HostPlex

  • Home
  • About Us
  • Pricing
  • Contact
  • Client Portal

Privacy Policy

Effective date: August 17, 2026  |  Last updated: August 17, 2026

This Privacy Policy explains how HostPlex (“HostPlex,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data in connection with hostplex.org, the Client Portal at clientportal.hostplex.org, our contact forms, billing and support operations, and the web hosting, server management, and server security services described in our Terms of Service and on our Pricing page. Please read it together with the Terms. By using our websites or Services, you acknowledge this Policy. If you do not agree, do not use the websites or Services.

This Policy is designed to be comprehensive. It distinguishes (a) personal data HostPlex collects as a business about customers, visitors, and inquiries, from (b) Content and end-user data that customers store on hosting or managed servers, for which the customer is typically the controller or “business” and HostPlex is a processor or “service provider.” Privacy requests about data inside a customer website should generally be directed to that customer first.

Contents

  1. Who we are
  2. Scope and roles
  3. Categories of personal data
  4. Website, cookies, and logs
  5. Contact form and sales inquiries
  6. Accounts, Client Portal, and billing
  7. Hosting plan data practices
  8. Server management data practices
  9. Server security data practices
  10. How we use data and legal bases
  11. Sharing, processors, and transfers
  12. Retention
  13. Security
  14. Your rights (GDPR and similar)
  15. United States state privacy laws
  16. Canada, UK, and other regions
  17. Children, marketing, and automated decisions
  18. Incidents, changes, and how to contact us

1. Who We Are

HostPlex is a hosting and infrastructure services business operated as described on our About page. We provide Budget and Premium web hosting, Server Management, Server Security, and custom packages. Our public website is hostplex.org. Customer account, billing, and many support functions are handled through the Client Portal.

For personal data we collect about visitors and customers to operate our own business (accounts, invoices, marketing of our own Services, website analytics we control), HostPlex is the data controller (or “business” under California law). For personal data that you or your end users upload into a hosting account, mailbox, database, or managed server, you are the controller (or “business”) and HostPlex is the processor (or “service provider”), except where we must process such data to protect our network, comply with law, or enforce the Terms.

Privacy, access, deletion, and similar requests about HostPlex-controlled data should be submitted through our contact page. We do not publish a staff mailbox on this website. Include enough detail for us to verify you and locate the records.

2. Scope and Roles

2.1 What this Policy covers

This Policy covers personal data processed in connection with:

  • Browsing hostplex.org and related marketing pages;
  • Submitting the public contact form (name, email address, business name, phone number, and message);
  • Creating and using a Client Portal account, ordering plans, invoicing, and support tickets;
  • Provisioning and operating Budget Web Hosting (Starter, Business, Enterprise) and Premium Web Hosting (Business Pro, Business Plus, Business Premium);
  • Delivering Server Management (Basic, Professional, Enterprise) and Server Security (Essential, Advanced, Enterprise);
  • Custom solutions, migrations, and professional services;
  • Security, fraud prevention, abuse handling, and legal compliance.

2.2 What this Policy does not make us responsible for

We are not responsible for privacy practices of third-party sites we link to, of payment networks, of your own privacy policy toward your end users, or of tools you install on a server (for example, analytics plugins on your CMS). If you embed third-party pixels on a hosted site, you are responsible for notices and consents those tools require.

2.3 Processor terms

When we act as processor, we process Customer Content only on documented instructions (the Terms, Order, and tickets you open), to provide the Services, and as required by law. You warrant that you have provided all notices and obtained all consents required for us to process end-user data, including for backups, logs, malware scanning, firewall inspection, and intrusion detection that your plan includes.

3. Categories of Personal Data We Process

Depending on how you interact with us, we may process the following categories. We do not require you to provide more than is needed for the relevant purpose, but if you withhold required account or billing data we may be unable to provide the Service.

3.1 Identity and contact data

Name, business or organization name, job title if you provide it, email address, phone number, postal or billing address, and portal usernames. Collected from you, from your colleagues whom you authorize, or from payment/identity checks.

