Legal
Privacy policy.
What we collect, why we collect it, how long we keep it and what you can ask us to do about it. Written to be read, not to be skipped.
1. Who we are
Echo Host Ltd (“we”, “us”) is the data controller for the personal data described in this policy. That means we decide what is collected and what happens to it, and we are the ones answerable for it. We are a company registered in England & Wales and we trade as Echo Host.
This policy covers the Echo Host website, the billing and client area, the game and web control panels we give you access to, and the support you receive from us. It explains how we handle your personal data under the UK GDPR and the Data Protection Act 2018.
It does not cover what your own users do on a server you rent from us. If you run a game server or a website on our platform and collect data from other people through it, you are the controller for that data and this policy does not speak for you.
The quickest way to reach us about anything on this page is support@echohost.co.uk.
2. What information we collect
We collect five kinds of information, and no more than we need for each.
Account details
Your name, email address, the username you choose, a phone number if you give us one, and the password you set. The password is stored as a hash, so nobody here can read it or tell you what it is — we can only help you reset it.
Billing details
Your billing address, your company name and VAT number if you are buying as a business, the invoices and receipts on your account, and a record of what you have bought and when it renews. We also see the card type and the last four digits so you can tell your payment methods apart.
We never see or store your full card number. Card details are entered directly with our payment provider, who is responsible for holding them. We only receive confirmation that a payment succeeded or failed, plus the reference needed to take the next renewal.
Technical and server data
The configuration of the services you rent: hostnames, ports, IP addresses allocated to you, plan and resource limits, the game or software you are running, and resource usage figures such as CPU, memory, storage and bandwidth. This is what tells us your service is healthy and correctly sized.
Support correspondence
The tickets and emails you send us, our replies, and any screenshots, log extracts or configuration files you attach. If you telephone us, we keep a written note of what was agreed. We do not record calls.
Server and access logs
Logs generated automatically as you use the platform: web server access logs, control panel and client area sign-in records, the actions taken in those panels, and connection logs from the services you run. These normally include an IP address, a timestamp and what was requested. IP addresses are personal data, which is why they are listed here.
3. Why we use it, and our lawful basis
Under the UK GDPR we need a lawful basis for each use of your data. Ours are set out below in plain terms.
- Setting up and running the services you ordered
- Performance of a contract. We cannot provision a server, give you panel access or keep it running without your account and service details.
- Taking payment, issuing invoices and chasing arrears
- Performance of a contract for the payment itself, and legal obligation for keeping the accounting records that UK tax law requires us to keep.
- Answering your support tickets
- Performance of a contract where the request is about a service you pay for, and our legitimate interest in helping people who write to us before they buy anything.
- Telling you about maintenance, incidents and changes to your service
- Legitimate interests. If a service you depend on is going to be interrupted, you need to know, and it would be perverse to make that optional.
- Keeping the platform secure, investigating abuse and preventing fraud
- Legitimate interests in protecting our network, our other customers and ourselves. This is why access logs exist and why we keep them for a while after the event.
- Meeting a legal or regulatory obligation, or responding to a lawful request
- Legal obligation. We only disclose what we are actually required to disclose, and we check that the request is valid before we act on it.
- Sending marketing email
- Consent, and only if you have opted in. We do not add customers to a marketing list automatically, and every marketing email has a working unsubscribe link. Withdrawing consent is easy and does not affect anything else on your account.
Where we rely on legitimate interests we have considered whether our interest is outweighed by your rights and freedoms. You can object to any of that processing — see your rights below.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
4. How long we keep it
We keep personal data for as long as it is doing a job, and then we get rid of it. In practice:
- Account details — for as long as your account is open, and for 12 months after you close it in case you come back or a query comes up. Then deleted.
- Invoices and accounting records — six years from the end of the accounting period they fall in, because UK tax law requires it. This is the one category we cannot delete on request.
- Support correspondence — two years after the ticket is closed, so we can see the history of a recurring problem.
- Server and access logs — up to 90 days in the normal course of things. Logs relating to an ongoing abuse or security investigation are kept until it is resolved.
- Server contents and backups — 14 days after a service ends, after which they are destroyed and cannot be recovered by us or by you. Take your data before then.
Where we are required to keep something longer — for example because of a legal claim or a live investigation — we keep only what is needed for that purpose.
5. Who we share it with
We do not sell your personal data, we do not rent it, and we do not share it with advertisers. We do not have advertisers.
A small number of suppliers process data on our behalf so that we can run the business. Each is bound by a written contract that limits them to acting on our instructions. They are, described by what they do rather than by name:
- Our payment provider — takes card payments, handles renewals and processes refunds and chargebacks.
