HostLuma ("HostLuma", "we", "us") provides hosting infrastructure and related services: Managed WordPress Hosting, AI App Hosting, and domain registration, delivered through our website and customer Portal at hostluma.co.uk. This policy explains what personal data we collect, why, and what rights you have over it.
We're a UK-based hosting provider and this policy is written to UK GDPR and the Data Protection Act 2018.
If you have questions, contact us at support@hostluma.co.uk.
When you create a Portal account, we store your email address, account status, and — for security purposes — the IP address and browser user agent recorded when the account was created and at each subsequent sign-in. We don't store a password: sign-in works by emailing you a one-time link, so there's no password on file to be breached or reused.
When you buy hosting, an AI App Hosting plan, or a domain, we store your email address, the product and billing cycle you chose, and identifiers from Stripe (session, customer, and subscription IDs) that let us reconcile your subscription. We do not receive or store your card number, expiry date, or CVC — Stripe's hosted Checkout collects that directly, and Stripe, not HostLuma, is responsible for securing it.
If you register or renew a domain through us, we pass your registrant details (name, email, address) to our registrar, Openprovider, who submits them to the relevant domain registry as required by ICANN/registry rules. Some registries publish parts of this data (WHOIS); where privacy/proxy registration is available for a TLD, we apply it by default.
If you connect a GitHub repository to deploy an app, we store your GitHub account identifier, the installation and repository identifiers you authorise, and the deployment metadata needed to build and serve your app (build status, preview domain, timestamps). We only access the repositories you explicitly grant us access to via GitHub's installation flow.
If you contact support, or if we run an internal audit or review of your account (for example, investigating a billing or abuse report), we keep a record of that request and its outcome.
If you join our affiliate program, we store your name, email address, and affiliate code so we can track and pay referral commissions. Click tracking on affiliate links records the referring page, UTM campaign parameters, and a salted, one-way hash of the visitor's IP address and browser user agent — not the raw IP or user agent — specifically so we can detect duplicate/fraudulent clicks without holding an identifiable visitor log.
If you subscribe to updates or request a free audit, we store your email address, optionally a business name, and where the sign-up came from, plus a token that lets you unsubscribe at any time without needing to log in.
Our servers keep operational logs (request logs, provisioning activity, security events) for troubleshooting and abuse prevention. These are retained for 14 days on a rolling basis and then automatically deleted.
| Purpose | Legal basis |
|---|---|
| Providing and provisioning the hosting/domain services you've purchased | Performance of a contract |
| Billing and payment processing | Performance of a contract; legal obligation (accounting/tax records) |
| Account security (sign-in logs, abuse detection) | Legitimate interests — keeping the platform secure |
| Domain registration with the registry | Legal obligation under registry rules; contract |
| Affiliate program administration | Contract (with the affiliate); legitimate interests (fraud prevention via hashed click data) |
| Newsletter emails | Consent — you can withdraw it at any time via the unsubscribe link |
| Responding to support requests | Contract / legitimate interests |
We share data only where it's necessary to run the service — never for advertising, and never sold. The specific companies involved are listed and kept current in our Subprocessor List; in summary, these cover payments (Stripe), domain registration (Openprovider), DNS (ClouDNS), content delivery (Bunny.net), source-code deployment (GitHub), certificates (Let's Encrypt), and the underlying servers themselves (OVH).
We may also disclose data where required by law, to enforce our Terms of Service or Acceptable Use Policy, or to protect the rights, property, or safety of HostLuma, our customers, or others.
Some of the subprocessors above operate outside the UK (notably GitHub and Let's Encrypt in the United States). Where we transfer personal data outside the UK, we rely on the UK's adequacy regulations or Standard Contractual Clauses / the UK International Data Transfer Addendum with the receiving party, as applicable.
The Portal sets one cookie, used only to keep you signed in. No analytics or advertising cookies are used anywhere on hostluma.co.uk. Full detail is in our Cookie Policy.
If an account is suspended — for non-payment after a grace period, or for a policy violation — we do not automatically delete your data or your hosted content. Suspension restricts access to the service; it does not destroy it. This is a deliberate design choice so that a billing hiccup or a paused account doesn't result in irreversible data loss. Data is only deleted following an explicit account closure or deletion request (see below), or after an extended period of confirmed non-payment in line with our published terms.
Under UK GDPR, you can ask us to:
To exercise any of these, email support@hostluma.co.uk. We'll respond within one month, as required by law. If you're unhappy with how we've handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk.
Hosting accounts run in isolated environments (CageFS) so one customer's account cannot read another's files or processes. Server-level malware and intrusion scanning (Imunify360) runs continuously. Connections to the Portal and to hosted sites use TLS certificates, issued and renewed automatically. We don't store passwords for Portal accounts at all, removing an entire class of credential-theft risk.
Our services are intended for businesses and individuals over the age of 18. We don't knowingly collect data from children.
We'll update the date at the top whenever this policy changes, and for material changes, we'll make reasonable efforts to notify active customers directly.
See also: Terms of ServiceCookie PolicyData Processing AgreementSubprocessor List

Real UK support with no outsourcing or ticket roulette. Get help with hosting, billing and WordPress support directly from the Host Luma team.
💬 Start WhatsApp Support → 💬 Open Live Chat ✉ support@hostluma.co.uk 💳 Customer Billing Portal© 2026 Host Luma. All rights reserved.