3.2 Account and authentication data

Portal logins, hashed passwords, SSH keys you upload, two-factor secrets or tokens, session identifiers, support-pin or account numbers, and access logs. We do not store plaintext passwords when our systems hash them; you should still treat credentials as confidential.

3.3 Commercial and billing data

Plan selections, invoice history, payment status, tax identifiers you supply, last-four digits or tokenized payment-method references, and communications about charges. Full card numbers are typically handled by payment processors, not stored in our marketing website database.

3.4 Technical and usage data

IP addresses, browser type, device type, referring URLs, pages viewed, timestamps, approximate location derived from IP, cookie identifiers, error logs, and Client Portal clickstream needed to operate the product.

3.5 Hosting and infrastructure data

Hostnames, DNS records, allocated IP addresses, resource-usage metrics (disk, bandwidth, CPU), ticket contents, migration files, and backups of Customer Content for plans that include backups. This may include personal data of your end users if such data exists in your sites, databases, or mailboxes.

3.6 Security telemetry

Firewall logs, IDS/IPS alerts, vulnerability-scan results, malware-scan hits, DDoS traffic metadata, authentication failures, and abuse reports. Enterprise Security and Advanced Security generate more telemetry than Essential Security or hosting-only Advanced Security features.

3.7 Support and correspondence

Tickets, contact-form submissions, chat or call notes if those channels are used, and attachments you send. Please avoid sending government ID images or payment-card PAN unless we specifically request a secure method.

3.8 Sensitive data

We do not seek special-category data (health, biometrics, precise religion, etc.) to run a hosting account. If you host such data in your applications, you are responsible for lawful basis, DPIAs, BAAs, or other contracts. HostPlex hosting is not offered as a dedicated HIPAA, PCI Level 1, or government-classified environment unless a custom Order expressly says so.

4. Website, Cookies, Logs, and Similar Technologies

4.1 Server logs

Like most websites, our web servers automatically record requests: IP address, user-agent, date/time, requested path, referrer, and response codes. We use logs to operate, debug, secure, and measure the site. Logs are not used to build a public profile of you. Retention is limited to what we need for security and operations, then logs are deleted or aggregated.

4.2 Cookies and local storage

We may use:

  • Strictly necessary cookies — session, load-balancing, CSRF protection, and login state for the Client Portal;
  • Preference cookies — such as dismissing a notice, language, or UI state;
  • Analytics cookies — if we deploy first-party or privacy-respecting analytics to understand aggregate traffic (pages viewed, approximate geography, device class). We will not sell analytics identifiers as a standalone product;
  • Marketing cookies — only if we later enable them; we will update this Policy and, where required, request consent.

You can control cookies through your browser. Blocking necessary cookies may break login or checkout. “Do Not Track” signals are not uniformly defined; we do not currently alter this Policy solely because a DNT header is present, but we do not track you across unrelated third-party sites for a data-broker profile.

4.3 Fonts and third-party resources

Our public site may load web fonts from third-party font providers. Those providers may see your IP address when the font is fetched. We use them to display typography, not to sell your data.

4.4 Client Portal

The Portal is a logged-in application. It uses additional cookies and security headers. Portal activity is associated with your account and used to provide billing, product management, and support.

5. Contact Form and Sales Inquiries

When you submit the contact form on hostplex.org, we collect the fields you enter, which currently include name, email address, business name, phone number, and your message (reason for contact). We also receive technical metadata such as time of submission and IP address as recorded by our servers.

We use this information solely to evaluate and respond to your inquiry, prepare quotes, prevent spam and abuse, and keep a record of pre-contract correspondence. Submissions are delivered to our internal operations mailbox and are not published on the website. We do not sell contact-form leads to unrelated third-party advertisers.

If you include personal data about another person in the message, you must have authority to provide it. Do not submit passwords, full payment-card numbers, or special-category data through the public form.

Legal bases typically include taking steps at your request before entering a contract, our legitimate interests in responding to business inquiries and preventing abuse, and consent where a local law requires consent for that contact. You may object to further marketing follow-up; transactional replies about an existing request may still be necessary.