- Our email provider — delivers account notices, invoices, support replies and service announcements.
- Our billing and support platform — holds your account record, invoices and tickets.
- Our network and DDoS mitigation providers — carry and filter the traffic going to your services, which necessarily means handling IP addresses.
- Domain registries and certificate authorities — where you ask us to register a domain or issue a certificate, the details required for that registration are passed on.
- Our accountants — see invoice records as part of preparing our accounts.
Beyond that, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or where we need to report abuse originating from a service on our network. If our business were ever sold or transferred, customer data would move with it and we would tell you before that happened.
6. Where your data is stored
Your data stays in the United Kingdom. Our servers sit in our own UK data centre, your services run on hardware we own, and your personal data is stored and processed here.
We do not transfer your personal data outside the UK. There is no offshore support desk, no overseas replica and no third-party cloud region holding a copy.
If that ever has to change, we will update this policy and put the safeguards required by UK data protection law in place before any transfer happens — not afterwards.
7. Cookies and local storage
This website sets no analytics cookies and no advertising cookies. There is no third-party tracking script on it, no advertising pixel, and nothing measuring you across other websites. That is also why you are not being asked to dismiss a cookie banner.
The site stores exactly one thing in your browser, using local storage rather than a cookie: an entry named eh:billing, holding the word “monthly” or “annual”. It exists so that if you switch the pricing tables to annual prices, they are still showing annual prices on the next page you open. It is never sent to our servers, it identifies nothing about you, and clearing your browser's site data removes it. If your browser blocks local storage, the site works exactly as before and simply forgets the setting.
Signing in is different. The client area and the game and web control panels are separate applications on their own subdomains, and they set a strictly necessary session cookie so that they can keep you logged in. Without it there is no way to stay signed in to an account. Those cookies do not track you and are not used for anything else.
8. How we protect your data
No host can promise perfect security, and you should be sceptical of any that does. What we can tell you is what we actually do:
- Traffic to this website, the client area and the panels is encrypted in transit with TLS.
- Passwords are stored hashed, never in plain text and never in a form we can reverse.
- Administrative access is limited to the staff who need it to do their job, and is logged.
- Infrastructure is patched on an ongoing basis and monitored around the clock.
Your side matters too: use a strong password you do not use anywhere else, turn on two-factor authentication where it is offered, and only give sub-user access to people you trust.
If a personal data breach happens and it is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the law requires us to.
9. Your rights
Under the UK GDPR you have the following rights over your personal data. They are free to use, and using one of them will never affect the service you receive.
- The right to be informed — to know what we do with your data. That is what this policy is for.
- The right of access — to get a copy of the personal data we hold about you.
- The right to rectification — to have inaccurate data corrected and incomplete data completed. Most of it you can edit yourself in the client area.
- The right to erasure — to have your data deleted where we no longer have a good reason to keep it. Accounting records are the usual exception.
- The right to restrict processing — to have us pause what we do with your data while a dispute or an accuracy question is sorted out.
- The right to data portability — to receive the data you gave us in a structured, commonly used, machine-readable format, or to have it sent to another provider.
- The right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time, which we will always honour.
- The right to withdraw consent — where we rely on consent, you can take it back at any time without affecting what was done beforehand.
- Rights around automated decisions — not to be subject to a decision based solely on automated processing that significantly affects you. We do not make decisions that way.
To use any of them, email support@echohost.co.uk from the address on your account and tell us what you want. We will reply within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you why within the first month. We may ask a question or two to confirm who you are — never more than we need to be sure.
10. Complaints and the ICO
If you are unhappy with how we have handled your personal data, please tell us first at support@echohost.co.uk. We would far rather fix it than have you take it elsewhere unresolved.
You do not have to come to us first, though, and you can complain to the UK's data protection regulator at any time. The Information Commissioner's Office can be reached at ico.org.uk/make-a-complaint or on 0303 123 1113. Complaining to the ICO costs nothing and does not affect any other right you have.
11. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we use your personal data — a new purpose, a new category of recipient, a longer retention period — we will email account holders before it takes effect rather than quietly editing the page.
12. How to contact us
For anything in this policy, including data subject requests, write to support@echohost.co.uk. We do not have a statutory obligation to appoint a Data Protection Officer, so your request goes to the people who run the platform and can actually act on it.
Our full registered company details, including our registered office address and company number, are available on request and appear on every invoice we issue.
Back to topThe rest of the small print.
Our Terms of Service set out the rules for using our services, and our Service Level Agreement sets out what we commit to on uptime and what happens if we miss it.