it pays out on availability and never on lost data.
4. Location and suppliers
Hosting hardware is in the United Kingdom. Personal data is handled in the UK and the EEA, and any supplier operating beyond that is covered by the safeguards named in the privacy policy, which also lists who those suppliers are.
Suppliers are reviewed before being adopted and are held to written terms at least as strong as the ones we owe you. Where we process on your behalf, the data processing addendum governs it.
5. Retention
Full periods live in the privacy policy. Broadly: account and billing records last the life of the account plus six years because tax law says so; tickets three years; raw server logs a few weeks.
Cancel a service and its data leaves live systems on schedule, then ages out of backups. We do not surgically edit backups to satisfy a deletion request — doing that destroys the integrity of the backup — so they are allowed to expire instead, with the data unavailable for use throughout.
6. The breach clock
A personal data breach that is likely to put people at risk goes to the Information Commissioner's Office inside 72 hours of us becoming aware. Where the risk to individuals is high, they hear from us directly and quickly.
Where the data is yours and we merely process it, you are told without undue delay, because your own 72-hour duty as controller starts running whether or not anyone has told you it has.
We would sooner report something that turns out to be nothing than sit on something while deciding how it will look.
7. Reporting a weakness
Found a hole? info@hostingfastnet.com, before it goes anywhere else, with a fair window to fix it. The same contact is published machine-readably at /.well-known/security.txt.
Test against your own account only, leave other people's data alone, and do not run denial-of-service experiments. Research inside those lines is welcome and we will not come after you for it.
8. Your half
None of this updates your plugins, invents good passwords or removes the contractor who still has your FTP details. Those obligations sit in the acceptable use policy, and they account for most of the compromises we actually see.
9. The company
HostingFast is a trading name of Vitalcare at Home Ltd, a company registered in England and Wales under Company No. 15098204. Registered office: Office 4648, 221–323 High Road, Chadwell Heath, Romford, England, RM6 6AX. Security contact: info@hostingfastnet.com.