6. Accounts, Client Portal, and Billing

To purchase Starter, Business, Enterprise, Business Pro, Business Plus, Business Premium, Basic/Professional/Enterprise Management, Essential/Advanced/Enterprise Security, or a custom package, we process identity, contact, contract, and payment data. This is required to perform the contract, invoice, collect tax, prevent fraud, and provide support.

Payment card data is processed by payment processors and banks. We receive confirmation, tokens, or limited card metadata (for example, last four digits, expiry month/year, and failure codes), not necessarily the full PAN/CVV, depending on the processor integration. Those processors act as independent controllers or as processors under their terms; you should also read their privacy notices at checkout.

We may run automated fraud checks (velocity, mismatched billing country, known-bad instruments). Purely automated refusal that produces legal effects would be subject to applicable automated-decision rules; most fraud reviews can be re-examined if you contact us with additional verification.

Invoices, tax records, and transaction logs are kept for the periods required by tax, accounting, and anti-fraud law, which may exceed the life of the hosting account.

7. Hosting Plan Data Practices

This section explains how personal data is handled on each published web hosting line. Resource sizes (storage and bandwidth) are service allotments; they also affect how much Customer Content—and therefore potentially how much end-user personal data—can reside on the platform.

7.1 Common hosting processing

For all Budget and Premium hosting plans we process: account identifiers; provisioned hostnames and IPs; access logs; control-panel actions; SSL certificate requests (which include domain names and validation records); and abuse/security telemetry needed to protect multi-tenant infrastructure. Email stored on the account, databases, and website files are Customer Content. We access Customer Content when necessary to provision, back up (if included), restore at your request, mitigate abuse, scan for malware on plans that include that feature, or comply with law.

Standard SSL issuance shares domain-validation data with certificate authorities. Certificate transparency logs may publish issued hostnames. That is inherent to public CA issuance.

7.2 Budget Starter ($3.99 / month)

Starter includes 10 GB storage, 500 GB monthly bandwidth, standard SSL, and email support. We retain support tickets and platform logs. We do not operate a daily customer backup product on Starter; incidental infrastructure snapshots, if any, are for our disaster recovery of the node, are not a customer-facing archive, and may be overwritten without notice. Personal data in your 10 GB of files is processed only as needed to host the site and handle abuse. Lower storage does not mean weaker legal protection; it means less Content is stored with us.

7.3 Budget Business ($14.32 / month)

Business includes 50 GB storage, unmetered transfer under fair use, priority support, and daily backups with approximately seven days of retention. Backup copies are additional processing of whatever personal data exists in the backed-up files and databases. Restores duplicate that data onto the live account. Backup media may reside in the same facility or another facility we use. You should not treat seven-day backups as a legal hold. If you need longer retention for your own compliance, keep independent archives.

7.4 Budget Enterprise ($20.14 / month)

Enterprise hosting includes 200 GB storage, unmetered fair-use transfer, 24/7 priority support for platform outages, daily backups with approximately fourteen days of retention, and hosting-level Advanced Security. Malware scanning and baseline WAF features may inspect web files and HTTP requests, which can include personal data in URLs, form posts, or file contents. Inspection is for threat detection and platform protection, not for advertising. Fourteen-day backups increase the window during which deleted live data may still exist in backup sets.

7.5 Premium Business Pro ($12.69 / month)

Business Pro includes 100 GB storage, unmetered fair-use transfer, standard SSL, and priority support. Daily backups are not part of the default published feature list; therefore we do not represent a customer backup copy as a Privacy-Policy retention store for this plan. Content exists primarily on live storage until you delete it or the account is terminated. You remain responsible for your own copies.

7.6 Premium Business Plus ($19.42 / month)

Business Plus includes 350 GB storage, unmetered fair-use transfer, priority support, and daily backups with approximately seven-day retention. Larger disk means potentially larger volumes of end-user personal data (for example, media libraries or CRM exports you store on the site). Our role remains processor for that Content. Fair-use bandwidth monitoring looks at volume and patterns, not at reading every payload for marketing.

7.7 Premium Business Premium ($26.77 / month)

Business Premium includes 500 GB storage, unmetered fair-use transfer, 24/7 priority support for platform outages, daily backups with approximately fourteen-day retention, and hosting-level Advanced Security. File inspection for malware and WAF rules may process request and file data as described for Budget Enterprise. 24/7 support means outage tickets may be handled at any hour by on-call personnel who will see ticket contents you submit.

7.8 Your duties as a hosting customer

You must post an appropriate privacy notice to your end users, honor their rights where you are controller, configure your CMS, forms, and cookies lawfully, and not use the account to collect data unlawfully. If an end user contacts HostPlex about data on your site, we may redirect them to you and, where the request is valid and you fail to act, we may take limited technical steps required by law (for example, disabling a clearly unlawful page) without becoming the editor of your business.

8. Server Management Data Practices

Management services require privileged access. Logs, configurations, monitoring metrics, and sometimes file contents will be visible to technicians. You must ensure that granting us access is lawful vis-à-vis your employees and customers (for example, system-administration notices).

8.1 Basic Management ($99.99 / month)

We process availability and resource metrics, weekly patch records, ticket data, and monthly operational reports. Monitoring may include HTTP checks that hit a URL you specify (which should not be a URL that leaks secrets). Email-support correspondence is stored in our ticket system. We do not continuously watch every process. Backup management is not included; we therefore do not create a HostPlex-operated backup dataset unless you separately configure one and ask us to inspect it.

8.2 Professional Management ($199.99 / month)

We process 24/7 monitoring alerts, daily patch records, performance metrics, weekly reports, and backup-job status for targets we manage. Alerting may page on-call staff who will see hostnames, IPs, and error text. Backup management means we may read backup logs and, when restoring or verifying, subsets of backed-up data. Those copies follow the retention of the backup target you provide or that is included in the Order. Monitoring data is used to run the service, not to profile your end users for advertising.

8.3 Enterprise Management ($399.99 / month)

In addition to Professional processing, we maintain a closer operational runbook, daily reports, automated backup review, and custom configuration documentation. A designated support group will have ongoing access to the environment. Custom configurations and reports may contain personal data if it appears in system files you ask us to tune (for example, application config with database user names). Real-time patching may involve short-notice access at any hour. You should assume authorized HostPlex personnel can access the server at the OS level for the life of the subscription.

9. Server Security Data Practices

Security products exist to inspect, filter, and record potentially hostile or anomalous activity. That necessarily involves processing traffic metadata and sometimes payload or file content. You authorize this processing for in-scope systems.

9.1 Essential Security ($20.99 / month)

We process firewall rule sets, certificate metadata, records of security updates we apply or recommend, basic monitoring events, and monthly audit notes. Monthly audits may include open-port lists and patch-lag observations. Data volumes are lower than higher tiers. We do not operate a 24/7 SOC on this plan, so continuous security-event pipelines are limited.

9.2 Advanced Security ($35.99 / month)

We process advanced firewall logs, DDoS mitigation metadata (source IPs, packet rates, signatures), IDS/IPS alerts, 24/7 monitoring events, weekly audit artifacts, and vulnerability-scan results. Scan results can include discovered software versions, misconfigurations, and, if authenticated scanning is used, more detailed findings. Alerts may contain URLs, usernames, or file paths. 24/7 monitoring means events can be viewed by on-call personnel at any time. Vulnerability data is sensitive operational data; we treat it as confidential customer information.

9.3 Enterprise Security ($78.99 / month)

We process enterprise firewall policy, advanced DDoS telemetry, real-time IDS data, SOC case notes, daily audit exceptions, penetration-test reports, and compliance-support workpapers you ask us to help prepare. Penetration testing produces a report of vulnerabilities and sometimes proof-of-concept evidence; that report is confidential and shared with authorized customer contacts. SOC case notes may include personal data of attackers (IP addresses) and of your users if their accounts were involved. Compliance support may involve reviewing configurations that contain personal data. We do not become your auditor. Test data and reports are retained as operational records for a limited period and as needed for legal defense or repeat-test comparison.

You must ensure that pen-testing authorization covers all systems we are asked to test and that you have notified any co-tenants or cloud providers whose rules require notice.

10. How We Use Personal Data and Legal Bases

10.1 Purposes

We use personal data to:

  • Provide, provision, maintain, upgrade, and support the Services you order;
  • Create and secure accounts, authenticate users, and prevent unauthorized access;
  • Process payments, invoices, refunds, chargebacks, and tax filings;
  • Communicate about the Services, including operational notices, abuse, and policy updates;
  • Respond to contact-form and support requests;
  • Monitor resource use, enforce fair use, and plan capacity;
  • Detect, investigate, and mitigate security incidents, fraud, spam, and AUP violations;
  • Perform backups and restores where included in the plan;
  • Improve reliability, documentation, and product design using aggregated or de-identified insights where possible;
  • Comply with law, lawful process, and enforcement of the Terms;
  • Establish, exercise, or defend legal claims.

10.2 Legal bases (GDPR / UK GDPR style)

Where European or UK data-protection law applies, we rely on:

  • Contract — processing needed to deliver the plan you bought, bill you, and provide support;
  • Legitimate interests — securing our network, preventing abuse, improving the platform, limited B2B communications about similar services, and defending claims, balanced against your rights;
  • Legal obligation — tax, accounting, responding to valid legal process, and child-safety reporting;
  • Consent — where we use optional marketing cookies or send optional marketing that law treats as consent-based; you may withdraw consent without affecting prior lawful processing;
  • Vital interests — rarely, if needed to protect someone’s life in an emergency.

When we act as processor, the customer’s legal bases toward end users are the customer’s responsibility. Our processing is justified as necessary to provide the processor services and to protect the platform.

10.3 No sale of personal information for advertising networks

HostPlex does not sell personal information for money to data brokers. We do not permit Customer Content to be used to train public AI models as a product. If a future feature would involve a “sale” or “share” under California law (for example, certain advertising cookies), we will update this Policy and provide opt-out mechanisms required at that time.

11. Sharing, Processors, and International Transfers

11.1 Who we share with

We share personal data with:

  • Service providers / subprocessors — datacenter and cloud infrastructure, transit, DDoS mitigation, DNS, certificate authorities, payment processors, invoicing tools, ticket systems, email-delivery transactional mail, and professional advisors (lawyers, accountants) under confidentiality;
  • Personnel and approved specialists — employees and contractors who need access to perform management, security, or support, bound by confidentiality;
  • Successors — in a merger, acquisition, or asset sale, subject to this Policy or equivalent protection;
  • Authorities — when required by law, valid legal process, or to protect rights, safety, and the network;
  • Other parties at your direction — for example, a consultant you authorize in a ticket, or a registrar if we manage a domain.

We do not share Customer Content with unrelated marketers. Abuse reports to other providers (for example, to stop an attack) may include IPs, URLs, and sample headers.

11.2 International transfers

HostPlex and its infrastructure providers may process data in the United States and other countries. Those countries may have different data-protection laws than your home country. Where required, we use appropriate safeguards such as standard contractual clauses, vendor due diligence, and transfer assessments. By using the Services from abroad, you understand that your data may be transferred to the locations where we and our processors operate.

11.3 Combined services

If you buy hosting plus management plus security, data flows among those functions (for example, a SOC alert may be correlated with a management patch ticket). We still limit access to personnel who need it.

12. Retention

We keep personal data only as long as needed for the purposes above, including legal, tax, and dispute-hold periods. Typical periods (which may be longer if a hold applies):

  • Contact-form inquiries that do not become customers: generally up to 24 months after last meaningful contact, unless you ask us to delete sooner and no legal hold applies;
  • Customer account and billing records: life of the account plus at least seven years or the minimum required by tax law, whichever is longer;
  • Support tickets: generally up to seven years after closure for operational and legal history;
  • Website server logs: typically 30–180 days unless needed longer for security investigations;
  • Hosting live Content: until you delete it or the account is terminated and deletion jobs complete;
  • Daily backups (Business, Business Plus): approximately 7 days rolling;
  • Daily backups (Enterprise hosting, Business Premium): approximately 14 days rolling;
  • Management backup targets: according to the destination’s retention that you purchase or configure;
  • Security telemetry: typically 30–365 days depending on severity and tier, longer for incident files;
  • Penetration-test reports: generally the relationship term plus up to seven years for professional records.

When retention expires, we delete or irreversibly de-identify data, except residual copies in encrypted backups that rotate out on their own schedule. Starter and default Business Pro accounts should not assume a HostPlex backup copy survives after live deletion.

13. Security Measures

We implement administrative, technical, and physical measures appropriate to the nature of a hosting provider, including access control, hashed passwords where applicable, TLS for the public website and Portal where configured, network firewalling, least-privilege staff access, and monitoring. Higher Server Security tiers add more detection and review; they still cannot guarantee absolute security.

You must also secure your applications, end-user collections, and credentials. Transmission of data over the public Internet is never perfectly secure. You use the Services at your own risk as to residual insecurity, subject to the Terms.

If we become aware of a breach affecting HostPlex-controlled personal data, we will notify affected customers and regulators as required by law. If a breach is confined to Customer Content because of a vulnerability in your application, we will notify the customer account contacts so you can notify your end users as required.

14. Your Rights (GDPR, UK GDPR, and Similar)

If you are in the EEA, UK, Switzerland, or another region with similar rights, you may have the right to:

  • Access personal data we hold about you as controller;
  • Rectify inaccurate data;
  • Erase data in certain cases (the “right to be forgotten”), subject to legal retention;
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Data portability for data you provided to us, where processing is automated and based on contract or consent;
  • Withdraw consent where processing is consent-based;
  • Lodge a complaint with a supervisory authority in your country of residence, place of work, or place of alleged infringement;
  • Not be subject to a solely automated decision producing legal or similarly significant effects, except as allowed by law.

To exercise these rights for HostPlex-controlled data, use the contact page and specify the right you wish to exercise. We may need to verify your identity. We will respond within the statutory period (generally one month under GDPR, extendable as permitted). We may refuse requests that are unfounded, excessive, or that would infringe others’ rights.

If your request concerns data on a customer’s hosted website, we will typically ask you to contact that customer. We are not required to search all customer databases for your name except as law specifically demands.

15. United States State Privacy Laws

15.1 California (CCPA/CPRA)

If you are a California resident, you may have the right to know the categories and specific pieces of personal information we have collected, the sources, purposes, and categories of third parties to whom we disclose it; to delete personal information (with exceptions, including completing a transaction, security, free speech, and legal compliance); to correct inaccurate information; to opt out of sale or sharing of personal information for cross-context behavioral advertising if we engage in such activities; and to not be discriminated against for exercising these rights.

In the preceding 12 months we may have collected the categories listed in Section 3 (identifiers, commercial information, internet/electronic activity, professional information, and inferences limited to fraud/security). We collect them from you, your devices, payment partners, and security systems. We use them for the purposes in Section 10. We disclose them to service providers as described in Section 11. We do not sell personal information for money. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.

To submit a California request, use the contact page and state that it is a California privacy request. You may use an authorized agent with proof of authority. We will verify using account information or other reasonably necessary checks. Financial incentives are not currently offered; if that changes we will describe terms at that time.

15.2 Other US states

Residents of states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others may have rights to access, delete, correct, and opt out of targeted advertising, sale, or certain profiling. We will honor applicable state laws. Because we are a B2B hosting provider and do not operate a consumer data marketplace, many “sale” and “targeted advertising” opt-outs will have limited practical effect beyond optional cookies we may add later. Appeals of a denied request may be submitted through the same contact page with the word “appeal.”

15.3 Nevada

Nevada residents may opt out of the sale of covered information under Nevada law by contacting us. We do not currently sell covered information as defined in that statute.

16. Canada, United Kingdom, and Other Regions

For individuals in Canada, we process personal information in accordance with applicable federal and provincial laws (including PIPEDA where it applies). We collect information for the purposes identified in this Policy. You may request access and correction through the contact page. We may process information in the United States or other countries with comparable contractual protections for service providers.

UK users have rights under UK GDPR and the Data Protection Act 2018 similar to those in Section 14, and may complain to the ICO. Users in Australia, New Zealand, Singapore, Brazil (LGPD), South Africa (POPIA), and other jurisdictions may have additional rights; we will apply this Policy and local mandatory law. Where local law requires a local representative or additional notice, we will provide it if we become established or targeted in a way that triggers that duty.

If you access the Services from a country that restricts cross-border hosting, you are responsible for determining that use of HostPlex is lawful for your Content.

17. Children, Marketing, Automated Decisions, and Other Notices

17.1 Children

Our Services are directed to adults and businesses. We do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies) as customers. If you believe a child has provided us account data, contact us and we will delete it. Customer websites may have their own audiences; those operators must comply with children’s privacy laws for their own collection. Hosting a site directed at children does not make HostPlex the operator of that site for COPPA purposes, except as a service provider storing Content.

17.2 Marketing communications

We may send service messages (invoices, abuse, downtime, Terms updates) regardless of marketing preference because they are part of the contract. Optional product news may be sent to business contacts based on legitimate interests or consent. You can opt out of optional marketing via the contact page or any unsubscribe method we provide. Opting out of marketing does not opt you out of billing or security notices.

17.3 Automated processing

We use automated tools for spam filtering on the contact form, fraud scoring on payments, malware signatures, IDS, and resource throttling. These tools can affect whether a message is delivered, a payment is accepted, or a site is temporarily limited. They are not used to produce a consumer credit-style profile for sale. You may contact us to request human review of a blocking decision that significantly affects you as a customer.

17.4 Employment applicants

If you apply for a role, we process resume and contact data to evaluate candidacy, based on contract steps and legitimate interests. Applicant data is retained for the hiring process and a limited period afterward for legal defense, then deleted or reduced.

17.5 Record of processing

We maintain internal records of our processing activities as required for an organization of our type, including purposes, categories of data, recipients, and retention outlines consistent with this Policy.

18. Incidents, Changes, and Contact

18.1 Data incidents

Please report suspected privacy or security incidents involving HostPlex systems through the contact page with “Security” or “Privacy” in the message. Do not attach exploit code. We may request additional verification before discussing account-specific facts.

18.2 Changes to this Policy

We may update this Privacy Policy to reflect new plans, laws, or practices. The “Last updated” date at the top will change. Material changes will be posted on this page and, where appropriate, noticed through the Client Portal or account contacts. Continued use after the effective date constitutes acknowledgment. If a change requires consent under applicable law, we will request it.

18.3 Relationship to the Terms

This Policy does not create warranties beyond the Terms of Service. Limitation of liability, indemnity, and dispute provisions in the Terms apply to privacy claims to the extent permitted by law. Mandatory data-protection rights that cannot be waived remain available.

18.4 How to contact us

For privacy questions, access or deletion requests, California or GDPR requests, authorized-agent submissions, and related correspondence, use our contact page. Provide your name, the email used on the account if any, a description of the request, and the applicable jurisdiction. We will not require you to create a paid account solely to submit a consumer rights request, but we will verify identity to a reasonable degree of certainty.

If we cannot resolve your concern, you may contact your local data-protection authority or, in California, the California Privacy Protection Agency or Attorney General, as applicable.

HostPlex

Premium hosting and web solutions for businesses worldwide.

Quick Links

  • Home
  • About Us
  • Pricing
  • Contact
  • Terms of Service
  • Privacy Policy

Services

  • Web Hosting
  • Server Management
  • Server Security

Contact

Get in touch

© 2026 HostPlex. All rights reserved.